Call Us Today! 877-659-2467

What does “Recognized Security Practices” mean?

HIPAA Compliance made easy

We have talked in the past about the Office for Civil Rights conducting a minimum of a 12 month look back for data security/ HIPAA compliance efforts. If an organization suffers a breach, with proper documentation fines may be waived. This is known as “Recognized Security Practices”. Every organization will have different documentation based on their network configuration and how data flows in and out of your information systems. This isn’t really anything new since data security requirements have been in place since the Security Rule was enacted. There have been updates over the last few years, and they are making some new revisions requiring covered entities and business associates to document their efforts now more than ever. NIST SP800-66 Rev. 2

This includes ensuring your policies and procedures are documented and followed by your staff. Our online system makes this task must easier by enabling the HIPAA compliance officer to download and share certain policies for employees to review. Plus, the confidentiality and acceptable use agreement that is signed via DocuSign demonstrates you have advised your employees they must follow your policies and procedures.

Another part of this documentation should be reports from your IT department/vendor. Again, depending on how you access ePHI (electronic protected health information), reports will vary from practice to practice. Some suggested reports are:

  1. Managed devices. You can use this as your inventory list instead of completing the list in your package. However, we still recommend documenting which devices have been used to access and/or store ePHI.
  2. In the report above, this may contain operating systems, patches / updates that have been applied, IP addresses, User ID, and a device name. All of this is useful information, and if the report does not contain this information, you need to look for another report.
  3. Software lists are very important since you can see if any employee has downloaded unauthorized software or if a computer has been compromised.
  4. Device health reports typically include information on anti-virus, last log in, some record failed logins, or that is in a different report. These are must have reports.
  5. Access logs may be located within the software the IT vendor utilizes to manage your network, within your domain controller, and within your EHR/PM software. These reports must be reviewed to ensure employees are only accessing ePHI based on their job function and to look for outside intrusions.
  6. Backup reports should demonstrate when backups are performed and to ensure they are successful.
  7. Summary reports are useful, but you must make sure you review them, and they can be lengthy.

There are times when certain devices cannot be updated or upgraded due to the nature of the equipment and the cost to do so. This would not necessarily be a violation if you demonstrate other means to protect your system. For example, either removing the outdated equipment from internet access or placing it on a separate network so it would not be accessible by other drives that contain ePHI. Your IT vendor should be able to guide you through the proper process based on your particular network.

Annual audits by a third party are highly recommended unless your IT vendor specializes in network security. Often, these two types of companies work well together. The IT vendor handles the day-to-day operations, and the network security companies hardens the systems.

Some organizations complain that this costs too much money. Trust me, this is much less expensive than a data breach. Plus, if you plan on obtaining cyber liability insurance, carriers are now asking detailed questions about data security and compliance efforts. If you do have a data breach and you do not have “qualified documentation”, your claim could be denied. Of course, the term “qualified documentation” is open to interpretation. They do have an outlandish wish list from what I have seen. Although I have always been a proponent of this insurance, I am starting to believe unless you already have a policy, you may not be able to obtain one. If you do apply now, you will need to have HEAVY data security in place. Which you should have anyway!

To find out more about how our online HIPAA Keeper™ can help your organization with HIPAA Compliance click here:

https://arismedicalsolutions.com/aris-hipaa-compliance-system-for-medical-offices/

Or to schedule a demo click the contact us tab and scroll down.

“Simplifying HIPAA through Automation, Education, and Support”

About Suze Shaffer

Suze Shaffer is the Owner and President of Aris Medical Solutions, a healthcare compliance company dedicated to simplifying HIPAA compliance. Through its online compliance solution, the HIPAA Keeper™, Aris Medical Solutions provides healthcare providers and business associates with the tools, documentation, training, and expert guidance needed to achieve and maintain HIPAA compliance.

Through the HIPAA Keeper™, Aris has assisted organizations nationwide with conducting risk analyses, developing risk management plans, implementing HIPAA Privacy and Security policies and procedures, and strengthening safeguards for protected health information. Aris Medical Solutions also considers applicable federal and state privacy and security requirements to help clients build a more comprehensive compliance program.

Suze is also a speaker and has presented at numerous conferences and professional events on HIPAA compliance, cybersecurity, risk management, and data breach prevention. Helping organizations understand their responsibilities and identify vulnerabilities before they result in a breach, audit, or investigation. She believes effective compliance begins with education. By helping organizations understand not only what they are required to do, but why those safeguards are important, organizations are better prepared to protect patient information and reduce their compliance risks.

At Aris Medical Solutions, the mission is simple: “Simplifying HIPAA” through education, expert guidance, and the HIPAA Keeper™, Aris Medical Solutions helps organizations turn complicated compliance requirements into a manageable, ongoing process.

The information provided reflects regulatory requirements and guidance available at the time of writing and is intended for educational purposes only. It should not be considered legal advice.

Share This HIPAA Blog

How to protect your organization from phishing attacks

May 2, 2022

Why it is so important to secure emails that contain PHI

July 5, 2022
©2026 Aris Medical Solutions – HIPAA Risk Management | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC