- Home
- » e-Newsletters
Tip: Play it safe, encrypt "data at rest"
EHR Connection, December 24, 2007
"Data at rest," which includes any stored data, usually held on a server, hard drive, or portable device, such as laptop computers, PDAs, smart phones, USB flash drives, CDs, DVDs, and floppy disks, is vulnerable if unencrypted.
Protect your facility and your patients' privacy with this six-step approach:
- Identify your data and determine its location with an inventory of all facility equipment.
- Conduct a systemwide risk assessment of your data to determine areas of weakness and need.
- Develop a policy that clearly states who can access data remotely and what data may be stored on portable devices.
- Implement technical mechanisms that require encryption and ensure that your IT department develops standards for encrypting all types of data in use at your facility.
- Develop a security incident response plan that clearly states how your organization will respond if a security breach involving lost data occurs.
- Know what applicable state laws require. Information about state notification laws is available at www.ncsl.org/programs/lis/CIP/priv/breach07.htm.
This tip was brought to you by the December issue of Briefings on HIPAA.
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- What does case-mix index mean to you?
- Capturing all necessary codes for IUD insertion and removal can be challenging
- QA:Coding multiple initial infusions
- News and briefs: Oklahoma Osteopathic Association against residency bill change
- HIPAA Q&A: Level of encryption needed for email
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- Q&A tackles coding questions about injections and infusions
- Joint Commission Center announces handoff communication solutions
- Inside best practice: Reduce patient falls with a stoplight
- Identify modifiable risk factors to prevent patient falls
- Searched