Government Mandates for Security Not Discussed
I recently attended the Armed Forces Communication and Electronics Association (AFCEA) Health IT Day held at the Mayflower Hotel in Washington DC and I felt like I should have been on the Mayflower not in the Mayflower. Listening to the discussions and banter relating to health care initiatives and information technology I was underwhelmed by the overall lack of creativity and the mixed messages between commercial utilization and government initiatives. For example— It was stated that “we at this agency will use commercial applications and best in class technology for our upcoming Electronic Health Record requirements. Not mentioned however was anything relating to the Federal Information Security Management Act (FISMA) or HIPAA both mandates in this space. You can’t have EHR without security and if FISMA is mandatory how can best in class commercial application that are not ported into a FISMA environment ever get certified and accredited. One comment was made about the creation of an app store similar to Apple Computers for the military… So let me get this straight… I now will be able to download an app for my mobile device to access my DOD records and files from my phone which of course phones have almost no security. One hand states ease of use; the other mandates securing the technology at its lowest common access point…the handset. We need creative thought leaders that understand security is not an option but a necessary mandate and then these leaders must fund industry to develop creative, best-in-class secure solutions.





