health information technology

profileeboraps
Ch14_HIPAA1.ppt

Security Planning
Susan Lincke

Complying with HIPAA and
HITECH

*

Security Planning: An Applied Approach | * | *

Objectives:

Students shall be able to:

Define HIPAA, Privacy Rule, Security Rule, CE, PHI.

Define threat, vulnerability, threat agent

Describe what Privacy Rule covers at a high level

Describe what Security Rule covers at a high level

Describe the difference between Required and Addressable for the Security Rule.

By the way, by now you are probably wondering if you will be tested on HIPAA. The good news is MINIMAL in Dr Lincke’s class. HIPAA will be used in class for the case study, but except for similar questions which are shown here, you will not be responsible for HIPAA on an exam.

*

Security Planning: An Applied Approach | * | *

HIPAA

Introduced by Senators Edward Kennedy & Nancy Kassebaum

Portability: Workers can continue health care between different employers

Group insurance cannot reject, not renew, or charge higher premiums of certain individuals

Simplify administration by creating a health care transaction standard

Accountability:

Penalties for non-compliance

Tax provisions

The main intent of the legislation was to protect workers by making their health status PRIVATE. This would impact their careers, getting health care insurance when they change jobs, etc. However, realistically we can see that it did not prevent existing insurance providers from dropping sick people or perhaps raising the health insurance price for the company, which resulted in the company dropping certain people.

Pre-existing Condition Rule:

  • An employer-provided health plan can only look back up to 6 months to declare a pre-existing condition.

Pre-existing condition: Only exists if the patient received treatment for the condition within the six months prior to enrolling in a health plan.

  • HIPAA limits the amount of time that an employer-provided health plan can make an employee wait for coverage because of a pre-existing condition to 12 months, but this period can be shortened in many situations.

*

Security Planning: An Applied Approach | * | *

HIPAA Titles

Title 1: Health Care Insurance Access, Portability, and Renewability

Title 2: Preventing Health Care Fraud & Abuse, Administrative Simplification, Medical Liability Reform

Title 3: Tax-related Health Provisions

Standardizes medical savings accounts

Title 4: Application and Enforcement of Group Health Insurance Requirements

Title 5: Revenue Offsets

Defines how employers can deduct company-owned life insurance premiums from income tax

There are 5 parts to HIPAA. We will focus on Title 2 (or part 2). Other parts discuss financial aspects – tax, revenue, or other matters.

*

Security Planning: An Applied Approach | * | *

Title 2 Has Three Rules

Transactions, Code Sets, and Identifiers: Standards for electronic transmission

  • Electronic Data Interchange: Standardized records for health care transactions

The Privacy Rule: Standard for Privacy of Individually Identifiable Health Information

The Security Rule: Security Standard for electronic patient health

In Title 2 we will look at the Privacy Rule and Security Rule. The standards for electronic transmission simply ensure that there is a standard method of transmitting data between doctor’s offices, hospitals, and insurance providers. We will not be concerned with that section. The Privacy Rule applies regardless of whether computers are used. The Security Rule only applies when computer are used – to ensure computer security.

*

Security Planning: An Applied Approach | * | *

Reasons for Legislation

Records of patients or insurance claims made publicly available by accident

Email reminder to take Prozac sent to 600 (not blind cc’d)

Woman fired from job after positive review but expensive illness

35% of Fortune 500 companies admitted checking medical records before hiring or promoting

People avoid using insurance when they have AIDS, cancer, STD, substance abuse or mental illness

Security Planning: An Applied Approach | * | *

Medical Identity Theft

When a person’s name and other parts of his/her medical identity are stolen for the purpose of getting medical services and goods.

Problems:

  • Medical info is for wrong person
  • Inaccurate health records
  • Wrong diagnosis
  • Fatal treatments
  • Imposter claims health care
  • Medical Insurance Fraud
  • Inaccurate Credit History: Bills sent elsewhere

1) A victim’s medical record and history could be wrong due to treatment notes about the thief.

2) The thief can steal health insurance information and make false claims using personal information obtained from the victim’s health records

3) The victim’s credit report could show unpaid medical charges that were not theirs.

  • If a doctor has incorrect information in a patients file, it could become life-threatening for the victim/patient if the doctor were to misdiagnose or give the wrong treatment to the patient.

*

Security Planning: An Applied Approach | * | *

Medical Identity Thieves:
Who can commit this crime?

Computer hackers

Members of organized crime rings

Health care providers (doctor’s, dentists, hospital employees)

Just a few examples…

*

Security Planning: An Applied Approach | * | *

Business Challenges Facing the Health Care Industry

Hospital computer systems contain notes from hospital employees and primary care physicians.

Health Insurance Companies collect and compile patient data from different providers.

Organizations MUST maintain the security of computer systems that hold health data.

*

Security Planning: An Applied Approach | * | *

Breach Notification Laws

State Laws, called Breach Notification Laws require CEs to notify patients when their PHI has been breached

If data is encrypted and laptop is lost, notification is not required

This often applies to any industry that uses personal information, such as Social Security Numbers

The Oregonian, May 2006

In one of Oregon’s largest security breaches, Providence

Health System disclosed that a burglar stole unencrypted

medical records on 365,000 patients kept on disks and

tapes left overnight in an employee’s van

*

This is another law, not associated with HIPAA. It is associated with nearly every state, including Illinois and Wisconsin.

If any personal information is disclosed to a third party, such as social security number, financial information (credit card, etc.), driver’s license information, then each person whose information was disclosed must be informed. Have you heard of people getting notices that their personal information was divulged? It is because of this law.

However, there is a way around it. If information was stolen, such as a disk or back-up tape walked away, and if this disk/tape was encrypted, then the people whose information was stolen do not need to be notified.

Discussion: This adds to the cost of the risk associated with privacy.

Security Planning: An Applied Approach | * | *

HITECH: Health Information Technology for Economic and Clinical Health Act (2009)

Breach Notification Rule:

Introduced notification requirements

  • Specifies how CE/BA should notify individuals and agencies if a breach of information occurs

PHI shall be encrypted in a way that is approved by HHS.

PHI shall be shredded or destroyed and disposed of properly.

HHS= Health & Human Services (part of US Govt)

Default: Provided by first-class mail to affected individuals within 60 days

Letter must include: description of the breach, the type of information involved in the breach, the steps the patient should take to protect themselves, and the detective, corrective, and preventive actions the CE is taking regarding the breach.

More than 500 people: must notify HHS and local press within 60 days

Less than 500 people: must notify HHS by submitting an annual report to HHS.

BA’s: Must notify CE within 60 days upon discovery. Must help CE notify the people that were affected by the breach.

*

Security Planning: An Applied Approach | * | *

Criminal Penalties for HIPAA

Then consider bad press, state audit, state law penalties, lost claims, …

$ Penalty Imprison-ment Offense
Up to $50K Up to one year Wrongful disclosure of individually identifiable health information
Up to $100K Up to 5 years …committed under false pretenses
Up to $500K Up to 10 years … with intent to sell, achieve personal gain, or cause malicious harm

As we can see (and from what I hear actually occurs) people are fined large amounts and can go to jail for not being careful with health information – or at least get fired.

*

Security Planning: An Applied Approach | * | *

HITECH Act (2009)

Penalties are prohibited if problem is corrected within 30 days and no willful neglect

Penalties pay for enforcement and redress for harm caused

Each Violation Max $ Per Year
CE/BA exercised reasonable diligence but did not learn about violation $100-$50k $1.5 Million
Violation is due to reasonable cause $1k- $50k $1.5 Million
CE/BA demonstrated willful neglect but corrected violation $10k-$50k $1.5 Million
CE/BA demonstrated willful neglect and took no corrective action $50k $1.5 Million

Security Planning: An Applied Approach | * | *

Health Care Organization
Covered Entities (CE)

Health care

Clearinghouse

Health Care Provider

(e.g., doctor, hospital)

Health plan

(e.g., HMO, PPO)

Standard

bills/records

Nonstandard

bills/records

Standard

bills/records

Covered Entities (CE) or organizations that must adhere to HIPAA. They include health care providers, health plans, and health clearinghouses. Clearinghouses turn nonstandard records into standardized records. (Remember Electronic Data Interchange from a previous slide?) Clearinghouses are not a concern when health care providers can interface directly with health plans, using standard records or bills.

Remember the term CE, you will see it again and again.

*

Security Planning: An Applied Approach | * | *

Health Care Organization

Health care

Clearinghouse

Health Care Provider

Health plan

Covered

Entities (CE)

Business Associates (BA)

Performs: Claims Processing

Transcription

Billing

Data Analysis

Independent organization

Work involves health info

Not bank or post office

Works

for

A Business Associate (BA) is an organization that works with a Covered Entity (CE) for purposes of processing claims, transcribing records, doing billing or data analysis of records. Because they work with health records, they too must be concerned with HIPAA. Banks and post offices are not BAs.

Remember the term BA, you will see it again.

*

Security Planning: An Applied Approach | * | *

Protected Health Information (PHI)

Health

Information

Relates to

Physical or

Mental health

or past/present/

future payment

Identifiers

Name

SSN

city or county

zip code

phone or fax

medical record #

fingerprint

Individually Identifiable

Health Information

Created or maintained by

CE or BA

Protected Health

Information

(PHI)

Covered by HIPAA

& HITECH

If YOU had AIDS, how could such identifiers

Identify you?

Let’s assume that an organization knew someone had AIDS or cancer, who lived in a rural area (only a zip code was known). Would that be enough to figure out who it was? What if it was known that Alice visited a cancer center. Would it be necessary to see Alice’s records to know that Alice might have cancer? Therefore ANY Health Information – billing information or even a visit to a doctor’s office – associated with any Identifier (part of an address, name or fingerprint) is what is known as Individually Identifiable Health Information (IIHI). When this is created or maintained by a CE or BA, then the information is protected as Protected Health Information (PHI) covered by HIPAA.

Remember the term PHI – you will see it again and again and again and …

*

Security Planning: An Applied Approach | * | *

Treatment, Payment & Health Care Operations (TPO)

Treatment

Provision & coordination

of health care among

health care providers,

including referral

Payment

Any activities

involved in

compensation

for health care:

billing, determining

coverage or eligibility

analyzing services

Health Care

Operations

Administrative

functions related

to health care:

financial or legal or

quality improvement,

training, certification,

case mgmt, business

planning

$

*

All of these are covered under HIPAA

Security Planning: An Applied Approach | * | *

HIPAA Standard Transactions

Plan Sponsor

(Employer)

Health Care Provider

(e.g., doctor, hospital)

Health plan

(e.g., HMO, PPO)

  • Health Plan Eligibility Inquiry
  • Certification & Authorization

of Referral

  • Health Care Claim
  • Health Care Claim Status Request
  • Enrollment or Disenrollment into

Health Plan

  • Health Plan Premium Payment
  • Health Care

Claim Payment

  • Certification &

Authorization

of Referral

*

Standard HIPAA transactions or records are shown above, also indicating the direction in which the transactions flow.

The Certification & Authorization of Referral just checks to see if the patient has permission. For example, to see a specialist, a patient must see the primary care giver, or a hospital may check to ensure with a Health Plan that an operation will be covered.

An Employer registers new employees through the Enrollment/Disenrollment, and makes payments for the insurance, too.

For many Request Transactions, there is also a Response Transaction in the opposite transaction.

This is not real important, other than to understand that standardized transactions do exist, what they are, and that they flow between Care Provider, and Health Plan and Plan Sponsor.

Security Planning: An Applied Approach | * | *

The Genetic Information Nondiscrimination Act of 2008

Protects against some types of genetic testing discrimination:

Insurance companies can’t make eligibility decision based on genetic testing results.

Insurance companies can’t base cost of premiums on genetic testing results.

Employers can’t hire, fire or make job decisions based on the use genetic testing.

Employers/Health Insurance Plans can not requiring genetic testing.

So if you carry the Breast Cancer gene, it cannot be a pre-existing condition.

*

Security Planning: An Applied Approach | * | *

The HIPAA
Privacy Rule

This rule affects all CEs and BAs, regardless of whether they use computers.

*

Security Planning: An Applied Approach | * | *

Privacy Rule: Develop Policies

CE/BAs shall:

Develop policies, procedures, and standards for how it will adhere to Privacy Rule. How will CE/BA:

  • use and disclose PHI?
  • protect patient rights?

Regularly review policies and procedures

Update policies when new requirements emerge

Monitor that policies/procedures are consistently applied throughout the organization

CE means Covered Entity. Remember?

*

Security Planning: An Applied Approach | * | *

Privacy Rule:
No NonHealth Usage of PHI

Health information is not to be used for nonhealth purposes, unless an individual gives explicit permission

The National Law Journal, May 30, 1994

A banker who also served on his county’s health board

cross-referenced customer accounts with patient

Information. He called due the mortgages of anyone

suffering from cancer.

PHI means Protected Health Information, remember?

*

Security Planning: An Applied Approach | * | *

Privacy Rule:
Need-to-Know Access

CE/BA Employees should have access only to what is absolutely required as part of their jobs.

What individuals should have access to PHI?

What categories of PHI should individuals have access to?

What conditions are required for access?

How will Business Associates & Trading Partners be informed and controlled?

Washington Post, March 1, 1995

The 13-year-old daughter of a hospital employee took a list of

patients’ names and phone numbers from the hospital when

visiting her mother at work. As a joke, she contacted patients

and told them they were diagnosed with HIV.

The questions on the bottom indicate that policies should exist to answer each of these. Need-to-know is an important concept, defined as : employees should have access only to what is absolutely required as part of their jobs.

*

Security Planning: An Applied Approach | * | *

Privacy Rule:
Protections against Marketing

CE must obtain permission before sending any marketing materials, with limited exceptions

Boston Globe, August 1, 2000

A patient at Brigham and Women’s Hospital in Boston

learned that employees had accessed her medical

record more than 200 times.

*

Can you imagine having some serious condition and receiving unwanted emails about it… at work?!

Discussion: What could go wrong with direct advertising, other than multi-record access?

Security Planning: An Applied Approach | * | *

Privacy Rule:
Establish Privacy Safeguards

Required

Shut or locked doors

Keep voice down

Clear desk policy

Privacy curtains

Password protection

Auto screen savers

Locked cabinets

Paper shredders

Not Required

Soundproof rooms

Redesign office space

Private hospital rooms (semiprivate ok)

OK for doctors to talk to nurses at nurse stations

Safeguards should be REASONABLE

The rules are supposed to be reasonable. The items on the left are considered reasonable, while the items on the right are considered to expensive to implement. As you can see these relate to non-computer privacy issues.

*

Security Planning: An Applied Approach | * | *

Privacy Rule:
Employee Training & Accountability

Each CE organization shall name one person who is accountable for Privacy Rule compliance

Each employee, volunteer, contractor shall be trained in privacy policies and procedures

  • Full and Part-time

New York Times, Jan. 19, 2002

Eli Lilly and Co. inadvertently revealed over 600 patient

e-mail addresses when it sent an all message to every

individual registered to receive reminders about taking

Prozac.

There must be one person who is the coordinator and champion (and fall guy/gal) for security.

But – everyone, full and part time, needs to be trained in HIPAA compliance. This includes CE employees and BA contractors.

*

Security Planning: An Applied Approach | * | *

Privacy Rule: Individual Privacy Rights

Patients have the right to:

See or obtain copies of medical information (except for psychotherapy notes)

Request correction to health record

Receive a Notice of Privacy Practices

Request restrictions as to who can see PHI

Request specific method of contact for sake of privacy

Know who has accessed PHI

File a complaint if their rights have been violated

Allow and withdraw authorizations for use and disclosure

CE must:

Respond to requests within 30 days

May extend delay with notice for another 30 days

Keep records of how PHI is disclosed

You are not allowed to see how mentally unfit you are, but physically unfit – yes.

Notice of Privacy Practices is something that a CE puts together which states the organizations policies related to privacy. Every CE must have such a document, and each patient must sign off that they have read it.

When patients request information or a correction, the CE must comply and are given 30 days, with a further extension of 30 days, as part of HIPAA.

If a CE makes amendments to the PHI, it must inform others of the amendments.

A CE does not have to amend PHI if:

1) It did not create the PHI.

2) It determines that the PHI in the record is accurate and complete.

If a CE decides to deny a request to amend PHI, it must send a written denial notice to the person who requested the amendment.

*

Security Planning: An Applied Approach | * | *

Notice of Privacy Practices

Privacy Requirements:

NPP must be available when asked for

NPP must be displayed prominently in the office

Health Plan must provide upon enrollment

Health Provider must provide on first service delivery

Both must request written acknowledgment of receipt of NPP

After change, revised NPP must be issued to clients within 60 days

Electronic Requirements (if web page):

Must be displayed prominently on web page

Must be emailed to customers after a change in NPP

If electronic is available, then the bottom two bullets must be done.

*

Security Planning: An Applied Approach | * | *

Required & Permitted Disclosures

Required Disclosure:

Patient (or personal representative, e.g., parent, next of kin)

Office of Civil Rights Enforcement: Investigates potential violations to Privacy Rule

Permitted Disclosure:

Minimum-Necessary PHI may be disclosed without authorization for: judicial proceedings, coroner/funeral, organ donation, approved research, military-related situations, government-provided benefits, worker’s compensation, domestic violence or abuse, some law enforcement activities

ID must be verified by proof of identity/badge and documentation

Disclosure is giving private health information to other people. In some cases it is allowed as described here and on subsequent pages.

Parents of children and legal caretakers of the incapacitated are allowed to get information under Required Disclosure.

A permitted disclosure is allowed for the reasons given, when ID is provided.

Health care providers are required to report evidence of child abuse and neglect by state law. Teachers have similar requirements and must report the information to state social services agencies or local law enforcement agencies.

CE’s may also disclose PHI without consent for:

  • Law enforcement activities to help identify or locate a suspect, witness, or missing person.

(This information is limited to identifying information (name, address and distinguishing physical characteristics).

2) Assistance in the apprehension of violent criminals such as information about a victim.

3) If a CE suspects that a death was cause by criminal activity, they can alert law enforcement.

*

Security Planning: An Applied Approach | * | *

More Disclosures

Routine Disclosure

Disclosures that happen periodically should be addressed in policies, procedures, forms

E.g.: Referral to another provider, school immunization, report communicable disease, medical transcription, births, deaths & other vital statistics

Non-routine Disclosure

CEs shall have reasonable criteria to review requests for non-routine PHI disclosures

E.g., Research disclosures

Incidental Disclosure

CEs shall have reasonable safeguards

E.g. Patient overhears advice given to another patient

Accidental Disclosure

Computer is stolen with PHI

Disclosures must be tracked for THREE years

A Routine Disclosure should be allowed by a specified procedure for the reasons given above.

A non-routine disclosure is a good reason which is not automatically approved. This may include research. In this case, a committee might decide whether the disclosure makes sense – with approval by the patient.

Incidental Disclosure is ok if in small unavoidable amounts, and practices are in place to prevent.

Accidental Disclosure is NOT allowed or permitted.

Example for communicable disease:

New York must report diseases that are highly contagious, diseases that might indicate bioterrorism and must report smallpox, anthrax, botulism, and typhoid immediately.

*

Security Planning: An Applied Approach | * | *

Disclosures Requiring Authorization

Research project (special conditions may allow)

Person outside health care system

Employer

  • However, employer may require authorization for drug test before hiring

Other insurance companies

Health care provider not involved in patient’s health care

Insurance company not paying patient’s claims

Lawyer

Patient should get copy of authorization

Here Authorization comes from the Patient. The patient may authorize some disclosures.

*

Security Planning: An Applied Approach | * | *

Sample Authorization Form

Disclosure Authorization Form

Description of Information:_____________________________________

Patient making authorized disclosure____________________________

Person receiving information:__________________________________

Purpose of the disclosure:

Authorization Expiration Date:________________

Patient Signature__________________________ Date:____________

A form to revoke authorization must be completed to terminate authorization.

Must be retained by CE for 6 years

Here is a copy of a sample authorization form the patient should sign. The patient can revoke authorization at any time.

As you can see, the CE must keep certain information for 6 years.

A valid authorization shall contain all of the information above.

A defective authorization isn’t valid.

Authorizations are defective after their expiration date has passed.

They are also defective if they are not completely filled out or the person has revoked the authorization.

*

Security Planning: An Applied Approach | * | *

Implementing ‘Minimum Necessary’

Minimum necessary: Just enough info to accomplish the main purpose

E.g., Send prescription for glasses to optician, not medical history

Data Classification

  • Sensitivity of information
  • Type of treatment required

Questions to Answer

  • What parts of record can each user type access?
  • How will we constrain access to implement view?

*

During a Disclosure, the minimum amount of information necessary should be provided. Minimum necessary is concerned that staff (e.g., medical administrators and nurses) see only what they need to on database forms and records, etc. For example, send the prescription for glasses to the optician, not the entire medical history. Data should be classified as to handling and treatment. For example, PHI is highly sensitive, compared to doctor’s schedules, for example. We will learn about this in future classes.

Security Planning: An Applied Approach | * | *

Business Associates (BA)

Legal

Actuarial

Accounting & Finance

Consulting

Administration &
Management

Accreditation

Must also be responsible with PHI

Not Business

Associates

Janitorial

Electrical

Phone

Vending

Copy

Conduit: Mail

Financial Institution:

Banks

There are rules for how BAs must be handled. BAs include the people on the left. Non-BAs are the people on the right.

*

Security Planning: An Applied Approach | * | *

Business Associate Contract (BAC)

CEs must request BA to sign a BAC:

BA will not disclose PHI

BA is liable for damage due to disclosure or misuse

BA will use safeguards to prevent misuse

BA will report any security incident or violation of agreement

BA will destroy or protect PHI upon termination of contract

CE can terminate contract if violation occurs

CE will provide BA copies of policies, procedures and materials for safeguarding

Etc.

BAs are equally liable as CEs, under HITECH Act

Security Planning: An Applied Approach | * | *

HITECH: Health Information Technology for Economic and Clinical Health Act (2009)

BA’s must follow the HIPAA Security Rule.

BA’s are held to the same standard as CE’s.

Health & Human Services (HHS) can:

  • require BA’s to comply with HIPAA.
  • enforce penalties on noncompliant BA’s.

HITECH Act: The Health Information Technology for Economic and Clinical Health or “The Act”

HHS: U.S. Dept. of Health & Human Services

Because of the expected increase in use and exchanges of EPHI (electronic protected health information), the HITECH Act was put into effect to strengthen HIPPA privacy and security protection of PHI by increasing fines for non-compliance, changes how compliance is enforced, and introduces the federal breach notification rule.

HITECH Act:

Increases fines for non-compliance and violations to Security & Privacy rules.

Introduced a federal breach notification rule.

Requires HHS to make sure that CE’s & BA’s comply with HIPPA through audits.

Gives states the ability to enforce HIPPA compliance.

*

Security Planning: An Applied Approach | * | *

Violation of HIPAA Privacy Rule:

WTHR Investigation Leads to Record $2.25M HIPAA Settlement, Indianapolis, IN, 2006:

Reported that CVS was “throwing sensitive personal information in the trash” (e.g.: unredacted pill bottles, prescription instruction sheets, pharmacy receipts with credit card information and health insurance account numbers.

After this, other CVS pharmacies were investigated and it was found that they also were improperly disposing of PHI.

In the settlement CVS was required to:

  • Create an information security program to protect personal information.
  • Requires that they get an independent audit every 2 years until 2029.
  • Pay $2.25 million to settle claims.

CVS agreed to:

  • Implement a security plan that complies with HIPAA’s Privacy Rule.
  • Protect information during disposal.
  • Develop employee training programs.

At this time, CVS’s privacy policy stated that “CVS Pharmacy wants you to know that nothing is more central to our operations than maintaining the privacy of your health information…”

CVS said that there was no verification of the reports made by the media, but settled the charges with the FTC & HHS to put this case behind them.

In the settlement CVS was required to:

Create an information security program that protects personal information.

Requires that they get an independent audit every 2 years until 2029.

Pay $2.25 million to settle the claims.

CVS agreed to:

Implement a security plan that would create security policy that complies with HIPAA’s Privacy Rule.

Protect information during disposal.

Develop employee training programs.

*

Security Planning: An Applied Approach | * | *

The HIPAA
Security Rule

+

The Security Rule applies to those CEs and BAs who use computerize PHI. We do not want hackers to get in.

*

Security Planning: An Applied Approach | * | *

Security Rule Enforces
Privacy Rule on Computers

Privacy Rule Security Rule

With or w/o computer With computer

Protect PHI Protect EPHI

Minimum Necessary Authentication &

Access Control

Accounting of Disclosures Unique Login Credentials

Authentication

Track modifications to EPHI:

Who did what when?

*

EPHI=Electronic Personal Health Information

This slide shows how Privacy Rule gets implemented on a computer, with the Security Rule.

Security Planning: An Applied Approach | * | *

Security Vocabulary

Asset: Diamonds

Threat: Theft

Vulnerability: Open door or windows

Threat agent: Burglar

Owner: Those accountable or who value the asset

Risk: Danger to assets

*

This is not only HIPAA but standard security vocabulary.

Vulnerability is not the threat itself, but the enabler for the threat.

To a computer, a threat could also be a power outage.

Security Planning: An Applied Approach | * | *

Security Rule Assures…

More Standard Security. These are the three goals of security.

Confidentiality: Only permitted people may see the data

Integrity: The data is correct

Available: The resources are available when needed.

(CIA) Remember it!!! You will see and hear it again, and again…

*

Security Planning: An Applied Approach | * | *

Security Services

Authentication

Access Control

Data confidentiality

Data integrity

Data backup & recovery

Nonrepudiation = Cannot say it wasn’t you who sent or received data

Risk Management

*

Authentication = login/password

Access Control = minimum necessary permissions provided (read/write/access/edit/delete)

Which address Confidentiality, Integrity, Availability?

Security Planning: An Applied Approach | * | *

Risk Management

Risk assessment

Policy & Procedures Maintenance

Security Program Enforcement

Audit logs, vulnerability assessments, audit for procedure adherence and control effectiveness

Patches are applied to software

Data is available, confidential, & integrity is protected

Risk Management is a requirement of HIPAA. Risk management assures that the cost of security controls (often simply called ‘controls’) is reasonable considering the risk. It means we have to consider how much it will cost us if someone breaks in (consider the cost of going to jail and paying HIPAA fines) and the cost of security controls. Hopefully, the security controls are cheaper than violating HIPAA! We will study risk assessment further in another chapter. Having said that, some policies are absolutely required, such as the bullets specified above.

*

Security Planning: An Applied Approach | * | *

Security Rule Standards

Administrative

Controls

Physical Controls

Technical Controls

Comprehensive Technology Neutral Scalable

Small

or

Large

Look to Best Practices

for Technology Answers

e.g. NIST

Security

Rule

Security

Rule

Security Rule should be:

Comprehensive: affecting administrative, physical and technical controls.

Technology neutral: HIPAA does not want to promote any specific hardware vendor.

Scalable: For small or large companies

NIST: National Institute of Standards & Technology

*

Security Planning: An Applied Approach | * | *

Three Areas of Safeguards

Security

Rule

Administrative: Administrative policies, procedures, and actions

to implement and maintain security controls to protect EPHI, including

risk mgmt, access control, contingency plans, incident response.

Physical: Protection of the physical access to terminals, laptops,

servers, backup tapes, CDs, memory, including viewing,

access, maintenance and disposal.

Technical: Protection using technology tools to protect EPHI,

including logs, encryption, authentication

Security Rule affects three major areas as shown above. We will see more of each of these.

*

Security Planning: An Applied Approach | * | *

Policies & Procedures

Policies and Procedures MUST BE:

Retained for 6 years after date of creation or last effect

Available to workers responsible for them

Must be updated regularly accommodating changes in environment & operations

Policies and procedures define how employees and contractors should do their jobs regarding security.

These policies/procedures must be readily available to them. They should also be updated, as the world changes.

Thus, new database or new medical function: appropriate changes to the policies/procedures.

Information must be retained for a minimum duration of 6 years. Effect: if a prescription is still active, then it is still in effect.

*

Security Planning: An Applied Approach | * | *

Security Rule Standard

DO IT!

This is recommended…

Address this in some way…

Implement equivalent alternative

measure….

If it doesn’t apply, document well

why not…

We do this instead:

…..

Security Rule elements are either Required (do as defined) or Addressable (may do in a different way but has same effect “Equivalent Alternative Measure” – or don’t need to do because this does not apply to us for reason given). Both need to be documented.

*

Security Planning: An Applied Approach | * | *

Administrative:
Security Mgmt Process

Risk Analysis: Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the CIA of EPHI held by the CE. R
Risk Mgmt: Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with the Security Rule R
Sanction Policy: Apply appropriate penalties against workforce members who fail to comply with the entity’s security policies and procedures R
Info System Activity Review: Implement procedures to regularly review records of IS activity, such as audit logs, access reports, and security incident tracking reports R

CIA = Confidentiality, Integrity, Availability

EPHI = Electronic Personal Health Information

CE= Covered Entities, extended to BAs by HITECH.

You can see that these are all REQUIRED – that means documented.

*

Security Planning: An Applied Approach | * | *

Security Mgmt Implications

The Sanction policy basically requires we all sign a confidentiality agreement and if someone breaks the rule, they could be fired.

We will need an IT person to regularly check logs to be sure our system was not broken into

Risk assessment must be ‘accurate and thorough’ – that will be a challenge!

And all are Rs…

Security Mgmt

Process

This helps to further explain the previous page.

*

Security Planning: An Applied Approach | * | *

Administrative:
Workforce Security

Authorization and/or Supervision: Implement procedures for the authorization and/or supervision of workforce members who work with EPHI or in locations where it might be accessed A
Workforce Clearance Procedure: Implement procedures to determine that the access of a workforce member to EPHI is appropriate A
Termination Procedures: Implement procedures for terminating access to EPHI when the employment of a workforce member ends… A

These are all As: Addressable. You can do this in the most cost-effective or simple way possible – but you must do this!

Workforce member = employee, contractor, volunteer.

This covers Authorization (think segregation of duties and authorization). Supervision of work is an appropriate form of segregation of duties. When someone leaves, their privileges shall be revoked.

*

Security Planning: An Applied Approach | * | *

Workforce Security Implications

.We must have procedures to allocate authorization, periodically check authorization, and procedures to terminate someone

They are asking for checks and balances with supervision or authorization

We are a three person operation, can we get away with not doing this?

Must we document our situation?

These are As.

Workforce

Security

*

With documentation, it may be possible to bypass if clear lack of need is evident: such as a single-doctor office.

Also possible: background checks.

Security Planning: An Applied Approach | * | *

Administrative:
Information Access Mgmt

Isolating Health Care Clearinghouse (CH) Function: If a health care CH is part of a larger organization, the CH operation must implement policies and procedures that protect the EPHI of the CH from unauthorized access by the larger organization R
Access Authorization: Implement policies and procedure for granting access to EPHI – e.g., through access to a workstation, transaction, program, process, or other mechanism A
Access Establishment & Modification: Implement policies and procedures that, based upon the entity’s access authorization policies, establish, document, review, and modify a user’s right of access to a workstation, transaction, program or process. A

*

1 is only applicable if you are a Clearinghouse which is part of a larger organization. (We don’t care.)

Items 2 & 3 are concerned with Access Control: giving read/write permissions, creating records, etc. Once privileges are granted, they may need to be changed as the position changes.

Security Planning: An Applied Approach | * | *

Info Access Mgmt Implications

It is an implementation: We must define a data owner for each major process

Isn’t this the same as the previous rule?

.And then our IT people must define how they will grant access based upon the data owner’s decisions.

Info Access

Mgmt

*

Data Owner = a person on the business side who knows who should be given privileges, based on job. IT should not be responsible for this.

Security Planning: An Applied Approach | * | *

Administrative:
Security Awareness & Training

What do you think these mean?

Security Reminders: Provide periodic security updates to members of the workforce A
Protection from Malicious Software: Implement procedures for guarding against, detecting, and reporting malicious software A
Login Monitoring: Implement procedures for monitoring login attempts and reporting discrepancies A
Password Mgmt: Implement procedures for creating, changing and safeguarding passwords A

These are pretty obvious, hopefully.

*

Security Planning: An Applied Approach | * | *

Administrative:
Contingency Plan

Data Backup Plan: Establish and implement procedures to create and maintain retrievable exact copies of EPHI R
Disaster Recovery Plan: Establish … procedures to restore any loss of data R
Emergency Mode Operation Plan: The emergency mode operation plan requires CEs to establish … procedures to enable continuation of critical business processes, while maintaining the security of EPHI while operating in emergency mode R
Testing & Revision Procedure: Implement procedures for periodic testing and revision of contingency plans. A
Applications & Data Criticality Analysis: Assess the relative criticality of specific applications and data in support of other contingency plan components. A

*

… = and implement as needed

We will have a whole week or two on this too. Hopefully this also is reasonably clear.

Security Planning: An Applied Approach | * | *

Administrative:
One-Line Safeguards

Assigned Security Responsibility: Identify the security official who is responsible for the development and implementation of the policies and procedures required by this rule for the entity. R
Security Incident Procedures: Implement policies & procedures to address security incidents. Identify and respond to suspected or known security incidents; mitigate … harmful effects of security incidents that are known to the CE; and document security incidents and their outcomes. R

*

… = to the extent practicable

Security Incident: When something goes wrong, that is not the time to decide what to do about it. These policies and procedures should be defined well ahead of time.

Security Planning: An Applied Approach | * | *

Administrative:
More One-Line Safeguards

Evaluation: Perform a periodic technical and nontechical evaluation, based initially upon the standards implemented under this rule and subsequently, in response to environmental or operations changes affecting the security of EPHI, that establishes the extent to which an entity’s security policies and procedures meet the requirements of this subpart R
BA Contracts and Other Arrangements: A BA [may] create, receive, maintain, or transmit EPHI on the CE’s behalf only if the CE obtains satisfactory assurances that the BA will appropriately safeguard the information. R

Evaluation = Test or audit. Note that this should occur periodically for both technical and nontechnical aspects.

*

Security Planning: An Applied Approach | * | *

Info Access Mgmt Implications

That makes sense when technology changes, but I guess we have to do it periodically as well, since the world changes.

According to Evaluation, we must self-test or be certified on a regular basis, to be sure we follow the Security Rule

We need to know who, what, when, where, why for incident response.

Who shall we name as our Security Manager?

Evaluation

*

This explains the previous page further.

Security Planning: An Applied Approach | * | *

Physical Safeguards:
Facility Access Controls

Facility Access Controls: Implement policies and procedures to limit physical access to electronic info systems and areas where sensitive paper documents are stored and any facilities in which they are housed, while ensuring authorized access
Contingency Operations A
Facility Security Plan A
Access Control & Validation Procedures A
Maintenance Records A

Now we are in the realm of Physical Controls: Think locks, key cards, guards, badges,

*

Security Planning: An Applied Approach | * | *

Physical Safeguards:
Facility Access Control

How will physical access be restricted to sensitive paper documents, terminals, server, backup copies, laptops, contingency operations in copy, view, or modify forms?

How are visitors controlled from accessing PHI/EPHI?

When repairs occur (to facility or systems) how will PHI/EPHI be safeguarded?

Security Planning: An Applied Approach | * | *

Physical Safeguards: Workstations

Workstation Use: Implement policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of a specific workstation or class of workstation that can be used to access EPHI R
Workstation Security: Implement physical safeguards for all workstations that can be used to access EPHI, to restrict access to authorized users R

Physical safeguards may include monitor hoods, positioning monitors so that others can not see them, minimal remote access, half-walls and doors preventing access, etc.

*

Security Planning: An Applied Approach | * | *

Workstation Use and Security

What functions will be performed on which workstations?

How will workstation access be limited when the user leaves their station?

How will theft of laptops be prevented?

How will the workstations be positioned?

What other physical safeguards (locked rooms, hoods) will be implemented to prevent shoulder surfing?

These must all be considered and documented.

*

Security Planning: An Applied Approach | * | *

Physical Safeguards:
Device & Media Controls

Device and Media Controls: Implement policies and procedures that govern the receipt and removal of hardware and electronic media and devices that contain EPHI into and out of a worksite or facility, and the movement of these items within the worksite or facility.
Disposal R
Media Reuse R
Accountability A
Data Backup and Storage A

How are disks disposed of? Are memory sticks allowed? How are they prevented? What happens if a computer goes in for repair? Can anyone work on these computers? How are tapes reused? Where are backups stored?

*

Security Planning: An Applied Approach | * | *

Device & Media Controls

How will media be erased or damaged before disposal or reuse?

Reformatting disk may not be adequate even for reuse

How, when and where has EPHI been moved or transferred? Documentation is necessary

How is a backup made and where/how stored?

*

Security Planning: An Applied Approach | * | *

Technical Safeguards:
Access Control

Access Control: Implement technical policies and procedures for electronic info systems that maintain EPHI. These policies and procedures should contain access protocols that will establish and enforce the entity’s other access policies, and allow access only to those persons or software programs that have been granted access rights
Unique User Identification R
Emergency Access Procedure R
Automatic Logoff A
Encryption and Decryption A

Security Planning: An Applied Approach | * | *

Technical Safeguards:
Access Control

How is each user uniquely identified to the system?

How does authentication occur?

In an emergency, what backup methods are used for authentication?

How does automatic logoff occur after a period of inactivity?

Which data is encrypted in storage and/or transmission?

Security Planning: An Applied Approach | * | *

Technical Safeguards:
Transmission Security

Transmission Security: Implement technical security measures to guard against unauthorized access to EPHI that is being transmitted over an electronic communications network
Integrity Controls A
Encryption A

Security Planning: An Applied Approach | * | *

Technical Safeguards:
Transmission Security

How are we sure that data is not modified or lost during transmission?

What encryption techniques are used to protect the security of EPHI transmitted over a public network?

Security Planning: An Applied Approach | * | *

Other Technical Safeguards

Audit Controls: Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use EPHI R
Integrity: Implement policies and procedures to protect EPHI at rest, meaning stored on organizational systems and applications, from improper alteration or destruction. A
Person or Entity Authentication: Implement procedures to verify that a person or entity seeking access to EPHI is the one claimed R

Audit Controls = Logs

Integrity = hashing or check codes (a sophisticated parity)

Authentication = something you are, have or know

*

Security Planning: An Applied Approach | * | *

Other Technical Safeguards

For which devices will the logs be monitored?

What log events should be archived for security purposes?

How will potential attacks found in logs be recorded, reported, and acted upon?

What techniques will be used to ensure stored data has not been modified (hashes, message digests?)

What authentication mechanisms will be used to assure that approved entities (people or systems) are accessing EPHI?

Security Planning: An Applied Approach | * | *

Question

An example of a vulnerability is

  • Theft
  • Burglar
  • Open door
  • Diamonds

Displaying slide show will result in the correct answer revolving.

See previous slide for reasons why the answer is correct.

*

Security Planning: An Applied Approach | * | *

Question

Protected Health Information is:

  • SSN, medical information
  • Name, SSN, medical information
  • Name, address, SSN, phone, medical information
  • Medical information stored in a computer

Look up slide on PHI for reasons why. Also there is a difference between EPHI and PHI.

*

Security Planning: An Applied Approach | * | *

Question

The Security Rule requires that:

  • Logs are monitored
  • An intrusion detection system is implemented
  • Cabinets containing PHI must be locked
  • Walls must be soundproof and all terminals outside of waiting room

Note that this applies to Security Rule. Two of these answers relate potentially to Security Rule, two relate to Privacy Rule. Two rules are not required by Security or Privacy rule, while two rules do apply (to Security or Privacy rule). Which are which?

*

Security Planning: An Applied Approach | * | *

Question

The Privacy Rule requires that:

  • Logs are monitored
  • An intrusion detection system is implemented
  • Cabinets containing PHI must be locked
  • Walls must be soundproof and all terminals outside of the waiting room

Ditto.

*

Security Planning: An Applied Approach | * | *

Question

The Addressable option for the Security Rule means:

  • Smaller organizations need not implement if they can justify it would be too expensive
  • HIPAA discusses alternative means to accomplish this, and the organization must select one
  • The CE must document how they accomplish this provision
  • This provision must be implemented or addressed in some way, although alternative implementations are allowed

‘A’ does not need to be implemented if there is an excellent document reason why (too expensive is not a good answer).

*

Security Planning: An Applied Approach | * | *

HIPAA protects Protected Health information (PHI)

Applicable to Covered Entities and their Business Associates

In General:

  • Privacy Rule covers Need-to-know, Disclosures, Notice of Privacy Practice, non-electronic privacy
  • Security Rule covers Administrative, Physical and Technical Safeguards
  • HITECH increases penalties for non-compliance

HIPAA is an example of state-of-the-art Privacy and Security regulation

Most of each chapter of this book is required for HIPAA

Summary

Security Planning: An Applied Approach | * | *

Not Covered in this Presentation

Some specialized material is not being covered as part of this presentation, including:

Hybrid Entities: Part Covered, Part Not

Organized Health Care Arrangement (OHCA): Group of doctors

Jointly Administered Govt. Program

Trading Partner: CEs exchange electronic transactions without clearinghouse

COBRA

*

We have not covered all of HIPAA – only the basics. There is more, but we won’t be discussing these areas.