4 ms·
Before even experimenting with this for patient data, I'd be interested in answers to at least the following basic questions: - what logging and auditing is in
by logjam 15y ago
Before even experimenting with this for patient data, I'd be interested in answers to at least the following basic questions:
- what logging and auditing is in place for telling a physician (who is ultimately responsible to his/her patients for their data) who accessed and/or changed data?
- are routine logs provided to users?
- how are backups done, and where do backups of data live?
- who, if anyone, at "drchrono" and/or any server farms used has access to my patient's data and/or backups?
- what is the retention policy for data? How do I get rid of data if needed (drilled all the way down through backups)?
- regardless of any verbiage about "never sharing data with a third party", what policy does "drchrono" have around dealing with subpoenas for patient information?
- what special precautions, if any, are in place for additional privacy around mental health and drug dependence issues?
The mashable advertisement indicates "All the data storage is HIPAA-compliant, as well." Is it? I'm a little confused by the following (difficult to parse) fragment on the website:
"The environment at drchrono currently encompasses the highest level of security as well as the Health Insurance Portability and Accountability Act of 1996 (HIPAA) security tenets that of the proposed regulations."
Perhaps someone from drchrono could let a potential user know if they actually claim "HIPAA compliance", and if so, reassure the user with details of how "compliance" was determined (ie via audit? - and who exactly is the "team of security experts" advertised?)
Less marketing-speak, more facts would be helpful.
- Skeletor 15y agoI'd love to talk with you offline about drchrono to go through all of your issues in detail. You can email support@drchrono.com to get a 1-1 conversation. For security and data issues the government Meaningful Use guidelines have very specific security and encryption standards we follow and are getting certified by a 3rd party government approved lab. drchrono is a professional service for doctors and we only generate revenue by having doctors pay us for premium services (e-prescribing, medical billing, clinical realtime speech to text.) So we never sell any data (even anonymized data) to any 3rd party like some other companies do.
- aaronblohowiak 15y agoWhy only 1-1 ? All of these questions seem reasonable and should be answered in your public materials.
- Skeletor 15y agoAll of these questions are answered in our privacy policy public pages. I could just tell people to RTFM, but doctors and potential customers often appreciate conversations that can address their specific concerns.
- aaronblohowiak 15y agoOh, great! Mentioning that they are in TFM while inviting a conversation would have been useful for us on-lookers. In general, I think that responding to a public request for information with an invitation to communicate privately raises concerns unless it also includes notice that the information is already available publicly (or soon will be made so.)
- aksbhat 15y agoDo you imply that services that sell anonymyzed patient data are unprofessional? Medicine has progressed because of sharing of information, and I dont see any harm in anonymyzed information being shared, as long as its a fair and open market.
- Skeletor 15y agoYes, companies that sell data about their doctors and patients are doing something dishonest in my view and we will never do it.
- aksbhat 15y agohttps://www.amia.org/files/workforthesecondaryuseofhealthdata_09_08_06_.pdf https://www.amia.org/files/workforthesecondaryuseofhealthdat... provides a good discussion about the subject. Then what are your thoughts about http://www.practicefusion.com/pages/pr/practice-fusion-teams-up-with-microsoft-windows-azure-marketplace.html http://www.practicefusion.com/pages/pr/practice-fusion-teams... ?