Guide for Security of EPHI

Posted by BAS - 23 April, 2015

header-picture

The Office of the National Coordinator for Health IT released a new guide addressing security of electronic protected health information. The guide can be found here. 

The guide is targeted at hospitals, providers and their business associates, but can provide some guidance for employers and their health plans. It suggests that covered entities adopt a step-by-step approach for implementing a security management process. The suggested approach includes:

  • Selecting a team
  • Documenting processes, findings and actions
  • Reviewing existing security of electronic protected health information through a security risk analysis
  • Developing an action plan
  • Managing and mitigating risks
  • Monitoring, auditing and updating security on an ongoing basis. 

The guide also details HIPAA breach notification requirements and explains encryption. A large focus of the guidance is on electronic health records, but some of the concepts can apply to any storage of electronic protected health information.

 


Recent Posts

Question of the Week - ACA Transmission: Accepted with Errors

read more

IRS Dirty Dozen: Phishing and Smishing

read more

Streamlining HR Document Management with MyEnroll360's Reference Library Feature

read more