Educause Security Discussion mailing list archives

Re: HIPAA Requires Encryption?


From: "Plesco, Todd" <tplesco () CHAPMAN EDU>
Date: Thu, 26 Aug 2010 15:06:24 -0700

The first question: Whom is the university's "covered entity" and where
are the data records (ePHI) which require HIPAA regulatory safeguard?
In other words, which part of the university conducts Medicare/Medicaid
billable transactions? Is that group a Hybrid Entity? (Is data being
co-mingled on the SQL server with non-covered entities?  (Often,
organizations do not understand if HIPAA is required and assume it is
simply because they have patient health records.  This is the first
thing to find out.)

Next, is there a Privacy or Compliance Officer overseeing the HIPAA
program whom can furnish details where all electronic patient
transactions take place?  

Also, don't forget to look at physical safeguards and archive/data
backup.  Lost backup tapes or mobile devices (laptops or thumb drives)
which are not encrypted have most often been where electronic HIPAA
breaches occur.

Feel free to write me back directly if you have more questions
(Previously, I was the CISO for one of the nation's largest metropolitan
health departments.)

Best,

Todd A. Plesco  CISM, CBCP

Chapman University, Director of Information Security

One University Drive, Orange, CA 92866

Phone: (714) 744-7979/Fax: (714) 744-7041

 

From: The EDUCAUSE Security Constituent Group Listserv
[mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Matthew Link
Sent: Thursday, August 26, 2010 1:19 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] HIPAA Requires Encryption?

 

Very recently, I inherited the job of focusing information security
efforts.  In the process of upgrade of a SQL server, a question has
arisen regarding the provision in HIPAA (Addressable) to encrypt EPHI at
rest on both the server and the backup media.  It does come at some
additional cost, though it's manageable.  Before proceeding, however, I
thought I'd ask if anyone has suggestions. 

 

Thanks, 

--Matthew Link. 

  Director, User Services 

  Information Services, UCM 

  660-543-8063 

  link () ucmo edu 


Current thread: