Securing the Medical Office with Taceo

>to establish an easy and affordable way to give their
patients medical advice over the web. The provider
OVERVIEWmust have the ability to send and receive protected
Operating a medical practice is assiduous workmedical advice from work or home and cannot
requiring great attention to detail on a variety ofafford the installation, maintenance and expensive
fronts. Patient privacy has always Been an importantlicensing fees associated with available server-based
concept in the medical profession. New laws aresolutions. Furthermore, the caregiver’s patients
taking this notion a step further, making it mandatoryare largely non-technical and will not bother with
for medical facilities to protect individuallyidentifiablecumbersome key exchange, s/mime and other
health information. Government regulations such asrequirements commonly associated with widely
the Health Insurance Portability andAccountability Actavailable encryption technologies.
(HIPAA) and others stipulate the how your digitalAdditionally, encryption software does not protect
records containing sensitive patient information shouldcontent after it has been delivered. Once opened,
be kept secure, but caring for your patient’sthe patient’s identifiable medical information is
privacy is just good business.totally exposed; email can be accidentally forwarded,
One of the most time and labor consuming tasks inlaptops and PCs can be lost or sold with PHI
maintaining an electronic medical record is importingremaining on the hard-drive, patient info could be
non-digital patient information such as radiologyleaked via virus, spy-ware or Trojan worm.
reports, hospital dictation andconsultation/referralUnauthorized individuals gain access and
letters is an extremely time and labor consuming taskdoctor-patient confidentiality is breached. The
in maintaining an electronic medical record. This iscaregiver must be able to ensure that received
unfortunate because most of this information isdocuments remain encrypted and can be deleted
already in digital format at the sender's location butfrom the patient’s computer after a given
printed to paper for transit. Transmitting digitaltime. How can the healthcare provider utilize the
information securely, however, can be problematic atpower of email to give medical advice while keeping
best. Simply emailing a document to an intendedsensitive patient data secure?
recipientwould potentially violate a patient's privacyTaceo helps healthcare professionals meet HIPAA
since the mail could be intercepted in transit or readrequirements for the secure storage, transmission
byunauthorized persons on the destination emailand delivery of identifiable patient information. Taceo
server before it is downloaded. Also, it wouldmakes the sending and receiving of secured email
beimpossible to tell whether or not the documentand documents quick and easy. From the desktop or
was tampered with or was sent by someoneMS Outlook®, providers can encrypt and apply
electronically pretending to be someone else. Forusage permissions to control and prevent actions as
example, to promote office efficiency, medicalofficesforwarding, cut/copy/paste, printing and disabling the
that want to allow physicians to provide electronicPrint Screen key. Email and documents can also be
mail as a means to transmit information are forced toset to “expire” and will become unreadable at a
have an “email disclaimer” that can notgiven time and date.
guarantee the privacy of information contained in anTaceo is by no means a comprehensiven overall
email. The information may be confidential andHIPAA security solution, however if used properly
subject to protection under the law, but the factcan help your business to inexpensively meet most
remains that no real protection is provided as aof the critical rules.
preventative for security breach of your information.TACEO FEATURES AND BENEFITS
Whether you are a healthcare provider, payer or• Protect EPHI from theft, misdirection and
pharmaceutical company you have electronicunauthorized distribution.• Allows primary care
information that must be protected. Essential Taceoproviders and specialists to instantly and securely
virtually eliminates the costs associated withshare patient records with little cost.• Enables
safeguarding Protected Health Information (PHI). Withpatients to easily access and securely reply to
Taceo you are now free to email medical advice toprotected emails containing medical advice,
your patients, send prescription requests to theprescription information and more from their home or
smallest of pharmacies and safely deliver patientwork computers.• Gives off-site providers an easy
records to referral doctors.method to access and reply to secure email sent
HEALTH INSURANCE PORTABILITY ANDacross disparate computing environments•
ACCOUNTABILITY ACT (HIPAA)Affordable security beyond the office firewall. Taceo
The Health Insurance Portability and Accountabilitycan ensure the proper use and protection of EPHI no
Act (HIPAA) of 1996 was designed to create a newmatter where it travels or where it is stored.•
national standard for protecting the privacy ofHelps ensure authenticity of EPHI with digital
patient’s health information. HIPAA alsosignatures.• Improve productivity by using the web
focused on improving the efficiency andto instantly & securely share sensitive data.•
effectiveness of the Healthcare system, byTaceo offers an affordable way to securely store
encouraging thedevelopment and adoption ofsensitive information on site.• Prevent unauthorized
Electronic Data Interchange (EDI) between healthcareaccess to your documents.• Prevent unauthorized
providers, payers and pharmaceutical organizations.distribution (no forwarding)• Prevent document
HIPAA also stipulates the strict requirement forediting (no cut, copy, paste)• Set expiration time
organizations to establish safeguards to protect thedate on email & documents.• Ensures
integrity and confidentiality of anconfidentiality and privacy.• Securely and
individual’sProtected Health Informationpermanently delete files to Department of Defense
(PHI).HIPAA applies to individual healthcare providers,standards (DOD 5220.22-M).• Patients can
health plans, and healthcare insurance providers.Thedownload Taceo for free.• Meet regulatory
law also pertains to organizations that deal with thecompliance requirements for privacy - HIPAA,
electronic PHI of customers, employers and patients.PIPEDA, 21 CFR Part 11, Sarbanes-Oxley
Civil and criminal penalties can result fromREDUCING YOUR VULNERABILIIES
noncompliance and security violations.No security software in the world is 100%
PENALTIES FOR HIPAA VIOLATIONSunbreakable, even the most advanced digital
HIPAA calls for civil and criminal penalties for securityencryption techniques can be broken or circumvented
and privacy breaches. General failure to comply isby some person or organization with enough
$100 per penalty; violations of an identicalmotivation,time and money. Taceo does not totally
requirement may not exceed $25,000 per year. Fornegate the risk of information leakage, for example a
example: it would be considered a violation to emailmalicious individual could take a digital photo of the
claim or file with identifiable patient information that isscreen or re-type the content into another document
not encrypted. Even though one requirement mayand distribute it. However, Taceo considerably
not exceed $25,000, HIPAA has more than 15 namedreduces the risk that sensitive data can be
security standards, which if repeatedly violated coulddisseminated to unauthorized individuals or groups.
quickly grow to more than $375,000. More severeTaceo Safeguards remain with the data no matter
criminal penalties also apply to more flagrant HIPAAwhere it travels or where it is stored. Even if a CD or
violations. Wrongful disclosure of PHI can result in aUSB thumb-drive containing protected data isstolen,
$50,000 penalty and up to one year in prison.the information contained therein will remain
Offense with intent to sell of misusepatientsencrypted and cannot be opened by unauthorized
protected health information is punishable with arecipients.
maximum $250,000 fine and/or 10 yearsTHE ANALOGUE TO DIGITAL MIGRATION
Imprisonment.Although it is often difficult to make the initial switch
TACEO: HELPING TO NAVIGATE THE HIPAAto using digital patient records, the cost savings can
MINEFIELD - COMMON HIPAA SCENARIOS ANDbe profound, especially when amortized over a
TACEOnumber of years. Benefits include better accuracy in
Medical office wishes to refer and identifiable PHI tohealth records, less time spent transcribing patient
another healthcare provider.notes, filling prescriptions and receiving quicker
A primary care physician examines an individual andpayment from insurance companies. For the most
determines that he would like to send the patient topart many healthcare practitioners have been slow to
another provider for further diagnosis or treatment.adopt digital medical records, as of April 2005 only
The physician then asks his/her assistant to assemble16.4% of doctors in the United States had made the
and email the patient’s history and physicalswitch. Reasons most often cited for the slow
(H&P), imaging reports, labs, progress notes, etc.adoption has been the costs in time and money. Fear
to the off-site healthcare provider for review.of complicated regulations also slow the transition;
Unfortunately, the physician and his assistant are inonce records are in the digital realm HIPAA standards
now violation of HIPAA regulations.must be strictly adhered.
Unprotected email is like sending a post-card throughAlthough the task appears daunting, individual and
cyber-space. While transiting it is routed throughsmaller medical practices can cost-effectively make
multiple servers, an email containing patient PHI canthe digital transition with largely low cost,
be easily read by people other than the designatedoff-the-shelf components.
recipient (the off-site provider). Furthermore, theTaceo, from Essential Security Software should be
patient’s records, because of an accidentalan integral part of any digital migration plan. Taceo
keystroke, could be unintentionally misdirected to ancan help your office secure the storage and
unknown party, thereby increasing the severity oftransmission of PHI. Because Taceo can be used on
the security breach. The physician’s assistantalmost any PC, it can beused to “bridge the
could have used Taceo to protect the email andgap” with offices of other healthcare providers
attachments. With the quick click of a button thethat have not yet made the switch to digital records.
worker could have prohibited the patient recordsWhether digital or analog, all organizations that deal
from being printed, forwarded and edited. Thewith patient medical information are subject to
outgoing documents would be encrypted andHIPAA ordinances.
un-accessible to anyone besides the intendedSUMMARY
recipient healthcare provider. (Even if the receivingAny healthcare provider or organization that works
healthcare provider is notfully set-up to work withwith patient healthcare data is at risk for losing
electronic patient healthcare information, they can stillcontrol of this information. Unprotected electronic files
securely view patientrecords without violating patientcontaining sensitive data can easily be accessed,
confidentiality.)altered, stolen and re-distributed to unauthorized
On-line Pharmaceutical Providerparties. Electronic protected healthinformation (EPHI)
A pharmaceutical provider fills prescriptions via on-lineis subject to stringent HIPAA regulations; penalties
ordering, but cannot meet HIPAA securetransmissionfor violation of HIPAA rules can result in stiff fines
requirements for emailing regarding prescriptions andand jail time. Loss of EPHI can place healthcare
medications, order confirmation, and other informationorganizations at great financialand legal risk.
to their patients. The organization could resort toTaceo, from Essential Security Software can help
analog methods such as calling each individualsmall to mid-size healthcare providers mitigate these
customer or sending information to the customersrisks. Taceo can also help organizations meet HIPAA
via standard post, however these methods are veryrequirements for the secure transmission, access and
inefficient and cost prohibitive. To meet HIPAAintegrity of EPHI. Taceo is effective, affordable and
regulations the on-line prescription provider musteasy-to-use software that enables healthcare
shoulder the burden of hiring and training a number ofproviders to securely store, transmit and receive
new employees atgreat cost. What is the on-linesensitive data. Taceo can encrypt and help control
pharmacy to do?access to almost any file. Protected email and
With Taceo, the pharmaceutical provider can securelydocuments are safeguarded against unauthorized
send prescription information, orderconfirmations andforwarding, editing, coping, and printing or screen
more to their clientele. The confidentiality andcapture.Taceo opens up a new realm of possibilities
integrity of emails containingprotected healthnever available before with such ease and
information (PHI) is enforced and maintained evenaffordability.Healthcare providers can securely email
after delivery. Nearly any customer with a PC1 canmedical information to their patients. Pharmacies can
easily download the free version of Taceo, enablinguse Taceo to send prescription order information to
them receive and reply protected email.doctors and customers alike.
Taceo’s usage permissions interface providesCaregivers can quickly and securely collaborate with
the company with an effective way to assign flexibleoff-site specialists thereby ensuring patients receive
rights management controls based on the profile ofgood treatment and much more.
the client. Emails Containing prescriptioninformation canSystem Requirements
be set to expire when no longer valid.- Microsoft Windows 2000/XP/2003 or newer
Healthcare giver wishes to provide individual patients- Microsoft .Net framework installed (if you
medical advice via emaildon’t have this Taceo will install it for you)
To provide added value, a healthcare provider wishes- Internet access.