By IT Brew Staff
less than 3 min read
Definition:
From an IT perspective, HIPAA means that IT teams handling protected health information (PHI) must implement security measures to protect that data from unauthorized access. In broad strokes, those measures can include:
- Physical: This includes locking down PCs and workstations where users can access sensitive patient data, but can extend to procedures such as safely disposing of devices like hard drives that contain PHI.
- Administrative: Proper employee training for handling PHI is vital.
- Technical: IT teams must restrict PHI access via two-factor authentication, encrypted transmission, and other techniques, in addition to regularly auditing their security procedures to ensure compliance.
There’s also a significant element of disaster planning in a successful HIPAA implementation. For example, entities that handle PHI must have policies and procedures in place to respond to cyberattacks and mitigate the damage related to data leaks. They also need to implement contingency plans for emergencies and other incidents that might result in PHI destruction (such as a natural disaster destroying hard drives containing patient data).
For cybersecurity professionals who work with healthcare companies and other entities that deal with sensitive patient data, complying with HIPAA requires conducting regular risk assessments, implementing the aforementioned technical safeguards and incident response plans, and informing staff about compliance and best practices. The consequences of failing to protect this data are high, with civil and criminal penalties that could break budgets and even land violators in jail.