HealthcareInfoSecurity.com - Information Security News, Regulations, & Education

Healthcare Information Security Podcasts

Healthcare Information Security RSS Feeds Healthcare Information Security iTunes Podcasts Healthcare Information Security Email Updates

How DLP Helps Target Encryption

Credit
Eligible
As a HealthcareInfoSecurity.com annual member, this content can be used toward your membership credits and transcript tracking. Click For More Info
May 20, 2010
Share

Interview with Steve Scott, IT security manager at St. Charles Health System in Oregon

A data loss prevention system can help focus efforts to encrypt sensitive patient information, says Steve Scott, IT security manager St. Charles Health System in Oregon.

In an exclusive interview, Scott explains how the three-hospital organization is using DLP for "detective work, such as to:

  • Identify where patient information is stored, including vulnerable spreadsheets and documents;
  • Track when users attempt to transmit patient information via unencrypted e-mail; and
  • Determine when business associates send the hospitals patient information without adequately protecting it.

The Oregon provider organization is in the early stages of encrypting patient data no matter where it resides, targeting the information through the DLP system. The strategy is part of its effort to comply with the HITECH Act.

It's also more strictly enforcing its policy of using secure e-mail. It uses DLP reports to educate staff members about messages they've attempted to send that contain unprotected sensitive information.