Last Day to Save $250 on SANS Chicago 2014

HIPAA Security Policy: Health Insurance Portability and Accountability Act

What is all the hype on HIPAA Security Policy?

HIPAA stands for Health Insurance Portability and Accountability Act.

From the HIPAA FAQ:

Passed in 1996, HIPAA is designed to protect confidential healthcare information through improved security standards and federal privacy legislation. It defines requirements for storing patient information before, during and after electronic transmission. It also identifies compliance guidelines for critical business tasks such as risk analysis, awareness training, audit trail, disaster recovery plans and information access control and encryption.

Complying with Security Standards

There are 18 information security standards in three areas that must be met to ensure compliance with the HIPAA Security Rule.

The three areas are:

  • Administrative Safeguards: Documented policies and procedures for day-to-day operations; managing the conduct of employees with electronic protected health information (EPHI); and managing the selection, development, and use of security controls.
  • Physical Safeguards: Security measures meant to protect an organization's electronic information systems, as well as related buildings and equipment, from natural hazards, environmental hazards, and unauthorized intrusion.
  • Technical Safeguards: Security measures that specify how to use technology to protect EPHI, particularly controlling access to it.