Since the signing of the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2009, many healthcare organizations have begun implementing certified electronic health record (EHR) systems to receive financial incentives for demonstrating meaningful use while improving the quality of care. To this end, healthcare organizations and other entities that have HIPAA regulatory requirements are seeking out consulting services from leading third-party vendors to get insight and recommendations aimed at strengthening the information technology (IT) controls surrounding these EHR systems.
 
To ensure a sound IT environment and that proper regulatory and environmental security controls are in place, Marcum recommends that its clients, and all organizations that adhere to HIPAA regulations, Meaningful Use and specifically, the security risk analysis required based on the HIPAA Security Rule 45 CFR 164.308, undergo vulnerability assessments/penetration testing, and perform application reviews.
With many organizations spending a great deal of money to implement an EHR system, very few are being proactive in protecting their investment from unauthorized individuals and malicious attacks. In 2013 alone, there were a total of 20 public healthcare data breaches resulting in approximately 670,000 records being compromised and $12.3 billion in medical identity theft costs. To protect against these kinds of attacks, the following testing should be performed:
• External Penetration Testing
• Internal Penetration Testing
• Wireless Network Assessments
• Internal Vulnerability Assessments
• Network Security Assessments
• IT Risk Assessments
 
Once an organization has implemented an EHR system, it is important to make sure that security controls were properly implemented by performing the following:
• Application Access Reviews ensure that all users are authorized, that access is restricted based on requirements for job responsibilities, and that there is an appropriate segregation of duties.
• Application Security Reviews ensure that security parameters such as unique user logins and strong password policies are adequate.
• Post-implementation application reviews ensure that all security configurations for the newly implemented system are appropriate and that user access was adequately reviewed.