HIPAA

    HIPAA Compliant Data Centers: How to Assess Them
    ,
    HIPAA Compliant Data Centers: How to Assess Them
    TL,DR: A HIPAA-compliant data center must hold a HIPAA Report On Compliance (HROC) document as the gold standard for verification. Target paid $18.5 million in settlement after a breach through one of its HVAC vendors Required elements include documented disaster recovery plans, physical access controls (RFID and surveillance), IP separation for ePHI storage, periodic risk…
    Healthcare Cybersecurity: Essential Practices for Protection
    , ,
    Healthcare Cybersecurity: Essential Practices for Protection
    TL,DR: Healthcare cyber security protects patient data, clinical systems, medical devices, and healthcare operations. Key threats include ransomware, phishing, insider risk, third-party exposure, and data breaches. Strong safeguards include HIPAA controls, access reviews, backups, monitoring, and employee training. In October 2021, a Japanese hospital was forced to shut down operations for months. Malicious actors encrypted…
    Hipaa compliance for software
    ,
    How to Ensure HIPAA Compliance for Software?
    TL,DR: Software handling ePHI must comply with HIPAA’s Privacy, Security, and Breach Notification Rules, covering encryption, access control, audit logging, and vendor agreements. Audit logs tracking ePHI access must be tamper-proof and retained for at least six years. Core technical safeguards include AES-256 encryption at rest, TLS 1.2 or higher in transit, role-based access control,…
    What is a HIPAA Identifier and How is it Used
    ,
    What is a HIPAA Identifier and How is it Used?
    TL,DR: HIPAA identifiers are 18 specific data attributes that can identify an individual, including name, geographic location, dates, phone numbers, SSN, medical record numbers, IP addresses, biometric identifiers, and full-face photographs PHI is created only when any of the 18 identifiers are linked to health information. Direct identifiers (like SSN) identify a person alone, while…
    What Is a HIPAA Consent Form and Why It Matters
    ,
    What Is a HIPAA Consent Form and Why It Matters?
    TL,DR: A HIPAA consent form lets covered entities use or disclose PHI under defined conditions. It should explain PHI use, patient permissions, privacy duties, complaint rights, contacts, purpose, and expiration. The article covers consent versus authorization, when HIPAA requires authorization, and includes a downloadable template. Healthcare practices and research centers access, transmit and store patient…
    HIPAA Compliant Text Messaging Rules and Safeguards
    ,
    HIPAA Compliant Text Messaging Rules and Safeguards
    TL,DR: HIPAA-compliant text messaging requires sufficient technical safeguards including end-to-end encryption, access controls, and audit trails. Standard SMS does not meet HIPAA standards because messages lack adequate encryption Messaging is compliant when patients are informed of texting risks, consent is obtained, end-to-end encryption is implemented, access controls are enforced, and complete audit trails are maintained…