HIPAA Security Rule (and selected Breach Notification Rule duties)
Administrative, physical and technical safeguards of the HIPAA Security Rule, plus the organisational requirements and the core Breach Notification Rule duties. Applies to covered entities and, since the HITECH Act, directly to business associates.
US Department of Health and Human Services, Office for Civil Rights · 45 CFR Part 164 Subparts C and D · United States · Official source
Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of electronic protected health information held by the entity.
Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.
Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity or business associate.
Implement procedures to regularly review records of information system activity, such as audit logs, access reports and security incident tracking reports.
Identify the security official who is responsible for the development and implementation of the policies and procedures required by the Security Rule.
Implement procedures for the authorisation and supervision of workforce members who work with electronic protected health information or in locations where it might be accessed.
Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate.
Implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends.
Implement policies and procedures for granting access to electronic protected health information, for example through access to a workstation, transaction, programme, process or other mechanism, on the minimum necessary standard.
Implement policies and procedures that, based upon the entity's access authorisation policies, establish, document, review and modify a user's right of access to a workstation, transaction, programme or process.
Implement a security awareness and training programme for all workforce members, including periodic security reminders, protection from malicious software, log-in monitoring and password management.
Identify and respond to suspected or known security incidents; mitigate, to the extent practicable, harmful effects of security incidents that are known to the entity; and document security incidents and their outcomes.
Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information.
Establish and implement procedures to restore any loss of data.
Establish and implement procedures to enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode.
Implement procedures for periodic testing and revision of contingency plans.
Perform a periodic technical and non-technical evaluation of the extent to which the entity's security policies and procedures meet the requirements of the Security Rule.
A covered entity may permit a business associate to create, receive, maintain or transmit electronic protected health information on its behalf only if it obtains satisfactory assurances, documented through a written business associate agreement, that the business associate will appropriately safeguard the information.
Implement policies and procedures to limit physical access to electronic information systems and the facilities in which they are housed, while ensuring that properly authorised access is allowed.
Specify the proper functions to be performed and the manner in which they are to be performed for workstations that access electronic protected health information, and implement physical safeguards to restrict access to authorised users.
Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of a facility, and the movement of these items within the facility, including disposal, media re-use, accountability and data backup and storage.
Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to authorised persons or software programmes, including unique user identification and emergency access procedures, with automatic logoff and encryption/decryption as addressable specifications.
Implement hardware, software and procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.
Implement policies and procedures to protect electronic protected health information from improper alteration or destruction, with mechanisms to authenticate ePHI as an addressable specification.
Implement procedures to verify that a person or entity seeking access to electronic protected health information is the one claimed.
Implement technical security measures to guard against unauthorised access to electronic protected health information that is being transmitted over an electronic communications network, with integrity controls and encryption as addressable specifications.
Implement a mechanism to encrypt and decrypt electronic protected health information. Where encryption is not implemented, the entity must document why it is not reasonable and appropriate and what equivalent alternative measure is in place.
Following the discovery of a breach of unsecured protected health information, notify each affected individual without unreasonable delay and no later than 60 days after discovery (§164.404); for a breach affecting more than 500 residents of a state or jurisdiction, also notify prominent media outlets (§164.406); notify HHS — within the same 60-day window for breaches affecting 500 or more individuals, and within 60 days of the end of the calendar year for smaller ones (§164.408). A business associate must notify the covered entity (§164.410).