HIPAA Overview: Controls Applicable To Our Organization
HIPAA Overview: Controls Applicable To Our Organization
HIPAA Overview: Controls Applicable To Our Organization
2 Security Vs Privacy 4
3 Administrative Safeguards 5
4 Physical Safeguards 6
5 Technical Safeguards 7
6 Incident Management 8
7 HITECH Amendment 9
• HIPAA stands for Health Insurance Portability and Accountability Act, 1996
• HIPAA defines policies, procedures and guidelines for maintaining the privacy and
security of Health Information
• Access Control
o Limit access.
o Unique user identification
o Emergency access procedure
o Automatic logoff
o Encryption and decryption
• Audit Controls
o Defines this requirement as implement of hardware, software, and/or procedural mechanism that record
and examine activity in information systems that contain or use.
o Appears that flexibility does not extend to having no audit trail mechanisms at all
• Integrity
o Policies and procedures to protect e-PHI from improper alteration or destruction
• Any activity that harms the resources or can cause harm to the
Organization and / or:
o Unauthorized changes or access of PHI or ePHI
o Criminal activity or natural disaster
• HITECH - Health Information Technology for Economical and Clinic Health Act
• HITECH act expands HIPAA Privacy and Security Rules further to the
Administrative, Physical and Technical Safeguards:
o Policies and Documentation
o New security breach reporting requirement
o Privacy Requirements
Health Information Exchange Organizations and Regional Health
Information Organizations (HIEs and RHIOs)
Criminal and Civil penalties: The act makes HIPAA’s criminal and civil
penalties applicable to business associates
o Security Breach reporting by covered entities (all associated individuals /
entities / organizations /