Health Information Management

The security rule includes the "password management" implementation specification. Will that help me make my case that passwords should change periodically?

HIPAA Weekly Advisor, July 12, 2004

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

Actually, that specification refers to training workforce members in topics such as how to make up good passwords and keep them secret. But your policy and standard fall under the technical "authentication" requirement.

If you depend on passwords to authenticate your ePHI users, strive to meet good practices including periodic password change. Common standards for end-user password change intervals are 60 days, 90 days, or even 180 days. Information security professionals agree it is risky to permit passwords (when used as single factor authentication) never to expire.

Editor's Note: This question was answered by Kate Borten, CISSP, CISM, president and founder of The Marblehead Group, Inc., a national security and privacy consulting firm focusing on the healthcare industry.



Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

  • Briefings on APCs

    Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

  • Medical Records Briefing

    Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

  • Briefings on Coding Compliance Strategies

    Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

  • Briefings on HIPAA

    How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

  • APCs Weekly Monitor

    This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

Most Popular

Related Articles