HIPAA Security 101 For Pathways - PowerPoint PPT Presentation

1 / 10
About This Presentation
Title:

HIPAA Security 101 For Pathways

Description:

Firewall between device managing ePHI and the Internet ... Updated and current anti-virus and anti-spyware software installed on PC. ... – PowerPoint PPT presentation

Number of Views:102
Avg rating:3.0/5.0
Slides: 11
Provided by: mask4
Category:

less

Transcript and Presenter's Notes

Title: HIPAA Security 101 For Pathways


1
HIPAA Security 101For Pathways Substance Abuse
Contractors
  • Matt P. Maskart, HIPAA Security Officer
  • Systems Engineer
  • Sept. 18th 2006

2
HIPAA Regulation
Transactions, Code Sets, Identifiers
Compliance Date 10/16/03
Privacy Compliance Date 4/14/2003
Security Compliance Date 4/20/2005
3
HIPAA Security
Security
  • Administrative Safeguards
  • Security Management
  • Authorization
  • Workforce Training
  • Physical Safeguards
  • Facility Access
  • Workstation Use
  • Media Control
  • Technical Safeguards
  • Access Control
  • Audit Controls

4
The Five Ws
  • Who has to comply?
  • Covered Entities
  • What information is important?
  • ePHI
  • Where is the ePHI?
  • Everywhere!
  • When do we have to be compliant?
  • April 21, 2005

5
Why (Goal and Scope)
  • Confidentiality
  • Integrity
  • Availability
  • Protection
  • Security
  • Privacy

Electronic Protected Health Information (ePHI)

Pathways Technology Consumer ePHI Consumers
6
Regulation Theme
  • You know best!
  • Technologically Neutral
  • Reasonable and Appropriate
  • Not just technical aspects
  • Ensure compliance by workforce

7
Pathways Road to Compliancy
Identified Risk
Identified Risk
Identified Risk
Identified Risk
Staff Training
Policies
Identified Risk
Procedures
Risk Analysis
Assignment of Responsibility
Analysis with State
Regulation Analysis
8
Substance Abuse Contractors
  • Management of Pathways PHI
  • Best Practices For Information Security
  • Firewall between device managing ePHI and the
    Internet
  • Limit or eliminate the access of Pathways ePHI
    when not located in a secure location
  • Updated and current anti-virus and anti-spyware
    software installed on PC.
  • Use access control methods to mitigate the
    possibility of admittance devices.

9
Recent Examples
  • Madrona Medical Group is asking thousands of
    patients to watch their credit reports after a
    former employee was charged with illegally
    downloading patient files onto his personal
    laptop computer. 8/11/06
  • VA missing second computer containing data on
    38,000 patients. 8/3/06
  • 21 year-old Unisys subcontractor charged with
    stealing a desktop computer with billing
    information on as many as 38,000 Department of
    Veterans Affairs medical patients. 9/11/06

10
  • Questions
  • Thank You For Your Help.
  • Matt
Write a Comment
User Comments (0)
About PowerShow.com