The security rule includes the "password management" implementation specification. Will that help me make my case that passwords should change periodically?
HIPAA Weekly Advisor, July 12, 2004
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Actually, that specification refers to training workforce members in topics such as how to make up good passwords and keep them secret. But your policy and standard fall under the technical "authentication" requirement.
If you depend on passwords to authenticate your ePHI users, strive to meet good practices including periodic password change. Common standards for end-user password change intervals are 60 days, 90 days, or even 180 days. Information security professionals agree it is risky to permit passwords (when used as single factor authentication) never to expire.
Editor's Note: This question was answered by Kate Borten, CISSP, CISM, president and founder of The Marblehead Group, Inc., a national security and privacy consulting firm focusing on the healthcare industry.
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- HIPAA Q&A: Level of encryption needed for email
- What does case-mix index mean to you?
- QA:Coding multiple initial infusions
- News and briefs: Oklahoma Osteopathic Association against residency bill change
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HIPAA Q&A: Level of encryption needed for email
- CMS has reformulated payments for some bilateral procedures
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q&A: Follow CMS' coding guidelines when using modifier -25
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- ED-to-inpatient transfers are flawed with safety gaps
- Searched