|
|
HIPAA
» Our HIPAA Initiatives
- HIPAA Compliance Program designed and driven by a cross-functional task force.
- Privacy officer designated for policy implementation, staff training and monitoring associates.
- Security officer designated for policy implementation, security of systems and PHI.
» Staff Education/ Training
- Completed over 1500 man-hours of awareness programs covering all employees.
- Ongoing training and testing programs link HIPAA education to staff reward.
- HIPAA resource directory to update employees on regulations, news and events.
» Privacy
- Every employee signs confidentiality agreement with severe penalties for HIPAA violations.
- Access to applications/databases defined on ‘need to know' and ‘minimum necessary' basis.
- HIPAA compliant procedures under implementation in risk areas like:
* data processing.
* fax and email communication to external agencies.
* information disclosure to payors, patients, family members and others.
* storage, retrieval and/or disposal of reports and physical records.
» Security
- Physical restrictions on access to work area and network center.
- Firewall protection for internal network from the world wide web.
- Enterprise-wide multiple virus protection system.
- 128-bit SSL and data encryption on all web based applications.
- Digital certificate authentication for all servers.
- Each user has unique login, power-on and screensaver passwords.
- Controlled media usage/movement through inventory logs and physical checks.
- User accounts to access shared resources like fax machines and photocopiers.
- Random screening of emails for attachments with PHI.
|