Your Money or Your Life

Jan. 3, 2012
We've spent gazillions of dollars on HIPAA Security compliance-- some needed, but some of which I think we contrive for no good reason... screening and trapping outbound email for HIPAA-sensitive terms is one of those risk mitigators that, to me, has incredibly low value. As we get our security feet on the ground in healthcare, we tend to spend big bucks locking the front door while leaving the backdoor wide open.

We've spent gazillions of dollars on HIPAA Security compliance-- some needed, but some of which I think we contrive for no good reason... screening and trapping outbound email for HIPAA-sensitive terms is one of those risk mitigators that, to me, has incredibly low value. As we get our security feet on the ground in healthcare, we tend to spend big bucks locking the front door while leaving the backdoor wide open.

I've had this theory that most of our patients would prefer that we protect their personal identity and financial information first, and then protect their personal health information. But, HIPAA has consumed us while Red Flag is a latecomer invitee to the party. That order of invitation and attention never made sense to me and I would argue that we need to balance our investment and attention in IS security risk management towards our patient's perspective of risk, not ours. Remember that, Risk = The Probability of Something Bad Happening x The Consequences. Many of us tend to focus on one or the other, but you need some of both to equal "Risk." Likewise, drive either variable towards zero, and you can forget about the other.

I'm running a simple little survey (which will drive PhD-survey designers nuts) to test the theory. Click here to take the one question survey: Your Money or Your Life and I will report the results in a few days.

Sponsored Recommendations

The Race to Replace POTS Lines: Keeping Your People and Facilities Safe

Don't wait until it's too late—join our webinar to learn how healthcare organizations are racing to replace obsolete POTS lines, ensuring compliance, reducing liability, and maintaining...

Transform Care Team Operations & Enhance Patient Care

Discover how to overcome key challenges and enhance patient care in our upcoming webinar on September 26. Learn how innovative technologies and strategies can transform care team...

Prior Authorization in Healthcare: Why Now?

Prepare your organization for the CMS 2027 mandate on prior authorization via API. Join our webinar to explore investment insights, real-time data exchange, and the benefits of...

Securing Remote Radiology with the Zero Trust Exchange

Discover how the Zero Trust Exchange is transforming remote radiology security. This video delves into innovative solutions that protect sensitive patient data, ensuring robust...