Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Identity Security

What is Identity Security and why do we need to pay such close attention to this?

Identity security is not just about authentication and authorization, it is at the heart of cybersecurity: authorized individuals have access to data when needed. Unauthorized access or escalated/excessive access rights can lead to data theft, sabotage, or worse, a breach.

The healthcare industry has a responsibility to protect the Confidentiality, Integrity and Availability (CIA) of patients’ data, or Protected Health Information (PHI). If identity security is not in place or followed with best practices, access privileges that may include malicious behavior are compromised. Without identity security an organization cannot hold users accountable for their actions.

Identity security is the foundation of a robust cybersecurity program and critical for managing related controls and policies. Given the increase every day of cybersecurity attacks on healthcare organizations, identity security can control the availability of systems and applications containing PHI.

Remember, “least privileged access” or “minimum necessary”.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


Author:

Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP