Manage EHR access and audit controls
HIM-HIPAA Insider, May 8, 2012
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
HIPAA requires covered entities (CEs) to implement technical policies and procedures for electronic information systems that limit access to electronic protected health information (ePHI) only to those persons or software programs that have been granted access rights [§164.312(a)] as specified in the administrative safeguards under access authorization, establishment, and modification [§164.308(a)(4)].
Implementation specifications include the requirement for unique user identification and an emergency access procedure. The specifications also address automatic logoff and encryption/decryption of data retained in systems.
Access controls should be consistent with the requirements for minimum necessary use [§164.512(d)(2)(i)]. CEs should identify the persons or classes of persons, as appropriate, in the workforce who need access to PHI to carry out their duties. For each such person or class of persons, CEs must identify the category or categories of PHI to which access is needed and any conditions appropriate to such access are identified.
This article was adapted from the April edition of Medical Records Briefings. Purchase the entire article.
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
Related Products
Most Popular
- Articles
-
- Note from Hugh
- CMS seeks comment on quality measures
- Note from the instructor: OIG report on usage of financial liability "G" modifiers
- Recent Recovery Auditor activity
- The week in Medicare updates
- Remind your workforce members to ’zip their lips’ when it comes to patient privacy
- CMS releases new QAPI resources
- HIPAA Q&A: Receiving faxed HEDIS requests
- Documentation of medical necessity drives successful RA appeals
- Shorter work week for interns may compromise patient safety
- E-mailed
-
- Note from the instructor: OIG report on usage of financial liability "G" modifiers
- Q/A: How do we report therapy G codes and modifiers for multiple therapies?
- HIPAA Q&A: Receiving faxed HEDIS requests
- CMS says it's not too late to avoid payment adjustments
- FDA makes new proposal related to C. diff and other threatening pathogens
- Shorter work week for interns may compromise patient safety
- Tip: Understand the three-day rule
- CMS releases new ICD-10 FAQs
- Demand a code for demand myocardial infarction
- Eyes see more ICD-10-CM codes because of laterality
- Searched
