Tags: Health Lawyer

If you are one of the approximately 78% of physician practices that has set up electronic health records (EHR) during the last few years, or if you are a business associate working for a physician practice that uses electronic health records, you cannot simply set aside thoughts regarding access and security of patient health records. Just like your computer, tablet or smart phone needs regular updates, your system for EHR must regularly be evaluated and updated. The Health Insurance Portability and Accountability Act (HIPAA) rules require that covered entities and business associates review and modify their security measures to safeguard their electronic protected health information (ePHI) in an ever-changing technology environment.

As part of this regular risk assessment, each covered entity must:

  1. identify and analyze potential risks to ePHI
  2. implement security measures that reduce risks and vulnerabilities (to a reasonable and appropriate level)
  3. designate a security official who is responsible for developing and implementing the security plan
  4. periodically assess how well security policies and procedures are meeting the requirements of the security rule
  5. train all workforce members regarding security policies and procedures
  6. have appropriate sanctions in place, and utilize them when necessary, for staff who do not follow security policies and procedures
  7. limit physical access to its facilities while ensuring that authorized access is allowed
  8. have technical controls in place (passwords, etc.) which only permit authorized personnel access to ePHI
  9. have audit controls in place that monitor and record who gains access to ePHI
  10. have integrity controls in place that ensure that ePHI is not improperly altered or destroyed
  11. have encryption mechanisms in place to ensure that ePHI is not accessed when transmitted over an electronic network.

For more information on how you can continue protecting your ePHI, contact the Goosmann Law Firm at info@goosmannlaw.com or (712) 226-4000.

Subscribe Our Blog

DISCLAIMER: The information in this blog post (“post”) is provided for general informational purposes only, and may not reflect the current law in your jurisdiction. By visiting this website, blog, or post you understand that there is no attorney client relationship between you and the Goosmann Law Firm attorneys and website publisher. No information contained in this post should be construed as legal advice from Goosmann Law Firm, PLC, or the individual author, nor is it intended to be a substitute for legal counsel on any subject matter. No reader of this post should act or refrain from acting on the basis of any information included in, or accessible through, this Post without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue from a lawyer licensed in the recipient’s state, country or other appropriate licensing jurisdiction.