Beginning on February 18, HHS will have the legal authority to enforce the breach notification laws set forth last year as part of section 13402 of the HITECH Act, within the American Recovery & Reinvestment Act (ARRA). The penalties can now be up to $1.5 million and require media notification in cases where 500 or more records are breached. Business associates, as well as covered entities, must now comply with the HITECH Act breach notification rule (which essentially makes modifications to the HIPAA Security Rule).
- Perform an extensive security review and indentify where electronic protected health information (PHI or ePHI) resides on your IT systems.
- Create a plan on protecting PHI.
- Data encryption provides a safe harbor from breach notification. Determine where PHI can be encrypted.
- Identify public facing extranet portals and web applications that can allow access to PHI.
- Identify databases that hold PHI.
- Execute the plan
- Implement data encryption where practical.
- For databases, implement a database security product to monitor database requests and protect from intrusion.
- For web apps, implement a web application security product to protect from cross-site scripting and various attacks to access databases to PHI.
- Protect endpoints such as laptops, tablets, etc with data at rest encryption by implementing whole disk encryption,
Experior Data helps customers plan and execute data security assessments and technology implementation for healthcare. Our proprietary Technical Security Audit includes a personalized review of your IT systems and well as a vulnerability scan of all your network components.
Related articles by Zemanta
- HITECH Act security breach rules now effective; federales give a six-month pass. Now’s the time to kick compliance efforts into high gear (healthblawg.typepad.com)
- HITECH and State Breach Notification (slideshare.net)
- Using Encryption Garners Exemption For Data Breach Notification (yro.slashdot.org)
- Son of HIPAA Breach Notification Rules and Business Associate Requirements: Who’s Ready? (healthblawg.typepad.com)
- The Cost of Fear | Why Docs Don’t Embrace Technology (Dr. Rob) (hunscher.typepad.com)
- PGP Corporation to Announce Acquisition (newswire.ca)



![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=3a0266f6-3270-43a7-9d5d-72d3000b6dd6)
- Encrypt and decrypt health information for backups, removable media, etc.





![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=6e87899c-e6e7-4f3a-9683-3d2ac9ec511b)
![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=7993140a-f705-4f45-909d-e89dd1de5bd5)

![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=caa87e61-a76d-48bd-b1f5-285d46a2e078)

![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=ddb01d91-1efe-4f93-ba81-d409929f5e90)
![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=0f8109dd-4181-4d3b-a3fb-759163ab8308)

![Reblog this post [with Zemanta]](http://img.zemanta.com/reblog_e.png?x-id=f109c045-b7ee-4c5f-b033-6660b8cf7572)
