HIPAA Tip: HIPAA Common Sense

We talk all the time about the same things: long, complex passwords, updating/patching systems and applications containing ePHI, enabling two-factor/multi-factor authentication whenever possible for systems storing ePHI (connecting either onsite or remotely), enabling encryption on business devices, especially if they will be traveling out of the office/center.

When you think about some of the areas within a healthcare environment that may be vulnerable or open to risk of exposing patient data, common sense would tell you without fail what to do to mitigate these risks.

  1. Clean desk policy enforced every night, including clearing faxes off physical fax machines (if still in use).
  2. Not only logging out of all systems and applications containing ePHI but also locking the computer (Ctrl+Alt+Del / Windows key + L key).
  3. Store keys to shredding bins, server rooms, basement access where older medical records are stored in a secure lock box or locked desk drawer with key personnel having access only.
  4. Network switch room or server room needs to be treated with respect – not doubled as the supply room or where the cleaning company stores their products.
  5. Business computers are just that – for business purposes only. Storing personal data or surfing the internet needs to be discontinued and reserved for personal devices only.

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.