Home
Hipaa Email Security Article
Top Links
Hipaa Regulation Links
Privacy Policy
Sitemap

Sponsored Links

 

Navigation

Hipaa form
Hipaa privacy training
Hipaa notice
Hipaa pre existing
Hipaa policy
Hipaa email
Hipaa business associate
Hipaa privacy officer
Hipaa compliant
Hipaa privacy rules
Hipaa privacy rule
Hipaa security
Hipaa it
Hipaa regulations
Hipaa summit



Books
HIPAA Plain & Simple: A Healthcare Professionals Guide to Achieve HIPAA and HITECH Compliance
HIPAA Plain & Simple: A Healthcare Professionals Guide to Achieve HIPAA and HITECH Compliance
by Carolyn P. Hartley Edward D., III Jones
Our Price: $64.87
Used from: $46.37

Stedman's Guide to the HIPAA Privacy & Security Rules
Stedman's Guide to the HIPAA Privacy & Security Rules
by Kathy Nicholls
Our Price: $44.50
Used from: $24.49

HIPAA for Health Care Professionals
HIPAA for Health Care Professionals
by Carole Krager Dan Krager
Our Price: $31.02
Used from: $6.85

HIPAA Survival Guide for Providers: Privacy, Security and the HITECH Act
HIPAA Survival Guide for Providers: Privacy, Security and the HITECH Act
by Carlos A. Leyva Deborah L. Leyva
The Practical Guide to HIPAA Privacy and Security Compliance
The Practical Guide to HIPAA Privacy and Security Compliance
by Kevin Beaver Rebecca Herold
Our Price: $87.75
Used from: $82.48



The Security Rule Of The HIPAA

The acronym HIPAA stands for the Health Insurance Portability and Accountability Act, which Congress voted to enact in 1996. The HIPAA was designed to address several issues related to health insurance coverage and confidentiality of medical data. One of the regulations put in place according to the HIPAA is the Security Rule, which was confirmed in 2003, and had a compliance data of 2005. While the Security Rule is similar to the Privacy Rule in that it was put in place to protect the confidentiality of personal medical records, it differs from the Privacy Rule in that it deals solely with electronic information. The three security areas that fall under the influence of the Security Rule are the administrative, physical, and technical areas.

  

The Administrative Aspect

Compliance with this part of the Security Rule requires that medical facilities create and follow a standard privacy procedure. A privacy officer must also be designated, who will be responsible for drawing up and enacting this privacy procedure. Under the security procedures, employees allowed access to sensitive electronic health information must be clearly identified. Such access must be limited to employees who require such information in order to properly carry out their job functions. The company must also ensure that any employees obtained through outsourcing come from an external company that also has a privacy procedure and complies with HIPAA regulations. Contingencies for situations such as backup of data and data recovery must be covered, and frequent audits should be conducted and properly documented.

The Physical Aspect

This portion of the Security Rule governs the safety and physical access aspects of the hardware and software used in the processing and storage of medical information. There must be a system in place to permit physical access only to those who are authorized to do so. Maintenance records, security checks, and visitor sign-ins must be carefully monitored and documented for future reference. Any monitor screens that are used to display sensitive medical information must be situated such that unauthorized persons will not be able to view content displayed on the screens. Areas with high human traffic should also be avoided. The disposal of old equipment must be conducted carefully, and care must be taken to ensure that no sensitive information is contained in any of the equipment being disposed of.

The Technical Aspect

This section of the Security Rule is concerned with ensuring that the computer and network systems are secure against external intrusion and that data being transmitted across the network is safe from interception by unauthorized parties. Information transmitted on open networks must be encrypted, and authentication procedures such as user names and passwords must be put in place to prevent unauthorized access. In addition, data should not be changed in any way, and data corroboration will be carried out in order to ensure the integrity of the data.

Medical facilities are required by law to follow the many regulations of the HIPAA Security Rule. All this is done so as to ensure the safety and integrity of any personal medical information stored and processed electronically, and to prevent such information from inadvertently falling into the wrong hands.


Leave a comment | View Comments


 


Office Depot

Videos

Loading...
Hipaa Law Headlines

Due Diligence Mitigates Liability Exposure Under HIPAA and the HITECH Act - Becker's Hospital Review


Due Diligence Mitigates Liability Exposure Under HIPAA and the HITECH Act
Becker's Hospital Review
Therefore, HIPAA covered entities, business associates and subcontractors need to comply with 45 CFR ยง164.504(e), which delineates the privacy terms required in HIPAA business associate agreements, pursuant to Section 13404 of the HITECH Act.

and more »

Read more...


Repeal and Replace. Or Maybe Just Repeal. - New Republic (blog)


Repeal and Replace. Or Maybe Just Repeal.
New Republic (blog)
We know this because the federal government tried it, in 1996, when President Clinton signed the Health Insurance Portability and Accountability Act (HIPAA). The impetus for that law was an effort to salvage something, even something modest, ...

and more »

Read more...


Appeals court upholds HIPAA conviction of EHR snooper - FierceEMR


Appeals court upholds HIPAA conviction of EHR snooper
FierceEMR
According to the court, "knowingly" under HIPAA applies to the act of obtaining the information, and that "the defendant need only know that he obtained individually identifiable health information relating to an individual.
Ninth Circuit Holds that Knowledge of HIPAA Is Not Necessary for Criminal ...JD Supra (press release)

all 2 news articles »

Read more...


HIPAA compliance: How to prepare for upcoming KPMG HIPAA audits - TechTarget


HIPAA compliance: How to prepare for upcoming KPMG HIPAA audits
TechTarget
If an unexpected audit is likely to highlight significant HIPAA compliance issues, consider retaining a HIPAA consulting firm to bring the organization into compliance as quickly as possible. These audits are required by law under the amendments made ...

and more »

Read more...


HIPAA changes could put tech companies on the hook - Mass High Tech


Mass High Tech

HIPAA changes could put tech companies on the hook
Mass High Tech
While the final regulations won't be known until the act is signed into law, Bernstein says the proposed changes will likely affect any businesses that contracts with a health care provider who is a HIPAA covered entity or a Health Plan to perform a ...
HIPAA changes could put health IT companies on the hookBoston Business Journal
Social Media Poses Potential Patient Privacy Violations for PhysiciansThe Hospitalist Online

all 10 news articles »

Read more...