ER Tech Pros uses Google Analytics to understand how users interact with our website, helping us improve your experience.
Data collected (e.g., pages visited, time spent, location) is anonymized and stored securely, with no personal information shared.
Learn more via Google’s Privacy Policy . To opt out, adjust your browser settings or use the Google Analytics Opt-out Add-on .
By clicking “Accept,” you consent to this data collection.
The entire HIPAA legislation is no quick read! Its length and technical jargon may make it difficult for you to know where and how to start becoming HIPAA compliant.
For healthcare providers wanting to take a step toward having a HIPAA-compliant practice, these basic HIPAA rules are a good place to start: Privacy, Security, and Breach Notification.
It’s also important to keep in mind that these apply to:
The HIPAA Privacy Rule largely covers protected health information (PHI). It points out the restrictions and conditions that need to be observed when using and/or disclosing PHI. It discusses what can and cannot be shared without patient authorization, and with whom such information can be disclosed.
The Privacy Rule also gives patients (or their nominated representatives) rights over their PHI. These rights include being able to obtain a copy of and/or examine their health records as well as being able to request necessary corrections.
Under the Privacy Rule, covered entities are strongly advised to:
Even when the use or disclosure of PHI is permitted under the HIPAA Privacy Rule, it still needs to go through the minimum necessary standard, which means that access to PHI is limited to the minimum amount of information necessary to fulfill the intended purpose of the particular disclosure, request, or use.
The HIPAA Security Rule defines and regulates the standards, methods, and procedures that must be applied to electronically stored, accessed, and transmitted PHI (ePHI).
The Security Rule comprises three parts—technical, physical, and administrative safeguards. Some safeguards must be implemented (required), while some can be implemented with a reasonable amount of flexibility (addressable).
Here they are according to
HIPAA Journal’s Compliance Checklist:
The technical safeguards focus on the technology used to protect and provide access to ePHI. HIPAA requires ePHI (at rest or in transit) to be encrypted according to
NIST standards once ePHI goes beyond an organization's internal firewalled servers.
The physical safeguards cover physical access to ePHI, whether these are stored in on-premise servers, on the cloud, or in an offsite data center.
The administrative safeguards focus on internal organization, workforce management, maintenance of security measures that ensure the protection of ePHI.
According to the US Department of Health and Human Services (HHS), a breach is generally defined as an impermissible use or disclosure under the HIPAA Privacy Rule that compromises the security or privacy of the PHI.
In the event of a PHI breach, the Breach Notification Rule requires covered entities to provide notifications to certain parties without unreasonable delay and in no case later than 60 days following the incident:
| What happens if you break HIPAA rules? Read HIPAA Compliance and Your Practice: Part 3 of 3
HIPAA compliance deals a lot more than just the basics, which is why you need a reliable partner as you take steps in getting that HIPAA Seal of Compliance for your healthcare practice.
ER Tech Pros is a managed service provider that specializes in giving healthcare practices the IT, cloud, and compliance technology they need to keep their data secure and their operations HIPAA compliant.
If you found the checklists above to be helpful and practical, we’ve got more in store for you!
Search Articles
ER Tech Pros is a managed service provider (MSP) that specializes in catering to the IT needs of businesses across the globe. We have offices in Sacramento and the Greater Fresno area.
We use our cutting-edge technology, extensive experience, and global team of technology experts to ensure your IT network is in its most secure and optimal state.
We focus on your IT so you can focus on growing your company.
8795 Folsom Blvd, Ste 205
Sacramento, CA 95826
1501 Howard Rd, Ste 2
Madera, CA 93637
(855) ER-TECH-1 / (855) 378-3241
info@ertech.io
Resources
Search this Site
ERTech Pros | All Rights Reserved.