Wednesday, October 20, 2010

Why do we make poor risk-based decisions?

By Donald Holden, CISSP-ISSMP 

 

Everybody makes decision about accepting risks, often without knowing the actual probability of an adverse outcome. In business, we talk about security being concerned with the management of risk. When we make critical decisions that affect the privacy, safety, or security of individuals or corporate assets, do we base these decisions on objectively determined probabilities or upon our perception of risk and rewards, in other words our gut feel? Our perception of risk can change when the adverse impact does not happen even though the actual probability has not changed. People who have been warned to evacuate due to a hurricane that then misses them, tend to minimize the risk of future hurricane warnings. Or if you own a house, have you installed a burglar and fire alarm? If so did you do so after a break-in or fire? The probability of a future break-in is the same before and after the event that may have caused you to install an alarm. Two academic studies provide valuable insight into how we react to perceived risk rather than calculated or statistical risk. 

The first study analyzed how we lower our perceived risk after we have successfully avoided a near-miss or had a close call. A near-miss is defined as an “event that could have been a failure but for luck or chance.”  The second study looked at how we postpone mitigating known critical risks based on short term optimizing goals. Or in the words of the authors, we have a “psychological bias toward short-term maximization instead of long-term planning—a psychological bias all humans share.”  Understanding and then overcoming these human biases in decision making is necessary to improving the safety and security of our corporate and personal environment. 

The first study concerning near-misses was published in Management Science[1] and discussed in the McDonough School of Business (Georgetown) Magazine[2]. Two professors, Robin Dillon-Merrill and Catherine Tinsley, from Georgetown’s McDonough School of Business looked at the impact of near-misses on how we make decisions using perceived risk rather than calculated or statistical risk. They looked at how the near-misses in the American Space Shuttle Program led to the Columbia Space Shuttle catastrophe.  Falling foam insulation during previous space shuttle had fallen during lift off; some had struck the heat tiles but caused no major damage. There had been a calculation of the risk that foam insulation could cause damage to tiles but the experience with near-misses affected the decisions that led to the Space Shuttle Columbia catastrophe in 2003 where the foam did cause major damage to the tiles. Basically, the professors’ research and subsequent experiments with people playing a simulation with near-misses showed that when people have a near-miss, they see it as successfully avoiding the adverse impact rather than a near failure that could happen again with an adverse outcome. Surprisingly, the researchers found that the participants in the experiments did not actually believe that there was a reduction in the calculated or statistical probability of the adverse impact. It was their perception of risk that was lowered; this was an emotional not a rational reaction to the near-misses. 

In an article Masters of Disasters[3] two professors at Wharton’s Risk Management and Decision Processes Center ran a computer simulation where participants are told that they have a house and a bank account with $20,000 which pays 10% interest and they were given a warning that an earthquake could occur at any moment and 3 to 5 mild to severe quakes will happen during the game. Players could spend money on structural improvements to the house or continue to earn interest on the money left in the bank. Although initially players spent some money on improvements, they postponed major improvements thinking that a severe quake would not happen in the next few minutes of the games. By taking these risks, all players lost everything when a quake did happen. Their initial perception of risk seems to change based on the non-occurrence of the quake and the opportunity to earn interest. The Quake players which included both students and then corporate executives found “a sense of security from observing the flimsiness of one another’s houses. If everyone around you has a house of straw, having a straw house yourself seems somehow safer.” Does this sound similar to how businesses look at security risks? 

The authors of the near-miss study recommend treating the near-miss events not as successes but as failures using counterfactual thinking; that is,  imagining how an outcome could have turned out differently, and how the antecedents that led to the event might have been different. Just as we try to learn from our mistakes and failures, we need to learn from the near-misses before they become failures. We should recognize that our experience with near-misses usually causes us to reduce our perception of risk. When we combine this tendency with our preferences for short term gain at the expense of longer term impacts, we can see how a range of risk-based decisions are more emotional than rational.  Recognizing this tendency in ourselves and others can help us make better and more rational risk-based decisions that affect safety and security. 

Last week’s quiz question
What fact about South Hall makes it unique among Norwich University buildings?

Answer: It is LEED certified as a “green” building.

You can learn what this means at:

Winner: William Westwater

This week’s quiz question
In what year did the current Norwich University library open?

Past winners
Andrey N. Chernyaev:  5 wins
Matt Bambrick: 3 wins
Dianne Tarpy: 2 wins
Bill Lampe: 2 wins
Scott Madden: 2 wins
Sam Moore
Autumn Crossett
Gil Varney, Jr.
Glen Calvo
Thomas Reardon
Sherryl Fraser
Srinivas Chandrasekar
Marc Ariano
Linda Rosa
Joanna D'Aquanni
Srinivas Bedre
Christian Sandy
Joseph Puchalski
Ken Desforges
William Westwater




[1] Dillon R, Tinsley C. “ How Near-misses influences decision making under risk.”  Management Science ,V54, 2008 Aug: 1425-40.
[2] Blose, Chris.  “Researching risky business.”, McDonough School of Business Magazine. 2009 June.
[3] Fagone J.  “Masters of disasters.”. Wharton Magazine. Summer 2010.

Monday, September 27, 2010

Health Providers Beware of the New HITECH Act

Tim Trow, MSIA student

The Health Information Technology for Economic and Clinical Health Act, or more commonly known as the HITECH Act, is part of the American Recovery and Reinvestment Act of 2009. This act appears to put some teeth ino the HIPAA regulation of 1996. The HITECH Act wants to provide some general and specific incentives for companies to adopt the electronic health record (EHR) systems for health organizations. With these incentives also comes greater increased privacy and security protections for consumers and potential increased liability for those that are not in compliance.
There are three main components to the new HITECH Act. They include:

1. Enforcement: Civil penalties have been increased under the new act. These penalties can exceed $250,000, with repeatable violations extending to $1.5 million. The new act also allows a state attorney general to bring an action on behalf of his or her residents. Also, HHS is now required to conduct periodic audits of covered entities and business associates.

2. Notification of breach: HITECH now imposes data breach notification requirements for unauthorized uses and disclosures of PHI. These are similar to the existing state data breach laws. This outlines the importance of this new act and how it is going to react to privacy and security concerns in regards to protection and reporting of known breaches of PII.

3. Business associates: Under the HITECH Act, business associates are now directly "on the compliance hook" since they are required to comply with the safeguards contained in the Security Rule. Most software vendors providing EHR systems will most likely qualify as business associates.

Companies and health providers should take a serious look at their current status in regards to HIPAA and more specifically around the new HITECH Act. There are some great incentives for health organizations that decide to comply with the new HITECH Act. Health providers can start by performing a Gap assessment of their current environment in relation to HIPAA regulations and the HITECH Act. A Gap assessment will provide a roadmap to address any deficiencies and should also include an evaluation of the current information security program that should address the three key components outlined above. A third-party, business associate program should be outlined to address and manage your key business partners. In addition, a formal data breach policy and process needs to be developed and supported by the organization’s leadership team. Lastly, legal and executive management need to understand the consequences and risk associated with not complying with HIPAA and the new HITECH Act.
Last week’s Quiz Question
Question: What is the statue of on the top of the Vermont state capitol dome?   
Answer:  Agriculture (or Ceres)
Winner: Scott Madden

This week’s quiz question
What fact about South Hall makes it unique among Norwich University buildings?

Past winners
Andrey N. Chernyaev:  5 wins
Matt Bambrick: 3 wins
Dianne Tarpy: 2 wins
Bill Lampe: 2 wins
Scott Madden: 2 wins
Sam Moore
Autumn Crossett
Gil Varney, Jr.
Glen Calvo
Thomas Reardon
Sherryl Fraser
Srinivas Chandrasekar
Marc Ariano
Linda Rosa
Joanna D'Aquanni
Srinivas Bedre
Christian Sandy
Joseph Puchalski
Ken Desforges