Welcome, Guest | Sign in

HIPAA:
  • About HIPAA

    The U.S. Health Insurance Portability and Accountability Act (HIPAA) of 1996, provides a set of instructions and guidelines for the encoding, privacy, security, integrity and availability of patient health data. HIPAA provides guidance in the selection and implementation of software packages for tracking client data. HIPPA security standard is divided into following categories:


    • Administrative Procedures
    • Physical Safeguards
    • Technical Data Security Services
    • Technical Security Mechanisms


  • Need for HIPAA

    HIPAA is to be enacted to standardize the secure transmission of billing information. If a system handles billing as well as client tracking, you certainly should ensure that your system supports these HIPAA standards. Automation, secure transaction, Privacy are expected to result in administrative efficiency.


    E-billing is slowly addressing security issues on their internal network. Hackers were able to hijack the company's Web sites by stealing the user name and password needed to make account changes at the Web site of Network Solutions.


    HIPAA applies to any organization that transmits any electronic billing information such as invoices, or information needed to look up insurance information to any health insurance company, including Medicare or Medicaid. This means that HIPAA typically regulates organizations providing counseling, therapy or other services that need to bill insurance companies.


    If you conduct any billing-related electronic communications with insurance companies, then all your data, processes, and systems throughout the organization are subject to the HIPAA guidelines, even if you bill only for one program or a few.


  • How HIPAA reduces risk?

    The 2009 American Recovery and Reinvestment Act (ARRA), includes a section called the Health Information Technology for Economic and Clinical Health (HITECH) Act. The HITECH Act adopts "electronic health records" (EHRs) to improve efficiency and lower healthcare costs. Due to the increase in privacy and security risks, the HITECH Act introduced new security and privacy related requirements for business associates under HIPAA.


    The fines for non-compliance with the HIPAA privacy rule have increased significantly with the introduction of the HITECH Act. An organization can now be fined up to $1,500,000 per calendar year for each violation.


  • IT & HIPPA

    Security standards apply to the protection of electronically stored or transmitted information from corruption by viruses or theft by hackers or sending PHI on unsecured channels. The security standards are not intended to address how paper information is stored. They mandate safeguards for physical storage maintenance, protection, and access to individual health information.


    Access to equipment containing useful information should be carefully controlled and monitored. Permission to access hardware and software must be limited to authorized individuals. Access controls must consist of security plans, maintenance records, and visitor sign-in and escorts. Workstations should be removed from high traffic areas and monitor screens should not be in direct view of the public. If the covered entities utilize contractors or agents, they too must be fully trained on their physical access responsibilities. Automated security updates are another feature that could be used to help limit the scope of security threats.


  • To follow HIPAA Standard IT have to do the following:

    Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights.


    Implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.


    Implement policies and procedures to protect electronic protected health information from improper alteration or destruction.


    Implement procedures to verify that a person or entity seeking access to electronic protected health information is the authorised one .


  • How we met HIPAA compliance requirements?

    Audit Control

    *Our Active Directory Solutions can manage and help organizations to gather information for regulatory audits. Administrative efficiency and quality can also be maintained. More than 150 out of box reports can be generated which inturn makes the audit more effective.


    *Bulk Management : JiJi AD Manager helps to save administrators time by making AD Management process simple

    Access control

    *Security Reports : User access report across entire network can be obtained. It is met through generating Security Reports.


    *Invalid Logon attempts: Recently Bad Logged on Users Report is used to find illegal logon attempt. This report generates the list of all users who tried to logon with bad password. Thus integrity and Entity authentication can be achieved.


    *Account Lockout: Use Account Lockout Policy Report to view details of locked out account, whenever invalid credentials are provided to access the account.


    *Inactive Users or Computers: Inactive Users or Computers reports are obtained based on last logon time to avoid illegal access.


    Privacy and security

    * Password Expiration Auditing: To ensure privacy and security, automatic checking of AD and reporting password and account expiry status message is necessary. Such an auditing can be done using JiJi Password and Account Expiration Notification Tool.


    * Secure password:Users have to reset their own passwords to avoid password attacks. Strong and secure password is achieved through JiJi Self Service Password Reset. Using Password Policy Reports, details of Default Domain Policy and Fine Grained Password Policies in Active directory can be obtained.


    * Cleanup directory:JiJi Active Directory Cleaner cleans up the unwanted users to maintain security.