Corporate Compliance

Tip: Ensure integrity of electronic information

Healthcare Auditing Weekly, February 26, 2007

HIPAA includes an integrity standard to ensure that electronic protected health information is protected, stored, and transmitted securely, using safe and secure software applications. Your organization's information security officials (ISO) should develop and perform the following activities to ensure information integrity:

  1. Review authentication policies, procedures, and tools against HIPAA standards, industry best practices, and the applications and data criticality analysis to ensure that the most appropriate practices are being required. The ISO should do this annually and whenever a new application is implemented.
  2. On a quarterly, random basis, apply a password cracker to detect weak password.
  3. Conduct facility walkthroughs annually to look for passwords.
  4. Review active account lists bimonthly against usage logs to determine that access termination has occurred and that password expiration is set appropriately.

    Strategies for Health Care Compliance
  • Strategies for Health Care Compliance

    News and real-life examples to increase the effectiveness of your compliance program. Strategies for Health Care Compliance...

  • Compliance Monitor

    This HTML e-mail newsletter delivers news on Medicare and Medicaid fraud and abuse, as well as recent documents and targets...

  • Medicare Weekly Update

    Each issue of Medicare Weekly Update includes the latest CMS proposed and final rules, CMS manual revisions, and...

  • Medicare Update for Physician Services

    Medicare Update for Physician Services is a free, monthly e-zine that delivers news and information to help physician...

Most Popular

Related Articles