Kenneth Bradberry: Risk Analysis Is Never-Ending

Published: March 8, 2010, 9:39 p.m.

A risk analysis should not be an annual event, but rather an ongoing process that's revisited whenever a healthcare organization adds or changes any application. That's the advice of Kenneth Bradberry, vice president and chief technology officer at ACS, a consulting firm recently acquired by Xerox.\n\n

In an interview during the HIMSS Conference in Atlanta, Bradberry said:\n\n

Compliance with the HITECH Act should begin with "good security practices at every layer," including infrastructure and application delivery;\n\nEncryption is paramount, especially as clinicians gain access to electronic health records via mobile devices; and \n\nLarger organizations need a full-time chief information security officer.