Quick Feedback Request
Highlighted Resources & Events
Need Assistance?
Would you like more assistance regarding Privacy and Security strategies or support in using any of the included resource sets?

  Request Support

 

The Quadruple Aim
Quadruple Aim

A Conceptual Framework

Improving the U.S. health care system requires four aims: improving the experience of care, improving the health of populations, reducing per capita costs and improving care team well-being. HITEQ Center resources seek to provide content and direction aligned with the goals of the Quadruple Aim

Learn More

Resource Overview

In order to effectively protect health IT systems, Health Center IT leadership needs to consider not only the physical and technical measures of protection for their site, but also the human and workflow measures required to provide the highest levels of privacy and security available throughout their organization.

Resources provided in this section include a set of curated best practices and gold standards for protecting  and effectively responding to health IT system threats. 

Health IT Privacy & Security Best Practices

Addressing Cybersecurity Threats in Health Centers

HITEQ Center, June 2025

Maddie Bishop-Harris 0 159

This article uses the 2020 incident at the Family Health Center of Worcester (FHCW) to explore innovative strategies to bolster health centers' cybersecurity, including leveraging group purchasing organizations (GPOs) for discounted solutions and implementing bug bounty programs to proactively strengthen systems. Ultimately, it investigates how these approaches can protect vital community health resources from the escalating tide of cyber threats.

Health Center Emergency Response Exercise Set

HITEQ Center, March 2025

Molly Rafferty 0 1432

The exercise cards in this set present scenarios and response-related questions designed to provide a quick (5–10 minute) method for health center staff to: Refresh knowledge of the content in their emergency and cyber incident response plans; Examine and troubleshoot procedures in their emergency and cyber incident response plans; Identify improvements to their emergency and cyber incident response plans; and Increase staff capacity to operationalize the actions outlined in their emergency and cyber incident response plans. The scenarios and questions on these cards can serve as a starting point to spark discussions amongst your team about scenarios and responses that are specific to the context of your health center (e.g., what extreme weather events are most common in your area?). The first five cases describe environmental scenarios, and the last two cases describe cybersecurity scenarios.

A Practical Guide on Intimate Partner Violence, Human Trafficking, and Exploitation and Technology Tools

HITEQ Center, January 2025

Molly Rafferty 0 2302

This practical guide features key tools and principles to help health centers (HCs) develop safe documentation for intimate partner violence, human trafficking, and exploitation (IPV/HT/E) in their electronic health records (EHRs) and other technology tools.  In 2020, the Health Resources and Services Administration’s (HRSA) introduced new Uniform Data System (UDS) data elements for health centers (HCs) to report on IPV and HT/E. With the evolving landscape of data use in medical settings, it is imperative that HC staff understand privacy principles and implement best practices to protect confidentiality for survivors of IPV/HT/E. This resource features guidelines on documenting IPV/HT/E in the EHR using a trauma-informed, survivor-centered approach. The guide also features tools that FUTURES has developed alongside health IT platforms, namely for eClinicalWorks and OCHIN Epic, to aid HCs in using the evidence-based CUES intervention that focuses on universal education approaches on IPV/HT/E. This guide is available as a PDF (4 pages) in English.

Health Center Resilience in the Face of Cyber Adversity

A Case Study of the Family Health Center of Worcester’s Ransomware Incident, February 2024

Molly Rafferty 0 5274
The use of ransomware — malicious software that restricts access to computer systems with financial demands — has escalated, targeting health centers and putting countless lives at risk. This dire reality came to the forefront during the alarming ransomware attack on the Family Health Center of Worcester, Inc. (FHCW), where the personal health information and care continuity for thousands of patients were compromised. This resource uses FHCW's experience as a case study to demonstrate the imperative of preparedness and the strength of a community-centered response in ensuring the continuity of healthcare services amidst the ever-growing tide of cyber vulnerabilities.
RSS

Acknowledgements

This resource collection was cultivated and developed by the HITEQ team with valuable suggestions and contributions from HITEQ Project collaborators.

Looking for something different or have something you think could assist?

HITEQ works to provide top quality resources, but know your needs can be specific. If you are just not finding the right resource or have a highly explicit need then please use the Request a Resource button below so that we can try to better understand your requirements.

If on the other hand you know of a great resource already or have one that you have developed then please get in touch with us by clicking on the Share a Resource button below. We are always on the hunt for tools that can better server Health Centers.

Request a Resource  Share a Resource