health information technology
Security Planning
Susan Lincke
Complying with HIPAA and
HITECH
*
Security Planning: An Applied Approach | * | *
Objectives:
Students shall be able to:
Define HIPAA, Privacy Rule, Security Rule, CE, PHI.
Define threat, vulnerability, threat agent
Describe what Privacy Rule covers at a high level
Describe what Security Rule covers at a high level
Describe the difference between Required and Addressable for the Security Rule.
By the way, by now you are probably wondering if you will be tested on HIPAA. The good news is MINIMAL in Dr Lincke’s class. HIPAA will be used in class for the case study, but except for similar questions which are shown here, you will not be responsible for HIPAA on an exam.
*
Security Planning: An Applied Approach | * | *
HIPAA
Introduced by Senators Edward Kennedy & Nancy Kassebaum
Portability: Workers can continue health care between different employers
Group insurance cannot reject, not renew, or charge higher premiums of certain individuals
Simplify administration by creating a health care transaction standard
Accountability:
Penalties for non-compliance
Tax provisions
The main intent of the legislation was to protect workers by making their health status PRIVATE. This would impact their careers, getting health care insurance when they change jobs, etc. However, realistically we can see that it did not prevent existing insurance providers from dropping sick people or perhaps raising the health insurance price for the company, which resulted in the company dropping certain people.
Pre-existing Condition Rule:
- An employer-provided health plan can only look back up to 6 months to declare a pre-existing condition.
Pre-existing condition: Only exists if the patient received treatment for the condition within the six months prior to enrolling in a health plan.
- HIPAA limits the amount of time that an employer-provided health plan can make an employee wait for coverage because of a pre-existing condition to 12 months, but this period can be shortened in many situations.
*
Security Planning: An Applied Approach | * | *
HIPAA Titles
Title 1: Health Care Insurance Access, Portability, and Renewability
Title 2: Preventing Health Care Fraud & Abuse, Administrative Simplification, Medical Liability Reform
Title 3: Tax-related Health Provisions
Standardizes medical savings accounts
Title 4: Application and Enforcement of Group Health Insurance Requirements
Title 5: Revenue Offsets
Defines how employers can deduct company-owned life insurance premiums from income tax
There are 5 parts to HIPAA. We will focus on Title 2 (or part 2). Other parts discuss financial aspects – tax, revenue, or other matters.
*
Security Planning: An Applied Approach | * | *
Title 2 Has Three Rules
Transactions, Code Sets, and Identifiers: Standards for electronic transmission
- Electronic Data Interchange: Standardized records for health care transactions
The Privacy Rule: Standard for Privacy of Individually Identifiable Health Information
The Security Rule: Security Standard for electronic patient health
In Title 2 we will look at the Privacy Rule and Security Rule. The standards for electronic transmission simply ensure that there is a standard method of transmitting data between doctor’s offices, hospitals, and insurance providers. We will not be concerned with that section. The Privacy Rule applies regardless of whether computers are used. The Security Rule only applies when computer are used – to ensure computer security.
*
Security Planning: An Applied Approach | * | *
Reasons for Legislation
Records of patients or insurance claims made publicly available by accident
Email reminder to take Prozac sent to 600 (not blind cc’d)
Woman fired from job after positive review but expensive illness
35% of Fortune 500 companies admitted checking medical records before hiring or promoting
People avoid using insurance when they have AIDS, cancer, STD, substance abuse or mental illness
Security Planning: An Applied Approach | * | *
Medical Identity Theft
When a person’s name and other parts of his/her medical identity are stolen for the purpose of getting medical services and goods.
Problems:
- Medical info is for wrong person
- Inaccurate health records
- Wrong diagnosis
- Fatal treatments
- Imposter claims health care
- Medical Insurance Fraud
- Inaccurate Credit History: Bills sent elsewhere
1) A victim’s medical record and history could be wrong due to treatment notes about the thief.
2) The thief can steal health insurance information and make false claims using personal information obtained from the victim’s health records
3) The victim’s credit report could show unpaid medical charges that were not theirs.
- If a doctor has incorrect information in a patients file, it could become life-threatening for the victim/patient if the doctor were to misdiagnose or give the wrong treatment to the patient.
*
Security Planning: An Applied Approach | * | *
Medical Identity Thieves:
Who can commit this crime?
Computer hackers
Members of organized crime rings
Health care providers (doctor’s, dentists, hospital employees)
Just a few examples…
*
Security Planning: An Applied Approach | * | *
Business Challenges Facing the Health Care Industry
Hospital computer systems contain notes from hospital employees and primary care physicians.
Health Insurance Companies collect and compile patient data from different providers.
Organizations MUST maintain the security of computer systems that hold health data.
*
Security Planning: An Applied Approach | * | *
Breach Notification Laws
State Laws, called Breach Notification Laws require CEs to notify patients when their PHI has been breached
If data is encrypted and laptop is lost, notification is not required
This often applies to any industry that uses personal information, such as Social Security Numbers
The Oregonian, May 2006
In one of Oregon’s largest security breaches, Providence
Health System disclosed that a burglar stole unencrypted
medical records on 365,000 patients kept on disks and
tapes left overnight in an employee’s van
*
This is another law, not associated with HIPAA. It is associated with nearly every state, including Illinois and Wisconsin.
If any personal information is disclosed to a third party, such as social security number, financial information (credit card, etc.), driver’s license information, then each person whose information was disclosed must be informed. Have you heard of people getting notices that their personal information was divulged? It is because of this law.
However, there is a way around it. If information was stolen, such as a disk or back-up tape walked away, and if this disk/tape was encrypted, then the people whose information was stolen do not need to be notified.
Discussion: This adds to the cost of the risk associated with privacy.
Security Planning: An Applied Approach | * | *
HITECH: Health Information Technology for Economic and Clinical Health Act (2009)
Breach Notification Rule:
Introduced notification requirements
- Specifies how CE/BA should notify individuals and agencies if a breach of information occurs
PHI shall be encrypted in a way that is approved by HHS.
PHI shall be shredded or destroyed and disposed of properly.
HHS= Health & Human Services (part of US Govt)
Default: Provided by first-class mail to affected individuals within 60 days
Letter must include: description of the breach, the type of information involved in the breach, the steps the patient should take to protect themselves, and the detective, corrective, and preventive actions the CE is taking regarding the breach.
More than 500 people: must notify HHS and local press within 60 days
Less than 500 people: must notify HHS by submitting an annual report to HHS.
BA’s: Must notify CE within 60 days upon discovery. Must help CE notify the people that were affected by the breach.
*
Security Planning: An Applied Approach | * | *
Criminal Penalties for HIPAA
Then consider bad press, state audit, state law penalties, lost claims, …
| $ Penalty | Imprison-ment | Offense |
| Up to $50K | Up to one year | Wrongful disclosure of individually identifiable health information |
| Up to $100K | Up to 5 years | …committed under false pretenses |
| Up to $500K | Up to 10 years | … with intent to sell, achieve personal gain, or cause malicious harm |
As we can see (and from what I hear actually occurs) people are fined large amounts and can go to jail for not being careful with health information – or at least get fired.
*
Security Planning: An Applied Approach | * | *
HITECH Act (2009)
Penalties are prohibited if problem is corrected within 30 days and no willful neglect
Penalties pay for enforcement and redress for harm caused
| Each Violation | Max $ Per Year | |
| CE/BA exercised reasonable diligence but did not learn about violation | $100-$50k | $1.5 Million |
| Violation is due to reasonable cause | $1k- $50k | $1.5 Million |
| CE/BA demonstrated willful neglect but corrected violation | $10k-$50k | $1.5 Million |
| CE/BA demonstrated willful neglect and took no corrective action | $50k | $1.5 Million |
Security Planning: An Applied Approach | * | *
Health Care Organization
Covered Entities (CE)
Health care
Clearinghouse
Health Care Provider
(e.g., doctor, hospital)
Health plan
(e.g., HMO, PPO)
Standard
bills/records
Nonstandard
bills/records
Standard
bills/records
Covered Entities (CE) or organizations that must adhere to HIPAA. They include health care providers, health plans, and health clearinghouses. Clearinghouses turn nonstandard records into standardized records. (Remember Electronic Data Interchange from a previous slide?) Clearinghouses are not a concern when health care providers can interface directly with health plans, using standard records or bills.
Remember the term CE, you will see it again and again.
*
Security Planning: An Applied Approach | * | *
Health Care Organization
Health care
Clearinghouse
Health Care Provider
Health plan
Covered
Entities (CE)
Business Associates (BA)
Performs: Claims Processing
Transcription
Billing
Data Analysis
Independent organization
Work involves health info
Not bank or post office
Works
for
A Business Associate (BA) is an organization that works with a Covered Entity (CE) for purposes of processing claims, transcribing records, doing billing or data analysis of records. Because they work with health records, they too must be concerned with HIPAA. Banks and post offices are not BAs.
Remember the term BA, you will see it again.
*
Security Planning: An Applied Approach | * | *
Protected Health Information (PHI)
Health
Information
Relates to
Physical or
Mental health
or past/present/
future payment
Identifiers
Name
SSN
city or county
zip code
phone or fax
medical record #
fingerprint
Individually Identifiable
Health Information
Created or maintained by
CE or BA
Protected Health
Information
(PHI)
Covered by HIPAA
& HITECH
If YOU had AIDS, how could such identifiers
Identify you?
Let’s assume that an organization knew someone had AIDS or cancer, who lived in a rural area (only a zip code was known). Would that be enough to figure out who it was? What if it was known that Alice visited a cancer center. Would it be necessary to see Alice’s records to know that Alice might have cancer? Therefore ANY Health Information – billing information or even a visit to a doctor’s office – associated with any Identifier (part of an address, name or fingerprint) is what is known as Individually Identifiable Health Information (IIHI). When this is created or maintained by a CE or BA, then the information is protected as Protected Health Information (PHI) covered by HIPAA.
Remember the term PHI – you will see it again and again and again and …
*
Security Planning: An Applied Approach | * | *
Treatment, Payment & Health Care Operations (TPO)
Treatment
Provision & coordination
of health care among
health care providers,
including referral
Payment
Any activities
involved in
compensation
for health care:
billing, determining
coverage or eligibility
analyzing services
Health Care
Operations
Administrative
functions related
to health care:
financial or legal or
quality improvement,
training, certification,
case mgmt, business
planning
$
*
All of these are covered under HIPAA
Security Planning: An Applied Approach | * | *
HIPAA Standard Transactions
Plan Sponsor
(Employer)
Health Care Provider
(e.g., doctor, hospital)
Health plan
(e.g., HMO, PPO)
- Health Plan Eligibility Inquiry
- Certification & Authorization
of Referral
- Health Care Claim
- Health Care Claim Status Request
- Enrollment or Disenrollment into
Health Plan
- Health Plan Premium Payment
- Health Care
Claim Payment
- Certification &
Authorization
of Referral
*
Standard HIPAA transactions or records are shown above, also indicating the direction in which the transactions flow.
The Certification & Authorization of Referral just checks to see if the patient has permission. For example, to see a specialist, a patient must see the primary care giver, or a hospital may check to ensure with a Health Plan that an operation will be covered.
An Employer registers new employees through the Enrollment/Disenrollment, and makes payments for the insurance, too.
For many Request Transactions, there is also a Response Transaction in the opposite transaction.
This is not real important, other than to understand that standardized transactions do exist, what they are, and that they flow between Care Provider, and Health Plan and Plan Sponsor.
Security Planning: An Applied Approach | * | *
The Genetic Information Nondiscrimination Act of 2008
Protects against some types of genetic testing discrimination:
Insurance companies can’t make eligibility decision based on genetic testing results.
Insurance companies can’t base cost of premiums on genetic testing results.
Employers can’t hire, fire or make job decisions based on the use genetic testing.
Employers/Health Insurance Plans can not requiring genetic testing.
So if you carry the Breast Cancer gene, it cannot be a pre-existing condition.
*
Security Planning: An Applied Approach | * | *
The HIPAA
Privacy Rule
This rule affects all CEs and BAs, regardless of whether they use computers.
*
Security Planning: An Applied Approach | * | *
Privacy Rule: Develop Policies
CE/BAs shall:
Develop policies, procedures, and standards for how it will adhere to Privacy Rule. How will CE/BA:
- use and disclose PHI?
- protect patient rights?
Regularly review policies and procedures
Update policies when new requirements emerge
Monitor that policies/procedures are consistently applied throughout the organization
CE means Covered Entity. Remember?
*
Security Planning: An Applied Approach | * | *
Privacy Rule:
No NonHealth Usage of PHI
Health information is not to be used for nonhealth purposes, unless an individual gives explicit permission
The National Law Journal, May 30, 1994
A banker who also served on his county’s health board
cross-referenced customer accounts with patient
Information. He called due the mortgages of anyone
suffering from cancer.
PHI means Protected Health Information, remember?
*
Security Planning: An Applied Approach | * | *
Privacy Rule:
Need-to-Know Access
CE/BA Employees should have access only to what is absolutely required as part of their jobs.
What individuals should have access to PHI?
What categories of PHI should individuals have access to?
What conditions are required for access?
How will Business Associates & Trading Partners be informed and controlled?
Washington Post, March 1, 1995
The 13-year-old daughter of a hospital employee took a list of
patients’ names and phone numbers from the hospital when
visiting her mother at work. As a joke, she contacted patients
and told them they were diagnosed with HIV.
The questions on the bottom indicate that policies should exist to answer each of these. Need-to-know is an important concept, defined as : employees should have access only to what is absolutely required as part of their jobs.
*
Security Planning: An Applied Approach | * | *
Privacy Rule:
Protections against Marketing
CE must obtain permission before sending any marketing materials, with limited exceptions
Boston Globe, August 1, 2000
A patient at Brigham and Women’s Hospital in Boston
learned that employees had accessed her medical
record more than 200 times.
*
Can you imagine having some serious condition and receiving unwanted emails about it… at work?!
Discussion: What could go wrong with direct advertising, other than multi-record access?
Security Planning: An Applied Approach | * | *
Privacy Rule:
Establish Privacy Safeguards
Required
Shut or locked doors
Keep voice down
Clear desk policy
Privacy curtains
Password protection
Auto screen savers
Locked cabinets
Paper shredders
Not Required
Soundproof rooms
Redesign office space
Private hospital rooms (semiprivate ok)
OK for doctors to talk to nurses at nurse stations
Safeguards should be REASONABLE
The rules are supposed to be reasonable. The items on the left are considered reasonable, while the items on the right are considered to expensive to implement. As you can see these relate to non-computer privacy issues.
*
Security Planning: An Applied Approach | * | *
Privacy Rule:
Employee Training & Accountability
Each CE organization shall name one person who is accountable for Privacy Rule compliance
Each employee, volunteer, contractor shall be trained in privacy policies and procedures
- Full and Part-time
New York Times, Jan. 19, 2002
Eli Lilly and Co. inadvertently revealed over 600 patient
e-mail addresses when it sent an all message to every
individual registered to receive reminders about taking
Prozac.
There must be one person who is the coordinator and champion (and fall guy/gal) for security.
But – everyone, full and part time, needs to be trained in HIPAA compliance. This includes CE employees and BA contractors.
*
Security Planning: An Applied Approach | * | *
Privacy Rule: Individual Privacy Rights
Patients have the right to:
See or obtain copies of medical information (except for psychotherapy notes)
Request correction to health record
Receive a Notice of Privacy Practices
Request restrictions as to who can see PHI
Request specific method of contact for sake of privacy
Know who has accessed PHI
File a complaint if their rights have been violated
Allow and withdraw authorizations for use and disclosure
CE must:
Respond to requests within 30 days
May extend delay with notice for another 30 days
Keep records of how PHI is disclosed
You are not allowed to see how mentally unfit you are, but physically unfit – yes.
Notice of Privacy Practices is something that a CE puts together which states the organizations policies related to privacy. Every CE must have such a document, and each patient must sign off that they have read it.
When patients request information or a correction, the CE must comply and are given 30 days, with a further extension of 30 days, as part of HIPAA.
If a CE makes amendments to the PHI, it must inform others of the amendments.
A CE does not have to amend PHI if:
1) It did not create the PHI.
2) It determines that the PHI in the record is accurate and complete.
If a CE decides to deny a request to amend PHI, it must send a written denial notice to the person who requested the amendment.
*
Security Planning: An Applied Approach | * | *
Notice of Privacy Practices
Privacy Requirements:
NPP must be available when asked for
NPP must be displayed prominently in the office
Health Plan must provide upon enrollment
Health Provider must provide on first service delivery
Both must request written acknowledgment of receipt of NPP
After change, revised NPP must be issued to clients within 60 days
Electronic Requirements (if web page):
Must be displayed prominently on web page
Must be emailed to customers after a change in NPP
If electronic is available, then the bottom two bullets must be done.
*
Security Planning: An Applied Approach | * | *
Required & Permitted Disclosures
Required Disclosure:
Patient (or personal representative, e.g., parent, next of kin)
Office of Civil Rights Enforcement: Investigates potential violations to Privacy Rule
Permitted Disclosure:
Minimum-Necessary PHI may be disclosed without authorization for: judicial proceedings, coroner/funeral, organ donation, approved research, military-related situations, government-provided benefits, worker’s compensation, domestic violence or abuse, some law enforcement activities
ID must be verified by proof of identity/badge and documentation
Disclosure is giving private health information to other people. In some cases it is allowed as described here and on subsequent pages.
Parents of children and legal caretakers of the incapacitated are allowed to get information under Required Disclosure.
A permitted disclosure is allowed for the reasons given, when ID is provided.
Health care providers are required to report evidence of child abuse and neglect by state law. Teachers have similar requirements and must report the information to state social services agencies or local law enforcement agencies.
CE’s may also disclose PHI without consent for:
- Law enforcement activities to help identify or locate a suspect, witness, or missing person.
(This information is limited to identifying information (name, address and distinguishing physical characteristics).
2) Assistance in the apprehension of violent criminals such as information about a victim.
3) If a CE suspects that a death was cause by criminal activity, they can alert law enforcement.
*
Security Planning: An Applied Approach | * | *
More Disclosures
Routine Disclosure
Disclosures that happen periodically should be addressed in policies, procedures, forms
E.g.: Referral to another provider, school immunization, report communicable disease, medical transcription, births, deaths & other vital statistics
Non-routine Disclosure
CEs shall have reasonable criteria to review requests for non-routine PHI disclosures
E.g., Research disclosures
Incidental Disclosure
CEs shall have reasonable safeguards
E.g. Patient overhears advice given to another patient
Accidental Disclosure
Computer is stolen with PHI
Disclosures must be tracked for THREE years
A Routine Disclosure should be allowed by a specified procedure for the reasons given above.
A non-routine disclosure is a good reason which is not automatically approved. This may include research. In this case, a committee might decide whether the disclosure makes sense – with approval by the patient.
Incidental Disclosure is ok if in small unavoidable amounts, and practices are in place to prevent.
Accidental Disclosure is NOT allowed or permitted.
Example for communicable disease:
New York must report diseases that are highly contagious, diseases that might indicate bioterrorism and must report smallpox, anthrax, botulism, and typhoid immediately.
*
Security Planning: An Applied Approach | * | *
Disclosures Requiring Authorization
Research project (special conditions may allow)
Person outside health care system
Employer
- However, employer may require authorization for drug test before hiring
Other insurance companies
Health care provider not involved in patient’s health care
Insurance company not paying patient’s claims
Lawyer
Patient should get copy of authorization
Here Authorization comes from the Patient. The patient may authorize some disclosures.
*
Security Planning: An Applied Approach | * | *
Sample Authorization Form
Disclosure Authorization Form
Description of Information:_____________________________________
Patient making authorized disclosure____________________________
Person receiving information:__________________________________
Purpose of the disclosure:
Authorization Expiration Date:________________
Patient Signature__________________________ Date:____________
A form to revoke authorization must be completed to terminate authorization.
Must be retained by CE for 6 years
Here is a copy of a sample authorization form the patient should sign. The patient can revoke authorization at any time.
As you can see, the CE must keep certain information for 6 years.
A valid authorization shall contain all of the information above.
A defective authorization isn’t valid.
Authorizations are defective after their expiration date has passed.
They are also defective if they are not completely filled out or the person has revoked the authorization.
*
Security Planning: An Applied Approach | * | *
Implementing ‘Minimum Necessary’
Minimum necessary: Just enough info to accomplish the main purpose
E.g., Send prescription for glasses to optician, not medical history
Data Classification
- Sensitivity of information
- Type of treatment required
Questions to Answer
- What parts of record can each user type access?
- How will we constrain access to implement view?
*
During a Disclosure, the minimum amount of information necessary should be provided. Minimum necessary is concerned that staff (e.g., medical administrators and nurses) see only what they need to on database forms and records, etc. For example, send the prescription for glasses to the optician, not the entire medical history. Data should be classified as to handling and treatment. For example, PHI is highly sensitive, compared to doctor’s schedules, for example. We will learn about this in future classes.
Security Planning: An Applied Approach | * | *
Business Associates (BA)
Legal
Actuarial
Accounting & Finance
Consulting
Administration &
Management
Accreditation
Must also be responsible with PHI
Not Business
Associates
Janitorial
Electrical
Phone
Vending
Copy
Conduit: Mail
Financial Institution:
Banks
There are rules for how BAs must be handled. BAs include the people on the left. Non-BAs are the people on the right.
*
Security Planning: An Applied Approach | * | *
Business Associate Contract (BAC)
CEs must request BA to sign a BAC:
BA will not disclose PHI
BA is liable for damage due to disclosure or misuse
BA will use safeguards to prevent misuse
BA will report any security incident or violation of agreement
BA will destroy or protect PHI upon termination of contract
CE can terminate contract if violation occurs
CE will provide BA copies of policies, procedures and materials for safeguarding
Etc.
BAs are equally liable as CEs, under HITECH Act
Security Planning: An Applied Approach | * | *
HITECH: Health Information Technology for Economic and Clinical Health Act (2009)
BA’s must follow the HIPAA Security Rule.
BA’s are held to the same standard as CE’s.
Health & Human Services (HHS) can:
- require BA’s to comply with HIPAA.
- enforce penalties on noncompliant BA’s.
HITECH Act: The Health Information Technology for Economic and Clinical Health or “The Act”
HHS: U.S. Dept. of Health & Human Services
Because of the expected increase in use and exchanges of EPHI (electronic protected health information), the HITECH Act was put into effect to strengthen HIPPA privacy and security protection of PHI by increasing fines for non-compliance, changes how compliance is enforced, and introduces the federal breach notification rule.
HITECH Act:
Increases fines for non-compliance and violations to Security & Privacy rules.
Introduced a federal breach notification rule.
Requires HHS to make sure that CE’s & BA’s comply with HIPPA through audits.
Gives states the ability to enforce HIPPA compliance.
*
Security Planning: An Applied Approach | * | *
Violation of HIPAA Privacy Rule:
WTHR Investigation Leads to Record $2.25M HIPAA Settlement, Indianapolis, IN, 2006:
Reported that CVS was “throwing sensitive personal information in the trash” (e.g.: unredacted pill bottles, prescription instruction sheets, pharmacy receipts with credit card information and health insurance account numbers.
After this, other CVS pharmacies were investigated and it was found that they also were improperly disposing of PHI.
In the settlement CVS was required to:
- Create an information security program to protect personal information.
- Requires that they get an independent audit every 2 years until 2029.
- Pay $2.25 million to settle claims.
CVS agreed to:
- Implement a security plan that complies with HIPAA’s Privacy Rule.
- Protect information during disposal.
- Develop employee training programs.
At this time, CVS’s privacy policy stated that “CVS Pharmacy wants you to know that nothing is more central to our operations than maintaining the privacy of your health information…”
CVS said that there was no verification of the reports made by the media, but settled the charges with the FTC & HHS to put this case behind them.
In the settlement CVS was required to:
Create an information security program that protects personal information.
Requires that they get an independent audit every 2 years until 2029.
Pay $2.25 million to settle the claims.
CVS agreed to:
Implement a security plan that would create security policy that complies with HIPAA’s Privacy Rule.
Protect information during disposal.
Develop employee training programs.
*
Security Planning: An Applied Approach | * | *
The HIPAA
Security Rule
+
The Security Rule applies to those CEs and BAs who use computerize PHI. We do not want hackers to get in.
*
Security Planning: An Applied Approach | * | *
Security Rule Enforces
Privacy Rule on Computers
Privacy Rule Security Rule
With or w/o computer With computer
Protect PHI Protect EPHI
Minimum Necessary Authentication &
Access Control
Accounting of Disclosures Unique Login Credentials
Authentication
Track modifications to EPHI:
Who did what when?
*
EPHI=Electronic Personal Health Information
This slide shows how Privacy Rule gets implemented on a computer, with the Security Rule.
Security Planning: An Applied Approach | * | *
Security Vocabulary
Asset: Diamonds
Threat: Theft
Vulnerability: Open door or windows
Threat agent: Burglar
Owner: Those accountable or who value the asset
Risk: Danger to assets
*
This is not only HIPAA but standard security vocabulary.
Vulnerability is not the threat itself, but the enabler for the threat.
To a computer, a threat could also be a power outage.
Security Planning: An Applied Approach | * | *
Security Rule Assures…
More Standard Security. These are the three goals of security.
Confidentiality: Only permitted people may see the data
Integrity: The data is correct
Available: The resources are available when needed.
(CIA) Remember it!!! You will see and hear it again, and again…
*
Security Planning: An Applied Approach | * | *
Security Services
Authentication
Access Control
Data confidentiality
Data integrity
Data backup & recovery
Nonrepudiation = Cannot say it wasn’t you who sent or received data
Risk Management
*
Authentication = login/password
Access Control = minimum necessary permissions provided (read/write/access/edit/delete)
Which address Confidentiality, Integrity, Availability?
Security Planning: An Applied Approach | * | *
Risk Management
Risk assessment
Policy & Procedures Maintenance
Security Program Enforcement
Audit logs, vulnerability assessments, audit for procedure adherence and control effectiveness
Patches are applied to software
Data is available, confidential, & integrity is protected
Risk Management is a requirement of HIPAA. Risk management assures that the cost of security controls (often simply called ‘controls’) is reasonable considering the risk. It means we have to consider how much it will cost us if someone breaks in (consider the cost of going to jail and paying HIPAA fines) and the cost of security controls. Hopefully, the security controls are cheaper than violating HIPAA! We will study risk assessment further in another chapter. Having said that, some policies are absolutely required, such as the bullets specified above.
*
Security Planning: An Applied Approach | * | *
Security Rule Standards
Administrative
Controls
Physical Controls
Technical Controls
Comprehensive Technology Neutral Scalable
Small
or
Large
Look to Best Practices
for Technology Answers
e.g. NIST
Security
Rule
Security
Rule
Security Rule should be:
Comprehensive: affecting administrative, physical and technical controls.
Technology neutral: HIPAA does not want to promote any specific hardware vendor.
Scalable: For small or large companies
NIST: National Institute of Standards & Technology
*
Security Planning: An Applied Approach | * | *
Three Areas of Safeguards
Security
Rule
Administrative: Administrative policies, procedures, and actions
to implement and maintain security controls to protect EPHI, including
risk mgmt, access control, contingency plans, incident response.
Physical: Protection of the physical access to terminals, laptops,
servers, backup tapes, CDs, memory, including viewing,
access, maintenance and disposal.
Technical: Protection using technology tools to protect EPHI,
including logs, encryption, authentication
Security Rule affects three major areas as shown above. We will see more of each of these.
*
Security Planning: An Applied Approach | * | *
Policies & Procedures
Policies and Procedures MUST BE:
Retained for 6 years after date of creation or last effect
Available to workers responsible for them
Must be updated regularly accommodating changes in environment & operations
Policies and procedures define how employees and contractors should do their jobs regarding security.
These policies/procedures must be readily available to them. They should also be updated, as the world changes.
Thus, new database or new medical function: appropriate changes to the policies/procedures.
Information must be retained for a minimum duration of 6 years. Effect: if a prescription is still active, then it is still in effect.
*
Security Planning: An Applied Approach | * | *
Security Rule Standard
DO IT!
This is recommended…
Address this in some way…
Implement equivalent alternative
measure….
If it doesn’t apply, document well
why not…
We do this instead:
…..
Security Rule elements are either Required (do as defined) or Addressable (may do in a different way but has same effect “Equivalent Alternative Measure” – or don’t need to do because this does not apply to us for reason given). Both need to be documented.
*
Security Planning: An Applied Approach | * | *
Administrative:
Security Mgmt Process
| Risk Analysis: Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the CIA of EPHI held by the CE. | R |
| Risk Mgmt: Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with the Security Rule | R |
| Sanction Policy: Apply appropriate penalties against workforce members who fail to comply with the entity’s security policies and procedures | R |
| Info System Activity Review: Implement procedures to regularly review records of IS activity, such as audit logs, access reports, and security incident tracking reports | R |
CIA = Confidentiality, Integrity, Availability
EPHI = Electronic Personal Health Information
CE= Covered Entities, extended to BAs by HITECH.
You can see that these are all REQUIRED – that means documented.
*
Security Planning: An Applied Approach | * | *
Security Mgmt Implications
The Sanction policy basically requires we all sign a confidentiality agreement and if someone breaks the rule, they could be fired.
We will need an IT person to regularly check logs to be sure our system was not broken into
Risk assessment must be ‘accurate and thorough’ – that will be a challenge!
And all are Rs…
Security Mgmt
Process
This helps to further explain the previous page.
*
Security Planning: An Applied Approach | * | *
Administrative:
Workforce Security
| Authorization and/or Supervision: Implement procedures for the authorization and/or supervision of workforce members who work with EPHI or in locations where it might be accessed | A |
| Workforce Clearance Procedure: Implement procedures to determine that the access of a workforce member to EPHI is appropriate | A |
| Termination Procedures: Implement procedures for terminating access to EPHI when the employment of a workforce member ends… | A |
These are all As: Addressable. You can do this in the most cost-effective or simple way possible – but you must do this!
Workforce member = employee, contractor, volunteer.
This covers Authorization (think segregation of duties and authorization). Supervision of work is an appropriate form of segregation of duties. When someone leaves, their privileges shall be revoked.
*
Security Planning: An Applied Approach | * | *
Workforce Security Implications
.We must have procedures to allocate authorization, periodically check authorization, and procedures to terminate someone
They are asking for checks and balances with supervision or authorization
We are a three person operation, can we get away with not doing this?
Must we document our situation?
These are As.
Workforce
Security
*
With documentation, it may be possible to bypass if clear lack of need is evident: such as a single-doctor office.
Also possible: background checks.
Security Planning: An Applied Approach | * | *
Administrative:
Information Access Mgmt
| Isolating Health Care Clearinghouse (CH) Function: If a health care CH is part of a larger organization, the CH operation must implement policies and procedures that protect the EPHI of the CH from unauthorized access by the larger organization | R |
| Access Authorization: Implement policies and procedure for granting access to EPHI – e.g., through access to a workstation, transaction, program, process, or other mechanism | A |
| Access Establishment & Modification: Implement policies and procedures that, based upon the entity’s access authorization policies, establish, document, review, and modify a user’s right of access to a workstation, transaction, program or process. | A |
*
1 is only applicable if you are a Clearinghouse which is part of a larger organization. (We don’t care.)
Items 2 & 3 are concerned with Access Control: giving read/write permissions, creating records, etc. Once privileges are granted, they may need to be changed as the position changes.
Security Planning: An Applied Approach | * | *
Info Access Mgmt Implications
It is an implementation: We must define a data owner for each major process
Isn’t this the same as the previous rule?
.And then our IT people must define how they will grant access based upon the data owner’s decisions.
Info Access
Mgmt
*
Data Owner = a person on the business side who knows who should be given privileges, based on job. IT should not be responsible for this.
Security Planning: An Applied Approach | * | *
Administrative:
Security Awareness & Training
What do you think these mean?
| Security Reminders: Provide periodic security updates to members of the workforce | A |
| Protection from Malicious Software: Implement procedures for guarding against, detecting, and reporting malicious software | A |
| Login Monitoring: Implement procedures for monitoring login attempts and reporting discrepancies | A |
| Password Mgmt: Implement procedures for creating, changing and safeguarding passwords | A |
These are pretty obvious, hopefully.
*
Security Planning: An Applied Approach | * | *
Administrative:
Contingency Plan
| Data Backup Plan: Establish and implement procedures to create and maintain retrievable exact copies of EPHI | R |
| Disaster Recovery Plan: Establish … procedures to restore any loss of data | R |
| Emergency Mode Operation Plan: The emergency mode operation plan requires CEs to establish … procedures to enable continuation of critical business processes, while maintaining the security of EPHI while operating in emergency mode | R |
| Testing & Revision Procedure: Implement procedures for periodic testing and revision of contingency plans. | A |
| Applications & Data Criticality Analysis: Assess the relative criticality of specific applications and data in support of other contingency plan components. | A |
*
… = and implement as needed
We will have a whole week or two on this too. Hopefully this also is reasonably clear.
Security Planning: An Applied Approach | * | *
Administrative:
One-Line Safeguards
| Assigned Security Responsibility: Identify the security official who is responsible for the development and implementation of the policies and procedures required by this rule for the entity. | R |
| Security Incident Procedures: Implement policies & procedures to address security incidents. Identify and respond to suspected or known security incidents; mitigate … harmful effects of security incidents that are known to the CE; and document security incidents and their outcomes. | R |
*
… = to the extent practicable
Security Incident: When something goes wrong, that is not the time to decide what to do about it. These policies and procedures should be defined well ahead of time.
Security Planning: An Applied Approach | * | *
Administrative:
More One-Line Safeguards
| Evaluation: Perform a periodic technical and nontechical evaluation, based initially upon the standards implemented under this rule and subsequently, in response to environmental or operations changes affecting the security of EPHI, that establishes the extent to which an entity’s security policies and procedures meet the requirements of this subpart | R |
| BA Contracts and Other Arrangements: A BA [may] create, receive, maintain, or transmit EPHI on the CE’s behalf only if the CE obtains satisfactory assurances that the BA will appropriately safeguard the information. | R |
Evaluation = Test or audit. Note that this should occur periodically for both technical and nontechnical aspects.
*
Security Planning: An Applied Approach | * | *
Info Access Mgmt Implications
That makes sense when technology changes, but I guess we have to do it periodically as well, since the world changes.
According to Evaluation, we must self-test or be certified on a regular basis, to be sure we follow the Security Rule
We need to know who, what, when, where, why for incident response.
Who shall we name as our Security Manager?
Evaluation
*
This explains the previous page further.
Security Planning: An Applied Approach | * | *
Physical Safeguards:
Facility Access Controls
| Facility Access Controls: Implement policies and procedures to limit physical access to electronic info systems and areas where sensitive paper documents are stored and any facilities in which they are housed, while ensuring authorized access | |
| Contingency Operations | A |
| Facility Security Plan | A |
| Access Control & Validation Procedures | A |
| Maintenance Records | A |
Now we are in the realm of Physical Controls: Think locks, key cards, guards, badges,
*
Security Planning: An Applied Approach | * | *
Physical Safeguards:
Facility Access Control
How will physical access be restricted to sensitive paper documents, terminals, server, backup copies, laptops, contingency operations in copy, view, or modify forms?
How are visitors controlled from accessing PHI/EPHI?
When repairs occur (to facility or systems) how will PHI/EPHI be safeguarded?
Security Planning: An Applied Approach | * | *
Physical Safeguards: Workstations
| Workstation Use: Implement policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of a specific workstation or class of workstation that can be used to access EPHI | R |
| Workstation Security: Implement physical safeguards for all workstations that can be used to access EPHI, to restrict access to authorized users | R |
Physical safeguards may include monitor hoods, positioning monitors so that others can not see them, minimal remote access, half-walls and doors preventing access, etc.
*
Security Planning: An Applied Approach | * | *
Workstation Use and Security
What functions will be performed on which workstations?
How will workstation access be limited when the user leaves their station?
How will theft of laptops be prevented?
How will the workstations be positioned?
What other physical safeguards (locked rooms, hoods) will be implemented to prevent shoulder surfing?
These must all be considered and documented.
*
Security Planning: An Applied Approach | * | *
Physical Safeguards:
Device & Media Controls
| Device and Media Controls: Implement policies and procedures that govern the receipt and removal of hardware and electronic media and devices that contain EPHI into and out of a worksite or facility, and the movement of these items within the worksite or facility. | |
| Disposal | R |
| Media Reuse | R |
| Accountability | A |
| Data Backup and Storage | A |
How are disks disposed of? Are memory sticks allowed? How are they prevented? What happens if a computer goes in for repair? Can anyone work on these computers? How are tapes reused? Where are backups stored?
*
Security Planning: An Applied Approach | * | *
Device & Media Controls
How will media be erased or damaged before disposal or reuse?
Reformatting disk may not be adequate even for reuse
How, when and where has EPHI been moved or transferred? Documentation is necessary
How is a backup made and where/how stored?
*
Security Planning: An Applied Approach | * | *
Technical Safeguards:
Access Control
| Access Control: Implement technical policies and procedures for electronic info systems that maintain EPHI. These policies and procedures should contain access protocols that will establish and enforce the entity’s other access policies, and allow access only to those persons or software programs that have been granted access rights | |
| Unique User Identification | R |
| Emergency Access Procedure | R |
| Automatic Logoff | A |
| Encryption and Decryption | A |
Security Planning: An Applied Approach | * | *
Technical Safeguards:
Access Control
How is each user uniquely identified to the system?
How does authentication occur?
In an emergency, what backup methods are used for authentication?
How does automatic logoff occur after a period of inactivity?
Which data is encrypted in storage and/or transmission?
Security Planning: An Applied Approach | * | *
Technical Safeguards:
Transmission Security
| Transmission Security: Implement technical security measures to guard against unauthorized access to EPHI that is being transmitted over an electronic communications network | |
| Integrity Controls | A |
| Encryption | A |
Security Planning: An Applied Approach | * | *
Technical Safeguards:
Transmission Security
How are we sure that data is not modified or lost during transmission?
What encryption techniques are used to protect the security of EPHI transmitted over a public network?
Security Planning: An Applied Approach | * | *
Other Technical Safeguards
| Audit Controls: Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use EPHI | R |
| Integrity: Implement policies and procedures to protect EPHI at rest, meaning stored on organizational systems and applications, from improper alteration or destruction. | A |
| Person or Entity Authentication: Implement procedures to verify that a person or entity seeking access to EPHI is the one claimed | R |
Audit Controls = Logs
Integrity = hashing or check codes (a sophisticated parity)
Authentication = something you are, have or know
*
Security Planning: An Applied Approach | * | *
Other Technical Safeguards
For which devices will the logs be monitored?
What log events should be archived for security purposes?
How will potential attacks found in logs be recorded, reported, and acted upon?
What techniques will be used to ensure stored data has not been modified (hashes, message digests?)
What authentication mechanisms will be used to assure that approved entities (people or systems) are accessing EPHI?
Security Planning: An Applied Approach | * | *
Question
An example of a vulnerability is
- Theft
- Burglar
- Open door
- Diamonds
Displaying slide show will result in the correct answer revolving.
See previous slide for reasons why the answer is correct.
*
Security Planning: An Applied Approach | * | *
Question
Protected Health Information is:
- SSN, medical information
- Name, SSN, medical information
- Name, address, SSN, phone, medical information
- Medical information stored in a computer
Look up slide on PHI for reasons why. Also there is a difference between EPHI and PHI.
*
Security Planning: An Applied Approach | * | *
Question
The Security Rule requires that:
- Logs are monitored
- An intrusion detection system is implemented
- Cabinets containing PHI must be locked
- Walls must be soundproof and all terminals outside of waiting room
Note that this applies to Security Rule. Two of these answers relate potentially to Security Rule, two relate to Privacy Rule. Two rules are not required by Security or Privacy rule, while two rules do apply (to Security or Privacy rule). Which are which?
*
Security Planning: An Applied Approach | * | *
Question
The Privacy Rule requires that:
- Logs are monitored
- An intrusion detection system is implemented
- Cabinets containing PHI must be locked
- Walls must be soundproof and all terminals outside of the waiting room
Ditto.
*
Security Planning: An Applied Approach | * | *
Question
The Addressable option for the Security Rule means:
- Smaller organizations need not implement if they can justify it would be too expensive
- HIPAA discusses alternative means to accomplish this, and the organization must select one
- The CE must document how they accomplish this provision
- This provision must be implemented or addressed in some way, although alternative implementations are allowed
‘A’ does not need to be implemented if there is an excellent document reason why (too expensive is not a good answer).
*
Security Planning: An Applied Approach | * | *
HIPAA protects Protected Health information (PHI)
Applicable to Covered Entities and their Business Associates
In General:
- Privacy Rule covers Need-to-know, Disclosures, Notice of Privacy Practice, non-electronic privacy
- Security Rule covers Administrative, Physical and Technical Safeguards
- HITECH increases penalties for non-compliance
HIPAA is an example of state-of-the-art Privacy and Security regulation
Most of each chapter of this book is required for HIPAA
Summary
Security Planning: An Applied Approach | * | *
Not Covered in this Presentation
Some specialized material is not being covered as part of this presentation, including:
Hybrid Entities: Part Covered, Part Not
Organized Health Care Arrangement (OHCA): Group of doctors
Jointly Administered Govt. Program
Trading Partner: CEs exchange electronic transactions without clearinghouse
COBRA
*
We have not covered all of HIPAA – only the basics. There is more, but we won’t be discussing these areas.