* Second part of interview with John Halamka, CIO of Caregroup Health Systems
At the Healthcare Information Management and Systems Society show in New Orleans last week, I caught up with John Halamka, CIO of Caregroup Health Systems of Boston. Halamka was speaking at HIMSS about the progress of standards for the interoperability of health information systems. I spoke to Halamka about compliance to regulations such as the Health Insurance Portability and Accountability Act (HIPAA) and data privacy. Here are some excerpts from our discussion.
Deni Connor: I think we’ve seen that as for compliance HIPAA has no teeth.
John Halamka: Yeah, yeah. I have a higher power than HIPAA – it’s called the Boston Globe. Imagine that instead of TJX [which suffered a data breach http://www.networkworld.com/news/2007/012707-tjx-breach-could-hurt-30.html] it was Beth Israel Deaconess [Halamka is also CIO there]. So you ask, is HIPAA the right thing to do – yes – if I didn’t do it and had a privacy spill [that would be] devastating. So we have to be very careful – I can’t always get money for compliance. We don’t have to be Sarbanes-Oxley compliant because we are a non-profit, but the State of Massachusetts requires we maintain all records for 30 years. So I do have my tapes from 30 years ago and there’s no device manufactured today that can read them.
Deni Connor: Though with the new Federal Rules of Civil Procedure, there’s virtually no organization untouched by compliance.
John Halamka: I actually look at SOX as a board member of Hippocrates.org. If you look at the cost of SOX for a small company, it can make you unprofitable.
Halamka is an out-spoken advocate of data privacy and data leakage. Network World has over the years published a series of stories about Halamka’s exploits, from having a VeriChip implanted to telling us his experience with ‘boutique’ research and analysis firms.




