
The rapid expansion of telemedicine to meet the ever-growing demand for health care services is raising concerns in some quarters that the security of sensitive patient data may be put at risk. Some observers worry that in their haste to put together an infrastructure for the delivery of health care services via telemedicine, the system’s architects have failed to build in enough security safeguards.
At the annual conference of the American Society for Healthcare Risk Management, held in Indianapolis in October 2015, M. Lauree Barreca, senior counsel for Johns Hopkins Health System, had some friendly advice for health care industry risk managers. According to a report from BusinessInsurance.com, Barreca said, “You as a risk manager and the risk management field have to be aware of what the [telemedicine] technologies are and how you’re going to react to them.”
Wide Array of Technologies
Barreca pointed out that telemedicine encompasses a wide variety of technologies, each of which poses its own distinctive security challenges. Among those various forms, perhaps the most widely recognized is video conferences between doctors and patients. Other common forms include home-based devices that monitor patients’ vital signs, such as blood glucose levels, blood pressure, and heart rate, as well as mobile apps that enable patients to check their medical records and recent test results.
Yet another area of telemedicine that could increase the risk of data theft is the forwarding of a patient’s medical data by a primary care physician to off-site specialists for second opinions, according to Barreca. She cited as an example a doctor’s request to a radiologist or pathologist to evaluate a patient’s test results.
Creation of Committees Urged
Margaret Garrett, who is also a senior counsel at Johns Hopkins as well as its director of risk management, suggested that health care systems create telemedicine committees to identify data security risks and map out plans to mitigate those risks. Such a committee, said Garrett, could draw its members from disparate disciplines within the overall health system. Members might include doctors, nurses, attorneys, risk managers, and IT specialists.
Similar observations were made recently by Michael Kaiser, executive director of the National Cyber Security Alliance. Interviewed by Mike Miliard, senior editor of Healthcare IT News, Kaiser says that “developing a well-trained and proactive workforce is key to hospitals and health systems as they stare down growing and evolving cyber security threats.”

Kaiser explains that his organization sees its primary mission as educational, raising public awareness “to help people use the Internet more safely and securely.” In furtherance of that goal, NCSA works with those in the health care industry to increase their know-how about safe and smart practices in cyberspace. Kaiser’s alliance has a partnership with the Healthcare Information and Management Systems Society, a nonprofit organization dedicated to improving the quality of health care through the use of information technology.
Kaiser takes exception to arguments that the health care industry is “fundamentally different” from other industries in terms of its privacy and security challenges. “It’s only different to the extent of the amount of information it collects about people,” he said. “The amount of information that accumulates about you is significantly more in the health care industry.”
Industry Widely Diversified
Complicating the challenge of securing sensitive patient data is the very diversified nature of the health care industry, according to Kaiser. As a result, protected health information flows between a variety of different types of organizations, including an individual doctor’s office, a diagnostic laboratory, a giant hospital or health system, as well as a wide array of insurers.
Kaiser believes that one of the keys to keeping this vast flow of data secure is to ensure that all those who handle this sensitive information are made keenly aware of their responsibility for safeguarding it. To accomplish this goal, Kaiser has some suggestions.
Creating a Culture of Cyber Security
To begin with, says Kaiser, “creating a culture of cyber security isn’t just about laying down rules and asking people to follow them. That’s part of it, and it’s kind of the way we think about it most of the time. But it’s really about starting at the top of an organization and throughout, getting everybody aware — to pay attention to and have their antennae up about risks and the kinds of things they’re doing that may cause risk.”

Yet another key challenge, says Kaiser, is how to drive home to all those who routinely handle sensitive information the stakes involved in protecting the data that passes through their hands day after day. One of the problems with cyber security, he notes, is the technical side of the equation that may be beyond the grasp of some employees who are competent in discharging their jobs but still somewhat technically challenged.
Cybersecurity Framework a Good Model
In an effort to overcome some gaps in employee comprehension of the problem, Kaiser suggests that the Cybersecurity Framework developed by the National Institute of Standards and Technology could serve as a model that is more easily understood. The framework is NIST’s response to a 2013 presidential order directing the agency to develop a “voluntary framework — based on existing standards, guidelines, and practices — for reducing cyber risks to critical infrastructure.”
The framework, first released in February 2014 and more recently updated in July 2015, was designed to serve as a model for small, medium, and large businesses across multiple industrial sectors, including the health care industry.
Kaiser also stresses the importance of the key elements of cyber security, which include “identifying the digital assets you have and need to protect; making sure you have ways to prevent those assets from being lost or stolen; making sure you would know if an incident occured; and being able to . . . respond to that incident and recover.”
Are Data Breaches Inevitable?
One of the biggest threats to the security of patient data in the telemedicine setting, says Kaiser, is the mindset that maintains data breaches are virtually impossible to protect against. Thinking like that, he says, has the potential to overwhelm employees and, ironically, undermine security.
“What you hear all the time is that you’re just bombarded with risk,” Kaiser says. “With risk and bad things: There’s a breach here, there’s a breach there. People need to be able to prioritize when they’ve already got a million things to do. What’s the most important thing I can do right now to make sure I’m protecting the most important data?”
To access additional articles about the latest developments in telemedicine and a host of related health topics, check out our blog.
Photo credits: Cisco Pics, Storm Nylen, datacate
Don Amerman is a freelance author who writes extensively about a wide array of nutrition and health-related topics.

We specialize in providing our over 1,000,000 customers with relevant product and condition information created by our professional editorial staff which includes our team of medical writers, medical practitioners, and health educators. eDrugStore.com Staff on Facebook