ENTtoday
  • Home
  • COVID-19
  • Practice Focus
    • Allergy
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Departments
    • Issue Archive
    • TRIO Best Practices
      • Allergy
      • Facial Plastic/Reconstructive
      • Head and Neck
      • Laryngology
      • Otology/Neurotology
      • Pediatric
      • Rhinology
      • Sleep Medicine
    • Career Development
    • Case of the Month
    • Everyday Ethics
    • Health Policy
    • Legal Matters
    • Letter From the Editor
    • Medical Education
    • Online Exclusives
    • Practice Management
    • Resident Focus
    • Rx: Wellness
    • Special Reports
    • Tech Talk
    • Viewpoint
    • What’s Your O.R. Playlist?
  • Literature Reviews
    • Allergy
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Events
    • Featured Events
    • TRIO Meetings
  • Contact Us
    • About Us
    • Editorial Board
    • Triological Society
    • Advertising Staff
    • Subscribe
  • Advertise
    • Place an Ad
    • Classifieds
    • Rate Card
  • Search

Why HIPAA, Protected Health Information Cybersecurity Best Practices Are Critical in COVID-19 Era

by Steven M. Harris, Esq. • October 19, 2021

  • Tweet
  • Email
Print-Friendly Version

Organizations have flexibility, particularly with the addressable requirements, in how they implement these security protocols. These addressable concerns are particularly important in the COVID-19 era given the rise in the use of telehealth.

You Might Also Like

No related posts.

Explore This Issue
October 2021

When calculating fines related to a breach, HHS is required to take cybersecurity into consideration and also reduce the extent and length of an audit if the entity being investigated has met industry-standard best practices security requirements. HHS is not permitted to increase fines or the length of an audit when an entity is found to be out of compliance with recognized security practices, however.

“Recognized security practices” means standards, guidelines, best practices, methodologies, procedures, and processes developed under the National Institute of Standards and Technology (NIST) Act, the Cybersecurity Act of 2015, and other programs, processes, or regulations that address cybersecurity now or in the future.

Starting earlier this year, HHS Office for Civil Rights investigators began routinely requesting information regarding a covered entity’s implementation of recognized security practices. Having such practices in place may be the key to avoiding hefty fines or penalties in the event of a breach.

Physical Access Protocols and Document Security

Another best practice is to ensure that physical security and document storage policies are up to date. To ensure that patient records are physically secure, organizations must ensure that their facilities are protected through office and warehouse entry control monitoring systems, cubicle and office security, and electronic device protocols.

Additionally, access validation systems (e.g., identification badges and scanned key cards) provide an additional layer of security to protect facilities from unwanted visitors. In the DHS HIPAA Security Information Series program on security standards and physical safeguards, a number of best practices are mentioned:

  • Locked doors, signs warning of restricted areas, surveillance cameras, and alarms;
  • Property controls, such as property control tags and engraving on equipment;
  • Personnel controls, such as identification badges, visitor badges, and/or escorts for large offices; and
  • Private security service or patrol for the facility.

Although some of the security measures above appear to be standard, such as locked doors, all are prone to decay and underuse. The best practice is to ensure that employees are routinely trained on the importance of carrying identification, locking doors, and remembering to validate individuals attempting to enter a company’s physical space.

Further, employees may be compelled to cheat some of these safeguards for ease, such as failing to lock documents securely between visits to the file room. The best practice is to enforce physical security measures commensurate with their importance and, as such, implement disciplinary policies for those who fail to adhere to company policies.

Pages: 1 2 3 4 | Single Page

Filed Under: Departments, Legal Matters Tagged With: COVID19, cybersecurityIssue: October 2021

You Might Also Like:

The Triological SocietyENTtoday is a publication of The Triological Society.

The Laryngoscope
Ensure you have all the latest research at your fingertips; Subscribe to The Laryngoscope today!

Laryngoscope Investigative Otolaryngology
Open access journal in otolaryngology – head and neck surgery is currently accepting submissions.

Classifieds

View the classified ads »

TRIO Best Practices

View the TRIO Best Practices »

Top Articles for Residents

  • Do Training Programs Give Otolaryngology Residents the Necessary Tools to Do Productive Research?
  • Why More MDs, Medical Residents Are Choosing to Pursue Additional Academic Degrees
  • What Physicians Need to Know about Investing Before Hiring a Financial Advisor
  • Tips to Help You Regain Your Sense of Self
  • Should USMLE Step 1 Change from Numeric Score to Pass/Fail?
  • Popular this Week
  • Most Popular
  • Most Recent
    • What Happens to Medical Students Who Don’t Match?
    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment
    • Why We Get Colds
    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?
    • Some Challenges Remain to Having a Universal Resident Leave Policy, But Otolaryngology Programs Are Getting Closer
    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment
    • What Happens to Medical Students Who Don’t Match?
    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?
    • Vertigo in the Elderly: What Does It Mean?
    • Neurogenic Cough Is Often a Diagnosis of Exclusion
    • Why We Get Colds
    • Are the Jobs in Healthcare Good Jobs?
    • What Really Works in Functional Rhinoplasty?
    • Is the Best Modality to Assess Vocal Fold Mobility in Children Flexible Fiberoptic Laryngoscopy or Ultrasound?
    • Three Primary Treatment Strategies Show No Differences in Swallow Outcome for Patients with Low- to Intermediate-Risk Tonsil Cancer

Polls

Do you have physician assistants in your otolaryngology practice?

View Results

Loading ... Loading ...
  • Polls Archive
  • Home
  • Contact Us
  • Advertise
  • Privacy Policy
  • Terms of Use
  • Cookie Preferences

Visit: The Triological Society • The Laryngoscope • Laryngoscope Investigative Otolaryngology

Wiley
© 2023 The Triological Society. All Rights Reserved.
ISSN 1559-4939