Top
10 HIPAA Security Tips
1. Perform a risk analysis. A security
risk analysis is the basis by which CEs should establish their priorities
and determine which security implementation specifications they
should address and in what order.
2.
Use unique identification. Based on a history of compromising security
for convenience, many CEs have used generic user IDs or the user
IDs have been shared. By providing secure, yet convenient access
to information through single sign-on technology, CEs can ensure
appropriate tracking of information access to a particular user.
3.
Implement access controls. Granular levels of access controls help
ensure that users are able to access only information deemed minimum
necessary to their requirements.
4.
Implement role-based access control. Wherever possible, the automation
of role-based user provisioning will help improve the minimum-necessary
process and could reduce current expenses for security management,
if automated.
5.
Monitor all security incidents. Consolidating and correlating log
information across the enterprise will assist in monitoring, reporting
and, ultimately, preventing security incidents.
6.
Provide secure, convenient access to ePHI. Improving security and
convenience of access to ePHI allows CEs to deliver value to their
users and improve the likelihood that users will follow security
policies and procedures.
7.
Monitor network utilization. Mitigate risks by monitoring utilization
of the network to help ensure that corporate resources are used
only for legitimate purposes.
8.
Minimize vulnerabilities across the network. Identify securityvulnerabilities
that may compromise the security and confidentiality of ePHI.
9.
Monitor enterprise-wide data protection policies and procedures.
Based on the disparate nature of data backup and recovery policies
and procedures for many CEs, implementing a storage management portal
will help ensure the availability of an exact, retrievable copy
of ePHI as required under the security rule.
10.
Improve utilization of storage resources. As the volume of data
continues to increase along with HIPAA requirements to ensure that
lost data can be recovered, deploying storage resource management
technology will help save money for CEs by improving utilization
of current resources before incurring new hardware expenses.
While every CE's situation and compliance
challenges are unique, paying attention to these areas should help
CEs form the basis for a strong HIPAA compliance strategy. By following
these steps, CEs can facilitate their compliance efforts while improving
user productivity and satisfaction, as well as reduce existing security
management expenses.
Once CEs meet their compliance needs,
they can also use these best practices to improve their overall
resource management, so they maximize the return on their technology
investments.
Petronella Computer Consultants,
Inc. can assist you by performing a free HIPAA security risk assessment.
This audit will alert you to weaknesses and risks in your HIPAA
compliance strategy. Customized compliance strategies involving
cost-efficient technology will assist you in maximizing your HIPAA
compliance efforts.
|