HIPAA Tip: Here’s What I Would Do When It Comes to HIPAA Compliance
Wondering what I would do if I owned a healthcare organization?
If I had an endless bank account:
- All users in systems and applications containing ePHI would have unique user IDs and 14-character passwords; this would include any medical devices used in the business.
- Encryption for all workstations, laptops and iPads containing ePHI.
- All staff use corporate email accounts with encryption enabled and are trained on the use of encryption.
- Multi-factor authentication (MFA) for logging into systems and applications containing ePHI remotely, as well as email accounts and remote user access into the organization’s network.
- Annual Vulnerability Scans on the network to detect weaknesses in the environment.
- Endpoint Detection and Response (EDR) and Managed and Detection Response (MDR) in place for the organization.
- Comprehensive Security Risk Analysis (SRA) completed annually.
- Disaster Recovery Plan / Contingency Plan updated at least annually and tested at least twice a year.
- Required policies and procedures per the HIPAA Rules are in place and updated/reviewed annually.
Here’s what I would do if I were on a budget:
- All users in systems and applications containing ePHI would have unique user IDs and 14-character passwords; this would include any medical devices used in the business.
- Encryption for all workstations, laptops and iPads containing ePHI.
- All staff use corporate email accounts with encryption enabled and are trained on the use of encryption.
- Multi-factor authentication (MFA) for logging into systems and applications containing ePHI remotely, as well as email accounts and remote user access into the organization’s network.
- Annual Vulnerability Scans on the network to detect weaknesses in the environment.
- Endpoint Detection and Response (EDR), and Managed and Detection Response (MDR) in place for the organization.
- Comprehensive Security Risk Analysis (SRA) completed annually.
- Disaster Recovery Plan / Contingency Plan updated at least annually and tested at least twice a year.
- Required policies and procedures per the HIPAA Rules are in place and updated/reviewed annually.
I think you see my point. Most of the critical steps to protecting a healthcare organization do NOT cost a fortune; however, they are crucial in protecting against cyber attacks and threat actors.
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP