HIPAA Tip: HIPAA Common Sense
We talk all the time about the same things: long, complex passwords, updating/patching systems and applications containing ePHI, enabling two-factor/multi-factor authentication whenever possible for systems storing ePHI (connecting either onsite or remotely), enabling encryption on business devices, especially if they will be traveling out of the office/center.
When you think about some of the areas within a healthcare environment that may be vulnerable or open to risk of exposing patient data, common sense would tell you without fail what to do to mitigate these risks.
- Clean desk policy enforced every night, including clearing faxes off physical fax machines (if still in use).
- Not only logging out of all systems and applications containing ePHI but also locking the computer (Ctrl+Alt+Del / Windows key + L key).
- Store keys to shredding bins, server rooms, basement access where older medical records are stored in a secure lock box or locked desk drawer with key personnel having access only.
- Network switch room or server room needs to be treated with respect – not doubled as the supply room or where the cleaning company stores their products.
- Business computers are just that – for business purposes only. Storing personal data or surfing the internet needs to be discontinued and reserved for personal devices only.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.