SlideShare a Scribd company logo
Industry	
  leading	
  Education	
  
Certified	
  Partner	
  Program	
  
	
  

•  Please	
  ask	
  questions	
  
•  For	
  todays	
  Slides	
  
http://compliancy-­‐group.com/slides023/	
  
•  Todays	
  &	
  Past	
  webinars	
  go	
  to:	
  
http://compliancy-­‐group.com/webinar/	
  
	
  

855.85HIPAA	
  
www.compliancygroup.com	
  
Maintaining	
  HIPAA	
  Compliance:	
  
Cloud	
  File	
  Sharing	
  and	
  Mobile	
  Devices	
  
Asaf	
  Cidon	
  
CEO,	
  Sookasa	
  
Cloud	
  File	
  Sharing	
  is	
  Booming	
  

Dropbox	
  
200M	
  Users	
  

Google	
  Drive	
  
120M	
  Users	
  

Box	
  
20M	
  Users	
  
Healthcare	
  Use	
  Case:	
  
Sync	
  and	
  Backup	
  
•  Sync	
  and	
  backup	
  
–  TranscripLons	
  
–  PaLent	
  charts	
  
–  Medical	
  bills	
  

•  Low	
  cost	
  alternaLve	
  
–  $100-­‐200	
  per	
  seat	
  
Healthcare	
  Use	
  Case:	
  
Mobile	
  Access	
  
•  Mobile	
  access	
  
–  Access	
  paLent	
  charts	
  on-­‐the-­‐go	
  
–  Work	
  from	
  home	
  
–  Home	
  care	
  
Healthcare	
  Use	
  Case:	
  
External	
  Sharing	
  
•  External	
  sharing	
  
–  Share	
  medical	
  images	
  
–  Send	
  medical	
  bills	
  
–  Send	
  receipts	
  to	
  suppliers	
  

•  Send	
  big	
  files	
  
–  CT	
  Scans,	
  X-­‐Rays	
  
The	
  Dark	
  Side	
  of	
  the	
  Cloud	
  
•  If	
  all	
  my	
  office	
  files	
  are	
  
synchronized	
  
everywhere…	
  
•  The	
  loss	
  of	
  a	
  laptop	
  or	
  
smartphone	
  causes	
  a	
  
HIPAA	
  breach!	
  
HIPAA	
  Breaches	
  AffecLng	
  500+	
  
Records	
  2006-­‐2013	
  [Source:	
  HHS]	
  
4.92%	
   1.31%	
  

Portable	
  Media	
  
Network	
  Server	
  

9.43%	
  
46.01%	
  

12.31%	
  
12.96%	
  

Computer	
  
Laptop	
  
EMR	
  
Paper	
  

13.04%	
  

E-­‐mail	
  
HIPAA	
  Breaches	
  AffecLng	
  500+	
  
Records	
  2006-­‐2013	
  [Source:	
  HHS]	
  
4.92%	
   1.31%	
  

Portable	
  Media	
  
Network	
  Server	
  

9.43%	
  
46.01%	
  

12.31%	
  
12.96%	
  

Computer	
  
Laptop	
  
EMR	
  
Paper	
  

13.04%	
  

E-­‐mail	
  

Most	
  breaches:	
  lost/stolen	
  devices	
  
The	
  Most	
  Common	
  HIPAA	
  Breaches	
  
•  Lost	
  and	
  stolen	
  devices	
  and	
  portable	
  media	
  
–  Over	
  1,000,000	
  devices	
  lost	
  every	
  week!	
  
–  22%	
  of	
  employees	
  report	
  they	
  have	
  lost	
  a	
  phone	
  
during	
  2012	
  

•  Employees	
  inappropriately	
  accessing,	
  using,	
  or	
  
transmidng	
  PHI	
  
Case	
  Study:	
  Stanford	
  Hospital	
  
06/2013	
  Stolen	
  laptop:	
  13,000	
  paLents	
  
01/2013	
  Stolen	
  laptop:	
  57,000	
  paLents	
  
07/2012	
  Stolen	
  laptop:	
  2,500	
  paLents	
  
09/2011	
  Accidental	
  online	
  sharing:	
  20,000	
  paLents	
  
01/2010	
  Stolen	
  laptop:	
  500	
  paLents	
  
Top	
  HIPAA	
  File	
  Sharing	
  Risks	
  
1.	
  Device	
  Loss	
  with	
  Unencrypted	
  PHI	
  
2.	
  Accidental	
  Sharing	
  of	
  PHI	
  
Top	
  HIPAA	
  File	
  Sharing	
  Risks	
  
1.	
  Device	
  Loss	
  with	
  Unencrypted	
  PHI	
  
2.	
  Accidental	
  Sharing	
  of	
  PHI	
  
3.	
  Unencrypted	
  PHI	
  on	
  Cloud?	
  
Top	
  HIPAA	
  File	
  Sharing	
  Risks	
  
1.	
  Device	
  Loss	
  with	
  Unencrypted	
  PHI	
  
2.	
  Accidental	
  Sharing	
  of	
  PHI	
  
3.	
  Unencrypted	
  PHI	
  on	
  Cloud?	
  

Solved	
  by	
  BAA	
  
Top	
  HIPAA	
  File	
  Sharing	
  Risks	
  
Not	
  Solved	
  by	
  BAA	
  

1.	
  Device	
  Loss	
  with	
  Unencrypted	
  PHI	
  
2.	
  Accidental	
  Sharing	
  of	
  PHI	
  
3.	
  Unencrypted	
  PHI	
  on	
  Cloud?	
  

Solved	
  by	
  BAA	
  
Dropbox	
  
Signed	
  BAA	
  
On-­‐device	
  EncrypLon	
  
Prevent	
  Accidental	
  
Sharing	
  
Access	
  Control	
  for	
  On-­‐
device	
  Data	
  
End	
  User	
  Experience	
  
and	
  Sync	
  
Popularity	
  
(Network	
  Effect)	
  

Box	
  

Google	
  Drive	
  
Ingredients	
  of	
  File	
  Sharing	
  HIPAA	
  Compliance	
  
1.  File	
  encrypLon	
  on	
  the	
  device	
  
2.  Control	
  access	
  to	
  files	
  with	
  white	
  
list	
  
–  People	
  
–  Devices	
  

3.  Audit	
  trail	
  and	
  emergency	
  access	
  
The	
  SoluLon	
  
1.	
  Device	
  Loss	
  with	
  Unencrypted	
  PHI	
  
2.	
  Accidental	
  Sharing	
  of	
  PHI	
  
3.	
  Unencrypted	
  PHI	
  on	
  Cloud?	
  

Solved	
  
Sookasa:	
  Shameless	
  Plug	
  
Dropbox	
  
Signed	
  BAA	
  
On-­‐device	
  
EncrypLon	
  
Prevent	
  Accidental	
  
Sharing	
  
Access	
  Control	
  for	
  
On-­‐device	
  Data	
  
End	
  User	
  
Experience	
  and	
  
Sync	
  
Popularity	
  
(Network	
  Effect)	
  

Box	
  

Google	
  Drive	
  

Sookasa	
  +	
  
Dropbox	
  
ü  HIPAA	
  Compliance	
  
ü  HITECH	
  Attestation	
  
ü  Risk	
  Assessment	
  

ü  Omnibus	
  Rule	
  Ready	
  
ü  Meaningful	
  Use	
  core	
  measure	
  15	
  

Free	
  Demo	
  and	
  60	
  Day	
  Evaluation	
  
www.compliancy-­‐group.com	
  
	
  

HIPAA	
  Hotline	
  	
  	
  
855.85HIPAA	
  
855.854.4722 	
  

More Related Content

PDF
The Basics: Reviewing & Producing ESI Evidence
PPTX
Webinar - Maximize Your Technology Donations Through TechSoup - 2017-03-28
PPTX
Umphrey hutcherson-ecu-cause2010-rev5
PPT
TechSoup for Libraries: Sustaining Technology to Serve Your Patrons: Dec. 2010
DOCX
LECTIO DIVINA DOMINICAL VI DE PASCUA ! QUIEN ME AMA GUARDARA MIS MANDAMIENTOS...
PDF
Squash Those IoT Security Bugs with a Hardened System Profile
PPTX
HIPAA Compliance in the Cloud
PDF
Internet of Things & Hardware Industry Report 2016
The Basics: Reviewing & Producing ESI Evidence
Webinar - Maximize Your Technology Donations Through TechSoup - 2017-03-28
Umphrey hutcherson-ecu-cause2010-rev5
TechSoup for Libraries: Sustaining Technology to Serve Your Patrons: Dec. 2010
LECTIO DIVINA DOMINICAL VI DE PASCUA ! QUIEN ME AMA GUARDARA MIS MANDAMIENTOS...
Squash Those IoT Security Bugs with a Hardened System Profile
HIPAA Compliance in the Cloud
Internet of Things & Hardware Industry Report 2016

Similar to Maintaining HIPAA Compliance with Cloud Based Solutions (20)

PPT
Disaster Planning What Organizations Need To Know To Protect Their Tech
KEY
LENDING IPADS TO MEDICAL STAFF: INTEGRATING IN INFORMATION WORKFLOW
PDF
materi_workshop_online_preservasi_arsip_seri_ke2_digital_preservation_1623134...
PPT
Remote Workers
PPT
3G HIT
PPT
Behind the Cloud: Cloud Computing Programs Demystified
PDF
Delay Tolerant Disaster Communication with the One Laptop Per Child XO
KEY
Lending Ipads to Medical Staff; Tablets in the Workplace – Guus Van Den Brekel
PPT
Practical Approaches to Cloud Computing at YOUR Library
PPTX
Webinar: Is the Cloud Right for You 2016-10-18
PPTX
UWA Research Week 2016
PPTX
Ciso Platform Webcast: Shadow Data Exposed
PDF
Briefing on US EPA Open Data Strategy using a Linked Data Approach
PPTX
The Future of Work
PPTX
Information Management - Data Processing
PDF
II-SDV 2014 Standing on the Shoulders of Giants: New strategies to involve mo...
PPTX
Enabling Dropbox for Business
PPTX
DSS ITSEC 2013 Conference 07.11.2013 - Accellion - The Secure File-Sharing P...
PPT
Embracing the IT Consumerization Imperative NG Security
PPTX
TheInternetDigitalSecurityfddreeere.pptx
Disaster Planning What Organizations Need To Know To Protect Their Tech
LENDING IPADS TO MEDICAL STAFF: INTEGRATING IN INFORMATION WORKFLOW
materi_workshop_online_preservasi_arsip_seri_ke2_digital_preservation_1623134...
Remote Workers
3G HIT
Behind the Cloud: Cloud Computing Programs Demystified
Delay Tolerant Disaster Communication with the One Laptop Per Child XO
Lending Ipads to Medical Staff; Tablets in the Workplace – Guus Van Den Brekel
Practical Approaches to Cloud Computing at YOUR Library
Webinar: Is the Cloud Right for You 2016-10-18
UWA Research Week 2016
Ciso Platform Webcast: Shadow Data Exposed
Briefing on US EPA Open Data Strategy using a Linked Data Approach
The Future of Work
Information Management - Data Processing
II-SDV 2014 Standing on the Shoulders of Giants: New strategies to involve mo...
Enabling Dropbox for Business
DSS ITSEC 2013 Conference 07.11.2013 - Accellion - The Secure File-Sharing P...
Embracing the IT Consumerization Imperative NG Security
TheInternetDigitalSecurityfddreeere.pptx
Ad

More from Compliancy Group (20)

PDF
HIPAA compliance for Business Associates- The value of compliance, how to acq...
PDF
HIPAA compliance tuneup 2016
PDF
How to safeguard ePHIi in the cloud
PDF
Business Associates: How to differentiate your organization using HIPAA compl...
PDF
Business Associates: How to become HIPAA compliant, increase revenue, and gai...
PDF
HIPAA 101- What all Doctors NEED to know
PDF
HIPAA Compliance and Non-Business Associate Vendors - Strategies and Best Pra...
PDF
How to prepare for OCR's upcoming phase 2 audits
PDF
Preparing for the unexpected in your medical practice
PDF
HIPAA Compliance and Electronic Protected Health Information: Ignorance is no...
PDF
How to Survive a HIPAA Audit
PDF
How to Effectively Negotiate a Business Associate Agreement: What’s Importan...
PDF
Meaningful Use vs HIPAA
PDF
How to Increase Your Profits Using Patient Payments on File, Recurring and On...
PDF
Why a Risk Assessment is NOT Enough for HIPAA Compliance
PDF
The must have tools to address your HIPAA compliance challenge
PDF
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
PDF
What you need to know about Meaningful Use 2 & interoperability
PDF
Just the Facts- Meaningful Use Stage 2 & ICD 10
PDF
Is Your EHR Safe? New Technologies for Auditing
HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance tuneup 2016
How to safeguard ePHIi in the cloud
Business Associates: How to differentiate your organization using HIPAA compl...
Business Associates: How to become HIPAA compliant, increase revenue, and gai...
HIPAA 101- What all Doctors NEED to know
HIPAA Compliance and Non-Business Associate Vendors - Strategies and Best Pra...
How to prepare for OCR's upcoming phase 2 audits
Preparing for the unexpected in your medical practice
HIPAA Compliance and Electronic Protected Health Information: Ignorance is no...
How to Survive a HIPAA Audit
How to Effectively Negotiate a Business Associate Agreement: What’s Importan...
Meaningful Use vs HIPAA
How to Increase Your Profits Using Patient Payments on File, Recurring and On...
Why a Risk Assessment is NOT Enough for HIPAA Compliance
The must have tools to address your HIPAA compliance challenge
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
What you need to know about Meaningful Use 2 & interoperability
Just the Facts- Meaningful Use Stage 2 & ICD 10
Is Your EHR Safe? New Technologies for Auditing
Ad

Recently uploaded (20)

PDF
Medical Evidence in the Criminal Justice Delivery System in.pdf
PPTX
Gastroschisis- Clinical Overview 18112311
PPTX
ca esophagus molecula biology detailaed molecular biology of tumors of esophagus
PPTX
Note on Abortion.pptx for the student note
PDF
Deadly Stampede at Yaounde’s Olembe Stadium Forensic.pdf
PPTX
1 General Principles of Radiotherapy.pptx
PPTX
POLYCYSTIC OVARIAN SYNDROME.pptx by Dr( med) Charles Amoateng
PPTX
surgery guide for USMLE step 2-part 1.pptx
PPT
ASRH Presentation for students and teachers 2770633.ppt
PPTX
post stroke aphasia rehabilitation physician
PPTX
Imaging of parasitic D. Case Discussions.pptx
PPTX
Important Obstetric Emergency that must be recognised
PPTX
Pathophysiology And Clinical Features Of Peripheral Nervous System .pptx
PPTX
15.MENINGITIS AND ENCEPHALITIS-elias.pptx
PDF
Human Health And Disease hggyutgghg .pdf
PPTX
ACID BASE management, base deficit correction
DOCX
NEET PG 2025 | Pharmacology Recall: 20 High-Yield Questions Simplified
DOCX
RUHS II MBBS Microbiology Paper-II with Answer Key | 6th August 2025 (New Sch...
PPTX
Neuropathic pain.ppt treatment managment
PPTX
Fundamentals of human energy transfer .pptx
Medical Evidence in the Criminal Justice Delivery System in.pdf
Gastroschisis- Clinical Overview 18112311
ca esophagus molecula biology detailaed molecular biology of tumors of esophagus
Note on Abortion.pptx for the student note
Deadly Stampede at Yaounde’s Olembe Stadium Forensic.pdf
1 General Principles of Radiotherapy.pptx
POLYCYSTIC OVARIAN SYNDROME.pptx by Dr( med) Charles Amoateng
surgery guide for USMLE step 2-part 1.pptx
ASRH Presentation for students and teachers 2770633.ppt
post stroke aphasia rehabilitation physician
Imaging of parasitic D. Case Discussions.pptx
Important Obstetric Emergency that must be recognised
Pathophysiology And Clinical Features Of Peripheral Nervous System .pptx
15.MENINGITIS AND ENCEPHALITIS-elias.pptx
Human Health And Disease hggyutgghg .pdf
ACID BASE management, base deficit correction
NEET PG 2025 | Pharmacology Recall: 20 High-Yield Questions Simplified
RUHS II MBBS Microbiology Paper-II with Answer Key | 6th August 2025 (New Sch...
Neuropathic pain.ppt treatment managment
Fundamentals of human energy transfer .pptx

Maintaining HIPAA Compliance with Cloud Based Solutions

  • 1. Industry  leading  Education   Certified  Partner  Program     •  Please  ask  questions   •  For  todays  Slides   http://compliancy-­‐group.com/slides023/   •  Todays  &  Past  webinars  go  to:   http://compliancy-­‐group.com/webinar/     855.85HIPAA   www.compliancygroup.com  
  • 2. Maintaining  HIPAA  Compliance:   Cloud  File  Sharing  and  Mobile  Devices   Asaf  Cidon   CEO,  Sookasa  
  • 3. Cloud  File  Sharing  is  Booming   Dropbox   200M  Users   Google  Drive   120M  Users   Box   20M  Users  
  • 4. Healthcare  Use  Case:   Sync  and  Backup   •  Sync  and  backup   –  TranscripLons   –  PaLent  charts   –  Medical  bills   •  Low  cost  alternaLve   –  $100-­‐200  per  seat  
  • 5. Healthcare  Use  Case:   Mobile  Access   •  Mobile  access   –  Access  paLent  charts  on-­‐the-­‐go   –  Work  from  home   –  Home  care  
  • 6. Healthcare  Use  Case:   External  Sharing   •  External  sharing   –  Share  medical  images   –  Send  medical  bills   –  Send  receipts  to  suppliers   •  Send  big  files   –  CT  Scans,  X-­‐Rays  
  • 7. The  Dark  Side  of  the  Cloud   •  If  all  my  office  files  are   synchronized   everywhere…   •  The  loss  of  a  laptop  or   smartphone  causes  a   HIPAA  breach!  
  • 8. HIPAA  Breaches  AffecLng  500+   Records  2006-­‐2013  [Source:  HHS]   4.92%   1.31%   Portable  Media   Network  Server   9.43%   46.01%   12.31%   12.96%   Computer   Laptop   EMR   Paper   13.04%   E-­‐mail  
  • 9. HIPAA  Breaches  AffecLng  500+   Records  2006-­‐2013  [Source:  HHS]   4.92%   1.31%   Portable  Media   Network  Server   9.43%   46.01%   12.31%   12.96%   Computer   Laptop   EMR   Paper   13.04%   E-­‐mail   Most  breaches:  lost/stolen  devices  
  • 10. The  Most  Common  HIPAA  Breaches   •  Lost  and  stolen  devices  and  portable  media   –  Over  1,000,000  devices  lost  every  week!   –  22%  of  employees  report  they  have  lost  a  phone   during  2012   •  Employees  inappropriately  accessing,  using,  or   transmidng  PHI  
  • 11. Case  Study:  Stanford  Hospital   06/2013  Stolen  laptop:  13,000  paLents   01/2013  Stolen  laptop:  57,000  paLents   07/2012  Stolen  laptop:  2,500  paLents   09/2011  Accidental  online  sharing:  20,000  paLents   01/2010  Stolen  laptop:  500  paLents  
  • 12. Top  HIPAA  File  Sharing  Risks   1.  Device  Loss  with  Unencrypted  PHI   2.  Accidental  Sharing  of  PHI  
  • 13. Top  HIPAA  File  Sharing  Risks   1.  Device  Loss  with  Unencrypted  PHI   2.  Accidental  Sharing  of  PHI   3.  Unencrypted  PHI  on  Cloud?  
  • 14. Top  HIPAA  File  Sharing  Risks   1.  Device  Loss  with  Unencrypted  PHI   2.  Accidental  Sharing  of  PHI   3.  Unencrypted  PHI  on  Cloud?   Solved  by  BAA  
  • 15. Top  HIPAA  File  Sharing  Risks   Not  Solved  by  BAA   1.  Device  Loss  with  Unencrypted  PHI   2.  Accidental  Sharing  of  PHI   3.  Unencrypted  PHI  on  Cloud?   Solved  by  BAA  
  • 16. Dropbox   Signed  BAA   On-­‐device  EncrypLon   Prevent  Accidental   Sharing   Access  Control  for  On-­‐ device  Data   End  User  Experience   and  Sync   Popularity   (Network  Effect)   Box   Google  Drive  
  • 17. Ingredients  of  File  Sharing  HIPAA  Compliance   1.  File  encrypLon  on  the  device   2.  Control  access  to  files  with  white   list   –  People   –  Devices   3.  Audit  trail  and  emergency  access  
  • 18. The  SoluLon   1.  Device  Loss  with  Unencrypted  PHI   2.  Accidental  Sharing  of  PHI   3.  Unencrypted  PHI  on  Cloud?   Solved  
  • 19. Sookasa:  Shameless  Plug   Dropbox   Signed  BAA   On-­‐device   EncrypLon   Prevent  Accidental   Sharing   Access  Control  for   On-­‐device  Data   End  User   Experience  and   Sync   Popularity   (Network  Effect)   Box   Google  Drive   Sookasa  +   Dropbox  
  • 20. ü  HIPAA  Compliance   ü  HITECH  Attestation   ü  Risk  Assessment   ü  Omnibus  Rule  Ready   ü  Meaningful  Use  core  measure  15   Free  Demo  and  60  Day  Evaluation   www.compliancy-­‐group.com     HIPAA  Hotline       855.85HIPAA   855.854.4722