Implications of Data Loss Prevention Software in Healthcare IT

Posted by skyhighnetworks on July 4th, 2014

Data Loss Prevention software helps healthcare organizations ensure proper levels of compliance with regulations such as HIPAA security, PCI, Joint Commission, and state privacy regulations. According to Douglass Associates analyst, Roger Chen, “Leveraging data loss prevention software in the 21st century is an absolutely crucial tool for  a healthcare IT organizations”.

Furthermore, Under the HITECH Act, implementing Data Loss Prevention meets the optimal usage criteria, allowing healthcare organizations to receive maximum reimbursement by providing controls to protect electronic health records. According to Heather Roszowski, chief information security officer of Fletcher Allen Healthcare,  “healthcare data security is a multifaceted, ever-shifting challenge, and requires simply one cue to allow entrance for an expensive security breach.” As just one missed sign can lead to a security disaster, leading to potential millions in settlement money claims, its curcial to be in the “pursuit of 100 percent”, states Roszkowski, who compares the sense of urgency required to be similar to the military approach to data security.

The most valuable technology that has helped Fletcher Allen, is data loss prevention software. Data loss prevention software is unique, as it can discover possible security vulnerabilities, and can also block confidential data when it is under wrongful utilization.

Recently, Fletcher Allen avoided a potential company disaster thanks to data loss prevention software. This case involved a nurse attempting to send 9000 patient records via Yahoo email. While in actuality, this nurse had legitimately positive intentions – she intended to work from home, as many people do.  Fortunately, the DLP software noticed this anamoly, and blocked the transfer from completing.

As DLP software is employed across an organization, it “discovers and indexes where all your sensitive information is,” states McMillian. “Then, based on the rules that you specify, in terms of where it can live, where it can go, how it has to be transmitted, what devices it can go on, etc.”

“Even well-intentioned users will break the rules occasionally, not meaning to. Unless you have the right technological controls in your architecture to help protect against those things, you can have all the policies and procedures in the world, and it ain't gonna save you."  Furthermore, a 9000 sensitive health record breach could result in millions in lawsuits and government fines, and mar the company image forever. "That incident alone, had it happened, would have (cost as much) as their DLP solution three times over, easily," says McMillan.

In summary, its crucial for healthcare information technology professionals to employ data loss prevention software solutions to prevent data catastrophes. Furthermore, in the United States of America, data loss prevention software meets operational use criteria as defined by the HITECH act, which means healthcare enterprises can receive the maximum amount of reimbursement by implementing systems to protect electronic health records. Organizations who fail to comply with government regulations and refuse to secure their highly sensitive data with data loss prevention security put themselves at severe risk in this era of ever evolving, resilient hackers and cybercriminals. Therefore, its in healthcare organizations best interest to embrace the cloud and employ security functions such as data loss prevention for best security & efficiency measures.


Author :
Skyhigh Networks, the Cloud Security Services company, enables companies to embrace Cloud Security Services with appropriate levels of security, compliance, and governance while lowering overall risk and cost. With customers in financial services, healthcare, high technology, media, manufacturing, and legal verticals, the company was a finalist for the RSA Conference 2013 Most Innovative Company award and was recently named a "Cool Vendor" by Gartner, Inc. Headquartered in Cupertino, Calif., Skyhigh Networks is led by an experienced team and is venture-backed by Greylock Partners and Sequoia Capital. For more information, visit us at http://www.skyhighnetworks.com/cloud-data-loss-prevention/ or follow us on Twitter@skyhighnetworks.

Like it? Share it!


skyhighnetworks

About the Author

skyhighnetworks
Joined: December 18th, 2013
Articles Posted: 85

More by this author