Personal Accountability for Data Stewardship 2014 1 st Year Medical Students Noella RawlingsJohn Soltys Director of ComplianceSenior Computer Specialist.

Slides:



Advertisements
Similar presentations
HIPAA Health Insurance Portability and Accountability Act of 1996
Advertisements

Computer and Mobile Device Equipment Security Brief May 29, 2008 Presented by: Kevin G. Sutton, Chief, Information Technology Unit.
INADEQUATE SECURITY POLICIES Each covered entity and business associate must have written polices that cover all the Required and Addressable HIPAA standards.
Mobile Devices: Know the RISKS. Take the STEPS. PROTECT AND SECURE Health Information.
Welcome to the SPH Information Security Learning Module.
Personal Accountability for Data Stewardship 1 st Year Medical Students – October 18, nd Year Medical Students – October 9, 2012 Noella RawlingsRichard.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
WORKFORCE CONFIDENTIALITY HIPAA Reminders. HIPAA 101 The Health Insurance Portability and Accountability Act (HIPAA) protects patient privacy. HIPAA is.
HIPAA Regulations What do you need to know?.
PERSONAL ACCOUNTABILITY FOR DATA STEWARDSHIP
Health information security & compliance
Invasion of Smart Phones in Clinical Areas Chrissy Kyak Privacy Officer University of Maryland Upper Chesapeake Health.
Springfield Technical Community College Security Awareness Training.
Personal Data Protection and Security Measures Justin Law IT Services - Information Security Team 25 & 27 November 2013.
1 Electronic Information Security – What Researchers Need to Know University of California Office of the President Office of Research May 2005.
KDE Employee Training. What IS a Data Breach? Unauthorized release (loss or theft) of Sensitive or Confidential Data, such as PII, PHI, etc. On site or.
IT Security is Everyone’s Responsibility Presented by Hooman Moayyed IT Security Awareness Program Manager.
Guide to Massachusetts Data Privacy Laws & Steps you can take towards Compliance.
Information Security Awareness:
Personal Data Protection and Security Measures Justin Law IT Services - Information Security Team 18, 20 & 25 March 2015.
DATA SECURITY Social Security Numbers, Credit Card Numbers, Bank Account Numbers, Personal Health Information, Student and/or Staff Personal Information,
1 Enterprise Security Your Information Security and Privacy Responsibilities © 2008 Providence Health & Services This information may be replicated for.
New Faculty Orientation to Privacy and Security at UF Susan Blair, Chief Privacy Officer Kathy Bergsma, Information Security.
HFS DATA SECURITY TRAINING
HIPAA What’s Said Here – Stays Here…. WHAT IS HIPAA  Health Insurance Portability and Accountability Act  Purpose is to protect clients (patients)
THE WHY AND HOW OF DATA SECURITY YOUR ROLE IN DATA STEWARDSHIP DEPARTMENT OF MEDICINE IT SERVICES.
Joel Garmon, Director, Information Security Mike Rollins, Security Architect Jeff Teague, Security Analyst, Senior 1
SECURITY: Personal Health Information Protection Act, 2004 this 5 min. course covers: changing landscape of electronic health records security threats.
New Data Regulation Law 201 CMR TJX Video.
Information Security Information Technology and Computing Services Information Technology and Computing Services
Obtaining, Storing and Using Confidential Data October 2, 2014 Georgia Department of Audits and Accounts.
Protecting Sensitive Information PA Turnpike Commission.
Securing Information in the Higher Education Office.
Information Security 2013 Roadshow. Roadshow Outline  Why We Care About Information Security  Safe Computing Recognize a Secure Web Site (HTTPS) How.
From HIPAA to HITECH OMH Briefing.
MOBILE DEVICE SECURITY. WHAT IS MOBILE DEVICE SECURITY? Mobile Devices  Smartphones  Laptops  Tablets  USB Memory  Portable Media Player  Handheld.
Security Awareness ITS SECURITY TRAINING. Why am I here ? Isn’t security an IT problem ?  Technology can address only a small fraction of security risks.
“ Technology Working For People” Intro to HIPAA and Small Practice Implementation.
ESCCO Data Security Training David Dixon September 2014.
Information Security 2013 Roadshow. Roadshow Outline  Why We Care About Information Security  Safe Computing Recognize a Secure Web Site (HTTPS) How.
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
Arkansas State Law Which Governs Sensitive Information…… Part 3B
 INADEQUATE SECURITY POLICIES ›Each covered entity and business associate must have written polices that cover all the Required and Addressable HIPAA.
What are the rules? Information technology is available to every student, faculty and staff member in support of the essential mission of the University.
A Road Map to Research at Jefferson: HIPAA Privacy and Security Rules for Researchers Presented By: Privacy Officer/Office of Legal Counsel October 2015.
Lessons Learned from Recent HIPAA Breaches HHS Office for Civil Rights.
Personal Accountability for Data Stewardship st Year Medical Students Noella RawlingsBrad Peda Director of ComplianceInformation Security Program.
Cyber Safety Jamie Salazar.
Introduction: Introduction: As technology advances, we have cheaper and easier ways to stay connected to the world around us. We are able to order almost.
Information Security Everyday Best Practices Lock your workstation when you walk away – Hit Ctrl + Alt + Delete Store your passwords securely and don’t.
Personal Data Protection and Security Measures Kelvin Lai IT Services - Information Security Team 12 & 13 April 2016.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
2015Computer Services – Information Security| Information Security Training Budget Officers.
POLICIES & PROCEDURES FOR HANDLING CONFIDENTIAL INFORMATION NOVEMBER 5 TH 2015.
Properly Safeguarding Personally Identifiable Information (PII) Ticket Program Manager (TPM) Social Security’s Ticket to Work Program.
Information Security Awareness Training
HIPAA Privacy and Security
Protecting PHI & PII 12/30/2017 6:45 AM
Lewis Creek Systems, LLC
East Carolina University
Lewis Creek Systems, LLC
Information Security 101 Richard Davis, Rob Laltrello.
Cybersecurity Awareness
HIPAA PRIVACY AWARENESS, COMPLIANCE and ENFORCEMENT
Welcome to the SPH Information Security Learning Module
Information Security Training
Colorado “Protections For Consumer Data Privacy” Law
Information Security in Your Office
School of Medicine Orientation Information Security Training
Presentation transcript:

Personal Accountability for Data Stewardship st Year Medical Students Noella RawlingsJohn Soltys Director of ComplianceSenior Computer Specialist School of MedicineUW Medicine IT Security 1

Defining data stewardship and your responsibilities Safeguarding confidential information DO’s and DON’Ts Current Security Threats Tools and resources Agenda 2

Being personally and professionally responsible for the security and integrity of confidential information, electronic or paper, entrusted to you. Confidential Information – protection of data required by law and includes: Protected health information (PHI) – protected by HIPAA Individual student records – protected by FERPA Personally identifiable information (PII) – financial information (e.g., credit card, bank), social security number and driver’s license number – protected by Washington’s breach notification law Other personal information - public employee’s home addresses, personal contact information, performance evaluations – protected by the Washington Public Records Law Proprietary intellectual property or trade secrets, research data – protected by the Washington Public Records Law What is Data Stewardship? 3

You are responsible for the safekeeping of data in your care Limit the data in your care to minimize the risk of loss Comply with UW Medicine and UW policies regarding the safekeeping of data Must encrypt mobile devices used to store or transmit confidential information containing PHI must be secured in transport (encrypted connections) Use strong password Must use UW approved cloud services Your Responsibilities 4

“Breach” is the unauthorized acquisition, access, use or disclosure of unsecured PHI and compromises the security or privacy of the PHI Breaches of unsecured PHI require notification to the Office of Civil Rights (OCR) and affected individuals. May also require notice to the media and posting on the UW Medicine website A breach is presumed and covered entity has burden of showing a breach has not occurred There are two ways to secure PHI Encryption Destruction Renders PHI unusable, unreadable or indecipherable What is a Breach? 5

Potential damage to personal, professional and institutional reputation Breaches are: Very costly – fines, sanctions and remediation Very time consuming – investigation, reporting Embarrassing – your name is reported to your Program Director, Department Chair, Dean of the School of Medicine, UW Medicine Chief Health System Officer and UW Medicine and School of Medicine Compliance Officials AND possible public notification Consequences of a Breach 6

Unencrypted laptop stolen from locked, parked car Briefcase containing PHI stolen from locked, parked car Backpack containing PHI stolen from locked, parked car Unencrypted laptop containing PHI and PII stolen from office in Health Sciences Building Recent Examples of Loss 7

If you use a mobile device to store or transmit PHI or PII, your mobile device MUST be encrypted! Rule Number One 8

NEVER leave confidential data in your car! Rule Number Two 9

Avoid taking confidential data off-site or downloading to portable or mobile devices If taking confidential data with you, you MUST obtain supervisor or department head approval Password protect all devices Use VPN to connect remotely Ensure the physical security of information - lock up confidential data (locking file drawer, safe, or other locked device) Prepare for the worst - protect yourself against theft - nobody thinks they will be a victim! Other Basic Do’s and Don’ts 10

CURRENT SECURITY THREATS 11

Phishing is a very common way accounts are stolen Don’t click links in and if you do, don’t enter your credentials UW Medicine periodically sends phishing messages to our workforce to help raise awareness – includes training YOU WILL RECEIVE PHISHING MESSAGES – be very wary and very cautious! PHISHING 12

Cryptolocker/Locker: Very destructive malware threat – encrypts your data and tries to sell it back to you Malware infection is obtained via attachments or by visiting/downloading a file (such as an MP3 file) from a website Sophos Anti-virus sometimes detects the malware (malware name used is Troj/Ransom-ACP) DON’T FALL FOR THIS SCHEME! MALWARE 13

NEVER open an attachment from an unknown source If the context of the message doesn’t make sense, delete the message or call the sender to verify the Always be wary of messages that ask you to update your password or confirm you account – UW IT support groups will never ask you to do this via a link in an Report any warning messages from antivirus or other software immediately. DO NOT CLICK ON THE LINK! Minimize the confidential information you store Encrypt the data and the device Keep your operating system and software up to date (Stay patched) Empty your “Trash bin” (Deleted Items) regularly or set it to empty automatically when you exit the program Contact your Department IT support staff for assistance with any device you use for work What Can You Do? 14

If you get infected, or think you may be infected, contact UW Medicine IT Security IMMEDIATELY! Report information security incidents when they occur. Contact IT Services Help Desk at If it is urgent, call Report the loss or theft of PHI to UW Medicine Compliance at or Immediately notify the Director of Compliance for the School of Medicine at or 206- Incident Reporting 15

TOOLS AND RESOURCES 16

Tools to Assist You in Safeguarding Data Encryption Complex passwords Physical data security - lock offices, files and computers Education and training materials Privacy, Confidentiality and Information Security Agreement (PCISA) Following policies restricting removal of data from worksites 17

UW Medicine Compliance Policies UW Medicine IT Security Policies UW Medicine Polices 18

Smartphone/Tablet Security If you use a smartphone or tablet (UW owned or your personal device) to conduct UW business, such as accessing your UW , we recommend: Auto lock device and use a strong password Enable encryption on the device Set an automatic lockout timer on the device Activate Tamper Wipe: i.e. phone is wiped clean after 10 pass code or PIN attempts (all data is deleted) Activate “find my phone” function Don’t use cloud back up services, such as iCloud or Google Drive, unless it is an approved cloud by UW Medicine IT Security for PHI or FERPA data Don’t store data on the SIM card 19

Encryption Resources Where to get information and help with encryption: Encryption guidelines mobile devices: sp sp Whole disk encryption guidelines: e.pdf e.pdf vice_Encryption/other_windows_linux_guidance.asp vice_Encryption/other_windows_linux_guidance.asp IT Services Help Desk: DOM IT Help Desk: 20

SkyDrive Pro Site (requires UW NetID): ion-technology/skydrivepro SkyDrive Pro (OneDrive) Resource 21

Educational Tools UW Medicine IT Security Phishing Awareness Announcement: ations/Phishing_Awareness_ _041212/default.asp ations/Phishing_Awareness_ _041212/default.asp Office of the Chief Information Security Officer phishing video: y.html y.html Phishing Resources 22

Other Resources Office of the Chief Information Security Officer training/ training/ computing/ computing/ UW Medicine IT Security 23

UW Medicine IT Services Help Desk: UW Medicine ITS Security Team: uwmed- UW Medicine Compliance: Noella Rawlings, UW School of Medicine, Director of Compliance: Contact Information 24

Questions ? 25