Tunitas Group Seminar Notes:
Details of the HIPAA Mandated Security Standards
 
Session Topics
Legislative Background and Intent

Health Insurance Portability and Accountability Act of 1996

  • Administrative Simplification Provisions
  • Health Care Transaction Standards
  • Unique Health Identifiers
  • Further Protection for Confidentiality of Electronic Health Records
  • Confidentiality of Electronic Health Records - HHS Recommendations
  • Security Provisions contained within the Act - Agenda
  • HIPAA Security Provisions - Legislative Intent
  • HIPAA Security Provisions - Applicability and Scope
  • HIPAA Security Provisions - Time Table
  • HIPAA Security Provisions - Enforcement
  • Security Regulations - HCFA's General Approach
  • Overall Security Management
     
  • Requirement for a formal security management process that includes:
  • Requirement that security be an assigned responsibility
  • Requirement for Security Certification
  • Requirement for Formal Mechanism of Processing Records
  • Requirement for Security Incident Procedures
  • Requirements for Specific Protections
     
  • HIPAA Security Matrix
  •  Schema for specific implementation requirements:
  • Security Regulations - Environmental Threats
  • Security Regulations - Personnel Threats
  • Security Regulations - Technological Threats to Enterprise Systems and Data
  • Security Regulations - Network Communications
  • Communication of Health Data - Politics and the HCFA View
  • Security Regulations - Electronic Signature
    Issues for the Small Provider
    Planning for Compliance - Next Steps
    Information Resources
    Copyright 1998 Tunitas Group.   All rights reserved.                                     October 10, 1998