System Analysis The computer system for ABC Healthcare is a unified network containing multiple elements. It consists of multiple computers connected a single Internet access point. The wireless access point allows for external and internal connections but does not distinguish between employees and customers. There is only one server for the entire company and there are no security separations within the network. The network does not have any firewall to prevent access from outside and a single switch moderates all internal connections. The use of personal computers is allowed with unmonitored connections to the system. The printer is connected directly to the network.
Legal and Ethical Issues …show more content…
The Gramm-Leach-Bliley Act and the Health Insurance Portability and Accountability Act both apply to ABC Healthcare. The GLB Act works to protect financial information and the company collects financial records to assist patients. The two parts of HIPAA, the security rule and the privacy rule, are applicable to different parts of the company’s performance. The security rule applies to providing physical, technical, and administrative restrictions on access to data. The privacy rule acts to provide protections to the data itself and prevent unsecure access or leakage of patient and employee data. There are laws which apply to the companies recording of the premises. This also applies to the possibilities of recording patient information and circumstances. For example, a recording device may not record private areas such as bathrooms and changing areas. These are considered major violations of employee and customer rights. In addition, there are state laws which could apply depending on the location of the company. Many states require a public posting of a notice where surveillance is being used. The fact that the company does not notify employees may affect employee satisfaction if it comes to …show more content…
The primary impact would be employee confidence in the company and a sudden drop in productivity resulting in the perceived lack of trust from the company. Most people consider unannounced surveillance a very significant violation of personal privacy. At the same time, employees who are aware of surveillance are less likely to perform unethical acts because they know they’re being watched. The company should seriously consider this aspect of the hidden surveillance. The company security issues are another matter entirely. The company could face serious impacts from their lack of security. The penetration of the company’s server and accessing of patient data would have a significant impact on the profitability of the company. The members of management could even face criminal charges connected to this issue. The lack of paper management surrounding the printer opens a large security issue with major consequences because the items are processed outside the company. All in all, the company has significant issues when it comes to security.