Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.
In this lesson, we will go through some essential HIPAA definitions and core terms to help you better understand the law, including encryption standards, business associate liabilities, and risk assessment structures.
All ePHI should be encrypted at rest and in transit wherever reasonable and appropriate. "Reasonable and appropriate" is not a matter of opinion; it refers to what a careful organization of your size, resources, and risk level would do to protect data. If encryption is not feasible, the reason must be documented and an equivalent safeguard implemented instead.
A Business Associate is any individual or entity that supports the healthcare industry and performs functions on behalf of a covered entity. Under HITECH regulations, business associates must comply directly with HITECH rules and assume financial liability for data breaches caused by their organization or employees.
Business associates are required to maintain:
A Risk Assessment consists of government-mandated questions to identify potential security gaps and risk levels. It requires a corresponding risk report featuring a clear roadmap to resolution. Questionnaires cover three main domains (Administrative, Technical, and Physical) and utilize three implementation levels:
Pro Tip #1: A Book of Evidence is your customized set of written policies and procedures explaining how your organization manages PHI and ePHI, including data breach notification protocols, disaster recovery, and privacy policies.
Pro Tip #2: Covered entities must provide patients with a copy of their Privacy Policy upon request. Business associates must make their privacy policies available to internal employees, downstream suppliers, and government auditors.