HIPAA Tip: Get Your House in Order!
Enough with the “I’ll get to that soon,…” thought process when it comes to HIPAA requirements and compliance regulations. Now more than ever, with cyber and ransomware attacks increasing at an exponential rate, organizations must know how strong (or weak) their security posture is.
Start with the annual Security Risk Analysis (SRA). Identify areas that need improvement for stronger security measures as well as policies and procedures and physical securities that may need tightening up.
- What technical securities need to be updated or added? Is the organization conducting an annual Vulnerability Scan to identify weaknesses within the environment? Have all Windows 10 Operating Systems (OS) been upgraded to Windows 11, or has extended licensing been purchased for the existing Windows 10 OS? Are passwords to systems and applications containing ePHI at minimum 12 characters?
- Are required policies and procedures in place per the HIPAA Security Rule? Have all policies been reviewed, revised and presented to staff where applicable? Do procedures need updating for the network and environment where changes occurred: servers offsite (cloud), change in the EMR or software solutions containing ePHI, Disaster Recovery Plan does not reflect the current status where data is stored either onsite or offsite?
- Have locks been changed or alarm codes reset since employees resigned or were terminated? Is there limited access into the server/network room? Who has access to older medical records either stored onsite or offsite? Is there an auto-lock (time-out) in place for all systems and applications containing ePHI?
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.