How to comply with HIPAA

How to comply with HIPAA

In the digital age, the protection of sensitive healthcare information is paramount. HIPAA, the Health Insurance Portability and Accountability Act, requires organizations to implement safeguards to secure individuals' protected health information (PHI).

We see lots of organizations implementing solutions to ensure HIPAA compliance. However, often these solutions fall short on meeting the requirements of the HIPAA Privacy Rule, leaving organizations vulnerable to the repercussions of non-compliance.

So how can you be sure your security solutions are supporting your organization to be HIPAA compliant? Read on as we explore:

Back to HIPAA basics

Who does HIPAA apply to?

Organizations who are required to conform to HIPAA are known as Covered Entities, including (but not limited to):

How does HIPAA protect patients?

The HIPAA Privacy Rule, issued by the US Department of Health and Human Services (HHS), creates national standards for the protection of individuals' medical records and other personal health information. The rule provides patients with more control over their health information and sets boundaries on the use and release of health records.

What is the HIPAA Privacy Rule?

The HIPAA Privacy Rule concerns the use and disclosure of protected health information by covered entities. It includes standards for individuals’ rights to understand and control how their information is used.
The Privacy Rule ensures individuals’ healthcare data is protected while allowing healthcare information to be shared in the delivery of high quality healthcare, and to protect the public’s health and wellbeing.

What is the HIPAA Security Rule?

The HIPAA Security Rule protects a subset of information covered by the Privacy Rule. This subset consists of individually identifiable health information that a Covered Entity creates, receives, maintains, or transmits in electronic form. This information is called electronic protected health information, or ePHI.
To comply with the HIPAA Security Rule, all Covered Entities must:

Is your solution HIPAA compliant?

Limitations of TLS

Many healthcare organizations rely on email and file transfer tools which utilize Transport Layer Security (TLS). However, this security measure is often misunderstood:

For these reasons, TLS does not ensure the "confidentiality, integrity, and availability of all e-PHI", "safeguard against anticipated threats to the security of the information" or "protect against anticipated impermissible uses or disclosures that are not allowed by the rule" - all of which are core principles of the HIPAA Security Rule.

How important is two-factor authentication (2FA) in HIPAA?

2FA adds an extra layer of protection by requiring users to provide additional verification beyond a password. It ensures that even if a password is compromised, unauthorized access to sensitive information is significantly more difficult. In our digital world, 2FA is commonplace for various online activities. To meet compliance with HIPAA, it is crucial for healthcare organizations to extend this security measure to protect ePHI.

Does HIPAA require 2FA?

HIPAA does not explicitly mandate two-factor authentication (2FA). However, if a Covered Entity or Business Associate assesses potential risks and discovers vulnerabilities that could be mitigated through 2FA, it becomes a recommended security measure aligned with the Security Standards for Workforce Security and Information Access Management. In the simplest terms, 2FA is a very effective measure for the protection of ePHI under HIPAA.

HIPAA checklist

For healthcare organizations, the below checklist is a good test of security best practice in relation to the use of email and file transfer services:

How to comply with HIPAA

In an increasingly interconnected world, healthcare organizations must go beyond the most basic requirements of HIPAA to meet compliance. Instead, covered entities must delve deeper, and examine and reevaluate the solutions they have in place for safeguarding sensitive data. Covered Entities cannot rely solely on transport layer security to protect ePHI. Solutions must ensure emails are protected in transit and at rest with advanced encryption, advanced key-management practices, and tools to prevent human error. The use of 2FA is integral for protecting against the threats and vulnerabilities within email systems. In fact, 2FA not only enhances data security, but reinforces an organization's commitment to safeguarding sensitive patient information. It is important to remember that HIPAA compliance is a multifaceted effort and requires a comprehensive approach. While 2FA is not explicitly mandated by HIPAA, it aligns with the evolving expectations for data protection in the digital landscape. Consultation with legal and compliance experts is advised to ensure full compliance with all relevant HIPAA provisions and to implement robust security measures to protect PHI effectively.