HIPAA · Domain 4
Technical & Physical Safeguards
About 15% of the exam
Technical safeguard standards
- Access control
- unique identification, emergency access, logoff, encryption
- Audit controls
- record and examine system activity
- Integrity
- confirm records were not altered
- Authentication
- prove the requester is genuine
- Transmission security
- integrity controls and encryption in transit
Physical safeguard standards
- Facility access controls
- who gets into the building
- Contingency operations
- access during disaster recovery
- Facility security plan
- protect equipment from tampering
- Access control and validation
- verify identity and escort visitors
- Maintenance records
- log repairs to physical security
- Workstation use
- what tasks each workstation performs
- Workstation security
- physical protection for those devices
- Device and media controls
- disposal, reuse, accountability and backup
Unique user identification
- Required, with no shared accounts
- Ties every action to a person
- Shared front desk logins fail here
- Supports audit trails and accountability
- Service accounts need named owners
Emergency access
- Required, not addressable
- Reach the records during a crisis
- Break glass accounts with heavy logging
- Tested so it works under pressure
- Reviewed after every use
Audit controls
- Capture logins and failed attempts
- Capture record access and changes
- Capture security setting modifications
- Collecting logs is not reviewing them
- Retention long enough to investigate
- Alerting on patterns beats manual reading
Transmission security
- Encrypt clinical mail in transit
- Modern protocols, not deprecated ones
- Integrity controls detect alteration en route
- Interfaces need authentication and logging
- Portals beat unprotected email attachments
Device and media controls
Required
- Disposal procedures for media holding records
- Media reuse only after removal
Addressable
- Accountability records of movement and owner
- Data backup before equipment moves
Leased imaging equipment with internal storage is the awkward case: agree sanitization in the lease and obtain written proof of destruction
Workstations and facilities
- Define which functions each workstation performs
- Position screens away from public view
- Privacy filters and automatic screen locks
- Escort visitors through sensitive areas
- Badge and log entry to server rooms
- Cleaning crews are a real exposure
- Protect against fire, flood and outages
Mobile and remote work
- Encrypt laptops and portable drives
- Remote wipe for lost devices
- Passcodes and biometric unlock enforced
- Personal devices need a written policy
- Transport with tracking and custody records
Disposal done properly
- Sanitize before donation or return
- Certificates of destruction from vendors
- Record method, date and serial numbers
- Sample and verify the sanitization
- Vendors may need an agreement
Technical failures investigators cite
- Shared logins across a department
- Outdated remote access protocols still running
- Automatic logoff disabled for convenience
- An unencrypted laptop stolen from a car
- Logs kept for two weeks only
- Application errors leaking record details
Technical, required against addressable
- Unique identification
- required, always
- Emergency access
- required, always
- Automatic logoff
- addressable, tuned to setting
- Encryption at rest
- addressable, document the choice
- Audit controls
- a standard with no specifications
- Integrity authentication
- addressable, checksums or signatures
- Transmission encryption
- addressable, expected in practice
Physical, required against addressable
- Disposal
- required, remove before discard
- Media reuse
- required, sanitize first
- Accountability
- addressable, track movements
- Data backup and storage
- addressable, copy before moving
- Contingency operations
- addressable, plan the access
- Workstation use
- a standard with no specifications
Layering the two families
- Lock the room
- Control who enters it
- Identify who logs in
- Limit what they can reach
- Record what they did
- Encrypt what leaves the building
- Sanitize what is thrown away
- Physical protects the box, technical the data
- One family cannot cover the other
- Both feed the same risk analysis
- Preserve evidence before restoring systems
Reference strip: access, audit, transmission, workstations, media
Access
- Unique identifiers, no sharing
- Emergency access always required
- Logoff and encryption addressable
Audit
- Record and examine activity
- Review, do not just collect
- Keep logs long enough
Transmission
- Encrypt clinical mail in transit
- Integrity controls detect tampering
- Retire weak protocols
Workstations
- Define the permitted functions
- Shield screens from view
- Lock unattended devices
Media
- Sanitize before reuse
- Certificates for destruction
- Track movements and owners
Quick exam traps
- Trap: Automatic logoff is a required implementation specification
- Trap: Encryption in transit is explicitly mandated by the Security Rule
- Trap: Physical safeguards only matter for servers kept on the premises
- Trap: Collecting audit logs satisfies the audit controls standard
- Trap: A shared front desk login is acceptable if the room is secure
- Trap: Wiping a leased device becomes the vendor's responsibility once returned
- Trap: Backups are a technical safeguard rather than a contingency duty
cybercertprep.com · original revision sheet written from the public body of knowledge