Data Backup and Security Blog

Three Important HIPAA-HITECH Compliance Webinars

Wednesday, November 3rd, 2010
Just a short note to let you know we are offering three (3) 90 minute Complimentary Live Webinars that you have requested. During the month of November, we are pleased to offer:
 
Learn from Mayra Scheuermann, Esq. and Carlos Leyva, Esq. why you need HITECH-ready Business Associate (BA) Contracts. In this webinar, attendees will benefit by learning:
 
Whether you’re a Covered Entity (CE), a Business Associate (BA) or a subcontractor, if you receive, store, process or transmit ePHI, you need to attend.  In this webinar, attendees will:
  • Review the HIPAA Security Final Rule
  • Learn about major changes brought about by The HITECH Act
  • Learn about the new Civil Monetary Penalty System
  • Learn practical, actionable steps to take today to mitigate risk and help assure compliance
  • Learn how to jump-start their program with a HIPAA Security Evaluation (45 CFR §164.308(a)(8))
  • View a demo of our HIPAA-HITECH Security Assessment ToolKit™
Register Now! - How to Conduct a HIPAA Security Risk Analysis
A HIPAA Security Risk Analysis (§164.308(a)(1)(ii)(A)) is also required by law to be performed by every Covered Entity and Business Associate. Discover how to achieve HIPAA-HITECH compliance with this Required Implementation Specification. In this webinar, attendees will learn about:
  • Risk Analysis essentials
  • Specific requirements outlined in HHS/OCR Final Guidance
  • A Practical Risk Analysis Methodology
  • Step-by-Step Instructions for completing a HIPAA Risk Analysis
  • Resources available to help you
  • Our HIPAA-HITECH Risk Analysis ToolKit™
We hope you can join us and benefit from our expertise! Register today:
 
800-704-3394
  • Share/Bookmark

bob.chaput@datamountain.com | (800) 704-3394 | Follow Bob on Twitter: twitter.com/BobChaput


 

Required versus Addressable HIPAA Implementation Specs

Thursday, September 2nd, 2010

The HIPAA Security Final Rule comprises Standards (what must be done) and Implementations Specifications (how it must be done) for creating policies, procedures and practices to prevent, detect, contain and correct security violations.

Implementation specifications are indicated as required or addressable.  As organizations work towards HIPAA-HITECH compliance, it is important to understand the difference.

A covered entity or business associate must comply with a required implementation specification must.  For example, all covered entities and business associates including small providers must conduct a “Risk Analysis” in accordance with Section 164.308(a)(1) of the Security Rule.

For addressable implementation specifications, covered entities must perform an assessment to determine whether the specification is a reasonable and appropriate safeguard in the covered entity’s environment. After performing the assessment, an organization decides if it will:

  • Implement the addressable implementation specification as stated;
  • Implement an equivalent alternative measure that allows the entity to comply with the standard; or,
  • Not implement the addressable specification or any alternative measures, if equivalent measures are not reasonable and appropriate within its environment.

Covered entities and business associates are required to document these assessments and all decisions. For example, all covered entities including small providers must determine whether “Encryption and Decryption” is reasonable and appropriate for their environment in accordance with Section 164.312(a)(1) of the Security Rule.

Factors that determine what is “reasonable” and “appropriate” include cost, size, technical infrastructure and resources. While cost is one factor entities must consider in determining whether to implement a particular security measure, some appropriate measure must be implemented.

An addressable implementation specification is not optional, and the potential cost of implementing a particular security measure does not free covered entities from meeting the requirements identified in the rule.

Our advice…

  • Don’t waste time debating about ‘addressable’ versus ‘required’.
  • Just do it! – the vast majority of the standards specifications make good business sense.
  • HIPAA Security Standards set a “floor” or “baseline” for security
  • Don’t make the mistake of thinking ‘addressable’ means ‘optional’; it does not!
  • Check out our HIPAA-HITECH compliance software to jump-start your program
  • Share/Bookmark

bob.chaput@datamountain.com | (800) 704-3394 | Follow Bob on Twitter: twitter.com/BobChaput