Monterey County Grand Jury • 2014-2015

Information Security at Natividad Medical Center:

Published: June 18, 2015 8 pages
View Original PDF

Findings and Recommendations 6 findings

F1
The separation of Natividad’s IT Department from the County’s IT Department in 2009 was warranted, due to unique regulations and auditing standards for health provider insti- tutions.
Related Recommendations (1)
R1
Natividad Medical Center share its IT Department model with other county hospitals as a standard of excellence when appropriate at all upcoming opportunities.
F2
Natividad Medical Center is exemplary of best practices in its protection of patients’ PHI.
Related Recommendations (1)
R2
Natividad Medical Center immediately review and ensure that its notices to the public about HIPAA breaches are written in languages commonly understood by the impacted persons.
F3
Natividad Medical Center has 24/7 IT Department staff well-equipped to prevent cyberat- tacks.
Related Recommendations (1)
R3
Natividad Medical Center continue to improve and update best practices for secure physi- cal delivery of PHI documents to other healthcare providers and individual patients while awaiting an active HIE for secure transmittals.
F4
Natividad Medical Center minimizes downtime of its IT networks by dedicated, continual monitoring.
No recommendations for this finding
F5
Language translation services should be utilized in preparing written notices to persons im- pacted by PHI breaches whose common language is other than English or Spanish.
No recommendations for this finding
F6
A weak link exists in security of PHI with hand-delivered paper documents.
No recommendations for this finding

Additional Recommendations 1

These recommendations are not explicitly linked to specific findings.