HIPAA · Domain 2
HIPAA Security Rule
About 30% of the exam
Scope and objectives
- Applies to
- electronic protected health information only
- Bound parties
- covered entities and business associates
- Confidentiality
- not available to unauthorized people
- Integrity
- not improperly altered or destroyed
- Availability
- accessible when authorized people need it
- Also required
- protect against reasonably anticipated threats
- And finally
- ensure workforce compliance with policies
Paper and spoken information sit under the Privacy Rule, so a Security Rule answer that turns on filing cabinets is usually the wrong one
Required against addressable
Required
- Implement the specification as written
- No alternative is acceptable
- Risk analysis is the clearest example
- Unique user identification is another
Addressable
- Assess whether it is reasonable
- Implement it, or an equivalent measure
- Or document why neither is appropriate
- Never a permission to ignore it
Too expensive is not documentation; the record has to show the analysis, the alternatives weighed, and the reasoning behind the final decision
Flexibility of approach
- Size, complexity and capabilities considered
- Technical infrastructure and existing security
- Cost of the measures weighed
- Probability and criticality of risks
- Small practices still need real controls
- Flexibility never excuses doing nothing
Risk analysis
- Cover every system touching electronic records
- Identify threats and existing controls
- Rate likelihood and potential impact
- Determine residual risk honestly
- Feed a documented risk management plan
- Update after significant changes
The safeguard families
- Administrative
- policies, people and oversight
- Physical
- facilities, workstations and media
- Technical
- access, audit, integrity and transmission
- Organizational
- contracts and plan documents
- Policies and documentation
- written, reviewed and retained
Documentation duties
- Write policies and procedures down
- Record every required action and decision
- Retain for six years
- Available to those who implement them
- Review and update periodically
- Back up the documentation itself
Technical safeguards at a glance
- Access control
- unique identifiers and emergency access
- Automatic logoff
- addressable, tuned to the setting
- Encryption at rest
- addressable, not flatly required
- Audit controls
- record and examine system activity
- Integrity
- detect improper alteration of records
- Authentication
- verify the requester is genuine
- Transmission security
- integrity controls and encryption
Organizational requirements
- Business associate contracts in place
- Associates must secure the information
- Report incidents back to the entity
- Subcontractors bound to the same terms
- Group health plan documents amended
Evaluation
- Periodic technical and nontechnical review
- Triggered by environmental or operational change
- Test controls, do not tick boxes
- Compare practice against written policy
- Feed findings into the risk plan
Encryption and the safe harbor
- Encryption is addressable, not required
- Meeting recognized standards secures the data
- Secured data avoids breach notification
- Compromised keys void the protection
- Document the standard you followed
- Tokenization can be an equivalent measure
Modern systems in scope
- Cloud services holding electronic records
- Connected medical devices on the network
- Mobile phones used by clinicians
- Legacy systems needing compensating controls
- Programming interfaces sharing patient data
- Shadow applications adopted by departments
Findings investigators report
- No enterprise wide risk analysis
- Analysis limited to the main system
- Addressable items skipped with no record
- Audit logs collected but never reviewed
- Terminated staff keeping active accounts
- No agreement with a key vendor
Building the program, step by step
- Inventory every system holding records
- Run the risk analysis
- Prioritize and plan risk management
- Implement the required specifications
- Decide addressable ones with reasoning
- Train the workforce
- Evaluate, document and repeat
- Security is a cycle, not a project
- The plan becomes evidence in an investigation
- Vendors sit inside the boundary
- Leadership owns the outcome
Rapid recall: standard families
- Administrative
- nine standards, most with specifications
- Physical
- four standards covering facilities and media
- Technical
- five standards on system controls
- Organizational
- contracts and plan documents
- Documentation
- written, retained and reviewed
Required specifications to memorize
- Risk analysis
- required, and the foundation
- Risk management
- required, acts on the analysis
- Sanction policy
- required, applied consistently
- Activity review
- required, look at the logs
- Unique user identification
- required, no shared accounts
- Emergency access
- required, get in during crises
Reference strip: scope, safeguards, specifications, encryption, evidence
Scope
- Electronic information only
- Entities and associates alike
- Confidentiality, integrity, availability
Safeguards
- Administrative, physical, technical
- Organizational contracts sit alongside
- Documentation ties it together
Specifications
- Required means implement it
- Addressable means decide and record
- Neither means optional
Encryption
- Addressable under the rule
- Recognized standards give safe harbor
- Keys compromised, protection gone
Evidence
- Six year retention
- Analysis, decisions and tests
- Policies matched by practice
Quick exam traps
- Trap: The Security Rule protects paper records as well as electronic ones
- Trap: Addressable means the specification is optional
- Trap: Encryption of stored data is a required implementation specification
- Trap: A small practice is exempt because the controls are unaffordable
- Trap: A risk analysis of the main clinical system is enough
- Trap: Business associates only owe the duties written into their contract
- Trap: Buying certified software satisfies the Security Rule
cybercertprep.com · original revision sheet written from the public body of knowledge