https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Specialty Practices


Understanding Healthcare Data Security and Privacy Obligations

  • Written by Dan Liutikas 1
  • August 31, 2015
Who's responsibility is it to ensure healthcare data the cloud is secure? It's everyone's responsibility, including the customer.

Simplicity and affordability of IT are two major selling points for end customers in moving to the cloud. But in highlighting the benefits, MSPs must take caution not to let customers think the cloud offers a cure-all for data privacy and security.

After moving data to the cloud, customers do not eschew responsibility for protecting private data. This fact is especially relevant for healthcare companies subject to Protected Health Information (PHI) rules under the Health Insurance Portability and Accountability Act (HIPAA). PHI pertains to health information linked to specific individuals transmitted and maintained in any medium, including electronic systems.

In their deals with healthcare customers, MSPs often act as intermediaries between end customers and cloud providers. This requires a delicate balance to ensure customers do their part to secure private data and cloud providers have the protocols and infrastructure in place to handle heavily regulated healthcare data. If you are an MSP specializing in this space, here are a few guidelines to consider:

Negotiate Wisely

When negotiating a deal, MSPs must explain that customers have a critical role in protecting end user data. Customers need to understand while the cloud typically provides added security, that data remains the customer’s responsibility when handled by their users in their facilities.

Users access the cloud from their company’s network. As part of your contract with the customer, you may take on the responsibility to keep the network—as well as the applications and systems within it—secure and reliable. Check that the network is already sufficiently robust to import and export the types and amounts of data used and stored by the company. If it isn’t, get the customer to commit to bring the infrastructure up to the required standards.

Address Control Issues

When PHI data is moved to the cloud, the Covered Entity (CE) loses some degree of control. As defined in HIPAA, CEs include health plans, healthcare clearinghouses and healthcare providers that transmit health information electronically.

The loss of control results from sending data to servers outside the customer’s firewall. Unless the customer pays for dedicated resources in a virtual private cloud, the data goes to a server shared by other customers of the cloud provider in a multi-tenancy arrangement. That’s how the public cloud works.

In addition to sharing a server, your customer’s data and workloads may travel from one server to another as the cloud provider sees fit. Such data transfers may cross geographic locations more than once, unbeknownst to the customer. Be sure to go over this with customers to set the right expectations.

Implement Access Safeguards

CEs rely on their cloud provider’s expertise to secure their data and manage user access to it.

But keep in mind cloud providers have to deal with the same security issues that affect any other computer system or network. They can make an even more attractive target for hackers because of the concentration of data they handle.

So they take precautions to control access to CE data such as imposing uniform, enterprise-wide management, privacy and security protocols. To further strengthen the privacy and security of those protocols, cloud providers may offer customers additional configurable security tools. That way, a customer has the ability to require stronger identifiers for users to access data that go beyond the cloud provider’s authentication requirements. This adds an extra layer of protection that is entirely up to the customer to impose.

Check the Provider’s Record

Getting healthcare customers to understand their role in data security is key, but don’t forget to check the cloud provider’s track record. It is important to gain assurance that the cloud provider is following proper privacy and security safeguards in compliance with HIPAA before entering a partnership.

And whenever you sign a contract, be it with the cloud provider or the end customer, make the time to ensure all parties understand their responsibilities and that the contract clearly spells them out.

The cloud opens up a lot of opportunity and promise, but it comes with a lot of risk and responsibility when deployed without measure. Take the proper steps to protecting you and your customers so that you both succeed.

Dan Liutikas is the Managing Attorney of ITLA | InfoTech Law Advocates, and also serves the greater IT industry as Chief Legal Officer of CompTIA, the premier IT trade association.

 

Tags: Agents Cloud Service Providers MSPs VARs/SIs Specialty Practices

Most Recent


  • Microsoft Exchange Hack: Cloud-Based Software Now Looks Less Scary
    A jump in the number of cloud subscriptions is likely.
  • XaaS
    How MSPs Can Take Advantage of the XaaS Business Model
    Providers can help IT deliver niche services that enhance agility and efficiency.
  • Mergers and acquisitions
    ARG Expands Investment Portfolio with NextWave Acquisition
    ARG adds to its technology services expertise with the acquisition.
  • Data management platform
    Informatica Bolsters Cloud Data Management Tools, Certs for Partners
    The company is responding to projections that enterprises will spend significantly more on cloud this year alone.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • 2020-21 Trends
    6 Big Trends Shaping the Managed Services Market
  • Security Vulnerability
    McAfee: Software Vulnerabilities Threaten Schools Amid Return to Campuses
  • phishing
    Phishing Email Warning Shows Cybercriminals Seizing on Tax Filing Delay, Vaccine Rollout
  • Enhance
    Claroty Partners Get Expanded, Enhanced Channel Program

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Enterprise Connect 2023 Expo Hall: RingCentral, VMware, Five9, Cisco, More

March 31, 2023

HP’s Head of Global Channel Strategy Talks Program Changes, Poly Opportunity

March 31, 2023

National Women’s History Month: Channel Women’s Advice for Newbies

March 31, 2023

Industry Perspectives

View all

Co-innovation Is Needed to Effect Energy Transformation

March 31, 2023

AI Spells the End of End User Security

March 30, 2023

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Kaseya, Post-Acquisition, Expanding ‘Well-Regarded’ Datto Partner Program

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

March 23, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Twitter

ChannelFutures

The shortage of talent in the tech industry gives women a great opportunity to build a career in tech says… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Check out our images from the expo floor at #EnterpriseConnect: @Microsoft @Zoom @GoTo @Cisco @googlecloud @ujetcx… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Learn about @comcastbusiness and some of the trends partners are seeing with #SMB customers. @craigschlagbaum… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

🤔 Interested in expanding on your brand or building a business from square one? @SkySwitchSays explains everythin… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Energy transformation and climate change calls for innovation now @VMware #channelpartners #energycrisis #technews… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Predictions are important when shaping your 2023 expectations & goals. #ChannelFutures is here to help out. We aske… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Mary Beth Walker on @HP adapting its partner program in response to partner feedback, and what latest launches mean… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

.@ConnectWise report shows cybercriminals will continue heavily targeting #MSPs in 2023. dlvr.it/Slnlrj https://t.co/eEY0pMLJaQ

March 31, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X