COMPLIANCE REQUIREMENTS The Health Insurance Portability and Accountability Act (HIPAA) of 1996 mandates significant changes in the legal and regulatory environments governing the provision of health benefits, the delivery and payment of healthcare services, and the security and confidentiality of individually identifiable protected health information (PHI). A sizable percentage of the initial HIPAA regulations pertain to maintaining the privacy of PHI. On February 20, 2003, the final HIPAA security regulations (68 Fed. Reg. 8334) were issued by the United States Department of Health and Human Services. These regulations are designed to ensure that a covered entity, referred to as CE, meets the necessary security requirements for PHI. The security rule's objective is to protect the confidentiality, integrity and availability of electronic. PHI. Meeting the security rules; requirements means protecting health care information stored on computers and the data transmitted on computer networks, both internal data networks and external networks such as the internet. PHI must be protected from compromise due to abuse by a disgruntled employee, mishandling by unauthorized or untrained personnel, and unauthorized access by a hacker, intruder or anyone without the "Need to know" or due to any system outages. There are four sections to the HIPAA Security Rule:
Each of these requirements must be further defined to put in place a practical approach to be able to comply.
|
|||
|
Allergy & Asthma Prevention & Treatment Center
Tel: 858.458.0940
9833 Pacific Heights Boulevard
|