AE March/April 2018 Vol 27 No 2 - 19

What are the benefits of cloud computing?
What are the risks?
Can those risks be effectively controlled?
are the top concerns that slow
healthcare organizations' adoption
of cloud computing.1 Yet those
are critical requirements for both
client-server and cloud-based
systems. So which is the better choice?
According to the Health Care
Industry Cybersecurity Task Force,
the answer may be the cloud. Its
Report on Improving Cybersecurity in
the Health Care Industry, released to
Congress in June 2017, states:
"Hosted cloud service providers
and hosting companies ... have
made significant advancements
in security controls and technologies.... These models can be
an appealing, cost-effective, and
feasible alternative for many small
and medium-size healthcare organizations .... By moving to a secure
cloud environment, healthcare
providers will have increased security and the ability to effectively use
their clinical resources to support
patients without having to worry
about maintaining their on-premises infrastructure and systems."2
Lee Kim, the director of security
and privacy at HIMSS, met with
the Task Force during its deliberations. She told AE recently, "The
main benefit of cloud computing
for a medical practice is the ability
to buy what you need on demand
... with someone else having to
maintain it." Unless a practice has
strong IT infrastructure in place
and the resources to support and
administer it, the cloud may offer
the more cost-effective option.

CONTROLLING RISKS
Moving data or a system to the
cloud does not, however, remove all
security obligations from a practice.
Rather, the Task Force stressed, it
creates shared responsibilities. This
is consistent with the Department
of Health and Human Services'
Guidance on HIPAA and Cloud
Computing, which stipulates that
covered entities enter business associate agreements with cloud providers and that providers who sign
BAAs are liable for compliance with
applicable HIPAA requirements.
Kim underscored the need for
due diligence and for checking a
vendor's reputation in the community, particularly in regard to security breaches and protected health
information. The main challenge of
cloud computing can be a lack of
transparency, she added. Therefore,
she advises practices to ask the
following types of questions:
* How long has the vendor been in
business?
* Does the vendor use third-party vendors?
* What is an appropriate service
level to expect?
* How often is software updated?
Is there a charge?
* Does the vendor carry insurance
for cyber liabilities?
* How will you get your data back
if the contract is terminated?
Additionally, Ferguson recommends that practices evaluate such
technical requirements as bandwidth before moving forward with
a cloud-based solution.

TOWARD BLUE SKIES
Kim stressed that practices need
to" negotiate and get what is
agreed upon in writing." She
also recommends
* Seeking out advice from your legal
counsel and perhaps an IT security consultant before buying.
* Having a clear line of communication and a good working relationship with your cloud provider.
* Having all the contingencies
and the "what ifs" mapped out
to address a lot of "would-be"
headaches down the road. AE
NOTES
HIMSS Analytics 2016 Cloud Survey.
(2016, October). Retrieved from
https://www.cleardata.com/wp-content/
uploads/2016/12/2016-HIMSS-Analytics-Cloud-Study.pdf
2
Health Care Industry Cyber Security
Task Force. (2017, June). Report on Improving Cybersecurity in the Healthcare
Industry. Retrieved from https://www.
phe.gov/preparedness/planning/cybertf/
documents/report2017.pdf
1

Jeanne S. Holden
(703-451-5903,
jeanneholden@yahoo.
com) is a freelance
writer-editor based in
Springfield, Va.

www.asoa.org // AE

19


https://www.cleardata.com/wp-content/uploads/2016/12/2016-HIMSS-Analytics-Cloud-Study.pdf https://www.cleardata.com/wp-content/uploads/2016/12/2016-HIMSS-Analytics-Cloud-Study.pdf https://www.cleardata.com/wp-content/uploads/2016/12/2016-HIMSS-Analytics-Cloud-Study.pdf https://www.phe.gov/preparedness/planning/cybertf/documents/report2017.pdf https://www.phe.gov/preparedness/planning/cybertf/documents/report2017.pdf https://www.phe.gov/preparedness/planning/cybertf/documents/report2017.pdf http://www.asoa.org

Table of Contents for the Digital Edition of AE March/April 2018 Vol 27 No 2

How We Can Successfully Lead
Advanced Administration: Administrator Success Factors—Needing a Tune-Up Is Expected
Advice for New Administrators: Introducing the Administrator Beginners Circle—The Go-To Resource for New Administrators
Business Operations: Some Things to Know About Professional Liability Insurance
Customer Care: Making a Diffi cult Journey A Little Easier
Fast Practice: Breaking Down Practice Cliques
Human Resources: Recruiting Strategies for Ophthalmology—Where to Search for New Physicians
InfoTech: Cloud Computing— Storms or Blue Skies?
Reimbursement: Embracing Change to Thrive in an Evolving Reimbursement World
Technicians: Creating a “Feeder Program” to Staff Your Clinic
Washington Watch: MIPS in 2018—Key Changes for Ophthalmic Practices
Taking Your Practice to the Top
Use Podcasts to Increase Practice Visibility—and Thrive
Trailblazing— How to Implement Career Pathing in Your Practice
Ocular Surface Disease: Reimbursement Considerations for the Evaluation and Management of Dry Eye
Retina: Should Retinal Specialists Be Integrated Into a Multispecialty Practice?
Asked and Answered
ASOA News
Bookshelf: Off Balance On Purpose: Embrace Uncertainty and Create a Life You Love
COE Corner: Preparing for the COE Exam – Keep Your Eye on the Prize
Focus on a Practice: Ohio Valley Eye Physicians & Surgeons, PLLC, on Operating a Practice in Two States
Gamechanger: Karen Bachman, COE, COMT, OCS, ROUB
Advertisers’ Index
Peer to Peer: What’s Your Favorite Technique for Holding a Productive Staff Meeting?
AE March/April 2018 Vol 27 No 2 - Cover1
AE March/April 2018 Vol 27 No 2 - Cover2
AE March/April 2018 Vol 27 No 2 - 1
AE March/April 2018 Vol 27 No 2 - 2
AE March/April 2018 Vol 27 No 2 - 3
AE March/April 2018 Vol 27 No 2 - 4
AE March/April 2018 Vol 27 No 2 - How We Can Successfully Lead
AE March/April 2018 Vol 27 No 2 - Advanced Administration: Administrator Success Factors—Needing a Tune-Up Is Expected
AE March/April 2018 Vol 27 No 2 - 7
AE March/April 2018 Vol 27 No 2 - Advice for New Administrators: Introducing the Administrator Beginners Circle—The Go-To Resource for New Administrators
AE March/April 2018 Vol 27 No 2 - 9
AE March/April 2018 Vol 27 No 2 - Business Operations: Some Things to Know About Professional Liability Insurance
AE March/April 2018 Vol 27 No 2 - 11
AE March/April 2018 Vol 27 No 2 - Customer Care: Making a Diffi cult Journey A Little Easier
AE March/April 2018 Vol 27 No 2 - 13
AE March/April 2018 Vol 27 No 2 - Fast Practice: Breaking Down Practice Cliques
AE March/April 2018 Vol 27 No 2 - 15
AE March/April 2018 Vol 27 No 2 - Human Resources: Recruiting Strategies for Ophthalmology—Where to Search for New Physicians
AE March/April 2018 Vol 27 No 2 - 17
AE March/April 2018 Vol 27 No 2 - InfoTech: Cloud Computing— Storms or Blue Skies?
AE March/April 2018 Vol 27 No 2 - 19
AE March/April 2018 Vol 27 No 2 - Reimbursement: Embracing Change to Thrive in an Evolving Reimbursement World
AE March/April 2018 Vol 27 No 2 - 21
AE March/April 2018 Vol 27 No 2 - Technicians: Creating a “Feeder Program” to Staff Your Clinic
AE March/April 2018 Vol 27 No 2 - 23
AE March/April 2018 Vol 27 No 2 - Washington Watch: MIPS in 2018—Key Changes for Ophthalmic Practices
AE March/April 2018 Vol 27 No 2 - 25
AE March/April 2018 Vol 27 No 2 - Taking Your Practice to the Top
AE March/April 2018 Vol 27 No 2 - 27
AE March/April 2018 Vol 27 No 2 - 28
AE March/April 2018 Vol 27 No 2 - 29
AE March/April 2018 Vol 27 No 2 - 30
AE March/April 2018 Vol 27 No 2 - 31
AE March/April 2018 Vol 27 No 2 - 32
AE March/April 2018 Vol 27 No 2 - 33
AE March/April 2018 Vol 27 No 2 - Use Podcasts to Increase Practice Visibility—and Thrive
AE March/April 2018 Vol 27 No 2 - 35
AE March/April 2018 Vol 27 No 2 - 36
AE March/April 2018 Vol 27 No 2 - 37
AE March/April 2018 Vol 27 No 2 - Trailblazing— How to Implement Career Pathing in Your Practice
AE March/April 2018 Vol 27 No 2 - 39
AE March/April 2018 Vol 27 No 2 - 40
AE March/April 2018 Vol 27 No 2 - 41
AE March/April 2018 Vol 27 No 2 - Ocular Surface Disease: Reimbursement Considerations for the Evaluation and Management of Dry Eye
AE March/April 2018 Vol 27 No 2 - 43
AE March/April 2018 Vol 27 No 2 - Retina: Should Retinal Specialists Be Integrated Into a Multispecialty Practice?
AE March/April 2018 Vol 27 No 2 - 45
AE March/April 2018 Vol 27 No 2 - Asked and Answered
AE March/April 2018 Vol 27 No 2 - 47
AE March/April 2018 Vol 27 No 2 - ASOA News
AE March/April 2018 Vol 27 No 2 - 49
AE March/April 2018 Vol 27 No 2 - Bookshelf: Off Balance On Purpose: Embrace Uncertainty and Create a Life You Love
AE March/April 2018 Vol 27 No 2 - 51
AE March/April 2018 Vol 27 No 2 - COE Corner: Preparing for the COE Exam – Keep Your Eye on the Prize
AE March/April 2018 Vol 27 No 2 - 53
AE March/April 2018 Vol 27 No 2 - Focus on a Practice: Ohio Valley Eye Physicians & Surgeons, PLLC, on Operating a Practice in Two States
AE March/April 2018 Vol 27 No 2 - 55
AE March/April 2018 Vol 27 No 2 - Gamechanger: Karen Bachman, COE, COMT, OCS, ROUB
AE March/April 2018 Vol 27 No 2 - 57
AE March/April 2018 Vol 27 No 2 - Advertisers’ Index
AE March/April 2018 Vol 27 No 2 - 59
AE March/April 2018 Vol 27 No 2 - Peer to Peer: What’s Your Favorite Technique for Holding a Productive Staff Meeting?
AE March/April 2018 Vol 27 No 2 - Cover3
AE March/April 2018 Vol 27 No 2 - Cover4
http://www.nxtbook.com/ygsreprints/ASOA/g107843_ae_julyaug19
http://www.nxtbook.com/ygsreprints/ASOA/g105962_ae_mayjun19
http://www.nxtbook.com/ygsreprints/ASOA/g104576_ae_marapr19
http://www.nxtbook.com/ygsreprints/ASOA/g103212_ae_janfeb19
http://www.nxtbook.com/ygsreprints/ASOA/g99529_ae_novdec18
http://www.nxtbook.com/ygsreprints/ASOA/g97160_ae_septoct18
http://www.nxtbook.com/ygsreprints/ASOA/g96528_ae_julyaugust18
http://www.nxtbook.com/ygsreprints/ASOA/g93925_ae_mayjune18
http://www.nxtbook.com/ygsreprints/ASOA/g92298_ae_marapr18
http://www.nxtbook.com/ygsreprints/ASOA/g89361_ae_janfeb18
http://www.nxtbook.com/ygsreprints/ASOA/g86698_ae_novdec17
http://www.nxtbook.com/ygsreprints/ASOA/g81746_ae_septoct17
http://www.nxtbook.com/ygsreprints/ASOA/g80299_ae_julaug17
http://www.nxtbook.com/ygsreprints/ASOA/g77256_ae_mayjun17
http://www.nxtbook.com/ygsreprints/ASOA/g74401_ae_marapr17
http://www.nxtbook.com/ygsreprints/ASOA/g72340_ae_janfeb17
http://www.nxtbook.com/ygsreprints/ASOA/ae_novdec16
http://www.nxtbook.com/ygsreprints/ASOA/ae_septoct16
http://www.nxtbook.com/ygsreprints/ASOA/ae_julaug16
http://www.nxtbook.com/ygsreprints/ASOA/asoa_mayjune2016
http://www.nxtbook.com/ygsreprints/ASOA/asoa_marapr2016
http://www.nxtbook.com/ygsreprints/ASOA/asoa_janfeb16
http://www.nxtbook.com/ygsreprints/ASOA/ae_novdec15
http://www.nxtbook.com/ygsreprints/ASOA/asoa_sepoct15
http://www.nxtbook.com/ygsreprints/APTA/g52750_apta_25ada
http://www.nxtbook.com/ygsreprints/ASOA/asoa_julyaug2015
http://www.nxtbook.com/ygsreprints/ASOA/asoa_mayjune2015
http://www.nxtbook.com/ygsreprints/ASOA/asoa_marapr2015
http://www.nxtbook.com/ygsreprints/ASOA/asoa_janfeb15
http://www.nxtbook.com/ygsreprints/ASOA/asoa_novdec14
http://www.nxtbook.com/ygsreprints/ASOA/asoa_sepoct14_AE
http://www.nxtbook.com/ygsreprints/ASOA/asoa_julaug14
http://www.nxtbook.com/ygsreprints/ASOA/ASOA_MayJunAE
http://www.nxtbook.com/ygsreprints/ASOA/ASOA_MarAprAE
http://www.nxtbook.com/ygsreprints/ASOA/ASOA_JanFebAE
http://www.nxtbook.com/ygsreprints/ASOA/ASOA_no4eZine
http://www.nxtbook.com/ygsreprints/ASOA/asoa_fall_2013
http://www.nxtbook.com/ygsreprints/ASOA/asoa_no3_ezine
http://www.nxtbook.com/ygsreprints/ASOA/asoa/asoa_summer_2013
http://www.nxtbook.com/ygsreprints/ASOA/ehr_cust_survey_Apr2013
http://www.nxtbook.com/ygsreprints/ASOA/asoa_no2_2013_ezine
http://www.nxtbookMEDIA.com