FISMA is becoming a roadblock for electronic health record implementation, Government Health IT magazine reported this week.
The Federal Information and Security Management Act (FISMA), passed by Congress in 2002 to better protect the federal government against cyber attacks, mandates information security standards for all federal agencies. This includes the flow of data between the Centers for Medicare and Medicaid (CMS) and their contractors—over 200 hundred of them, processing billions of Medicare claims. The new worry from CMS, according to Government Health IT, is that healthcare providers sharing EHR files will be required to meet FISMA standards, which include an annual security test and FISMA certification.