Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: New Year’s Resolutions

When is the best time to get your HIPAA House in order? Now!

  • Step One: Review active users in all systems and applications containing ePHI (including Windows/Active Directory), to ensure workforce members no longer employed have been disabled. During the audit (which needs to be done regularly, not just annually), review users’ privileges in these systems – think minimum necessary rule.
  • Step Two: Request a list of managed devices from your IT company/department, along with the current Operating System (OS). Any outdated / end of life computers or servers must be updated, replaced, decommissioned (per HIPAA standards), or immediately removed from the network. Inventory diagnostic machines that are connected to computers, to guarantee there are no end of life systems actively running on the network environment.
  • Step Three: Conduct a HIPAA Security Risk Analysis (SRA) right away if this has not been completed in the past year. This is a HIPAA requirement and the first item HHS OCR will request when undergoing an investigation (patient complaint, security incident, breach). The SRA will give your organization the baseline for where vulnerabilities exist and highlight the most critical areas that must be addressed right away for security and compliance.

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.