Background
ArchCare is an integrated delivery network (IDN) operated by the Archdiocese of New York. The ArchCare care delivery system is comprised of traditional long-term residential care and short-term rehabilitation, nursing home alternatives that enable seniors and others with chronic health needs to continue to live safely and independently, home health services for infants, children and adults, health plans that coordinate all of a member’s healthcare needs and the Medicare and Medicaid benefits for which they are eligible, family-centered end-of-life and palliative care and specialized care for people with exceptional needs.
Challenges
In 2002, ArchCare deployed DataMotion’s secure mailbox solution, giving selected employees the option to encrypt email messages containing PHI on an as-needed basis. However, with HITECH giving HIPAA regulations more “teeth” (including OCR audits) ArchCare wanted to expand its usage to automatically monitor all of its outbound email for PHI. Even with extensive employee training, policies and procedures for sending PHI, ArchCare worried something would get missed.
Additionally, and with the proliferation of electronic protected health information (ePHI) generated by electronic health records (EHRs), ArchCare required an additional layer of security provided by Direct Secure Messaging (Direct), the national encryption standard for clinical data exchange introduced by the US Department of Health and Human Services (HHS). The adoption of Direct by ArchCare’s referral partners as a preferred data exchange method further heightened the need to implement the enhanced encryption capability.
Ensuring HIPAA and HITECH Compliance
Enable information exchange, internally and externally, while ensuring compliance with HIPAA and HITECH.
Automated Monitoring
Automatically monitor all employees’ email communications containing PHI (Protected Health Information) to ensure security and compliance with HIPAA.
Optimizing Email Infrastructure
Leverage Microsoft Exchange email server and other existing infrastructure.
Easy Maintainance
Easy to maintain and reduce the risk of false positives.
Simplification
Require no recipient software & no user training.
User-Friendly
Accessible and easy to use by a wide variety of end-users including care coordinators, patients, care givers, clinicians and administrators.
Direct Secure Messaging
ArchCare extended its use of DataMotion’s secure email technology to the entire enterprise by adding the secure email content filter to act as a safety net. Additionally, they integrated DataMotion’s registration authority (RA), certificate authority (CA), and health information service provider (HISP) accredited DataMotion Direct service to facilitate direct secure messaging and clinical data exchange with referral healthcare providers & health systems.
Streamlined PHI Encryption Process
The content filter automatically detects and encrypts emails containing PHI. All email content and attachments from 1,600 ArchCare addresses are now scanned for PHI and encrypted as needed. Employees no longer need to remember to securely send sensitive health information.
Streamlining Health Data Exchange
Direct connections link ArchCare with HISPs and referral partners, facilitating secure clinical data exchange through certified EHR technology. As healthcare reform progresses, Direct is increasingly vital for interoperable health information exchange at ArchCare.
Results
- Greatly reduced risk exposure from email communications
- Increased compliance with HIPAA/HITECH regulations
- Increased user confidence
- Security enforcement can now be measured by tracking all secure and non-secure communications
“Our ability to share data is greatly enhanced and risk exposure is significantly reduced by extending DataMotion secure email technology across our enterprise. Automated filtering of email messages and files empowers us to identify and encrypt sensitive financial, clinical and other private information.”
Mitze Amoroso, vice president and chief information officer, ArchCare.
“We have engaged DataMotion at my company for data transfers. The platform's file transfer solution enables us to securely transfer files between different sites, ensuring that sensitive information is not compromised during the transfer process. It also offers us a robust and secure messaging solutions that allow team members and clients to collaborate in a secure manner.”
This Use Case might also interest you
Secure Your Confidential Data. Ensure Compliance.
Contact us to learn more about how our solutions can help your organization achieve its data security and compliance goals.