• Home
  • Practice Focus
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
    • How I Do It
    • TRIO Best Practices
  • Business of Medicine
    • Health Policy
    • Legal Matters
    • Practice Management
    • Technology
    • AI
  • Literature Reviews
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Career
    • Medical Education
    • Professional Development
    • Resident Focus
  • ENT Perspectives
    • ENT Expressions
    • Everyday Ethics
    • From TRIO
    • The Great Debate
    • Letter From the Editor
    • Rx: Wellness
    • The Voice
    • Viewpoint
    • SUO Corner
  • TRIO Resources
    • Triological Society
    • The Laryngoscope
    • Laryngoscope Investigative Otolaryngology
    • TRIO Combined Sections Meetings
    • COSM
    • Related Otolaryngology Events
  • Home
  • Practice Focus
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
    • How I Do It
    • TRIO Best Practices
  • Business of Medicine
    • Health Policy
    • Legal Matters
    • Practice Management
    • Technology
    • AI
  • Literature Reviews
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Career
    • Medical Education
    • Professional Development
    • Resident Focus
  • ENT Perspectives
    • ENT Expressions
    • Everyday Ethics
    • From TRIO
    • The Great Debate
    • Letter From the Editor
    • Rx: Wellness
    • The Voice
    • Viewpoint
    • SUO Corner
  • TRIO Resources
    • Triological Society
    • The Laryngoscope
    • Laryngoscope Investigative Otolaryngology
    • TRIO Combined Sections Meetings
    • COSM
    • Related Otolaryngology Events
  • Search

Why HIPAA, Protected Health Information Cybersecurity Best Practices Are Critical in COVID-19 Era

by Steven M. Harris, Esq. • October 19, 2021

  • Tweet
  • Email a link to a friend (Opens in new window) Email
Print-Friendly Version

Organizations have flexibility, particularly with the addressable requirements, in how they implement these security protocols. These addressable concerns are particularly important in the COVID-19 era given the rise in the use of telehealth.

You Might Also Like

  • Avoid Data Breaches, HIPAA Violations When Posting Patients’ Health Information Online
  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Senate Bill Targets Medical Device Cybersecurity
  • Internal Due Diligence Review Critical for Physician Practices
Explore This Issue
October 2021

When calculating fines related to a breach, HHS is required to take cybersecurity into consideration and also reduce the extent and length of an audit if the entity being investigated has met industry-standard best practices security requirements. HHS is not permitted to increase fines or the length of an audit when an entity is found to be out of compliance with recognized security practices, however.

“Recognized security practices” means standards, guidelines, best practices, methodologies, procedures, and processes developed under the National Institute of Standards and Technology (NIST) Act, the Cybersecurity Act of 2015, and other programs, processes, or regulations that address cybersecurity now or in the future.

Starting earlier this year, HHS Office for Civil Rights investigators began routinely requesting information regarding a covered entity’s implementation of recognized security practices. Having such practices in place may be the key to avoiding hefty fines or penalties in the event of a breach.

Physical Access Protocols and Document Security

Another best practice is to ensure that physical security and document storage policies are up to date. To ensure that patient records are physically secure, organizations must ensure that their facilities are protected through office and warehouse entry control monitoring systems, cubicle and office security, and electronic device protocols.

Additionally, access validation systems (e.g., identification badges and scanned key cards) provide an additional layer of security to protect facilities from unwanted visitors. In the DHS HIPAA Security Information Series program on security standards and physical safeguards, a number of best practices are mentioned:

  • Locked doors, signs warning of restricted areas, surveillance cameras, and alarms;
  • Property controls, such as property control tags and engraving on equipment;
  • Personnel controls, such as identification badges, visitor badges, and/or escorts for large offices; and
  • Private security service or patrol for the facility.

Although some of the security measures above appear to be standard, such as locked doors, all are prone to decay and underuse. The best practice is to ensure that employees are routinely trained on the importance of carrying identification, locking doors, and remembering to validate individuals attempting to enter a company’s physical space.

Further, employees may be compelled to cheat some of these safeguards for ease, such as failing to lock documents securely between visits to the file room. The best practice is to enforce physical security measures commensurate with their importance and, as such, implement disciplinary policies for those who fail to adhere to company policies.

Pages: 1 2 3 4 | Single Page

Filed Under: Departments, Legal Matters Tagged With: COVID19, cybersecurityIssue: October 2021

You Might Also Like:

  • Avoid Data Breaches, HIPAA Violations When Posting Patients’ Health Information Online
  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Senate Bill Targets Medical Device Cybersecurity
  • Internal Due Diligence Review Critical for Physician Practices

The Triological SocietyENTtoday is a publication of The Triological Society.

Polls

More and more medical trainees are taking dedicated, prolonged gap years. Did you?

View Results

Loading ... Loading ...
  • Polls Archive

Top Articles for Residents

  • Is the SLOR in Otolaryngology Residency Applications Contributing to Rural Disparities?
  • Applications Open for Resident Members of the ENTtoday Editorial Board
  • A Resident’s View of AI in Otolaryngology
  • Call for Resident Bowl Questions
  • Resident Pearls: Pediatric Otolaryngologists Share Tips for Safer, Smarter Tonsillectomies
  • Popular this Week
  • Most Popular
  • Most Recent
    • Office Laryngoscopy Is Not Aerosol Generating When Evaluated by Optical Particle Sizer
    • Some Laryngopharyngeal Reflux Resists PPI Treatment
    • Cochlear Implants Improve Performance and Net Savings in Infants
    • Top 10 LARY and LIO Articles of 2024
    • Empty Nose Syndrome: Physiological, Psychological, or Perhaps a Little of Both?
    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment
    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?
    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?
    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment
    • Keeping Watch for Skin Cancers on the Head and Neck
    • Short-Term Efficacy of Biologics in Recalcitrant AFRS: A Systematic Review and Meta-Analysis
    • The Devaluation of Otolaryngology: An Evaluation of CMS’s Involvement in Physician Reimbursement
    • Embolized Middle Meningeal Artery as a Surgical Landmark in Infratemporal Fossa
    • Lord of the (Magnetic) Rings: Rigid Bronchoscopy for Aspirated Magnetic Foreign Bodies in Tertiary Bronchi
    • What Otolaryngologists Can Learn from Athletes

Follow Us

  • Contact Us
  • About Us
  • Advertise
  • The Triological Society
  • The Laryngoscope
  • Laryngoscope Investigative Otolaryngology
  • Privacy Policy
  • Terms of Use
  • Cookies

Wiley

Copyright © 2026 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1559-4939