HIPAA Tip: Checklist for Information Technology Team
Your Information Technology (IT) team needs to be one of your nearest and dearest comrades in securing the organization from all the scary and nasty threat actors trying to steal patient data, sabotage critical software (EMRs, scheduling, billing), or worse, halt patient care with a ransomware attack or breach.
Confirm the following with your IT team/department:
- Patching Windows Operating Systems for all computers is up to date. Have remote business devices checked in case they are not always turned on/in use.
- Endpoint Detection Response (EDR) solution for all business devices that is centrally managed with real-time updates.
- Wireless access for the internal/corporate/private wireless network must be checked to ensure no personal devices are running on this network. If personal devices are found they need to be knocked off, to use only the Guest or Staff wireless.
- Firewall firmware must be checked to confirm the latest firmware version has been uploaded/updated. Firewall logs checked to have 365-day retention versus a free 7-day retention for logs.
- Encryption for emails containing ePHI or sensitive data, with staff trained on how to use the tool. Encryption enabled for all portable devices.
- 2 factor/multi-factor authentication (2FA/MFA) for remote connections into systems containing ePHI, connections for third parties accessing the organization’s data, and email connections outside of the business environment from personal devices.
- Backups for critical data are maintained in multiple locations, all important data has been identified (and is part of the backups), and testing of backups is completed at minimum bi-annually and sent to the organization.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.