SEP 1, 2009 4:44am ET

Related Links

Obama: Better Federal Data Quality, Availability within Year
May 23, 2012
Bloomberg Launches Data Management Service with PolarLake Buy
May 23, 2012
Dispatches from MIT CIO Symposium
May 22, 2012

Web Seminars

Smarter Service and Security for Citizens
Available On Demand

Effort to Certify Health IT Security

Print
Reprints
Email

The Health Information Trust Alliance, an industry consortium working to improve the understanding of information security issues in health care, is spearheading efforts to develop health IT security certification programs.

Called HITRUST, the alliance last spring unveiled its Common Security Framework for electronic health information. The framework is an attempt to standardize health IT security best practices, standards and regulations in a single certifiable tool. The framework includes a best-practices security implementation manual, a cross-referenced standards and regulations matrix, and a readiness assessment toolkit.

But information security professionals and other purchasers often are confused as to which functions a particular product supports. The new certification program is an effort to classify security products by functionality to help providers and payers better understand the products that will help organizations fix the security gaps they have, says Daniel Nutkis, CEO of HITRUST. Criteria will focus on helping organizations determine a product's capabilities, functionality, effectiveness and support of security practices.

The alliance will not become a certifier, but will work with existing information security certifiers and vendors, and providers and payers to develop a certification program that other entities can operate, Nutkis says. "We're adopting criteria and processes by which third-parties can certify products."

A steering committee of security vendors and certifiers will develop the program, assisted by an advisory firm of health care provider and payer organizations. Steering committee members include certifying firms ICSA Labs and NSS Labs, and vendors McAfee, CA, Cisco Systems, nCircle, RSA, the security division of EMC, Symantec, Trend Micro and VeriSign.

Certification criteria will focus on the needs for securing protected health information.

Certified products would receive the "CSF Ready" designation to enable organizations to more quickly assess that a product or service does what is expected and meets the requirements of HITRUST's Common Security Framework.

HITRUST is seeking additional vendors and industry stakeholders to participate in the initiative. More information is available at hitrustalliance.net/csfready.

This article can also be found at HealthDataManagement.com.

Joseph Goedert is news editor at Health Data Management.

Filed under:

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.