If a breach of unsecured PHI occurs, how do I repair my reputation?
One of the more challenging assets to recover is your reputation as a trustworthy guardian of patient information and confidences. Once systems are restored, an independent security consultant or auditor should be retained to verify that your systems have been remediated against the vulnerability that permitted the loss to occur. The audit should evaluate whether "best practices" have been appropriately utilized. Documented evidence that you have affirmatively addressed past security problems is key component in responding to concerns from patients, clinicians, business partners, regulators or accreditation bodies.
Resources - Mitigating Harm
Resources - Containing Exploits
Register for the HealthIT and Quality Improvement eNewsletter
Comments?
E-mail the HealthIT e-mail box: healthit@hrsa.gov