HIPAA Tip: Administrative Safeguards
The HIPAA Security Rule defines Administrative Safeguards (45 CFR § 164.308) as “administrative actions, and policies and procedures, to manage the selection, development, implementation, and maintenance of security measures to protect electronic Protected Health Information and to manage the conduct of the Covered Entities’ workforce in relation to the protection of that information.”
The Administrative Safeguards comprise over half of the HIPAA Security Rule requirements. The Security Management Process standard requires Covered Entities to establish policies and procedures to prevent, detect, contain, and correct security violations:
- Risk Analysis
- Risk Management
- Sanction Policy
- Information System Activity Review
- Workforce Security
- Information Access Management
- Security Awareness and Training
- Assigned Security Responsibility
- Security Incident Procedures
- Contingency Plan
- Business Associate Agreements/Contracts
All of the Administrative Safeguards and the Implementation Specifications must be in place for all Covered Entities and Business Associates. HHS.gov Administrative Safeguards.
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP