Guest Article: 8 Mistakes to Avoid when Securing Cloud Services

There’s solid demand these days for services like DropBox.com or Box.net that allow easy but secure file sharing to occur with proper privacy restrictions and audit tracking. I was pleasantly surprised to learn that there are a few companies, such as FolderGrid, trying to solve the problem of HIPAA-compliant file sharing. What FolderGrid is doing, though, is quite unique in healthcare – creating infrastructure software for other health IT developers to build on top of.

A new NIST new guide The Common Misuse Scoring System (CMSS): Metrics for Software Feature Misuse Vulnerabilities, (NISTIR 7864) is available for download. In the health IT and medical device security world we’re often wondering how to classify vulnerabilities so that we can appropriately prioritize them and ensure they get corrected. Here’s how NIST describes their new guide (copied from their website, emphasis is mine): A new guide from the National Institute of Standards and Technology (NIST) describes a “scoring system” that computer security managers can use to assess the severity of security risks arising from software features that, while beneficial to accomplishing a task, are at least partially designed under an assumption that users are operating these features as intended.

The fiscal challenges confronting the healthcare industry around the world requires shifting the delivery of care from expensive centralized settings to lower cost settings while seeking to improve quality and patient experience. Organizations such as hospitals, Integrated Delivery Networks (IDNs) and newly created Accountable Care Organizations (ACOs) are trying to find the right mix of technology, facilities, clinical personnel, and information sharing to address these issues. Telehealth and “connected care” experiments have shown that many types of expensive care that had been, in the past, reserved for office visits or hospital attendance can easily be done in the home or a lower cost setting.

Most health IT interoperability and connectivity discussions these days center around HL7, CCD, and other structured data interchange. However, the vast majority of data (in terms of size) is shared as images and documents. The DICOM and PACS standards are very successful but given the number of questions I get about them from readers it seems there’s still a lot of guidance and support needed. To help answer some of the most common technical questions, I reached out to a fellow health IT expert, Herman Oosterwijk from OTech.

There are very few “no brainers” in hospital technology purchases – most of the decisions about what to buy and how to implement what we buy are complex. However, one decision is pretty easy – you have to put in asset management and tracking solutions for obvious reasons. But, how do you make sure that you can achieve a meaningful ROI on your purchase? I reached out to Marcus Ruark, Vice President at Intelligent InSites, and a seasoned technology executive with a deep understanding of healthcare operations and business processes to help answer that question.

Most health IT interoperability and connectivity discussions these days center around HL7, CCD, and other structured data interchange. However, the vast majority of data (in terms of size) is shared as images and documents. The DICOM and PACS standards are very successful but given the number of questions I get about them from readers it seems there’s still a lot of guidance and support needed. To help answer some of the most common technical questions, I reached out to a fellow health IT expert, Herman Oosterwijk from OTech.

The Department of Defense (DoD) recently released their mobile device strategy that talks about how to enable the use of mobile devices in defense applications. The DoD ‘s requirements around security and reliability for mobile apps and devices are just as stringent as those that should be implemented in healthcare so there’s probably a lot for CIOs and CTOs to take from it. The DoD Mobile Device Strategy focuses on “improving three areas critical to mobility: wireless infrastructure, mobile devices, and mobile applications, and works to ensure these areas remain reliable, secure and flexible enough to keep up with fast-changing technology.

The nice folks at HealthAdministrationDegrees.com recently interviewed me about my thoughts on healthcare IT and how to get jobs in the industry. The following questions came up: How did you get started blogging, and what was the goal behind your blog the Healthcare IT Guy? How can someone get started working in healthcare IT? How important is it to have a medical or healthcare background in addition to an IT background?

Today’s reality of patient management is “disjointed care” and most of the collaborators in a patient’s care team don’t know what each other is doing for the patient in real time. Knowing all the different participants in the patient’s care team (providers, payers, family members, etc.) and coordinating and integrating their electronic activities is what successful EHRs must handle with ease as they look to graduate from basic retrospective documentation systems to modern patient collaboration platforms.

Medigy Innovation Network

Connecting innovation decision makers to authoritative information, institutions, people and insights.

Medigy Logo

The latest News, Insights & Events

Medigy accurately delivers healthcare and technology information, news and insight from around the world.

The best products, services & solutions

Medigy surfaces the world's best crowdsourced health tech offerings with social interactions and peer reviews.


© 2023 Netspective Media LLC. All Rights Reserved.

Built on Jan 17, 2023 at 9:26am