Tag: identity theft

Loading...

There is no shortage of data in the healthcare industry. Unfortunately, more data doesn’t always mean better data – especially when it comes to patient information. A unique patient identifier (UPI) is a method for standardizing patient identification. Individuals are assigned a unique code, and that code, rather than a Social Security Number, name, or address, is what is used by healthcare organizations to identify and manage patient information. A standardized code like this not only protects sensitive health information but supports the exchange of data between healthcare organizations and states as it is a number and format easily read and recognized by all. While a UPI has yet to be nationally recognized and implemented, a foundation has certainly been made and the industry is perfectly poised to move forward. How a unique patient identifier is used in healthcare The UPI helps healthcare organizations link the right records together, preventing duplicate records from being created. There are many ways duplicate accounts or variances can occur: address differences, name variations, maiden names and even user entry error. With UPIs, providers and payers can link records together and have one complete record and view of the patient or member, ultimately leading to a better experience and increased patient safety. Without reliable records, patient safety takes a hit. Misidentification can contribute to incorrect treatments and adverse medication interactions that have had life-altering or fatal consequences. The UPI’s ability to achieve accurate record match rates for every patient and member also improves efficient, patient-centered care coordination, as well as population health management strategies, prescription drug monitoring programs (PDMPs), social determinants of health and more. It is important to note that the UPI is not a patient-facing number and is not known to the patient or provider. It does not collect or share any clinical claims or diagnostic information; its purpose is simply to link records together giving providers and payers a complete view of someone’s identity. The patient experience within a real network A healthcare organization’s ability to manage patient data is apparent from the beginning. An inadequate system can force patients to fill out forms they’ve already filled out multiple times or undergo duplicate tests as they travel between facilities. It can also confuse patients who have similar information, such as first and last names, during the identification process. In an ecosystem built around a strong healthcare network, these discrepancies can be avoided. Patients are given a unique identifier that remains consistent across every healthcare facility they visit, from physicians’ offices to hospitals, pharmacies, specialists, long-term care facilities, and more. All providers that patients visit know exactly who they are. And it isn’t just greater comfort and convenience that patients gain from a well-connected healthcare network. Managing patients and their data is vital for reducing medical errors. One Johns Hopkins study found that medical errors account for more than 250,000 deaths annually in the United States. Healthcare efficiency within a real network The challenge of managing patient data across the entire healthcare ecosystem isn’t new — interoperability has been a hot button issue for years now. While there are several master patient indexes that organizations can use to match patients with appropriate demographic data, these still include gaps, overlaps, and outdated patient information. These indexes can’t keep up with simple things such as name and address changes or data entry errors. Therefore, providers and payers who rely on them have trouble matching their patients and members accurately. A more effective solution involves combining these data sets to create complete identities and profiles, where every piece of new data is instantly updated and verified. For example, if a provider has a patient in their EHR twice under two spellings of the patient’s name in error, a UPI would link those two profiles, creating a singular view of the patient in that provider’s system. Similarly, a UPI can help facilitate interoperability between healthcare providers. For example, if a pharmacy has a patient listed under a maiden name but the doctor has that same patient under a married name, the prescription during the ePrescribing process might not get associated with the right profile. If both organizations have the UPI on record and submit it during the transaction, the systems will match the patient using the UPI. Every authorized care team member can immediately access the updated data related to a patient or member’s identity, which offers benefits far beyond treatment. For providers, this could mean increased collections. For payers, it could look like improved medication adherence. For example, ValleyCare Health System in northern California was struggling with hundreds of bills being returned each month because of wrong patient addresses. When the health system implemented an identity verification program, it decreased the amount of returned mail by 90 percent. The network effect in a nutshell Sorting through clinical data issues takes up a great deal of time. The administrative costs of healthcare account for nearly 8 percent of U.S. healthcare expenditures. By identifying patients through unique socioeconomic factors, healthcare organizations can more efficiently and accurately manage data and put it to good use. A healthcare network tied together by streamlined data management provides an environment where duplicate or inaccurate information is detected and corrected almost immediately. Both patients and members are accurately identified, and their data retains its quality at every stage of care. When combined with other patient engagement solutions, such as patient portals, data and identity management tools create the infrastructure needed for healthcare to truly become one cohesive, patient- and member-centric network. Unique patient identifiers in the news Until recently, the use of federal funds for the adoption of a national patient identifier (NPI) was prohibited. The ban has limited the Department of Health and Human Services (HHS) from interacting with healthcare organizations to develop and implement an NPI strategy. In the years since the funding ban put the brakes on a universal approach, many disparate software solutions have been created which don’t talk or share information with each other. Integrating these systems in an industry of this scale will take a concerted effort. The ban was lifted in July of 2020, giving HHS the ability to evaluate a full range of patient matching solutions and enable it to work with the private sector to identify a solution that is cost-effective, scalable, secure and one that protects patient privacy. Karly Rowe, Vice President, Patient Access, Identity, and Care Management Products at Experian Health believes that “private-sector entities have already developed the technological foundation for data interoperability through the creation of UPIs that are maintained in a master person index.” These solutions are vendor neutral, meaning data can flow freely between disparate electronic health systems, regardless of size or location. With federal funding back on the table, “UPIs could be adopted with government oversight of private sector offerings and the creation of national standards to ensure quality patient matching and identification.” At the end of 2019, Experian Health announced that every person in the United States (about 328 million Americans) had successfully been assigned a unique UPI, powered by Experian Health Universal Identity Manager (UIM) and NCPDP Standards™ (the “UPI”). Combining Experian’s expansive data assets and innovative UIM technology along with the unique ability NCPDP brings to share the UPI throughout the healthcare ecosystem using the NCPDP Telecommunication Standard and its SCRIPT Standard, each individual in the U.S. that has received medical care or utilized a pharmacy has been processed through the solution and assigned a UPI. As new patients enter the healthcare ecosystem, this number will continue to grow. Learn more about unique patient identifiers Having a single, unified and accurate view of patients and members is a challenge that plagues the healthcare system. Now, there is promise of a comprehensive solution that reduces the barriers to make healthcare safer. Interested in learning more about unique patient identifiers and how Experian Health can help?  

Published: January 26, 2021 by Experian Health

Medical identity theft is a growing concern for healthcare organizations in the digital age. In 2017, healthcare data breaches accounted for 24% of all data breaches, rising to 29% in 2018. In just 12 months, the total number of personal medical records exposed jumped from 5.3 million to 9.9 million. In fact, healthcare data breaches tend to expose many more individual records than other industries. For example, according to the Identity Theft Resource Center, 43.9% of breaches in the first half of 2019 were in business, while only 36.9% were in healthcare. But for healthcare, this meant exposing a staggering 77.4% of all records left vulnerable to identity theft, compared to just 9.5% by business breaches. The potential impact of a healthcare data breach seems to be further-reaching than in other fields. At the same time, healthcare is slightly behind other industries when it comes to data security. Financial services have a two-decade head start to refine their anti-fraud strategies. This, coupled with the fact that medical identities are worth 20 to 50 times more to fraudsters than financial identities, means medical identity theft is increasingly appealing to criminals. It’s a big concern, but healthcare organizations can use data to fight data theft. When you’re armed with the right information, you can put in place the right strategy to protect your patients. What is medical identity theft? Medical identity theft is when someone uses another person’s health-related identifying information without them knowing. This could include their name and address, Social Security number, health records, or insurance information. Fraudsters can use this information to access medical services without paying, submit false insurance claims, or buy drugs. They pretend to be someone else to access services illegally. In addition, that personal information could be used for other kinds of identity fraud or blackmail. What are the consequences of medical identity theft? Karly Rowe, Vice President New Product Development, Identity & Care Management Product at Experian Health, says: “For patients, the impact of having their personal information stolen, and then possibly used to make false claims in their name, can be hugely violating. When someone’s record becomes overlaid with a thief’s record, this can have massive consequences for that person’s future treatment. It’s a major stress to sort out – both administratively and financially. And for organizations, there’s obviously the reputational hit. The relationship between provider and patient is based on trust. When you fail to secure your patients’ most personal information, you risk losing that trust for good.” It’s also a major cost. Medical fraud in the U.S. is estimated to cost somewhere between $80 billion and $230 billion, with the cost to individual providers and payers coming in at around $2 million per breach. To tackle the problem, healthcare organizations are stepping up their security practices across the board. A HIMSS survey, in partnership with Experian Data Breach Resolution, reported that data security strategies have improved. Ninety-two percent of those asked had performed a formal risk analysis, and more than half had increased their patient data security budget. A number of organizations also teamed up to form the Medical Identity Fraud Alliance, to mobilize the industry to tackle the problem. Still, there’s a ways to go. 3 ways to leverage data insights to prevent medical identity theft Protecting patient data calls for a data-based solution. Here are three ways to leverage consumer data and technology to protect your patients and keep their information safe: Resolve patient identities. Accurate patient data is the cornerstone of data management. If your records aren’t entirely reliable to begin with, keeping them safe and secure will be much harder. Put preventative measures in place to minimize the risk of duplicates and errors. Assigning a Universal Patient Identifier (UPI) will let you follow the entire patient journey, so you have a complete, accurate and secure picture of each patient. Protect patient identities. Patient portals allow people to access their health information from their personal devices. It’s convenient and can improve engagement and health outcomes. Unfortunately, they can also become vulnerable to breaches by data thieves. You have to make it easy for patients to use portals, but difficult for fraudsters to get their hands on that personal data. As patient portals gain popularity, you must have the right technology in place to validate and protect patient identities. Automating patient enrollment with a tool like Precise ID® can help authenticate patient identities from the start using identity-proofing, fraud management and device recognition. Enrich patient identities. With data insights, you can check that your patient is who they say they are the moment they arrive in reception. Using the broadest and most trustworthy datasets, identity verification solutions make constant checks, so you have a single, accurate and 360° view of each patient. Not only is this ‘golden record’ the cornerstone of patient care and experience, it’ll let your staff update patient data during intake without manual corrections. Medical records contain some of the most sensitive personal information, so it’s vital to safeguard it with the strongest security that exists. — Download this free eBook to learn how to evolve today\'s patient matching technologies or find out more about how to protect your patient data and prevent medical identity theft.

Published: August 20, 2019 by Experian Health

  Medical identity theft is a growing problem for the healthcare industry: nearly 15.1 million patient records were compromised in 2018, an increase of nearly 270% on the previous year. While providers are busy rolling out patient portals and electronic medical records to better serve consumers, criminals are sneaking through the cracks to steal patient data and profit from vulnerable health systems. The rapid rise in medical identity theft is partly explained by the fact that it goes undetected for much longer than other types of identity theft, giving criminals more time to use stolen personal information for financial gain. It’s also a lot more lucrative. Medical identities can be used to access treatment and drugs, make fraudulent benefits claims and even create fake IDs to buy and sell medical equipment. This can be devastating for victims, both emotionally and financially. Unlike credit card theft, where victims aren’t considered financially liable, 65% of people who fall prey to medical identity fraudsters are left with hospital bills running into the tens of thousands. The compromised medical record is tough to reconcile, jeopardizing future medical treatment. For providers, a data breach can mean significant reputational damage and loss of trust, and huge financial consequences – each breach costs an average of $2.2 million. But what’s most alarming for providers is that more than half of data breaches originate within the organization. Unfortunately, many providers lack sufficient security protocols and detection tools to safeguard the data they’re holding. The good news is that the tools exist to help you protect your patient data. What can healthcare providers learn from other industries about identity protection? Banking and financial services have pioneered identity protection over the last twenty years, and healthcare can learn a lot by looking at what’s worked in those industries. For consumers, using digital technology to pay your bills, book flights and buy pretty much anything is the norm, all with reassuringly quick fraud detection and resolution. Healthcare has been a little slower to embrace digitization in this way. Despite the opportunities, fears around security, privacy and inconveniencing patients have stalled efforts to transform outmoded processes. Drawing on two decades of innovations in other fields, fast-paced technological developments mean many of the early challenges around implementing safe and secure patient portals have been overcome. 6 strategies to keep patient data safe Here are six smart ways to ensure your organization has done everything possible to safeguard patient data.     Tell your patients how you’re keeping their data safe Patient trust is at the heart of a successful patient-provider relationship. Share the steps your organization is taking to secure patient information, so patients feel reassured and confident in using their portal. Data security should be a key strand in your patient engagement messaging.     Verify patient identities to protect access to medical records To avoid HIPAA violations, it’s critical to ensure you’re giving access to the right patient. Secure log-in monitoring and device intelligence can help you confirm that the person trying to log in is who they say they are. When something doesn’t add up, identity proofing questions can be triggered to provide an extra check. In an exciting new development, the healthcare industry is also starting to see the use of biometrics to supplement existing identity-proofing solutions. Just as you might use facial recognition to unlock your smartphone, there are now ways to authenticate your healthcare consumers’ identity using the same technology.     Automate patient portal enrollment You want your portal to be as secure as possible, but not at the expense of your patients’ time and effort. An automated enrollment process can eliminate the hassle of long, complicated set-ups and reduce errors at the same time.       Arm your organization with a multi-layered security strategy There is no silver bullet for protecting patient information—it will require various tools. A robust data security strategy will be multi-layered, including device recognition, identity proofing and fraud management.     Educate staff on security threats and warning signs Data breaches aren\'t all malicious – human error is a massive component, from mailing personal data to the wrong patients, to accidentally publishing data on public websites or leaving a laptop behind after getting off the subway. Training staff on the potential pitfalls will help them help you in protecting confidential patient information.     Develop a robust device strategy ‘Bring Your Own Device’ arrangements (BYOD) are convenient for staff and patients, but personal devices need to be secured when accessing patient information across the network. Make sure your teams, patients and visitors are aware of how to log-on securely to WiFi and follow best practice to keep data safe. In a climate of ‘doing more with less’, healthcare leaders are turning to other industries to find ways to boost quality of care and streamline operational efficiency. Automation, digitization and consumer-centric approaches make good business sense across the board, but they’re sensible investments for your data security strategy too. Investing in secure patient identities is a way to prevent painful and unnecessary losses down the line – and it’s what patients have come to expect. ⁠— Find out what more you could do to shore up your data security and prevent medical identity theft.

Published: July 23, 2019 by Experian Health

“Build it and they will come” might work for 1980s movie characters, multinational coffee franchises and beloved sports teams, but it’s not a great engagement strategy for most consumer-facing organizations – especially in healthcare. Take patient portals, for example. Giving your patients a way to access their health records can help improve their health outcomes, increase compliance with care plans, and create a more positive healthcare experience overall. But do your customers know the portal exists? Do they know how it could serve them? Do they trust it? You’ve built it, but how many patients are actually logging on? In 2017, over half the US population had access to a patient portal. Around half of those people used it at least once in the previous year. Of those who didn’t, 59% said it was because they didn’t feel they needed to access an online medical record, and 25% were worried about privacy and security. This tells us two things: If healthcare providers want to increase the number of patients using their portal, they need to proactively communicate the benefits to those patients, and healthcare providers could do more to reassure patients they take portal security seriously. If patients discover that using the portal is better than not using it, and that they can do so securely, they will be more likely to log on. You can address both in your patient engagement and marketing strategies. Perhaps the better mantra is: “if you solve their problem and tell them about it, they will come”. Balancing portal security and patient convenience Your patient portal is more than just a platform for patients to access test results, sort out bills or schedule appointments. It’s a way to nurture the patient-provider relationship. And at its heart, that relationship is about trust. One way to build trust is to ensure your portal meets the strictest of security measures without creating an excessive admin burden for patients. You can do this with a security strategy that layers up several protective measures to help you tackle common areas of vulnerability, including weak ID verification, over-reliance on password-protection, and failure to encrypt sensitive data. A few practical ways to keep your patient portal secure include: using ID verification when someone signs up for the portal using device intelligence and identity proofing when a user signs in to the portal deploying extra security checks where the risk of identity fraud is higher putting systems in place to flag and respond to security breaches as fast as possible. A solution like PreciseID® can help you take care of your patients’ privacy and security behind the scenes. They’ll see just enough to reassure them that you’re taking their security seriously, without any protracted log-in process that puts them off using the portal altogether. Marketing your patient portal so more patients benefit from it Solving your patients’ concerns about security is just one route to boosting portal utilization. Another important way to ensure more patients use and benefit from the patient portal is to actively encourage them to access their online records regularly. Research suggests individuals who are encouraged to use their online medical record by their provider are almost twice as likely to access it, compared to those who weren’t actively encouraged. So how do you convince your patients of the benefits of regularly logging on? That it’s not just a convenient way to manage their medical journey, but could result in better health? The answer lies in consumer data – the lifestyle, demographic, psychographic and behavioral information that gives you a fuller understanding of what drives your patients. Experian Health’s ConsumerView data analytics can capture insights that let you reach out to your consumers with the right message, in the right way, at the right time.  Do they live a busy lifestyle? Reassure them that the portal can save them time. Are there lifestyle factors that may hinder their adherence to medication? Encourage them to use the portal to make sure their prescriptions are up to date. If you discover your consumers are big social media users, you might target your portal engagement campaign through those channels. Equally, if a consumer doesn’t have any social media accounts, there would be no point investing in Facebook ads. Personalization makes your patients feel taken care of, leading to greater trust, loyalty and satisfaction. Increase patient portal engagement today In the wake of consumerism and IT transformation across many other industries, a tailored and digitally secure healthcare service is a must.  “Consumers now expect to be provided with a turnkey, individual experience that is fast and seamless,”  said Kristen Simmons, Experian Health’s senior vice president of strategy and innovation. Your patient portal must be seen to provide a valuable and secure service. While there’s a way to go to increase the number of patients making full use of portals, the tools exist to support healthcare providers’ engagement goals. Learn more about how your organization can leverage consumer insights to improve patient retention and engagement. 

Published: July 16, 2019 by Experian Health

  The roll-out of patient portals has been a slow burn. While consumer finance, retail and other markets have given customers secure electronic access to their personal information for decades, healthcare has been playing catch-up. But thanks to regulatory pushes, such as the Promoting Interoperability and Meaningful Use programs and the Affordable Care Act, digitized health records are now the norm. Over half of healthcare consumers in the US use patient portals to access their health information at the click of a button – just as they do with their bank accounts or grocery deliveries. Aside from the convenience factor, research suggests that when patients have access to their health records through patient portals, they experience better health outcomes, greater satisfaction levels, and improved communication with their provider. There’s a higher chance of spotting errors. Adherence to medications is increased, and care becomes more accessible for some otherwise hard-to-reach patients. For providers, this sense of ownership, transparency and connection contributes to elevated consumer loyalty and engagement. As consumers embrace online portals to view their medical records and lab results, renew prescriptions, schedule appointments, and in some cases pay bills, they expect and assume their provider will keep that data secure. Providers must balance convenience and security. Unfortunately, some patients remain unconvinced of their providers’ ability to get this balance right. Patients worry about portal privacy and security Despite the upsides, a quarter of patients with access to online portals in 2017 chose not to access them because of worries about privacy and security. They’re right to be cautious: medical identities are said to be worth 20-50 times more than financial identities. It\'s no wonder identity thieves are increasingly targeting the healthcare industry. In 2018, the US Department of Health and Human Services’ Office for Civil Rights (OCR) reported 351 data breaches of 500 or more healthcare records, resulting in the exposure of more than 13 million patient records. Hackers are always on the lookout for vulnerabilities to exploit, with patient medical records, log-in credentials, passwords and other authentication credentials among their top five targets. Without adequate IT security, your prized patient engagement tools – like patient portals – can become an open door for hackers. As a provider, your job is to make it easy for patients to access and manage their own data, but hard for fraudsters to get their hands on sensitive data.​​​​​​​​​​​​​​ ​​​​​​​How to keep patient portals secure The good thing about being somewhat late to the party is that healthcare organizations can learn from other industries in how they have tackled online security challenges without creating too much of a burden for consumers. Think about how consumers authenticate their accounts for financial services or even social media profiles. Typically, there\'s an email to verify they are who they say they are, or a two-factor authentication process with a code sent to their cell phone. Most patient portals don\'t have these layers of security. At Experian Health, we recommend a multi-layered solution incorporating device recognition (especially important as more users access portals via cell phones and tablets), identity proofing and fraud management. Here are some examples: Sign-up screening When someone enrolls in the portal, use identity proofing to ensure they are who they say they are. It’s particularly important to ask out-of-wallet questions, such as their city of birth, first car model, or previous address to make sure they’re not an imposter.     Log-in monitoring Device intelligence will help you confirm the patient is using a cell phone or tablet your system recognizes, to minimize the risk of someone else accessing their account. This technology will tell you if the device is associated with previous fraudulent activities or potentially impersonating multiple patients. If a device fails to meet the risk threshold, identity proofing questions can be used to verify the user’s right to access the account. Additional checks on risky requests Some patient portal activities, like downloading medical records and editing a patient’s profile, increase the risk. You’d want to add an extra layer of control here, such as additional out-of-wallet questions, to safeguard your patient’s data. Rapid response and damage containment Given the sensitivity and richness of medical data, an attack on the portal can be devastating for patients and costly for providers. In the event of an attack, providers can put in place early warning systems to flag up which patients have been compromised and trigger rapid response measures to shut down the attack and prevent the damage from spreading. Promote interoperability Physicians and care providers need to share information on patients in the course of providing good care. But how are they doing this? To keep that data secure and ensure it’s only seen by the right people, you can set up your systems to share data across different platforms in a safe and secure way. Underlying all of this is the need to reassure your patients that you can be trusted with their data. Victoria Dames, Senior Director of Product Management, Experian Health, explains: “Healthcare breaches are nothing new, and neither is hackers’ and identity thieves’ penchant for medical records. What is new, however, is the broad range of tools that organizations can now utilize to stop them from accessing that personal data. Give patients the peace of mind they deserve by taking advantage of up-to-date solutions that actually work in our ever-evolving tech climate.” Learn more about how protect patient portals and encourage more patients to enjoy the full benefits of their patient portal, knowing that their sensitive personal details are safe.

Published: June 11, 2019 by Experian Health

People increasingly expect immediate access to information at their fingertips. They want online access for everything from food delivery to healthcare. But as healthcare organizations enroll more patients through online access, how do they protect themselves from data breaches without impeding patient engagement?   Data breaches are more prevalent and costlier than ever. Up 6.4 percent in 2018 compared to 2017, the global costs of data breaches reached $3.86 million last year.   The healthcare industry has been particularly hard-hit. Over 90 percent of organizations have experienced a data breach since 2016, and more than 180 million records have been stolen since 2015.   Just last year, a Missouri-based healthcare organization discovered that its patient portal was vulnerable for more than a month after hackers installed malware. In that time, almost 6,000 patients’ debit and credit card numbers could have been compromised. This incident alone demonstrates that improving cybersecurity in healthcare is vitally important.   This is why one of New York\'s largest medical groups, AdvantageCare Physicians, made it a priority to strengthen the security of its Epic MyChart by adding a multilayer identity verification step at the time of patient enrollment and throughout every portal access request thereafter.   Patient identity verification secures patient portals   More than just satisfying the need for constant connectivity, patient portals are exceptionally helpful. They allow patients to access test results, view their medical record, schedule appointments online, and communicate with their providers from their mobile devices.   Despite online platforms being a target for hackers, AdvantageCare Physicians executives know that patient portals help patients engage in their healthcare and empower them to take control of their health. So the organization turned to the same technology that is trusted by banks, retailers, and government agencies to protect this valuable tool.   Identity-proofing technology can quickly authenticate patients when they access an online portal by evaluating the identity, device, and risk factors of a given user. This multilayered check happens in a second so patients aren’t left waiting on a load screen. Through continuous protection that ensures complete security without sacrificing ease of use, patients\' trust grows because they know their electronic medical records are safe.   This patient trust can go a long way. A Software Advice study found that due to concerns about data breaches, 21 percent of patients keep information from their doctors. Securing its patient healthcare portal with Experian Health’s Precise ID helps AdvantageCare Physicians open up communication to provide better care. This, in addition to improving access to resources, supports the organization’s goals of improving health management and promoting wellness.   These additional verification steps also protect AdvantageCare Physicians from compliance risks. For example, the Centers of Medicare and Medicaid Services’ Promoting Interoperability standards set out requirements for collecting and maintaining electronic medical information to ensure healthcare cybersecurity. Experian’s Precise ID complies with this and many other programs.   Decreased need for IT support   Given the many advantages of a fully protected patient portal, AdvantageCare Physicians\' final concern was the effect of increased self-service traffic. More users accessing the portal more regularly might create bottlenecks. But patient identity proofing actually increases the platform’s user bandwidth.   For example, Precise ID streamlines the process for patients signing up. Traditionally, AdvantageCare Physicians\' IT department would have to validate each new patient identity on the back end, but Precise ID can quickly authenticate these users. This has reduced the need for IT support by 80 percent. IT also spends less time correcting records because letting patients create their own accounts increases accuracy while reducing the number of duplicates.   Online self-service platforms for healthcare organizations like AdvantageCare Physicians enhance patient care. But just like any other online transaction, patients need to know that any information they provide through the portal is secure. Sufficient cybersecurity for its healthcare portal lets AdvantageCare Physicians focus on delivering the personalized resources patients need without the worry of a data breach.   Learn more about how to reduce risks during patient enrollment.

Published: March 5, 2019 by Experian Health

In a recent healthcare information technology survey, more than 40 percent of chief information officers identified patient matching as healthcare’s top IT concern. And though a quarter of the respondents admitted it wasn’t a current priority for their organizations, they did say that it very much should be. There’s no shortage of reasons why, but the most pressing is the need to reduce medical errors, which account for over 250,000 deaths in the United States every single year. Case in point: Seventeen percent of CIOs acknowledged that errors in matching data with the right medical identities have led directly to adverse outcomes for patients. The numbers speak for themselves: Healthcare organizations must find more effective ways to manage the data within their networks. That begins with building a robust medical database that not only hoses data, but also knows how to match it with the proper patients. How robust EMPIs streamline workflows An enterprise master patient index (EMPI) is a database that can help you clean up your data and eliminate duplicate and inaccurate records. It uses algorithms to match exact data elements among disparate records, as well as elements that fall within an acceptable range of possible compatibility. Using technology that can apply an algorithm of probabilistic and referential matching methodologies will allow healthcare organizations to expand beyond the limitations of conventional single methodology matching, as both probabilistic and referential matching techniques provide a higher degree of likeliness. The system assigns these data points to unique identities that follow patients throughout the organization. Any new data generated within the network is also attached to this identity, meaning physicians, specialists, pharmacists, and other members of the patient’s care team can access and update it as needed. EMPI support tools and unique patient identities are building blocks toward creating a healthcare ecosystem that’s truly interoperable. According to an April 2018 survey by Black Book, hospitals with an EMPI report “consistently correct patient identification at an overall average 93 percent of registrations and 85 percent of externally shared records among non-networked providers.” Unfortunately, not all healthcare systems possess the IT infrastructure to support these programs. And as long as some organizations fail to integrate similar platforms, providers won’t reap the benefits of industry-wide interoperability — and patients will continue to suffer. Whether it’s a frustrating billing mix-up, privacy breach, or a detrimental (or even fatal) misdiagnosis, many errors can be successfully prevented with an EMPI. Filling in the holes The goal of such a system should be to standardize data entry and access within each healthcare organization, as well as across the entire industry. Such a network could protect, govern, and match unique patient identities across every discipline and every aspect of their care continuum. But in order for the system to achieve these goals, you need to be sure you’re feeding it relevant, recent patient information. To ensure you have enough patient data to build an EMPI that accurately matches profiles, ask yourself these questions: 1. What kind of medical care have my patients received before this visit? When patients enter a new hospital, they’re given a brand-new identity, or patient number, that’s only relevant to that healthcare system. The identity you assign them within your own organization doesn’t provide any insight about what they’ve experienced before their current visit — and that’s the crux of the matter. When patient information is siloed within a specific system, you have no view of the patient’s medical history. But when it’s shared across systems and fed into a more dynamic and interoperable data management system, patients will ultimately receive better care. 2. Who are my patients when they’re not “patients”? It’s important to understand who patients are when they’re not in the hospital. Yes, they’re husbands and wives, mothers and fathers, brothers and sisters. But some could be physically fit, while others haven’t seen the inside of a gym in years. Some might get regular checkups, but others cannot afford to see a physician regularly. All of these traits factor into your patients’ identities. With a comprehensive EMPI, you can tie them together to understand the environmental and socioeconomic factors that influence your patients’ health. You can then identify what social determinants of health need to be addressed or could potentially influence the efficacy of certain treatments. 3. Can we identify patients without a picture ID? Biometrics such as fingerprints and iris scans are more secure forms of identification than a photo ID. They’ll not only make it easier to identify patients, but will also offer heightened security against fraud. That being said, even biometric identification isn’t 100 percent secure unless it’s part of a database, such as the EMPI, that accurately matches patient identities with relevant medical data. Accepting that the healthcare industry needs better data management and patient-matching strategies is the first step to realizing those goals. EMPIs have shown organizations the value in universal patient identities. Now, they simply need comprehensive databases that are robust enough to keep patient identities consistent across the entire healthcare ecosystem.

Published: November 8, 2018 by Experian Health

Not every healthcare organization embraced electronic medical records (EMRs) at first. But the incentives and regulations put in place by Meaningful Use and the Affordable Care Act have made it necessary to implement them. Now, organizations are not only embracing EMRs, but also making it easier for their patients to access and manage them through remote portals. According to the Office of the National Coordinator for Health IT, approximately 63 percent of patients who used portals did so at their doctors’ recommendation. Despite the growing popularity of patient portals, there are still more than 25 percent of patients who refuse to use them for fear of jeopardizing their data. Considering the sensitive nature of their protected health information (PHI), along with the nearly 5.6 million health records that were compromised last year, those fears are more than reasonable. What can providers do? Hackers have honed in on the healthcare industry for two main reasons: the treasure trove of valuable information in medical records and a sometimes dated approach to cybersecurity. In fact, between 2009 and 2016, more than 30 percent of all big data breaches occurred within healthcare systems. Without proper encryption methods, login redundancies, and detection tools, portals are almost as easily accessible to hackers as they are to authorized users. As their usage grows, that lack of security will become an exponentially greater threat to patients’ PHI and identities. “Many of us are accustomed to keeping the same name and password with our accounts, and as we know, that information is very lucrative to the right individuals,\" says Victoria Dames, Director of Identity Management for Experian Health. \"While it\'s our due diligence to constantly change them, there are certain scenarios where maybe we forgot to change them or we don’t regularly login and that password may sit idle. When that happens, you want to make sure that you have the right technology in place to be able to catch somebody potentially logging in, trying to impersonate a patient.” Providers can’t lower the value of PHI to make it less attractive to hackers, but they can protect it more effectively with up-to-date cybersecurity measures. These four tips can help organizations bring their patient portal security up-to-date and keep their networks safe from unauthorized access: 1. Automate the portal sign-up process. Automating the initial sign-up process can stop false enrollments into the portal at the source. When implemented correctly, the automation will only require the patient to enter a few pieces of information, and then the software can confirm the user’s identity on the back end. 2. Leverage multilayer verification. After patients have signed up to access the portal, using multilayer verification can ensure all future sessions are equally secure. For example, two-factor authentication adds additional protection on top of conventional login credentials. In addition to a password or PIN, users also have to provide something personal such as a cell phone number, ZIP code, fingerprint, iris scan, or more. If the user’s device, account ID, and/or password are compromised, two-factor authentication can ensure the organization’s network remains safe. 3. Keep anti-virus and malware software up-to-date. Multilayer verification protects users’ direct access to portals, but there are other, more frequent vulnerabilities that also need attention. For instance, HIMSS Analytics recently found that 78 percent of providers experienced ransomware and malware attacks last year. Email is the avenue of choice for malware, and these attacks constantly evolve to slip past conventional security measures. If anti-virus software is outdated, it remains vulnerable to every new iteration of malware that attacks the network. Most solutions allow for automatic opt-ins so updates are downloaded and installed as soon as they’re made available. 4. Promote interoperability standards. When primary care physicians, specialists, and healthcare payers talk to one another throughout the course of a patient’s care, it isn’t always through email. When their systems aren’t compatible, they can’t communicate as clearly and securely as they need to. Interoperability makes it possible for disparate systems to share medical histories and patient data while making that data easily understandable on either system. Because interoperability is essential for improving the continuum of care, the Centers for Medicare and Medicaid Services provide standards for healthcare organizations to promote it. More patients and providers are optimistic about using technology to improve the healthcare experience. However, one in five patients remain so suspicious of healthcare data security that they refuse to even divulge some information to their physicians. Fortunately, with the right tools, organizations can effectively strengthen portal security and boost the confidence their patients have in them.

Published: October 16, 2018 by Experian Health

There\'s no question that portals increase patient engagement. According to the Office of the National Coordinator for Health IT, almost eight in 10 patients appreciate the improved access to healthcare information afforded to them by self-service systems. Unfortunately, portal systems also offer an obvious target for healthcare hackers. Within a patient portal, criminals can steal medical identity data, which is worth somewhere between 20 and 50 times as much as financial data, such as credit card numbers. They then use the stolen information to submit fraudulent claims, fill prescriptions, and resell medical equipment. What\'s more, because many healthcare organizations lack proper detection tools and some patients neglect to check their explanation of benefits (EOB) statements, health data breaches tend to go undetected longer than those in other sectors. No wonder healthcare data security incidents rose 211 percent in 2017, according to the 2018 \"McAfee Labs Threats Report.\" Protecting patients\' data with technology Patient portals engender patient engagement and loyalty, but if a data breach occurs, that loyalty is quickly lost. Besides losing patients’ trust, healthcare organizations that experience a data breach face potentially severe HIPAA penalties. Healthcare firms can learn a great deal from how other industries have met similar security challenges without overburdening consumers. Providers can use best-in-class technologies, data and analytics systems, and their deep understanding of patient needs to manage risks and protect patient identities. To arm providers against breaches, Experian Health offers Precise ID® with Digital Risk Score to protect portal users’ identities from their first sign-in to their last. By automating the portal signup process, it stops false enrollments at the source. Then, using multilayer verification, it provides access protection for future sessions. Because Precise ID takes less than a second to evaluate access risks, patients don\'t need to sit through loading screens. On the provider side, Precise ID satisfies the Centers of Medicare and Medicaid Services\' Promoting Interoperability standards, minimizing compliance risks. At a time when one in five patients withhold information from physicians because of data breach concerns, Precise ID builds trust between patients and providers by protecting patients\' data from unauthorized access. Giving patients the power to access their medical information through portal technology has been one of the past decade\'s biggest steps forward in improving patient-provider relationships. But with that reward comes responsibility: Providers must protect portals from unauthorized access and theft of medical records. With Precise ID with Digital Risk Score, providers get the security they need, and patients get the seamless access they\'ve come to expect.

Published: June 5, 2018 by Experian Health

Categories

Subscription title JR New new

Description This is a test

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Archives

Subscription title

Description
Subscribe