<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-4384692836709903146.post9050335274259919710..comments</id><updated>2009-10-13T06:31:12.780-07:00</updated><title type='text'>Comments on Life as a Healthcare CIO: My Privacy and Security lessons learned</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://geekdoctor.blogspot.com/feeds/9050335274259919710/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default'/><link rel='alternate' type='text/html' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html'/><author><name>John Halamka</name><uri>http://www.blogger.com/profile/04550236129132159307</uri><email>jhalamka@caregroup.harvard.edu</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>8</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4384692836709903146.post-4494892276419241682</id><published>2009-10-08T09:46:37.275-07:00</published><updated>2009-10-08T09:46:37.275-07:00</updated><title type='text'>John, your post mentions privacy but essentially f...</title><content type='html'>John, your post mentions privacy but essentially focuses on security alone. This is understandable given that we know a lot more about security, both technically and functionally, then we do about privacy. No question that the two are hand in glove, but they do present different challenges and a different focus. In my eyes privacy (I&amp;#39;m thinking of confidentiality as the same thing) is about data consent and representation of preferences. Preferences are defined by multiple parties, governmental, organizational and consumer. A reconciled final consent is then operationalized via security systems. &lt;br /&gt;&lt;br /&gt;What is still unclear is how we will translate what may be complicated consent preferences into enforceable security policies. I suspect this will take some time to work through because the kinds of preferences we often hear (perhaps with some regulatory expectations-think 42 CFR Part 2) will present very new challenges to current security systems. &lt;br /&gt;&lt;br /&gt;HL7 working groups are beginning to address this but we still have a way to go.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/4494892276419241682'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/4494892276419241682'/><link rel='alternate' type='text/html' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html?showComment=1255020397275#c4494892276419241682' title=''/><author><name>Rob M</name><uri>http://www.blogger.com/profile/11501088919382561275</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html' ref='tag:blogger.com,1999:blog-4384692836709903146.post-9050335274259919710' source='http://www.blogger.com/feeds/4384692836709903146/posts/default/9050335274259919710' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-4384692836709903146.post-7594496424936915152</id><published>2009-10-07T14:06:48.234-07:00</published><updated>2009-10-07T14:06:48.234-07:00</updated><title type='text'>One area of security that I see ignored or taken f...</title><content type='html'>One area of security that I see ignored or taken for granted is the need to provide physical security of electronic information systems.  Just as paper records are physically kept away from unauthorized access, IT and network equipment must also be secured from unwarranted human contact.  In my experience though, physicians, especially those in ambulatory care or private practices, often compromise security as a result of a poorly planned IT implementation.  For example, while walking through the exam area of a primary care provider, I came across a data closet with the door wide open and a box fan in the threshold.  The IT equipment was running too hot and kept crashing, so the only solution was to open the door in an attempt to cool the room.  A patient could have very easily taken down this doctor’s network with a single accidental button push, or worse could happen if a nefarious-type happened upon the data arrays.&lt;br /&gt;&lt;br /&gt;While data security can be improved with processes and software, a breach in physical security can have dire consequences as well.  Proper use of power, cooling and lockable enclosures should be the starting point of developing a high availability / highly secure IT network.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/7594496424936915152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/7594496424936915152'/><link rel='alternate' type='text/html' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html?showComment=1254949608234#c7594496424936915152' title=''/><author><name>Dan Draper</name><uri>http://www.liebert.com</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html' ref='tag:blogger.com,1999:blog-4384692836709903146.post-9050335274259919710' source='http://www.blogger.com/feeds/4384692836709903146/posts/default/9050335274259919710' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-4384692836709903146.post-3720295170141472844</id><published>2009-10-07T09:48:44.577-07:00</published><updated>2009-10-07T09:48:44.577-07:00</updated><title type='text'>RE: "Patients will trust electronic health care re...</title><content type='html'>RE: &amp;quot;Patients will trust electronic health care records only if they believe their confidentiality is protected via good security.&amp;quot;&lt;br /&gt;&lt;br /&gt;There is more to it than that. Patients will need access control over their own data, and auditing of access in order to trust the system.  There have been too many breaches of SSN&amp;#39;s and credit card numbers from other businesses for ordinary consumers to automatically trust their health care provider, just because of encryption technology.&lt;br /&gt;&lt;br /&gt;Remediating a lost credit card is a hassle, but not hard, and the credit card companies usually cover any financial loss.  What is the remediation if your personal health record is exposed?  I realize that some people don&amp;#39;t consider their health records highly confidential, but others do.  What do you do for them when data is stolen?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/3720295170141472844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/3720295170141472844'/><link rel='alternate' type='text/html' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html?showComment=1254934124577#c3720295170141472844' title=''/><author><name>kc cowan</name><uri>http://www.blogger.com/profile/15982312502906902020</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html' ref='tag:blogger.com,1999:blog-4384692836709903146.post-9050335274259919710' source='http://www.blogger.com/feeds/4384692836709903146/posts/default/9050335274259919710' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-4384692836709903146.post-3931186817308213618</id><published>2009-10-07T09:22:16.727-07:00</published><updated>2009-10-07T09:22:16.727-07:00</updated><title type='text'>LOA level 2 protections (required by CCHIT) are no...</title><content type='html'>LOA level 2 protections (required by CCHIT) are not enough to stop MITM attacks, where identity can be spoofed using wildcard SSL certs as demonstrated at Blackhat.&lt;br /&gt;&lt;br /&gt;By separating out identity as a managed service from the XML, the relevant HL7 RIM messages and ICD codes can be delivered, and bound late in the process to the identity data when it appears as a CCD/CCR. &lt;br /&gt;&lt;br /&gt;Even better is an approach that can actually separate out the bad data that should not be in the patient&amp;#39;s EHR when it may have originated due to valid service records for billing, but attached to the wrong person due to medical identity theft or coding mistakes.&lt;br /&gt;&lt;br /&gt;I think that process was made clear by epatientDave, that crossing security domains requires agreed upon abstractions which can be achieved by a national level schema, which does not get lost in translation.&lt;br /&gt;&lt;br /&gt;HITSP has demonstrated that this can be done effectively and at low cost between states, harmonized with state privacy laws using directory technology such as LDAP and X.500. &lt;br /&gt;&lt;br /&gt;Taking a national approach has  value IMHO since the entire country (330 million plus people) falls under several defined OIDs, or containers for example, c=US, 1.3.6.1 and elsewhere, and the states can run their own ID management under the standard FIPS codes, which means they apply their own governance, and can network their own identity attributes (such as patient identifiers compatible with PIX NHIN, hDATA) as they, and the organizations in that state choose to negotiate. &lt;br /&gt;&lt;br /&gt;BTW, this is with or without Federal participation, which from a data modeling view of X.500 exists at the level of another complex bi-lateral peering and groupings of organizations, and not necessarily (but can be, none the less) as the root, such as how SAFE Bio-Pharma currently is connected to the Federal Bridge PKI. &lt;br /&gt;&lt;br /&gt;For obvious security reasons you don&amp;#39;t want people registering in the .mil domain for example, but the US container is open in the domain name space. A container like c=US is a way to have a national policy, and state policies at the same time, since it can be enforced in schema, and traceable in requirements. One state might have totally different gender requirements for example than another, as to what attributes where allowed. Want your social networking profile to be exposed to the health system? That really is possible with Web 2.0.&lt;br /&gt;&lt;br /&gt;Patient identity is clearly spelled out in the architecture...&lt;br /&gt;http://www.connectopensource.org/download/attachments/17629260/CONNECT+Release+2.2+Software+Architecture_100309.pdf?version=1 &lt;br /&gt;&lt;br /&gt;Now it&amp;#39;s the practical matter of making the data and authentication and authorization portable, by letting the end user choose how they want move it, and providing transparency into the process. &lt;br /&gt;&lt;br /&gt;To have your choice of identity providers, and what attributes you want to share, means that actors can link different technologies, and still end up with a consistent result which is based on open systems. &lt;br /&gt;&lt;br /&gt;Since LDAP and X.500 have already been vetted into the higher levels of LOA, plus patient identifiers are already written into HIPPA, the problem space is fairly simple for many people who want a secure, proven, international standards based approach. &lt;br /&gt;&lt;br /&gt;For others that would prefer to be on the bleeding edge of emerging web services and want to transmit their PHR/EHR/EMR via some other API, to deal with the complexity of the security domain with whom they are trying to communicate, that&amp;#39;s just doable (especially globally), but not at the same level of scalability as a national/state solution.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/3931186817308213618'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/3931186817308213618'/><link rel='alternate' type='text/html' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html?showComment=1254932536727#c3931186817308213618' title=''/><author><name>dining_phil</name><uri>http://www.blogger.com/profile/12252983630493459378</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html' ref='tag:blogger.com,1999:blog-4384692836709903146.post-9050335274259919710' source='http://www.blogger.com/feeds/4384692836709903146/posts/default/9050335274259919710' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-4384692836709903146.post-6587163595501329753</id><published>2009-10-07T06:49:13.718-07:00</published><updated>2009-10-07T06:49:13.718-07:00</updated><title type='text'>If security is a process doesn't it need to be a s...</title><content type='html'>If security is a process doesn&amp;#39;t it need to be a systematic process? So where do procedures (e.g. ISO27001, NIST SP800-39) for   developing, implementing and maintaining information security  / risk management systems fit into the picture?</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/6587163595501329753'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/6587163595501329753'/><link rel='alternate' type='text/html' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html?showComment=1254923353718#c6587163595501329753' title=''/><author><name>AlanS</name><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html' ref='tag:blogger.com,1999:blog-4384692836709903146.post-9050335274259919710' source='http://www.blogger.com/feeds/4384692836709903146/posts/default/9050335274259919710' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-4384692836709903146.post-5845577044616810351</id><published>2009-10-07T06:26:02.985-07:00</published><updated>2009-10-07T06:26:02.985-07:00</updated><title type='text'>John - 

Your observations on Identity and Access ...</title><content type='html'>John - &lt;br /&gt;&lt;br /&gt;Your observations on Identity and Access Management (IdAM) and Privacy are spot on. The security community, and in particular the identity management community have been struggling with these issues for a while and there are emerging solutions that can address some of the concerns you raised (for example, please take a look at http://tinyurl.com/ydqlfx4). &lt;br /&gt;&lt;br /&gt;Overall, any security system  can only be as good as its weakest component, and security policies and procedures - both online and offline - are critical factors in such a system. &lt;br /&gt;&lt;br /&gt;Going forward, we should also not loose sight of a very critical issue: scalability. Any security control will have an impact on performance and - as such - limit the system&amp;#39;s scalability. We really need to start looking into highly scalable architecture patterns (such as REST) in order to be able to scale to internet orders of magnitude. As such, federation technologies will likely be also more important. &lt;br /&gt;&lt;br /&gt;Regards, &lt;br /&gt;&lt;br /&gt;Gerald Beuchelt</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/5845577044616810351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/5845577044616810351'/><link rel='alternate' type='text/html' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html?showComment=1254921962985#c5845577044616810351' title=''/><author><name>Gerald Beuchelt</name><uri>http://blog.beuchelt.org/</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html' ref='tag:blogger.com,1999:blog-4384692836709903146.post-9050335274259919710' source='http://www.blogger.com/feeds/4384692836709903146/posts/default/9050335274259919710' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-4384692836709903146.post-2827178860959285367</id><published>2009-10-07T05:35:49.129-07:00</published><updated>2009-10-07T05:35:49.129-07:00</updated><title type='text'>Thanks for sharing this on your blog.

I would add...</title><content type='html'>Thanks for sharing this on your blog.&lt;br /&gt;&lt;br /&gt;I would add, as corollaries:&lt;br /&gt;1) A key objective of security is to mitigate risks in accordance with clear and realistic policies.  It is very important to keep  security policies and risk analysis up-to-date.&lt;br /&gt;2) The role of administrative controls and insurance is as important as standards and technology.  They are relatively easy to use and may be the least costly choices.&lt;br /&gt;3) There is no such thing as shrink-wrapped security.  There are many  who will try to sell it to you, however.&lt;br /&gt;4) Do not pay more for risk mitigation than the value of the underlying risks.&lt;br /&gt;5) The most frequent security breaches come from trusted users.  Security auditing, and reading audit reports, is critical.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/2827178860959285367'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/2827178860959285367'/><link rel='alternate' type='text/html' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html?showComment=1254918949129#c2827178860959285367' title=''/><author><name>Glen</name><uri>http://www.blogger.com/profile/01091662588248850398</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html' ref='tag:blogger.com,1999:blog-4384692836709903146.post-9050335274259919710' source='http://www.blogger.com/feeds/4384692836709903146/posts/default/9050335274259919710' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-4384692836709903146.post-6974889643769290122</id><published>2009-10-07T05:26:11.612-07:00</published><updated>2009-10-07T05:26:11.612-07:00</updated><title type='text'>One point I'd like to add is that privacy and secu...</title><content type='html'>One point I&amp;#39;d like to add is that privacy and security must be weighed against other considerations, such as patient safety.  A security policy that prevents access to lifesaving information to ensure patient privacy isn&amp;#39;t necessarily acting in the best interests of the patient.  As you said, that&amp;#39;s like a library that never loans out any books.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/6974889643769290122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/4384692836709903146/9050335274259919710/comments/default/6974889643769290122'/><link rel='alternate' type='text/html' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html?showComment=1254918371612#c6974889643769290122' title=''/><author><name>Keith W. Boone</name><uri>http://www.blogger.com/profile/16883038460949909300</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://geekdoctor.blogspot.com/2009/10/my-privacy-and-security-lessons-learned.html' ref='tag:blogger.com,1999:blog-4384692836709903146.post-9050335274259919710' source='http://www.blogger.com/feeds/4384692836709903146/posts/default/9050335274259919710' type='text/html'/></entry></feed>