Key Provisions of the Proposed
HIPAA Security & Electronic Signature Standards

 

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) created a mandate on the US Department of Health and Human Services (HHS) to adopt many new standards for this nation's health information system and to facilitate administrative simplification. Recently, a Notice of Proposed Rulemaking (NPRM) was issued pursuant to the HIPAA requirements for security of health information. Below is a brief outline of the NPRM's key provisions.

Applicability:

These standards must be followed in all electronic health data transmissions. In addition, the security provisions apply to all electronic health data which is maintained (i.e., held by providers - even if not transmitted to other parties electronically).

Entities affected:
Department of Health and Human Services
Health Plans
Health Information Clearinghouses
Providers

Concept & Approach:
Comprehensive
Technology-Neutral
Scalable
Defines a set of requirements - but is not prescriptive of implementation choices

Security Standards:

Type of Standard: Requirement (partial list): Implementation (examples):
Administrative Procedures Internal audit  
  Information access control Access authorization, establishment & modification Evaluation/Certification of computer system security
  Contingency planing Application & data criticality analysis, Data backup plan, Disaster recovery plan, Emergency mode operation plan, Testing & revision
  Chain of trust partner agreement  
  Formal mechanism for processing records  
  Personnel security Clearance procedure, Supervision, Training, etc.
  Termination procedures Locks changed, etc.
  Training Awareness training, Periodic security reminders, etc.
Physical Safeguards Media controls Data backup & storage, Disposal
  Physical access controls Disaster recovery, Facility security plan, Maintenance records
  Work station usage  
Technical Security Services Access control Procedure for emergency access; Context-, Role- and/or User-based access; Encryption
  Audit controls  
  Authorization control Role- or User-based access
  Data authentication  
  Entity authentication Automatic logoff, Biometric, Password, PIN, Telphone callback, Token, Unique user identification
Technical Security Mechanisms Communications/network controls Access controls, Alarm, Audit trail, Encryption, Integrity controls, Message authentication

Electronic Signature Standard:

If an entity chooses to utilize an electronic signature, a cryptologically based digital signature will be required. Its attributes must include:
Message integrity
Non-repudiation
User authentication

It is desirable if the signature also allows:
Ability to add attributes
Continuity of signature capability
Countersignatures
Independent verifiability
Interoperability
Multiple signature
Transportability

What the Security & Electronic Signature Standards mean to states:

The Standards are applicable to the states in their role as health care providers and/or health plans. In particular, meeting the Electronic Signature standard will meet all federal and state statutory requirements for written signatures - in these transactions.

Effects on individual states will vary based the implementation choices which have been made for Medicaid and other state-administered health care plans, as well as the states' information collection practices generally.