• Home
  • Practice Focus
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
    • How I Do It
    • TRIO Best Practices
  • Business of Medicine
    • Health Policy
    • Legal Matters
    • Practice Management
    • Tech Talk
    • AI
  • Literature Reviews
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Career
    • Medical Education
    • Professional Development
    • Resident Focus
  • ENT Perspectives
    • ENT Expressions
    • Everyday Ethics
    • From TRIO
    • The Great Debate
    • Letter From the Editor
    • Rx: Wellness
    • The Voice
    • Viewpoint
  • TRIO Resources
    • Triological Society
    • The Laryngoscope
    • Laryngoscope Investigative Otolaryngology
    • TRIO Combined Sections Meetings
    • COSM
    • Related Otolaryngology Events
  • Search

Why HIPAA, Protected Health Information Cybersecurity Best Practices Are Critical in COVID-19 Era

by Steven M. Harris, Esq. • October 19, 2021

  • Tweet
  • Click to email a link to a friend (Opens in new window) Email
Print-Friendly Version

Organizations have flexibility, particularly with the addressable requirements, in how they implement these security protocols. These addressable concerns are particularly important in the COVID-19 era given the rise in the use of telehealth.

You Might Also Like

  • Avoid Data Breaches, HIPAA Violations When Posting Patients’ Health Information Online
  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Senate Bill Targets Medical Device Cybersecurity
  • Internal Due Diligence Review Critical for Physician Practices
Explore This Issue
October 2021

When calculating fines related to a breach, HHS is required to take cybersecurity into consideration and also reduce the extent and length of an audit if the entity being investigated has met industry-standard best practices security requirements. HHS is not permitted to increase fines or the length of an audit when an entity is found to be out of compliance with recognized security practices, however.

“Recognized security practices” means standards, guidelines, best practices, methodologies, procedures, and processes developed under the National Institute of Standards and Technology (NIST) Act, the Cybersecurity Act of 2015, and other programs, processes, or regulations that address cybersecurity now or in the future.

Starting earlier this year, HHS Office for Civil Rights investigators began routinely requesting information regarding a covered entity’s implementation of recognized security practices. Having such practices in place may be the key to avoiding hefty fines or penalties in the event of a breach.

Physical Access Protocols and Document Security

Another best practice is to ensure that physical security and document storage policies are up to date. To ensure that patient records are physically secure, organizations must ensure that their facilities are protected through office and warehouse entry control monitoring systems, cubicle and office security, and electronic device protocols.

Additionally, access validation systems (e.g., identification badges and scanned key cards) provide an additional layer of security to protect facilities from unwanted visitors. In the DHS HIPAA Security Information Series program on security standards and physical safeguards, a number of best practices are mentioned:

  • Locked doors, signs warning of restricted areas, surveillance cameras, and alarms;
  • Property controls, such as property control tags and engraving on equipment;
  • Personnel controls, such as identification badges, visitor badges, and/or escorts for large offices; and
  • Private security service or patrol for the facility.

Although some of the security measures above appear to be standard, such as locked doors, all are prone to decay and underuse. The best practice is to ensure that employees are routinely trained on the importance of carrying identification, locking doors, and remembering to validate individuals attempting to enter a company’s physical space.

Further, employees may be compelled to cheat some of these safeguards for ease, such as failing to lock documents securely between visits to the file room. The best practice is to enforce physical security measures commensurate with their importance and, as such, implement disciplinary policies for those who fail to adhere to company policies.

Pages: 1 2 3 4 | Single Page

Filed Under: Departments, Legal Matters Tagged With: COVID19, cybersecurityIssue: October 2021

You Might Also Like:

  • Avoid Data Breaches, HIPAA Violations When Posting Patients’ Health Information Online
  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Senate Bill Targets Medical Device Cybersecurity
  • Internal Due Diligence Review Critical for Physician Practices

The Triological SocietyENTtoday is a publication of The Triological Society.

Polls

Would you choose a concierge physician as your PCP?

View Results

Loading ... Loading ...
  • Polls Archive

Top Articles for Residents

  • Applications Open for Resident Members of ENTtoday Edit Board
  • How To Provide Helpful Feedback To Residents
  • Call for Resident Bowl Questions
  • New Standardized Otolaryngology Curriculum Launching July 1 Should Be Valuable Resource For Physicians Around The World
  • Do Training Programs Give Otolaryngology Residents the Necessary Tools to Do Productive Research?
  • Popular this Week
  • Most Popular
  • Most Recent
    • A Journey Through Pay Inequity: A Physician’s Firsthand Account

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Complications for When Physicians Change a Maiden Name

    • Excitement Around Gene Therapy for Hearing Restoration
    • “Small” Acts of Kindness
    • How To: Endoscopic Total Maxillectomy Without Facial Skin Incision
    • Science Communities Must Speak Out When Policies Threaten Health and Safety
    • Observation Most Cost-Effective in Addressing AECRS in Absence of Bacterial Infection

Follow Us

  • Contact Us
  • About Us
  • Advertise
  • The Triological Society
  • The Laryngoscope
  • Laryngoscope Investigative Otolaryngology
  • Privacy Policy
  • Terms of Use
  • Cookies

Wiley

Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1559-4939