HIPAA · Domain 3
Administrative Safeguards
About 20% of the exam
The nine administrative standards
- Security management process
- analysis, management, sanctions, activity review
- Assigned security responsibility
- one named security official
- Workforce security
- authorization, clearance and termination
- Information access management
- who reaches which systems
- Awareness and training
- reminders, malware, logins, passwords
- Security incident procedures
- respond to and report incidents
- Contingency plan
- backup, recovery and emergency mode
- Evaluation
- periodic review against the rule
- Business associate contracts
- written assurances from vendors
Security management process
Required parts
- Risk analysis of all electronic records
- Risk management reducing risk sufficiently
- Sanction policy applied to violations
- Information system activity review
How it fails
- Analysis scoped to one system
- A plan written but never funded
- Sanctions inconsistent across ranks
- Logs generated and never read
Everything else in the rule depends on the risk analysis, which is why investigators ask for it first and judge the rest against it
Workforce security
- Authorization before access is granted
- Supervision of people near sensitive systems
- Clearance procedures such as background checks
- Termination procedures revoking access promptly
- Applies to volunteers and trainees
Sanction policy
- Written and known to everyone
- Proportional to the violation's severity
- Applied consistently regardless of seniority
- Distinguish mistakes from deliberate snooping
- Document what was applied and why
Information access management
- Access authorization by role and need
- Establish and modify access over time
- Isolate clearinghouse functions where they exist
- Periodic reviews confirm access still fits
- Remove access on the last day
Awareness and training
- Security reminders on a schedule
- Protection from malicious software
- Log in monitoring and reporting
- Password management practices
- Phishing recognition and reporting
- New joiners trained within reason
Contingency plan
- Data backup plan
- required, retrievable exact copies
- Disaster recovery plan
- required, restore lost data
- Emergency mode operation
- required, keep critical processes running
- Testing and revision
- addressable, prove the plan works
- Criticality analysis
- addressable, rank the systems
- Backups never tested
- the classic audit finding
Incident procedures
- Detect and report the incident
- Assess what information was involved
- Contain and eradicate the cause
- Mitigate the harmful effects
- Document outcomes and lessons
- Feed the risk analysis
- Decide whether breach rules apply
- Every security incident needs a response
- Only some incidents become reportable breaches
- The team spans clinical, legal and technical
- Escalation paths agreed before the crisis
Assigned responsibility
- One named security official required
- The privacy official may be separate
- Authority and budget to act
- Leadership still owns the outcome
- Duties documented, not assumed
Vendor management
- An agreement before any access
- Discovery of unsanctioned services in use
- Security review proportional to the risk
- Right to audit and receive reports
- Incident terms with real deadlines
- Offboarding returns or destroys data
Group health plan duties
- Plan documents amended before disclosure
- The sponsor certifies it will safeguard
- Separation between plan and employer functions
- Summary information has looser rules
- Enrollment data sits outside the plan
Required against addressable
- Risk analysis
- required, no alternative
- Sanction policy
- required, apply it consistently
- Activity review
- required, read the logs
- Termination procedures
- addressable, but always expected
- Training program
- addressable, in practice essential
- Testing the plan
- addressable, and often skipped
Retention and review
- Documentation
- six years from last effect
- Training records
- keep proof of attendance
- Risk analysis
- refresh after significant change
- Access reviews
- on a defined schedule
- Plan testing
- at least annually in practice
Turning findings into action
- List the findings with owners
- Rate them by risk, not ease
- Choose controls or compensating measures
- Set dates and track them
- Retest and close with evidence
- Report progress to leadership
- Unpatched legacy systems need compensating controls
- Segmentation and monitoring buy time
- Accepting risk requires a documented decision
- Open findings become enforcement evidence
Reference strip: process, people, access, continuity, vendors
Process
- Analysis, management, sanctions, review
- One named security official
- Evaluate against the rule
People
- Authorize, supervise, clear, terminate
- Train and remind regularly
- Sanctions proportional and consistent
Access
- Grant by role and need
- Review that it still fits
- Remove on the last day
Continuity
- Backup, recovery, emergency mode
- Rank systems by criticality
- Test before you need it
Vendors
- An agreement before access
- Discover shadow services
- Audit and offboard properly
Quick exam traps
- Trap: Administrative safeguards are paperwork rather than real controls
- Trap: The security official must be a technical specialist
- Trap: Training once at hire satisfies the awareness standard
- Trap: Backups that exist do not need to be tested
- Trap: A signed vendor agreement makes the vendor's security their problem alone
- Trap: Sanctions should be identical whatever the intent behind the violation
- Trap: Contingency planning belongs to the physical safeguards
cybercertprep.com · original revision sheet written from the public body of knowledge