Showing posts with label ePHI. Show all posts
Showing posts with label ePHI. Show all posts

Wednesday, October 19, 2016

Ten HIPAA Security Tips Saving Small Practice’s Time, Money and Reputation


This article was submitted by contributing author, Vic Berger.

My business practice focuses on helping organizations understand their risks related to security. Cyber Security is one risk every organization struggles with. Small businesses face the same types of risks as bigger companies but lack the staffing and resources to respond the same as a large organization. I am frequently asked by small business owners “What cost effective recommendations would you make for my business to make it more secure?” Here are my top ten recommendations for small businesses when dealing with information security.

1.                  Have A Written Security Policy
Every business needs a good written information security policy. This is the basis for your security plan, as well as your legal safety net when something happens. There is no single action a company can take that is more important. Yet this is often the first issue I find in audits of companies of every size, and in every sector.  The plan needs to be well written; read and understood by every employee in the company; and consistently maintained.  There are numerous templates and examples of security policies on the internet. Many consulting companies will tailor a stock plan to suit your organization.

2.                  Encrypt Everything
The first rule of I.T. security is “no solution is perfect 100% of the time”. You cannot always trust prevention methods to keep your data safe. The only way to consistently assure the protection of your data is to encrypt it so it cannot be read. This is especially important with cloud or internet based storage accounts. Dropbox, Google Drive, OneDrive, Box, and Egnyte are all great tools, but no cloud provider will guarantee the security of your data, and all have recently been breached. My basic rule of thumb is: if it is on the internet, consider it public access unless you have encrypted it. You can encrypt your cloud storage using a simple to use (and free for personal use) encryption program from nCryptedcloud that supports Dropbox, Box, Google Drive, OneDrive, and Egnyte available at https://www.encryptedcloud.com/  You can also use a portable USB format hardware encryption and key management device from BlackSquare called Enigma, at www.blacksquaretechnologies.com for personal and small business encryption on portable devices, computers, and cloud accounts.
  
3.                  Protect Your Website
Current information security statistics indicate that 85% of all websites have one or more significant security vulnerabilities. I apply patches to my websites almost daily to keep up with newly discovered vulnerabilities. There are three basic types of websites, with three different recommendations based on what you use:
A.      A static web page with basic company information that doesn’t change. Your biggest risk is disruption or defacing of this type of website. Your hosting provider or ISP will take care of the service disruption. For defacing, keep a good site backup and do a complete CLEAN restore as soon as possible (hackers leave behind gotchas).
B.      An interactive or dynamic web site with user content and/or e-commerce. Often these are created using a standard Content Management Software (CMS) package like WordPress, Joomla, or Drupal.  These are best left to a professional company to update and manage if possible. If you must do it yourself, get a good book on securing your type of CMS. Subscribe to the vulnerability notification feed for your CMS type (all of the common solutions have this). Check your website against new vulnerabilities often.
C.      A site dedicated to internet e-commerce or a highly interactive site where users log in to access content.  Hire this one out! Do not try to do this yourself unless information security is your core business, or you have an I.T. staff with specialized training and certifications in internet security.

4.                  Data Backups
I see irreplaceable data lost almost every day. I have seen it in government agencies, fortune 500 companies, and in every industry vertical. It can be from a data breach, a hardware failure, a natural disaster, or from human error. Whatever the reason, there is no excuse for not having good backups. You should have at least one full data backup per week. More if your data changes frequently. Store the backups offsite, and somewhere safe.  I suggest the granite vault at Perpetual Storage www.perpetualstorage.com, it is the safest storage site in the country. You should also buy a GoBox and store everything you would need to rebuild your business after a major disaster.

5.                  Avoid Consumer Grade
If you can buy an I.T. product at a local box store, electronics retailer, or office supply store it is probably consumer grade, and not designed for business. This includes firewalls, routers, wireless access points, servers, storage, networking devices, tape drives, or anything that protects, moves, or manages your data. Yes, commercial grade is more expensive, for a reason: It Is Commercial Grade! Consumer grade security equipment was designed to protect a few ports and protocols commonly used by consumers. Business applications use different ports and protocols. It either does not run behind consumer grade equipment or you have to poke holes in your security to make it work. Consumer grade security is also easy to breach. Commercial grade uses much better security methods, and is consistently tested. Call your local I.T. reseller and ask them what they recommend.

6.                  Know Your Risks
Knowing what you have, that would be of value to someone else, helps you determine what to focus on to protect. Do you have sensitive or privileged data? Is your data unique or valuable? Are there government regulations like HIPAA or Sarbanes-Oxley that affect your industry? Are customers or consumers ever given access to your data? How many employees do you have, and what risk areas do they create? Beyond what is already addressed elsewhere in this whitepaper, as a minimum you need: Antivirus (web search free antivirus), Anti spyware (web search free anti-spyware), and a good security shell for your organization (Try Arellia www.arellia.com). If you have customers that are EVER by your work computers you need an anti-keystroke logging solution (StrikeForce www.strikeforcetech.com). Your mail and web should have mandatory content filters (either through your ISP or your firewall).

7.                  Plan For BYOD
BYOD stands for bring your own device. This is a huge shift in the government and corporate sector, but probably business as usual in small businesses. Small businesses often use what they have, even if it is a personal device. This is increasingly creating security issues. What your employees, knowingly or unknowingly, have on their devices, and what they do with them in their own time is now brought into your environment. This can open up security holes as well as create liability issues. Make sure that BYOD is clearly defined and covered in your security policy. There is technology that can restrict the security vulnerabilities of personal devices, so ask your local I.T. reseller for assistance. Finally, make sure your employees clearly understand your expectations and limits where BYOD is concerned.
 
8.                  Who Is Guarding The Sheep
This applies whether you are a fortune 500 company or a small business. I.T. administrators have great power. They can view privileged information, and have an extremely high level of system access and control, more than even the owners and senior executives of the company. This is a great responsibility, but also a huge temptation. It is very common to discover that I.T. administrators have been inside payroll files, HR files, or other personal or sensitive material. A good security shell like Arellia (see #6) creates log files to review, but that means that someone has to faithfully do this. Again, start with policy and clearly define responsibilities and expectations. Two person integrity is always prudent where money and manpower permit. And as always, rule #2 applies: Encrypt everything!

9.                  Physical Security Is Information Security
Theft is about opportunities, and criminals use them very effectively. Data from a stolen laptop is easier to obtain than hacking. Why brute force passwords when you can easily install a keystroke logger. A screwdriver to the back door is as good as a key if there is no other security. You must have good physical security policies and practices to have good information security. Cameras are effective and have become reasonably cheap. Programs that wipe stolen devices are commonly available. Keeping sensitive information and records locked away after hours deters opportunistic thieves. Think like a criminal, and then protect yourself from what you would exploit.

10.              Know When To Call For Help
             I am a passable plumber, marginal carpenter, and just plain dislike auto mechanics. I can do all three if required but usually end up spending more time, effort, and money than what I had intended. I can tackle small jobs but I leave the major projects to the professionals. I.T. Security is a highly specialized field with significant training and experience necessary to operate at a professional level. Your whiz kid nephew, who is good with computers, does not have that level of training or the required experience. This is especially important when there is an incident. Less than 3% of all I.T. professionals have the security experience and certification necessary to handle a data breach. I leave significant plumbing, carpentry, and auto mechanics jobs to the professionals, leave your major I.T. security issues to the professionals as well.

This article was submitted by a contributing author:
Vic Berger
CEO, Opsis Technologies
855-99OPSIS


For more information on protecting your office regarding this issue or additional HIPAA, OSHA, HR, and Medicare resources, please visit our web site: http://www.hcsiinc.com or email support at: support@hcsiinc.com.



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, September 7, 2016

Do You Know Who Your Employees Are?

This new monthly cyber awareness alert from the Department of Health and Human Services’ Office for Civil Rights (OCR) prods organizations to closely evaluate the risks their employees pose.


Insider threat is becoming one of the largest threats to organizations and some cyberattacks may be insider-driven. Although all insider threats are not malicious or intentional, the effect of these threats can be damaging to a Covered Entity and Business Associate and have a negative impact on the confidentiality, integrity, and availability of its ePHI. According to a survey recently conducted by Accenture and HfS Research, 69% of organization representatives surveyed had experienced an insider attempt or success at data theft or corruption. Further, it was reported by a Covered Entity that one of their employees had unauthorized access to 5,400 patient’s ePHI for almost 4 years.

US CERT defines a malicious insider threat as a current or former employee, contractor, or business partner who meets the following criteria:
  • has or had authorized access to an organization’s network, system, or data;
  • has intentionally exceeded or intentionally used that access in a manner that negatively, affected the confidentiality, integrity, or availability of the organization’s information; or information systems.

According to a survey conducted by U.S. Secret Service, CERT Insider Threat Center, CSO Magazine, and Deloitte, the most common e-crimes committed by insiders are:
  • unauthorized access to or use of organization information;
  • exposure of private or sensitive data;
  • installation of viruses, worms, or other malicious code;
  • theft of intellectual property.

Covered Entities and Business Associates should consider:
  • Developing policies and procedures to mitigate the possibility of theft of ePHI, sabotage of systems or devices containing ePHI, and fraud involving ePHI. These policies and procedures should enforce separation of duties and least privileges, while also applying rules that control and manage access, configuration changes, and authentication to information systems and applications that create, receive, maintain, or transmit ePHI.
  • Conducting screening processes on potential employees to determine if they are trustworthy and appropriate for the role for which they are being considered. Effective screening processes can be applied to allow for a range of implementations, from minimal to more stringent procedures based on the risk analysis performed by the entity and role of the potential employee. Examples of potential screening processes could include checks of the HHS OIG LEIE (List of Excluded Individuals and Entities) to check for health care fraud and related issues and criminal history checks to verify past criminal acts. When implementing a screening process, please be sure to review and comply with any applicable federal, state or local laws regarding the use of screening processes as part of the hiring process.
  • Following US CERT steps to protect ePHI from insider threats: 
1. Consider threats from insiders and business associates in enterprise-wide risk assessments.
2. Clearly document and consistently enforce policies and controls.
3. Incorporate insider threat awareness into periodic security training for all employees.
4. Beginning with the hiring process, monitor and respond to suspicious or disruptive behavior.
5. Anticipate and manage negative issues in the work environment.
6. Know your assets.
7. Implement strict password and account management policies and practices.
8. Enforce separation of duties and least privilege.
9. Define explicit security agreements for any cloud services, especially access restrictions and monitoring capabilities.
10. Institute stringent access controls and monitoring policies on privileged users.
11. Institutionalize system change controls.
12. Use a log correlation engine or security information and event management (SIEM) system to log, monitor, and audit employee actions.
13. Monitor and control remote access from all end points, including mobile devices.
14. Develop a comprehensive employee termination procedure.
15. Implement secure backup and recovery processes.
16. Develop a formalized insider threat program.
17. Establish a baseline of normal network device behavior.
18. Be especially vigilant regarding social media.
19. Close the doors to unauthorized data exfiltration.

 HCSI
Source(s): US-CERThttp://www.hhs.gov/ocr/, HCSI 


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, May 4, 2016

Do You Understand The HIPAA Security Risk Management Process?

Risk Analysis Requirements Under The Security Rule
HCSI
The HIPAA Security Rule requires that covered entities (your practice) conduct a Security Risk Analysis/Assessment for your organization, at minimum, once per year. It is critical that practices perform the Security Risk Analysis for several reasons. Not only is it important to comply with HIPAA, Health and Human Services (HHS) and Office of Civil Rights' (OCR) rules and regulations, but also for what you should consider to be a more motivational reason, to protect your practice (and bank account) from what could become debilitating fines and penalties.

The Security Management Process standard in the Security Rule requires each organization to “implement policies and procedures to prevent, detect, contain, and correct security violations.” (45 C.F.R. § 164.308(a)(1).), that apply to their particular practice. Risk Analysis is one of four required implementation specifications that provide instructions to implement the Security Management Process standard. This article will cover the Risk Analysis implementation specification of that standard. Section 164.308(a)(1)(ii)(A) states:
RISK ANALYSIS (Required). 

Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the organization. (Each organization must evaluate for itself the most appropriate answers to the questions contained in your own Risk Analysis.) From the information gained while conduction your Risk Analysis you should prepare a Security Risk Action Plan documenting your findings, your conclusions and plans to address risk issues.

This Action Plan should identify the current state of your practice from 3 areas: Environmental, Facility and Hardware/Software controls, [aka human, natural, and environmental threats].  It should also correlate issues from high to low risk and prescribe plans of action to address these issues in priority as deemed necessary.  Document your plans based on those risk analysis findings and your practice's available resources to best approach the reduction of your higher risk level issues and document your best practice policies and procedures going forward to mitigate damage, disruption or loss of Protected Health Information (PHI). The Security Rule requires the Risk Analysis to be documented but does not require a specific format. (See 45 C.F.R. § 164.316(b)(1).) The Risk Analysis documentation is a direct input to your Risk Action Plan and overall Risk Management Process.
The following questions are examples that your organization could consider as part of a risk analysis. These sample questions are not prescriptive and merely identify issues an organization may wish to consider in implementing the Security Rule:

1. Have you identified the e-PHI within your organization? This includes e-PHI that you create, receive, maintain or transmit.
2. What are the external sources of e-PHI? For example, do vendors or consultants create, receive, maintain or transmit your e-PHI?
3. What are the human, natural, and environmental threats to information systems that contain e-PHI?

In addition to an express requirement to conduct a Risk Analysis, the Rule indicates that a Risk Analysis is a necessary tool in reaching substantial compliance with many other standards and implementation specifications. For example, the Rule contains several implementation specifications that are labeled “addressable” rather than “required.” (68 FR 8334, 8336 (Feb. 20, 2003).) An addressable implementation specification is not optional; rather, if an organization determines that the implementation specification is not reasonable and appropriate the organization must document why it is not reasonable and appropriate and adopt an equivalent measure if it is reasonable and appropriate to do so. (See 68 FR 8334, 8336 (Feb. 20, 2003); 45 C.F.R. § 164.306(d)(3).)   

The OCR in recent months has acknowledged that providers are not making compliance implementation a priority to their practices. Thus, the increased risk of unauthorized access, use, and disclosure of protected (yet quite vulnerable) PHI is still a factor. Not to mention the risk of practices not appropriately implementing other critical areas of compliance, which also pose significant vulnerability to practices as well as the heightened risk of significant fines and penalties. While this information only briefly describes the risk to your practice, providers, workforce, and patients, the message to take away here is that the Office of Civil Rights means business - so much, in fact, that it was decided that the best and only way to make sure that practices understand the significance of compliance is for OCR (along with governing entities such as HIPAA, and others) to increase efforts of enforcement.

There is no such thing as "under the radar" or "off the grid" for practicing providers today. One component of enforcement is in HIPAA Security. It's a priority for HIPAA to ensure that potentially patient identifying and vulnerable information is secure. And rightfully so, when you consider the risk of potential identity theft, medical identity theft, and other dangers posed to patients due to the amount and types of information that health care providers have on each patient. Not to mention, the difficulty in finding the source of and stopping the effects of identity theft or medical identity theft, should that occur (which it does, all too often).
 
Organizations should use the information gleaned from their Risk Analysis as they, for example:
  1. Design appropriate personnel screening processes. (45 C.F.R. § 164.308(a)(3)(ii)(B).) 
  2. Identify what data to backup and how. (45 C.F.R. § 164.308(a)(7)(ii)(A).) 
  3. Decide whether and how to use encryption. (45 C.F.R. §§ 164.312(a)(2)(iv) and (e)(2)(ii).) 
  4. Address what data must be authenticated in particular situations to protect data integrity. (45 C.F.R. § 164.312(c)(2).)
  5. Determine the appropriate manner of protecting health information transmissions. (45 C.F.R. § 164.312(e)(1).)
Though there are other components of compliance, the Security Risk Analysis is one very essential component to compliance, and for many reasons. The Security Risk Assessment shows your practice's good faith effort in establishing and maintaining appropriate policies and procedures that meet guidelines and minimize risk to your practice, patients and their protected information. The Security Risk Analysis is required as a way for practices to show ongoing monitoring of critical business systems.

Enforcement of this area is at an all time high and will continue to gain steam. The best thing practices can do is to be proactive and show initiative. Also, note that the Security Risk Analysis/Assessment is also required for Meaningful Use attestation. Practices that are found to have received incentive payments through Meaningful Use but have not appropriately conducted a Security Risk Analysis/Assessment per attestation requirements are having to refund all of the incentive payments received as well as run the very high risk of more in depth investigations and other potential penalties.

Risk Analysis is the first step in an organization’s Security Rule compliance efforts. Risk analysis is an ongoing process that should provide the organization with a detailed understanding of the risks to the confidentiality, integrity, and availability of e-PHI. The outcome of the risk analysis process is a critical factor in assessing whether a required implementation specification or an equivalent measure is reasonable and appropriate. 



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, December 4, 2015

Dr. Jones is a News Star and His Patients Will Never Forget

The most misunderstood, unknown, or ignored of the HIPAA compliance rules is Breach Notification.


Dr. Jones had a lot of work to do over the weekend. He took his laptop from his office and put it in his car to take home. On the way home, Dr. Jones made a quick stop at the store. Upon returning to his car, Dr. Jones noticed that his car had been broken into. The laptop from his office was one of the items that had been stolen. Having the laptop stolen did not constitute a breach. However, the patient's information on that laptop did not have proper security protections, so now this situation is a breach. With more than 650 patients and their protected health information in the hands of unauthorized individuals, according to the HIPAA Breach Notification Rule, Dr. Jones must report this incident to each individual patient, the local media outlets, and to the Secretary of Health and Human Services. In all likelihood, Dr. Jones' reputation and that of his practice will suffer greatly. He will lose the trust of his patients and the financial effects will be felt for a long time.

What is the Breach Notification Rule?
Simply put, the Breach Notification Rule requires all covered entities and business associates to provide notification if there is a breach of unsecured protected health information (PHI).

What is considered unsecured PHI?
PHI is considered unsecured when it has not been rendered unusable, unreadable, or indecipherable to unauthorized persons who access it through various means that have been specified in HIPAA guidance. Covered entities and business associates that secure their patients PHI, using documented policies and procedures, are not required to provide notifications following a breach of such information.

What is considered a breach?
Health and Human Services (HHS) states that a breach is, "an impermissible use or disclosure under the Privacy Rule that compromises the security or privacy of the protected health information."

Are there exceptions to the Breach Notification Rule?
Yes, there are three exceptions to the Breach Notification Rule as defined by HHS:

  1. "Unintentional acquisition, access, or use of protected health information by a workforce member or person acting under the authority of a covered entity or business associate, if such acquisition, access, or use was made in good faith and within the scope of authority."
  2. "Inadvertent disclosure of protected health information by a person authorized to access protected health information at a covered entity or business associate to another person authorized to access protected health information at the covered entity or business associate, or organized health care arrangement in which the covered entity participates. In both cases, the information cannot be further used or disclosed in a manner not permitted by the privacy rule.
  3. If the covered entity or business associate has a good faith belief that the unauthorized person to whom the impermissible disclosure was made, would not have been able to retain the information.
When a Breach Occurs
Following the discovery of a breach, the covered entity must notify each individual whose PHI was, or is reasonably believed to have been, inappropriately accessed, acquired, or disclosed. If the business associate discovers the breach, it must notify the covered entity and identify the affected individuals.

Timeliness
Notification must be made without reasonable delay and no later than 60 days after discovery of the breach.

Required Notifications
  • Individuals - Written notice must be mailed by first-class mail to the individuals last know address or sent via email if the individual has specified a preference for email communication.
  • Media - If the unsecured PHI of 500 or more residents of a state or jurisdiction is, or is reasonably believed to have been, accessed, acquired, or disclosed during a breach, notice must be provided to prominent media outlets serving the state or jurisdiction.
  • Secretary of HHS - All breaches must be reported by March 1st of each year. If the breach involved 500 or more individuals, notice must be provided immediately. Otherwise, the covered entity may keep a log of breaches and submit the information annually. You can find a list of covered entities experiencing breaches of 500 or more individuals here, http://1.usa.gov/1Q58Jgb
It is important for your office to be compliant with the Breach Notification Rule. Not understanding the requirements will not help your office during a HIPAA audit. Privacy Rule, Security Rule, and Breach Notification are all areas that will be scrutinized during an audit of your HIPAA Compliance Program. Being out of compliance with the Breach Notification Rule will put your office at risk and could destroy your reputation that you have worked so hard to build.

For more information on the Breach Notification Rule, visit:

If you have any questions, feel free to email support@hcsiinc.com

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, November 5, 2015

HIPAA Workforce Security

HIPAA policies and procedures ensure all employees have appropriate ePHI access


Security Rule Language: Implement policies and procedures to ensure all members of its workforce have appropriate access to electronic protected health information (ePHI), as provided under paragraph (a) (4) of this section, and to prevent those workforce members who do not have access under paragraph (a) (4) of this section from obtaining access to electronic protected health information.”
45 CFR 164.308 (a)(3)(i)

The Workforce Security standard requires that you implement policies and procedures to ensure that all members of your workforce have appropriate access to ePHI and to prevent those workforce members who do not have access from obtaining access to ePHI. The type and extent of access to your information systems containing ePHI must be based on your Risk Analysis. Your Risk Analysis must consider the following factors:

• The importance of the applications running on the information system
• The value or sensitivity of the ePHI on the information system
• The extent to which the information system is connected to other information systems

Access to your information systems containing ePHI must be authorized only for your properly trained workforce members having a legitimate need for specific information in order to accomplish job responsibilities. All such access must be defined and documented. Such access must be regularly reviewed and revised as necessary.

Access to your information systems containing ePHI must be established through a formal, documented process. This process must include:

• Identification and definition of permitted access methods
• Identification and definition of how long access will be granted to user
• Procedure for granting a workforce member an access method (e.g. password or token) or changing an existing access method
• Procedure for managing access rights in networked environment
• Appropriate tracking and logging of actions of authorized workforce members on our information systems containing ePHI.

Your workforce members must not attempt to gain access to your information systems containing ePHI for which they have not been given proper authorization.

Following these policies and procedures will help prevent unauthorized access to ePHI while giving appropriate access to designated employees so that they can do their job.

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Tuesday, October 27, 2015

HIPAA Definitions

Here are some of the basic definitions of HIPAA compliance

Business Associate: A person or company that acts on behalf of a covered entity performing functions that involve the use or disclosure of Protected Health Information (PHI) for claims processing, billing, quality assurance, etc. Members of a covered entity’s work force are not business associates.

Covered Entity: All health plans, all health care clearinghouses, and any health care provider who transmits health information in electronic form in connection with a covered electronic transaction.

Designated Record Set (DRS): A record that contains information utilized and maintained for the purpose of making decisions about an individual’s health care.

Electronic Protected Health Information (ePHI): Individually identifiable health information that is transmitted, maintained or stored in electronic form.

Privacy: Scalable set of standards governing the patient’s rights over the use and disclosure of their own protected health information (PHI).

Protected Health Information (PHI): Individually identifiable health information maintained or stored in electronic or any other form or medium. It includes medical, demographic, and financial information about the patient.

Security: Specific measures a health care entity must take to protect ePHI from unauthorized breaches of privacy, or loss of integrity. It is scalable, flexible, and generally addressable.

Transactions: Electronic transmission of information between two parties to carry out financial or administrative activities related to health care.

Understanding these basic HIPAA terms is vital to your office being successfully compliant with the HIPAA regulations.


For questions about this topic, email me at jhuff@hcsiinc.com

To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Wednesday, October 7, 2015

Emergency Access Procedures

Your practice must establish procedures so your employees know how to obtain electronic protected health information (ePHI) during an emergency.


Access controls will still be necessary under emergency conditions, although they may be very different from those used in normal operational circumstances. For example, in a situation when normal environmental systems, including electrical power, have been severely damaged or rendered inoperative due to a natural or man-made disaster, procedures should be established beforehand to provide guidance on possible ways to gain access to needed electronic protected health information. 

Follow these tips on how your practice can meet emergency access requirements:

·         Review your contingency plan to determine what processes you have in place to provide rapid access to ePHI in an emergency
·         Have backup copies of any ePHI that you deem critical
·         Have plans to restore the system and data inside your facility and at an alternative site

·         Document the names and roles of individuals with administrative privileges who can grant access in a crisis.

For more information on this and other topics related to HIPAA, HR, OSHA, and Medicare, please email support@hcsiinc.com or visit our web site at http://www.hcsiinc.com

Monday, October 5, 2015

Workstation Security

HIPAA Security Rule and how it effects your workstation


Workstation security defines the physical security controls and practices used to restrict access to information stored on computer workstations and peripheral equipment such as printers and fax machines. The HIPAA Security Rule specifies that you must implement physical safeguards for all workstations that access electronic protected health information (ePHI). In addition to protecting ePHI, the Security Rule is also in place to help protect from fluctuations in electricity. Plugging computer workstations into an electrical power strip that has a built-in surge protector.

Your workstations containing ePHI must be placed in locations that minimize the risk of unauthorized access to them. It is important for you to take reasonable measures to prevent unauthorized persons from viewing ePHI on your workstations. Examples of such preventative action include, placing workstations, printers, fax machines, scanners, and electronic devices. in secured areas and be sure that all monitors are positioned or shielded so that data shown on the screen is not visible to unauthorized persons.



The level of physical protection provided for your workstations containing ePHI must be commensurate with that of identified risks. An assessment of the risks to your workstations that can access ePHI must be conducted at least annually.

Your employees are required to report loss or theft of any access device, such as a card, that allows access to secured areas of your office. In addition, all of your portable workstations or electronic devices must be securely maintained when in the possession of an employee.

Compliance with the HIPAA Security Rule requires a proactive effort by everybody within your office. Having everybody involved in protecting ePHI, will help your office comply with the Security Rule regulations and that will greatly assist in protecting your office should an audit occur.


For more information on this and other HIPAA, HR, OSHA, and Medicare related topics, please email support@hcsiinc.com or visit our website at http://www.hcsiinc.com

Monday, September 28, 2015

Duties of the HIPAA Compliance Security Officer

Specific responsibilities of this important role


While there are similarities between the HIPAA Compliance Privacy Officer position and the HIPAA Compliance Security Officer role, the differences are worth taking note of.

The HIPAA Compliance Security Officer serves as the process director for all ongoing activities that serve to provide appropriate access to and protect the confidentially of patient, provider, employee, and business information in compliance with the practice policies and standards. Rather than the in-person exchange and office environment, this positions is more focused on the information technology side of HIPAA compliance.

The responsibilities of the HIPAA Compliance Security Officer include, but are not limited to:

  • Ensures that your information systems comply with all applicable federal laws and regulations.
  • Ensures that none of your information systems compromises the confidentiality, integrity, or availability of any other of your information systems.
  • Develops, documents, and ensures proper dissemination of appropriate security information systems and the data contained within them.
  • Ensures that any of your newly acquired information systems have features that support required and/or addressable Security Rule implementation specifications.
  • Coordinates the selection, implementation, and administration of your security controls.
  • Ensures that your workforce members receive regular security awareness training.
  • Conducts periodic Risk Analysis of your information systems and security processes.
  • Develops and implements an effective Risk Management program.
  • Regularly monitors and evaluates threats and risks to your information systems that contain electronic protected health information (ePHI).
  • Develops and monitors/audits records of your information systems’ activity to identify inappropriate activity.
  • Maintains an inventory of all of your information systems that contain ePHI.
  • Creates an effective security incident policy and related procedures.
  • Ensures adequate physical security controls exist to protect your ePHI.
  • Coordinates with your Privacy Office to ensure that security policies, procedures, and controls support compliance with the HIPAA Privacy Rule.
  • Evaluates new security technologies that may be appropriate for protecting your information systems that contain ePHI.
While there are some apparent differences between the HIPAA Compliance Privacy Officer and the HIPAA Compliance Security Office, their main focus remains the same; to protect the privacy and security of all patient protect health information.

For more information on this and other HIPAA, HR, OSHA, and Medicare related topics,  please email support@hcsiinc.com or visit our web site at http://www.hcsiinc.com

Other articles on a related topic:

Duties of the HIPAA Compliance Privacy Officer

Proper PHI Disposal

HIPAA Violations and Social Networking


Tuesday, September 22, 2015

Proper PHI Disposal

Dispose of PHI properly and help eliminate this area of potential liability



When PHI and ePHI is no longer needed by your office or you have maintained your archived records for the specified period of time, it is vital that these documents and electronic document be disposed of properly. By disposing of these documents and electronic documents properly, you are greatly lessening your chance of this critical area of compliance being a liability for your organization or practice.

In general, examples of proper disposal methods may include, but are not limited to:
• For PHI in paper records, shredding, burning, pulping, or pulverizing the records so that PHI is rendered essentially unreadable, indecipherable, and otherwise cannot be reconstructed.
• Maintaining labeled prescription bottles and other PHI in opaque bags in a secure area and using a disposal vendor as a business associate to pick up and shred or otherwise destroy the PHI.
• For PHI on electronic media, clearing (using software or hardware products to overwrite media with non-sensitive data), purging (degaussing or exposing the media to a strong magnetic field in order to disrupt the recorded magnetic domains), or destroying the media (disintegration, pulverization, melting, incinerating, or shredding).

In addition to the properly disposing of PHI and ePHI, it is important to remember that you must also properly dispose of all PHI that has been accessed by any electronic device. If the device is no longer going to be used, it is very difficult to properly dispose of the ePHI files on these devices, so HIPAA suggest the entire device is destroyed.

Properly disposing of all PHI and ePHI is improve greatly reduce the risk of a health information breach, thus improving your chances of avoiding a violation fine.

For more information on protecting your office with this issue and other HIPAA, HR, OSHA, and Medicare topics, please visit our web site: http://www.hcsiinc.com or email support at support@hcsiinc.com.

Source: http://bit.ly/1MGGOlm