Ethics Scenario Our town medical center has hired a new chief information office
ID: 352411 • Letter: E
Question
Ethics Scenario
Our town medical center has hired a new chief information officer who is responsible for the information security plan. She has decided that HIPAA is outdated, complying with HIPAA security standards is too costly, and that the medical center would be better to save the money spent and use to deal with a data breach. She has stated that her philosophy is that, “Nothing is going to stop breaches, so why waste our money?” This is concerning to you in your role as the privacy officer and you are preparing to meet with her and discuss the important of compliance with both the security and privacy rules.
Is there an ethical dilemma?
How should the privacy officer respond?
Explanation / Answer
The privacy officer face an ethical dilemma on being mandated to not comply with HIPAA guidelines to save the additional cost incurred to implement it. HIPAA guideline protects the data from falling into wrong hands. But on the other hand, it is almost impossible to prevent any instance of data breach so the argument about why invest to fail also holds some validity.
Irrespective of this, her basic responsibility as a privacy officer is to safeguard the data of the medical center and if she complies with the instructions of the Chief Information Officer, she would not be justifying her position her role. Moreover, any data security breach would be her responsibility and she would be held accountable for any unwanted incident. So she has to act upon this situation on priority.
I believe she should quantitavely explain the CIO about the indirect benefits attained by the center by implementing HIPAA guidelines. Moreover, she should also project the extremities of things that can happen if the guidelines are not adhered to. She can elaborate upon the success instances when a data breach was successfully prevented. She could also explain the reasons behind previous security breaches and how the center plan to prepare itself for both present and future vulnerability. At last, if she fails to convince the CIO in the favor of HIPAA implementation, she should request for involvement of other stakeholder like CEO, etc in this decision making.
Please like and provide reviews in comments.
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.