Welcome to your ultimate radiology resouce


Securing the Medical Office with Taceo

OVERVIEW
To provide added value, a healthcare provider
Operating a medical practice is assiduouswishes to establish an easy and affordable
work requiring great attention to detail on away to give their patients medical advice
variety of fronts. Patient privacy has alwaysover the web. The provider must have the
Been an important concept in the medicalability to send and receive protected medical
profession. New laws are taking this notion aadvice from work or home and cannot afford
step further, making it mandatory for medicalthe installation, maintenance and expensive
facilities to protect individuallylicensing fees associated with available
identifiable health information. Governmentserver-based solutions. Furthermore, the
regulations such as the Health Insurancecaregiver's patients are largely
Portability and Accountability Act (HIPAA)non-technical and will not bother with
and others stipulate the how your digitalcumbersome key exchange, s/mime and other
records containing sensitive patientrequirements commonly associated with widely
information should be kept secure, but caringavailable  encryption  technologies.
for your patient's privacy is just good
business.Additionally, encryption software does not
protect content after it has been delivered.
One of the most time and labor consumingOnce opened, the patient's identifiable
tasks in maintaining an electronic medicalmedical information is totally exposed; email
record is importing non-digital patientcan be accidentally forwarded, laptops and
information such as radiology reports,PCs can be lost or sold with PHI remaining on
hospital dictation and consultation/referralthe hard-drive, patient info could be leaked
letters is an extremely time and laborvia virus, spy-ware or Trojan worm.
consuming task in maintaining an electronicUnauthorized individuals gain access and
medical record. This is unfortunate becausedoctor-patient confidentiality is breached.
most of this information is already inThe caregiver must be able to ensure that
digital format at the sender's location butreceived documents remain encrypted and can
printed to paper for transit. Transmittingbe deleted from the patient's computer after
digital information securely, however, can bea given time. How can the healthcare provider
problematic at best. Simply emailing autilize the power of email to give medical
document to an intended recipient wouldadvice while keeping sensitive patient data
potentially violate a patient's privacy sincesecure?
the mail could be intercepted in transit or
read by unauthorized persons on theTaceo helps healthcare professionals meet
destination email server before it isHIPAA requirements for the secure storage,
downloaded. Also, it would be impossible totransmission and delivery of identifiable
tell whether or not the document was tamperedpatient information. Taceo makes the sending
with or was sent by someone electronicallyand receiving of secured email and documents
pretending to be someone else. For example,quick and easy. From the desktop or MS
to promote office efficiency, medical officesOutlook®, providers can encrypt and apply
that want to allow physicians to provideusage permissions to control and prevent
electronic mail as a means to transmitactions as forwarding, cut/copy/paste,
information are forced to have an "emailprinting and disabling the Print Screen key.
disclaimer" that can not guarantee theEmail and documents can also be set to
privacy of information contained in an email."expire" and will become unreadable at a
The information may be confidential andgiven  time  and  date.
subject to protection under the law, but the
fact remains that no real protection isTaceo is by no means a comprehensiven overall
provided as a preventative for securityHIPAA security solution, however if used
breach  of  your  information.properly can help your business to
inexpensively meet most of the critical
Whether you are a healthcare provider, payerrules.
or pharmaceutical company you have electronic
information that must be protected. EssentialTACEO  FEATURES  AND  BENEFITS
Taceo virtually eliminates the costs
associated with safeguarding Protected Health• Protect EPHI from theft, misdirection
Information (PHI). With Taceo you are nowand unauthorized distribution. • Allows
free to email medical advice to yourprimary care providers and specialists to
patients, send prescription requests to theinstantly and securely share patient records
smallest of pharmacies and safely deliverwith little cost. • Enables patients to
patient  records  to  referral  doctors.easily access and securely reply to protected
emails containing medical advice,
HEALTH INSURANCE PORTABILITY ANDprescription information and more from their
ACCOUNTABILITY  ACT  (HIPAA)home or work computers. • Gives
off-site providers an easy method to access
The Health Insurance Portability andand reply to secure email sent across
Accountability Act (HIPAA) of 1996 wasdisparate computing environments •
designed to create a new national standardAffordable security beyond the office
for protecting the privacy of patient'sfirewall. Taceo can ensure the proper use and
health information. HIPAA also focused onprotection of EPHI no matter where it travels
improving the efficiency and effectiveness ofor where it is stored. • Helps ensure
the Healthcare system, by encouraging theauthenticity of EPHI with digital signatures.
development and adoption of Electronic Data• Improve productivity by using the web
Interchange (EDI) between healthcareto instantly & securely share sensitive data.
providers, payers and pharmaceutical• Taceo offers an affordable way to
organizations. HIPAA also stipulates thesecurely store sensitive information on site.
strict requirement for organizations to• Prevent unauthorized access to your
establish safeguards to protect the integritydocuments. • Prevent unauthorized
and confidentiality of an individual'sdistribution (no forwarding) • Prevent
Protected Health Information (PHI). HIPAAdocument editing (no cut, copy, paste)
applies to individual healthcare providers,• Set expiration time/date on email &
health plans, and healthcare insurancedocuments. • Ensures confidentiality
providers. The law also pertains toand privacy. • Securely and permanently
organizations that deal with the electronicdelete files to Department of Defense
PHI of customers, employers and patients.standards (DOD 5220.22-M). • Patients
Civil and criminal penalties can result fromcan download Taceo for free. • Meet
noncompliance  and  security  violations.regulatory compliance requirements for
privacy - HIPAA, PIPEDA, 21 CFR Part 11,
PENALTIES  FOR  HIPAA  VIOLATIONSSarbanes-Oxley
HIPAA calls for civil and criminal penaltiesREDUCING  YOUR  VULNERABILIIES
for security and privacy breaches. General
failure to comply is $100 per penalty;No security software in the world is 100%
violations of an identical requirement mayunbreakable, even the most advanced digital
not exceed $25,000 per year. For example: itencryption techniques can be broken or
would be considered a violation to emailcircumvented by some person or organization
claim or file with identifiable patientwith enough motivation, time and money. Taceo
information that is not encrypted. Evendoes not totally negate the risk of
though one requirement may not exceedinformation leakage, for example a malicious
$25,000, HIPAA has more than 15 namedindividual could take a digital photo of the
security standards, which if repeatedlyscreen or re-type the content into another
violated could quickly grow to more thandocument and distribute it. However, Taceo
$375,000. More severe criminal penalties alsoconsiderably reduces the risk that sensitive
apply to more flagrant HIPAA violations.data can be disseminated to unauthorized
Wrongful disclosure of PHI can result in aindividuals or groups. Taceo Safeguards
$50,000 penalty and up to one year in prison.remain with the data no matter where it
Offense with intent to sell of misusetravels or where it is stored. Even if a CD
patients protected health information isor USB thumb-drive containing protected data
punishable with a maximum $250,000 fine andis stolen, the information contained therein
or  10  years  Imprisonment.will remain encrypted and cannot be opened by
unauthorized  recipients.
TACEO: HELPING TO NAVIGATE THE HIPAA
MINEFIELD  - COMMON HIPAA SCENARIOS AND TACEOTHE  ANALOGUE  TO  DIGITAL  MIGRATION
Medical office wishes to refer andAlthough it is often difficult to make the
identifiable PHI to another healthcareinitial switch to using digital patient
provider.records, the cost savings can be profound,
especially when amortized over a number of
A primary care physician examines anyears. Benefits include better accuracy in
individual and determines that he would likehealth records, less time spent transcribing
to send the patient to another provider forpatient notes, filling prescriptions and
further diagnosis or treatment. The physicianreceiving quicker payment from insurance
then asks his/her assistant to assemble andcompanies. For the most part many healthcare
email the patient's history and physicalpractitioners have been slow to adopt digital
(H&P), imaging reports, labs, progress notes,medical records, as of April 2005 only 16.4%
etc. to the off-site healthcare provider forof doctors in the United States had made the
review. Unfortunately, the physician and hisswitch. Reasons most often cited for the slow
assistant are in now violation of HIPAAadoption has been the costs in time and
regulations.money. Fear of complicated regulations also
slow the transition; once records are in the
Unprotected email is like sending a post-carddigital realm HIPAA standards must be
through cyber-space. While transiting it isstrictly  adhered.
routed through multiple servers, an email
containing patient PHI can be easily read byAlthough the task appears daunting,
people other than the designated recipientindividual and smaller medical practices can
(the off-site provider). Furthermore, thecost-effectively make the digital transition
patient's records, because of an accidentalwith largely low cost, off-the-shelf
keystroke, could be unintentionallycomponents.
misdirected to an unknown party, thereby
increasing the severity of the securityTaceo, from Essential Security Software
breach. The physician's assistant could haveshould be an integral part of any digital
used Taceo to protect the email andmigration plan. Taceo can help your office
attachments. With the quick click of a buttonsecure the storage and transmission of PHI.
the worker could have prohibited the patientBecause Taceo can be used on almost any PC,
records from being printed, forwarded andit can be used to "bridge the gap" with
edited. The outgoing documents would beoffices of other healthcare providers that
encrypted and un-accessible to anyone besideshave not yet made the switch to digital
the intended recipient healthcare provider.records. Whether digital or analog, all
(Even if the receiving healthcare provider isorganizations that deal with patient medical
not fully set-up to work with electronicinformation  are subject to HIPAA ordinances.
patient healthcare information, they can
still securely view patient records withoutSUMMARY
violating  patient  confidentiality.)
Any healthcare provider or organization that
On-line  Pharmaceutical  Providerworks with patient healthcare data is at risk
for losing control of this information.
A pharmaceutical provider fills prescriptionsUnprotected electronic files containing
via on-line ordering, but cannot meet HIPAAsensitive data can easily be accessed,
secure transmission requirements for emailingaltered, stolen and re-distributed to
regarding prescriptions and medications,unauthorized parties. Electronic protected
order confirmation, and other information tohealth information (EPHI) is subject to
their patients. The organization could resortstringent HIPAA regulations; penalties for
to analog methods such as calling eachviolation of HIPAA rules can result in stiff
individual customer or sending information tofines and jail time. Loss of EPHI can place
the customers via standard post, howeverhealthcare organizations at great financial
these methods are very inefficient and costand  legal  risk.
prohibitive. To meet HIPAA regulations the
on-line prescription provider must shoulderTaceo, from Essential Security Software can
the burden of hiring and training a number ofhelp small to mid-size healthcare providers
new employees at great cost. What is themitigate these risks. Taceo can also help
on-line  pharmacy  to  do?organizations meet HIPAA requirements for the
secure transmission, access and integrity of
With Taceo, the pharmaceutical provider canEPHI. Taceo is effective, affordable and
securely send prescription information, ordereasy-to-use software that enables healthcare
confirmations and more to their clientele.providers to securely store, transmit and
The confidentiality and integrity of emailsreceive sensitive data. Taceo can encrypt and
containing protected health information (PHI)help control access to almost any file.
is enforced and maintained even afterProtected email and documents are safeguarded
delivery. Nearly any customer with a PC1 canagainst unauthorized forwarding, editing,
easily download the free version of Taceo,coping, and printing or screen capture. Taceo
enabling them receive and reply protectedopens up a new realm of possibilities never
email.available before with such ease and
affordability. Healthcare providers can
Taceo's usage permissions interface providessecurely email medical information to their
the company with an effective way to assignpatients. Pharmacies can use Taceo to send
flexible rights management controls based onprescription order information to doctors and
the profile of the client. Emails Containingcustomers  alike.
prescription information can be set to expire
when  no  longer  valid.Caregivers can quickly and securely
collaborate with off-site specialists thereby
Healthcare giver wishes to provide individualensuring patients receive good treatment and
patients  medical  advice  via  emailmuch more.



1 A B C D E 70 71 72 74 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 106 107 109 111 112