Tuesday, May 17, 2005

Early Observations

Now that the HIPAA Security Rule has been in effect for almost a month, I have had the opportunity to see how well agencies are actually implementing the rule. It's a mixed bag but here are a few things to think about.

1. If a workstation or laptop containing EPHI is seriously infected with Spyware or a Virus, it is considered a Security Incident and must be logged in your Security Incident Log. (See the 12/21/04 post on this blog).

2. If a workstation or laptop containing EPHI is lost in a fire or some other type of accident it is a Security Incident and must be logged in your Security Incident Log and must be documented in your Equipment Disposal Log. The same is true if the device is stolen. Other steps may need to be taken as well such as changing passwords, notifying authorities, etc.

3. If servers, workstations, laptops, or other devices containing EPHI are showing errors in their Security Event Logs, this may be a Security Incident and must be logged in your Security Incident Log.

The Risk assessment requirement of the Security Rule should have produced a list of all devices that contain EPHI. This list is very useful for determining which of the above incidents may or may not need to be logged.

Each of these types of incidents has occurred in the last month to our some of our Clients. In each case I'm not sure that HIPAA Security compliance popped up the way it should have. We have all spent a lot of time creating policies and procedures to meet the requirements of the Rule. Let's make sure that we practice what we defined.

7 Comments:

At 11:51 AM, Anonymous Anonymous said...

I think the admin of this website is really working hard in support of his
web page, for the reason that here every data is quality based information.


Review my website: www.phil-zib.uni-koeln.de

 
At 8:36 PM, Anonymous Anonymous said...

It's appropriate time to make some plans for the future and it is time to be happy. I have learn this submit and if I may just I wish to suggest you few interesting things or suggestions. Perhaps you could write next articles relating to this article. I wish to read more things approximately it!

my site :: men's
armitron watches

 
At 2:35 AM, Anonymous Anonymous said...

Hello there I am so excited I found your blog page, I really found you by error, while I was browsing
on Google for something else, Regardless I am here now and would just like to say
thanks for a marvelous post and a all round entertaining blog (I also love the theme/design), I
don’t have time to read through it all at the minute but I have saved it and also
included your RSS feeds, so when I have time I will
be back to read a lot more, Please do keep up the awesome b.



Here is my site :: seo expert

 
At 10:24 PM, Anonymous Anonymous said...

Hi there every one, here every one is sharing these kinds
of know-how, therefore it's fastidious to read this web site, and I used to visit this website everyday.

Look at my blog post :: vaccineeducationonline.org

 
At 4:26 AM, Anonymous Anonymous said...

It's remarkable to pay a quick visit this web page and reading the views of all colleagues regarding this post, while I am also eager of getting experience.

Take a look at my site :: remote control hobbies

 
At 10:32 PM, Anonymous Anonymous said...

If you desire to grow your experience only keep visiting this website and be updated with
the newest news update posted here.

my blog post - victorinox swiss army watches for women

 
At 1:00 PM, Anonymous Anonymous said...

You are so awesome! I do not think I have read a single
thing like that before. So wonderful to discover another person with some genuine thoughts on this topic.
Seriously.. thank you for starting this up. This web site is one thing that's needed on the web, someone with a bit of originality!

My web blog; akribos

 

Post a Comment

<< Home