By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Modern Health CareModern Health Care
Notification Show More
Latest News
Australia’s Medical Board to disallow ‘tick and flick’ online prescribing
June 6, 2023
South Korea begins move to make telemedicine permanent
June 6, 2023
Providence nurses, clinicians authorize strikes
June 5, 2023
Nurses speak out on plans for nurse educator layoffs at Cambridge Health Alliance
June 5, 2023
Mayo Clinic reveals more expansion details
June 5, 2023
Aa
  • Home
  • News
  • Physicians
  • Telehealth
  • Hospitals
  • Opioids
  • Opinion
  • Acquisitions
  • Fraud
  • Legislation
  • Home Health
Reading: National Institutes of Health Had Information Technology Control Weaknesses Surrounding Its Electronic Health Record System
Share
Aa
Modern Health CareModern Health Care
  • Home
  • News
  • Physicians
  • Telehealth
  • Hospitals
  • Opioids
  • Opinion
  • Acquisitions
  • Fraud
  • Legislation
  • Home Health
Search
  • Home
  • News
  • Physicians
  • Telehealth
  • Hospitals
  • Opioids
  • Opinion
  • Acquisitions
  • Fraud
  • Legislation
  • Home Health
Have an existing account? Sign In
News

National Institutes of Health Had Information Technology Control Weaknesses Surrounding Its Electronic Health Record System

OIG
OIG March 2, 2020
Updated 2020/03/02 at 3:00 PM
Share
SHARE

02-26-2020 | A-18-19-06003 | Complete Report | Report in Brief

Contents
Why We Did This ReviewHow We Did This ReviewWhat We FoundWhat We Recommend and NIH Comments

Why We Did This Review

For fiscal year 2019, the Department of Health and Human Services (HHS), Office of Inspector General (OIG) received $5 million in congressional appropriations to conduct oversight of the National Institutes of Health (NIH) grant programs and operations. Among the issues of interest to Congress were matters pertaining to cybersecurity protections and NIH compliance with Federal requirements.

The Clinical Research Information System (CRIS) contains the Electronic Health Records (EHR) for patients of NIH’s Clinical Center. The data and the IT security controls protecting the data are of significant importance to both HHS and the Federal government. OIG engaged CliftonLarsonAllen LLP (CLA) to conduct this audit.

The objective was to determine if the EHR System at NIH—also known as CRIS—has effective IT controls and to understand how NIH receives, processes, stores and transmits EHR records into CRIS.

How We Did This Review

CLA reviewed NIH’s policies and procedures; tested system security controls and configurations; and inspected public information on NIH’s website. CLA also conducted interviews with NIH Clinical Center staff to determine how NIH ensures the integrity of EHR data as well as to document how NIH ingest EHR records.

What We Found

CLA found that NIH had certain controls in place to secure EHR information and information systems. However, NIH’s information security policies and practices were not operating effectively to preserve the security, confidentiality, integrity, and availability of NIH’s EHR information and information systems, resulting in potential risks of unauthorized access, use, disclosure, disruption, modification, or destruction. Specifically, (i) the primary and alternate processing sites were located adjacent to each other on the NIH campus and not geographically distinct; (ii) servers supporting the EHR were still in operation despite nearing end-of-life on extended support without an effective transition plan; and (iii) terminated users and inactive accounts were not deactivated in a timely manner.

These weaknesses existed because, at the time of the fieldwork, NIH located their alternate processing site in the same geographic location as their primary site; NIH delayed software upgrades until completion of system upgrades had been completed; and NIH had not yet fully implemented the automated tool that was intended to ensure users and inactive accounts were deactivated timely. CLA shared the preliminary findings with NIH in advance of issuing the draft report. Before issuing the draft report, NIH implemented some of the recommendations.

What We Recommend and NIH Comments

CLA recommends that NIH Clinical Center Management (1) Complete the NIST requirements for implementing an alternative processing site that is a reasonable and viable option. Identify, document, and implement actions to mitigate risks of using existing alternative site based on the risk assessment results until compliant alternate site is established; (2) implement policies and procedures to ensure all software is upgraded or replaced prior to end of life; and (3) ensure that the automated CRIS User Account Management tool is operating so that all changes to user privileges are authorized, properly documented, and inactive accounts are deactivated.

NIH concurred with all of the recommendations and described actions it has taken or plans to take to address the findings.

Filed under: National Institutes of Health

You Might Also Like

Common Herbicide Causes Genital Abnormalities in Frogs

Free mRNA for Your Baby?

Americans Injured by the COVID-19 Vaccine Have to Prove Causation to Receive Compensation

Research Shows Huge Spike in MND Risk Among Former International Players

Research Shows Huge Spike in Motor Neurone Disease Risk Among Former International Rugby Players

OIG March 2, 2020
Share this Article
Facebook TwitterEmail Print
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow US

Find US on Social Medias
Facebook Like
Twitter Follow
Youtube Subscribe
Telegram Follow

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!

[mc4wp_form]
Popular News
AcquisitionsHospitals

Trinity cuts ribbon on new hospital

Beckers Hospital Review Beckers Hospital Review April 17, 2023
Is being male an advantage or disadvantage in nursing? 27 men weigh in
VA awards millions to veteran suicide tech challenge winners
Progress flatlining, deaths soaring: World Heart Federation addresses global cardiovascular disease
Carbon Health airs dispute with Anthem Blue Cross
- Advertisement -
Ad imageAd image
Global Coronavirus Cases

Confirmed

0

Death

0

More Information:Covid-19 Statistics

©Your Health Wire. All Rights Reserved.

  • Home
  • News
  • Physicians
  • Telehealth
  • Hospitals
  • Opioids
  • Opinion
  • Acquisitions
  • Fraud
  • Legislation
  • Home Health

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?