The Health Insurance Portability and Accountability Act of 1996 (HIPAA) created a mandate on the US Department of Health and Human Services (HHS) to adopt many new standards for this nation's health information system and to facilitate administrative simplification. Recently, a Notice of Proposed Rulemaking (NPRM) was issued pursuant to the HIPAA requirements for security of health information. Below is a brief outline of the NPRM's key provisions.
Applicability:
These standards must be followed in all electronic health data transmissions. In addition, the security provisions apply to all electronic health data which is maintained (i.e., held by providers - even if not transmitted to other parties electronically).
Entities affected:
| Department of Health and Human Services | |
| Health Plans | |
| Health Information Clearinghouses | |
| Providers |
Concept & Approach:
| Comprehensive | |
| Technology-Neutral | |
| Scalable | |
| Defines a set of requirements - but is not prescriptive of implementation choices |
Security Standards:
| Type of Standard: | Requirement (partial list): | Implementation (examples): |
| Administrative Procedures | Internal audit | |
| Information access control | Access authorization, establishment & modification Evaluation/Certification of computer system security | |
| Contingency planing | Application & data criticality analysis, Data backup plan, Disaster recovery plan, Emergency mode operation plan, Testing & revision | |
| Chain of trust partner agreement | ||
| Formal mechanism for processing records | ||
| Personnel security | Clearance procedure, Supervision, Training, etc. | |
| Termination procedures | Locks changed, etc. | |
| Training | Awareness training, Periodic security reminders, etc. | |
| Physical Safeguards | Media controls | Data backup & storage, Disposal |
| Physical access controls | Disaster recovery, Facility security plan, Maintenance records | |
| Work station usage | ||
| Technical Security Services | Access control | Procedure for emergency access; Context-, Role- and/or User-based access; Encryption |
| Audit controls | ||
| Authorization control | Role- or User-based access | |
| Data authentication | ||
| Entity authentication | Automatic logoff, Biometric, Password, PIN, Telphone callback, Token, Unique user identification | |
| Technical Security Mechanisms | Communications/network controls | Access controls, Alarm, Audit trail, Encryption, Integrity controls, Message authentication |
Electronic Signature Standard:
If an entity chooses to utilize an electronic signature, a cryptologically based digital signature will be required. Its attributes must include:
| Message integrity | |
| Non-repudiation | |
| User authentication |
It is desirable if the signature also allows:
| Ability to add attributes | |
| Continuity of signature capability | |
| Countersignatures | |
| Independent verifiability | |
| Interoperability | |
| Multiple signature | |
| Transportability |
What the Security & Electronic Signature Standards mean to states:
The Standards are applicable to the states in their role as health care providers and/or health plans. In particular, meeting the Electronic Signature standard will meet all federal and state statutory requirements for written signatures - in these transactions.
Effects on individual states will vary based the implementation choices which have been made for Medicaid and other state-administered health care plans, as well as the states' information collection practices generally.