HIPAA Tip: Stay on Top of HIPAA Requirements
We’ve all heard about the HIPAA Security Rule Notice of Proposed Rule Making (NPRM) submitted in December 2024. Fast forward, we were expecting some of the proposals to come into enforcement in May 2026. The Department of Health and Human Services (HHS) is reviewing the rule, with no confirmed date for finalization.
What does this mean for healthcare organizations and their Business Associates? Work harder and smarter to secure your institution against cyber-attacks and breaches, at the same time moving forward with HIPAA compliance; that’s what it means.
- Conduct an annual HIPAA Security Risk Analysis (SRA) that will identify potential vulnerabilities and risks to the Confidentiality, Integrity and Availability (CIA) of ALL Protected Health Information (PHI/ePHI) the organization is responsible for.
- Encryption for emails containing ePHI or sensitive data is NOT an option; all data in transit must be encrypted. Data stored on servers, workstations, laptops and backup devices must be encrypted with AES-256 or equivalent encryption protocols.
- Vulnerability Scans are automated processes that identify weaknesses in networks and applications. Any compliance expert will recommend, at minimum, an annual Vulnerability Scan to address security vulnerabilities proactively before attackers can exploit and gain access into your network.
- 2 Factor or Multi-Factor Authentication (2FA/MFA) whenever possible: remote access into systems and applications containing ePHI within the business environment as well as from home offices; connections to corporate emails from any device; third parties/vendors accessing the organization’s servers or work computers.
Compliance Is Ongoing
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.