Citations: HIPAA Security Rule

No citations match the current filters.
SS.164.306
SNow
Reference: HSR.001
Security Standard (SS): Ensures the confidentiality, integrity, and availability of all electronically protected health information.
SS.164.306.a1
SNow
Reference: HSR.002
General Requirements: Ensure the confidentiality, integrity, and availability of all electronic protected health information the covered entity or business associate creates, receives, maintains, or transmits.
SS.164.306.a2
SNow
Reference: HSR.003
Additional Requirements: Protect against any reasonably anticipated threats or hazards to the security or integrity of such information.
SS.164.306.b2
SNow
Reference: HSR.004
Used Security Measures: The size, complexity, and capabilities of the covered entity or business associate.
AS.164.308
SNow
Reference: HSR.005
Administrative Safeguards (AS): Defines administrative actions to manage the selection, development, implementation, and maintenance to protect electronic PHI.
AS.164.308.a1-i
SNow
Reference: HSR.006
Security Management Process: Implement policies and procedures to prevent, detect, contain, and correct security violations
AS.164.308.a1-ii-a
SNow
Reference: HSR.007
Risk Analysis: Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.
AS.164.308.a1-ii-b
SNow
Reference: HSR.008
Risk Management: Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with §164.306(a).
AS.164.308.a1-ii-d
SNow
Reference: HSR.009
Information System Activity Review: Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.
AS.164.308.a2
SNow
Reference: HSR.010
Assigned Security Responsibility: Identify the security official who is responsible for the development and implementation of the policies and procedures required by this subpart for the covered entity or business associate.
AS.164.308.a3-i
SNow
Reference: HSR.011
Workforce Security: Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information, as provided under paragraph (a)(4) of this section, and to prevent those workforce members who do not have access under paragraph (a)(
AS.164.308.a3-ii-a
SNow
Reference: HSR.012
Authorization and/or Supervision: Implement procedures for the authorization and/or supervision of workforce members who work with electronic protected health information or in locations where it might be accessed.
AS.164.308.a3-ii-b
SNow
Reference: HSR.013
Workforce Clearance Procedure: Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate.
AS.164.308.a3-ii-c
SNow
Reference: HSR.014
Establish Termination Procedures: Implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends or as required by determinations made as specified in paragraph (a)(3)(ii)(b).
AS.164.308.a4-i
SNow
Reference: HSR.015
Information Access Management: Implement policies and procedures for authorizing access to electronic protected health information that are consistent with the applicable requirements of subpart E of this part.
AS.164.308.a4-ii-b
SNow
Reference: HSR.016
Access Authorization: Implement policies and procedures for granting access to electronic protected health information, for example, through access to a workstation, transaction, program, process, or other mechanism.
AS.164.308.a4-ii-c
SNow
Reference: HSR.017
Access Establishment and Modification: Implement policies and procedures that, based upon the covered entity's or the business associate's access authorization policies, establish, document, review, and modify a user's right of access to a workstation, transaction, program, or process.
AS.164.308.a5-i
SNow
Reference: HSR.018
Security Awareness and Training: Implement a security awareness and training program for all members of its workforce (including management).
AS.164.308.a5-ii-a
SNow
Reference: HSR.019
Security Reminders: Periodic security updates.
AS.164.308.a5-ii-b
SNow
Reference: HSR.020
Protection from Malicious Software: Procedures for guarding against, detecting, and reporting malicious software.
AS.164.308.a5-ii-c
SNow
Reference: HSR.021
Log-In Monitoring: Procedures for monitoring log-in attempts and reporting discrepancies.
AS.164.308.a5-ii-d
SNow
Reference: HSR.022
Password Management: Procedures for creating, changing, and safeguarding passwords.
AS.164.308.a6-i
SNow
Reference: HSR.023
Security Incident Procedures: Implement policies and procedures to address security incidents.
AS.164.308.a6-ii
SNow
Reference: HSR.024
Response and Reporting: Identify and respond to suspected or known security incidents; mitigate, to the extent practicable, harmful effects of security incidents that are known to the covered entity or business associate; and document security incidents and their outcomes.
AS.164.308.a7-i
SNow
Reference: HSR.025
Contingency Plan: Establish (and implement as needed) policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, and natural disaster) that damages systems that contain electronic protected health information.
AS.164.308.a7-ii-a
SNow
Reference: HSR.026
Data Backup Plan: Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information.
AS.164.308.a7-ii-b
SNow
Reference: HSR.027
Disaster Recovery Plan: Establish (and implement as needed) procedures to restore any loss of data.
AS.164.308.a7-ii-c
SNow
Reference: HSR.028
Emergency Mode Operation Plan: Establish (and implement as needed) procedures to enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode.
AS.164.308.a7-ii-d
SNow
Reference: HSR.029
Testing and Revision Procedure: Implement procedures for periodic testing and revision of contingency plans.
AS.164.308.a7-ii-e
SNow
Reference: HSR.030
Application and Data Criticality Analysis: Assess the relative criticality of specific applications and data in support of other contingency plan components.
AS.164.308.a8
SNow
Reference: HSR.031
Evaluation: Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under this rule and subsequently, in response to environmental or operational changes affecting the security of electronic protected health information, which establishes the extent t
AS.164.308.b3
SNow
Reference: HSR.032
Written Contract or Other Arrangement: Document the satisfactory assurances required by paragraph (b)(1) or (b)(2) of this section through a written contract or other arrangement with the business associate that meets the applicable requirements of § 164.314(a).
PS.164.310
SNow
Reference: HSR.033
Physical Safeguards (PS): Physical safeguards are intended to protect a Covered Entity’s or Business Associate’s buildings, equipment, and systems.
PS.164.310.a1
SNow
Reference: HSR.034
Facility Access Controls: Implement policies and procedures to limit physical access to [an entity’s] electronic information systems and the facility or facilities in which they are housed, while ensuring that properly authorized access is allowed.
PS.164.310.a2-i
SNow
Reference: HSR.035
Contingency Operations: Establish (and implement as needed) procedures that allow facility access in support of restoration of lost data under the disaster recovery plan and emergency mode operations plan in the event of an emergency.
PS.164.310.a2-ii
SNow
Reference: HSR.036
Facility Security Plan: Implement policies and procedures to safeguard the facility and the equipment therein from unauthorized physical access, tampering, and theft.
PS.164.310.a2-iii
SNow
Reference: HSR.037
Access Control and Validation Procedures: Implement procedures to control and validate a person’s access to facilities based on their role or function, including visitor control, and control of access to software programs for testing and revision.
PS.164.310.a2-iv
SNow
Reference: HSR.038
Maintain Maintenance Records: Implement policies and procedures to document repairs and modifications to the physical components of a facility which are related to security (for example, hardware, walls, doors, and locks).
PS.164.310.b
SNow
Reference: HSR.039
Workstation Use: Implement policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of a specific workstation or class of workstation that can access electronic protected health
PS.164.310.c
SNow
Reference: HSR.040
Workstation Security: Implement physical safeguards for all workstations that access electronic protected health information, to restrict access to authorized users.
PS.164.310.d1
SNow
Reference: HSR.041
Device and Media Controls: Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information, into and out of a facility, and the movement of these items within the facility.
PS.164.310.d2-i
SNow
Reference: HSR.042
Disposal: Implement policies and procedures to address the final disposition of electronic protected health information and/or the hardware or electronic media on which it is stored.
PS.164.310.d2-ii
SNow
Reference: HSR.043
Media Re-Use: Implement procedures for removal of electronic protected health information from electronic media before the media are made available for re-use.
PS.164.310.d2-iii
SNow
Reference: HSR.044
Accountability: Maintain a record of the movements of hardware and electronic media and any person responsible therefore.
PS.164.310.d2-iv
SNow
Reference: HSR.045
Data Backup and Storage Procedures: Create a retrievable, exact copy of electronic protected health information, when needed, before movement of equipment.
TS.164.312
SNow
Reference: HSR.046
Technical Safegurds (TS): The HIPAA technical safeguards relate to the technology used by Covered Entities and Business Associates.
TS.164.312.a1
SNow
Reference: HSR.047
Access Controls: Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights as specified in § 164.308(a)(4).
TS.164.312.a2-i
SNow
Reference: HSR.048
Unique User Identification: Assign a unique name and/or number for identifying and tracking user identity.
TS.164.312.a2-ii
SNow
Reference: HSR.049
Emergency Access Procedure: Establish (and implement as needed) procedures for obtaining necessary electronic protected health information during an emergency.
TS.164.312.a2-iii
SNow
Reference: HSR.050
Automatic Logoff: Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity.
TS.164.312.a2-iv
SNow
Reference: HSR.051
Encryption and Decryption: Implement a mechanism to encrypt and decrypt electronic protected health information.
TS.164.312.b
SNow
Reference: HSR.052
Audit Controls: Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.
TS.164.312.c1
SNow
Reference: HSR.053
Integrity: Implement policies and procedures to protect electronic protected health information from improper alteration or destruction.
TS.164.312.c2
SNow
Reference: HSR.054
Mechanism to Authenticate ePHI: Implement electronic mechanisms to corroborate that electronic protected health information has not been altered or destroyed in an unauthorized manner.
TS.164.312.d
SNow
Reference: HSR.055
Person or Entity Authentication: Implement procedures to verify that a person or entity seeking access to electronic protected health information is the one claimed.
TS.164.312.e1
SNow
Reference: HSR.056
Transmission Security: Implement technical security measures to guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network.
TS.164.312.e2-i
SNow
Reference: HSR.057
Integrity Controls: Implement security measures to ensure that electronically transmitted electronic protected health information is not improperly modified without detection until disposed of.
TS.164.312.e2-ii
SNow
Reference: HSR.058
Encryption: Implement a mechanism to encrypt electronic protected health information whenever deemed appropriate.
PP.164.316
SNow
Reference: HSR.059
Policies, Procedures and Documentation (PP): Implements reasonable and appropriate policies and procedures.
PP.164.316.a
SNow
Reference: HSR.060
Policies and Procedures: Implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements of this subpart, taking into account those factors specified in §164.306(b)(2)(i), (ii), (iii), and (iv). This standard is not to b
PP.164.316.b1
SNow
Reference: HSR.061
Documentation: Maintain the policies and procedures implemented to comply with this subpart in written (which may be electronic) form. If an action, activity or assessment is required by this subpart to be documented, maintain a written (which may be electronic) record or the action, activity, or a
PP.164.316.b2-i
SNow
Reference: HSR.062
Time Limit: Retain the documentation required by paragraph (b)(1) of this section for 6 years from the date of its creation or the date when it last was in effect, whichever is later.
PP.164.316.b2-ii
SNow
Reference: HSR.063
Availability: Make documentation available to those persons responsible for implementing the procedures to which the documentation pertains.
PP.164.316.b2-iii
SNow
Reference: HSR.064
Updates: Review documentation periodically, and update as needed, in response to environmental or operational changes affecting the security of the electronic protected health information.
Graph Explorer