PART 3 OF 4: The Security Rule and Safeguarding ePHI
Protecting electronic health information in practice.
As practices have moved to electronic records, the Security Rule has become central to HIPAA compliance. It requires practices to protect electronic protected health information through a combination of administrative, physical, and technical safeguards — and to base those safeguards on an honest assessment of their own risks. This post addresses what the Security Rule requires.
The risk analysis
The foundation of Security Rule compliance is a thorough, documented risk analysis: an assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the practice's ePHI. Many enforcement actions trace directly to the absence of a genuine risk analysis. It is not a one-time exercise; it should be revisited as the practice and its technology change.
Administrative safeguards
These are the policies and workforce measures that manage security:
-
A designated security official responsible for the program.
-
Workforce training and sanctions for violations.
-
Access management so staff reach only the ePHI their roles require.
-
A contingency plan for data backup and disaster recovery.
Physical and technical safeguards
Physical safeguards protect the facilities and devices where ePHI lives — facility access controls, workstation security, and device and media controls. Technical safeguards protect the data itself, through access controls, audit logging, integrity controls, and transmission security such as encryption of ePHI in transit and at rest.
Business associate agreements
Any vendor that creates, receives, maintains, or transmits ePHI on the practice's behalf — billing companies, IT and cloud providers, and many software platforms — must be bound by a business associate agreement. The practice should maintain a current inventory of its business associates and confirm an agreement is in place with each.
How West Coast Health Law Can Help
We help practices meet the Security Rule — conducting and documenting risk analyses, drafting safeguard policies, and putting compliant business associate agreements in place with every vendor that touches ePHI.
West Coast Health Law offers a FREE consultation which you may schedule by clicking the button on our website.
This article is provided for general informational purposes only and does not constitute legal advice or create an attorney-client relationship. Laws change and every practice is different; consult a qualified attorney about your specific circumstances.
Comments
There are no comments for this post. Be the first and Add your Comment below.
Leave a Comment