Securing the Medical Office with Taceo

OVERVIEWTo provide added value, a healthcare provider
Operating a medical practice is assiduous workwishes to establish an easy and affordable way
requiring great attention to detail on a variety ofto give their patients medical advice over the
fronts. Patient privacy has always Been anweb. The provider must have the ability to send
important concept in the medical profession. Newand receive protected medical advice from work
laws are taking this notion a step further, makingor home and cannot afford the installation,
it mandatory for medical facilities to protectmaintenance and expensive licensing fees
individually identifiable health information.associated with available server-based solutions.
Government regulations such as the HealthFurthermore, the caregiver's patients are largely
Insurance Portability and Accountability Actnon-technical and will not bother with cumbersome
(HIPAA) and others stipulate the how your digitalkey exchange, s/mime and other requirements
records containing sensitive patient informationcommonly associated with widely available
should be kept secure, but caring for yourencryption technologies.
patient's privacy is just good business.Additionally, encryption software does not protect
One of the most time and labor consuming taskscontent after it has been delivered. Once opened,
in maintaining an electronic medical record isthe patient's identifiable medical information is
importing non-digital patient information such astotally exposed; email can be accidentally
radiology reports, hospital dictation andforwarded, laptops and PCs can be lost or sold
consultation/referral letters is an extremely timewith PHI remaining on the hard-drive, patient info
and labor consuming task in maintaining ancould be leaked via virus, spy-ware or Trojan
electronic medical record. This is unfortunateworm. Unauthorized individuals gain access and
because most of this information is already indoctor-patient confidentiality is breached. The
digital format at the sender's location but printedcaregiver must be able to ensure that received
to paper for transit. Transmitting digitaldocuments remain encrypted and can be deleted
information securely, however, can be problematicfrom the patient's computer after a given time.
at best. Simply emailing a document to anHow can the healthcare provider utilize the power
intended recipient would potentially violate aof email to give medical advice while keeping
patient's privacy since the mail could besensitive patient data secure?
intercepted in transit or read by unauthorizedTaceo helps healthcare professionals meet HIPAA
persons on the destination email server before itrequirements for the secure storage, transmission
is downloaded. Also, it would be impossible to telland delivery of identifiable patient information.
whether or not the document was tampered withTaceo makes the sending and receiving of
or was sent by someone electronically pretendingsecured email and documents quick and easy.
to be someone else. For example, to promoteFrom the desktop or MS Outlook®, providers
office efficiency, medical offices that want tocan encrypt and apply usage permissions to
allow physicians to provide electronic mail as acontrol and prevent actions as forwarding, cut
means to transmit information are forced to havecopy/paste, printing and disabling the Print Screen
an "email disclaimer" that can not guarantee thekey. Email and documents can also be set to
privacy of information contained in an email. The"expire" and will become unreadable at a given
information may be confidential and subject totime and date.
protection under the law, but the fact remainsTaceo is by no means a comprehensiven overall
that no real protection is provided as aHIPAA security solution, however if used properly
preventative for security breach of yourcan help your business to inexpensively meet
information.most of the critical rules.
Whether you are a healthcare provider, payer orTACEO FEATURES AND BENEFITS
pharmaceutical company you have electronic• Protect EPHI from theft, misdirection
information that must be protected. Essentialand unauthorized distribution. • Allows
Taceo virtually eliminates the costs associatedprimary care providers and specialists to instantly
with safeguarding Protected Health Informationand securely share patient records with little cost.
(PHI). With Taceo you are now free to email• Enables patients to easily access and
medical advice to your patients, send prescriptionsecurely reply to protected emails containing
requests to the smallest of pharmacies and safelymedical advice, prescription information and more
deliver patient records to referral doctors.from their home or work computers. •
HEALTH INSURANCE PORTABILITY ANDGives off-site providers an easy method to
ACCOUNTABILITY ACT (HIPAA)access and reply to secure email sent across
The Health Insurance Portability and Accountabilitydisparate computing environments •
Act (HIPAA) of 1996 was designed to create aAffordable security beyond the office firewall.
new national standard for protecting the privacyTaceo can ensure the proper use and protection
of patient's health information. HIPAA also focusedof EPHI no matter where it travels or where it is
on improving the efficiency and effectiveness ofstored. • Helps ensure authenticity of
the Healthcare system, by encouraging theEPHI with digital signatures. • Improve
development and adoption of Electronic Dataproductivity by using the web to instantly &
Interchange (EDI) between healthcare providers,securely share sensitive data. • Taceo
payers and pharmaceutical organizations. HIPAAoffers an affordable way to securely store
also stipulates the strict requirement forsensitive information on site. • Prevent
organizations to establish safeguards to protectunauthorized access to your documents.
the integrity and confidentiality of an individual's• Prevent unauthorized distribution (no
Protected Health Information (PHI). HIPAA appliesforwarding) • Prevent document editing
to individual healthcare providers, health plans, and(no cut, copy, paste) • Set expiration
healthcare insurance providers. The law alsotime/date on email & documents. •
pertains to organizations that deal with theEnsures confidentiality and privacy. •
electronic PHI of customers, employers andSecurely and permanently delete files to
patients. Civil and criminal penalties can result fromDepartment of Defense standards (DOD
noncompliance and security violations.5220.22-M). • Patients can download
PENALTIES FOR HIPAA VIOLATIONSTaceo for free. • Meet regulatory
HIPAA calls for civil and criminal penalties forcompliance requirements for privacy - HIPAA,
security and privacy breaches. General failure toPIPEDA, 21 CFR Part 11, Sarbanes-Oxley
comply is $100 per penalty; violations of anREDUCING YOUR VULNERABILIIES
identical requirement may not exceed $25,000No security software in the world is 100%
per year. For example: it would be considered aunbreakable, even the most advanced digital
violation to email claim or file with identifiableencryption techniques can be broken or
patient information that is not encrypted. Evencircumvented by some person or organization
though one requirement may not exceedwith enough motivation, time and money. Taceo
$25,000, HIPAA has more than 15 named securitydoes not totally negate the risk of information
standards, which if repeatedly violated couldleakage, for example a malicious individual could
quickly grow to more than $375,000. More severetake a digital photo of the screen or re-type the
criminal penalties also apply to more flagrantcontent into another document and distribute it.
HIPAA violations. Wrongful disclosure of PHI canHowever, Taceo considerably reduces the risk
result in a $50,000 penalty and up to one year inthat sensitive data can be disseminated to
prison. Offense with intent to sell of misuseunauthorized individuals or groups. Taceo
patients protected health information is punishableSafeguards remain with the data no matter
with a maximum $250,000 fine and/or 10 yearswhere it travels or where it is stored. Even if a
Imprisonment.CD or USB thumb-drive containing protected data
TACEO: HELPING TO NAVIGATE THE HIPAAis stolen, the information contained therein will
MINEFIELD - COMMON HIPAA SCENARIOS ANDremain encrypted and cannot be opened by
TACEOunauthorized recipients.
Medical office wishes to refer and identifiable PHITHE ANALOGUE TO DIGITAL MIGRATION
to another healthcare provider.Although it is often difficult to make the initial
A primary care physician examines an individualswitch to using digital patient records, the cost
and determines that he would like to send thesavings can be profound, especially when
patient to another provider for further diagnosisamortized over a number of years. Benefits
or treatment. The physician then asks his/herinclude better accuracy in health records, less time
assistant to assemble and email the patient'sspent transcribing patient notes, filling prescriptions
history and physical (H&P), imaging reports, labs,and receiving quicker payment from insurance
progress notes, etc. to the off-site healthcarecompanies. For the most part many healthcare
provider for review. Unfortunately, the physicianpractitioners have been slow to adopt digital
and his assistant are in now violation of HIPAAmedical records, as of April 2005 only 16.4% of
regulations.doctors in the United States had made the switch.
Unprotected email is like sending a post-cardReasons most often cited for the slow adoption
through cyber-space. While transiting it is routedhas been the costs in time and money. Fear of
through multiple servers, an email containingcomplicated regulations also slow the transition;
patient PHI can be easily read by people otheronce records are in the digital realm HIPAA
than the designated recipient (the off-sitestandards must be strictly adhered.
provider). Furthermore, the patient's records,Although the task appears daunting, individual and
because of an accidental keystroke, could besmaller medical practices can cost-effectively
unintentionally misdirected to an unknown party,make the digital transition with largely low cost,
thereby increasing the severity of the securityoff-the-shelf components.
breach. The physician's assistant could have usedTaceo, from Essential Security Software should
Taceo to protect the email and attachments. Withbe an integral part of any digital migration plan.
the quick click of a button the worker could haveTaceo can help your office secure the storage
prohibited the patient records from being printed,and transmission of PHI. Because Taceo can be
forwarded and edited. The outgoing documentsused on almost any PC, it can be used to "bridge
would be encrypted and un-accessible to anyonethe gap" with offices of other healthcare
besides the intended recipient healthcare provider.providers that have not yet made the switch to
(Even if the receiving healthcare provider is notdigital records. Whether digital or analog, all
fully set-up to work with electronic patientorganizations that deal with patient medical
healthcare information, they can still securely viewinformation are subject to HIPAA ordinances.
patient records without violating patientSUMMARY
confidentiality.)Any healthcare provider or organization that
On-line Pharmaceutical Providerworks with patient healthcare data is at risk for
A pharmaceutical provider fills prescriptions vialosing control of this information. Unprotected
on-line ordering, but cannot meet HIPAA secureelectronic files containing sensitive data can easily
transmission requirements for emailing regardingbe accessed, altered, stolen and re-distributed to
prescriptions and medications, order confirmation,unauthorized parties. Electronic protected health
and other information to their patients. Theinformation (EPHI) is subject to stringent HIPAA
organization could resort to analog methods suchregulations; penalties for violation of HIPAA rules
as calling each individual customer or sendingcan result in stiff fines and jail time. Loss of EPHI
information to the customers via standard post,can place healthcare organizations at great financial
however these methods are very inefficient andand legal risk.
cost prohibitive. To meet HIPAA regulations theTaceo, from Essential Security Software can help
on-line prescription provider must shoulder thesmall to mid-size healthcare providers mitigate
burden of hiring and training a number of newthese risks. Taceo can also help organizations
employees at great cost. What is the on-linemeet HIPAA requirements for the secure
pharmacy to do?transmission, access and integrity of EPHI. Taceo
With Taceo, the pharmaceutical provider canis effective, affordable and easy-to-use software
securely send prescription information, orderthat enables healthcare providers to securely
confirmations and more to their clientele. Thestore, transmit and receive sensitive data. Taceo
confidentiality and integrity of emails containingcan encrypt and help control access to almost
protected health information (PHI) is enforced andany file. Protected email and documents are
maintained even after delivery. Nearly anysafeguarded against unauthorized forwarding,
customer with a PC1 can easily download the freeediting, coping, and printing or screen capture.
version of Taceo, enabling them receive and replyTaceo opens up a new realm of possibilities never
protected email.available before with such ease and affordability.
Taceo's usage permissions interface provides theHealthcare providers can securely email medical
company with an effective way to assign flexibleinformation to their patients. Pharmacies can use
rights management controls based on the profileTaceo to send prescription order information to
of the client. Emails Containing prescriptiondoctors and customers alike.
information can be set to expire when no longerCaregivers can quickly and securely collaborate
valid.with off-site specialists thereby ensuring patients
Healthcare giver wishes to provide individualreceive good treatment and much more.
patients medical advice via email