Laserfiche WebLink
Policy Statement <br />The Administrative Safeguards portion of the Security Rule (collectively referred to as "Administrative <br />Safeguards ") addresses administrative measures and the policy and procedures for their use that protect <br />ePHI and control access to it. It includes administrative actions, and policies and procedures, to manage <br />the selection measures to protect electronic protected health information and to manage the conduct of <br />the covered entity's workforce in relation to the protection of that information. <br />Policy Interpretation and Implementation <br />Standards and Implementation <br />Specifications <br />Approach <br />Coordination with Privacy <br />Policies and Procedures <br />Definition of Protected Health 4. Protected Health Information (PHI) means individually <br />Information (PHI) identifiable Information relating to: <br />a. The past, present or future physical or mental <br />health or condition of an individual <br />b. The provision of health care to an individual; <br />c. The past, present or future payment for health <br />care provided to an individual. <br />Definition of Electronic 5. Electronic Protected Health Information (ePHI) means <br />Protected Health Information PHI maintained or transmitted in electronic media, <br />(ePHI) including, but not limited to, electronic storage media <br />(i.e., hard drives, digital memory medium) and <br />transmission media used to exchange information in <br />electronic storage media (i.e., internet, extranet, and <br />other networks). PHI transmitted via facsimile and <br />telephone is not considered to be transmissions via <br />electronic media. <br />Record Retention 6. A copy of all HIPAA covered information and any <br />revisions shall be maintained for a period of at least six <br />(6) years. Such retention may be in printed or electronic • <br />format, or both. <br />HIPAA Security Officer 7 The HIPAA Security Officer is responsible for the <br />development and implementation of the HIPAA policies <br />City of Ramsey HIPAA Security Policy <br />Administrative Safeguards - Generally <br />1. The Administrative Safeguards portion of the Security <br />Rules consists of nine standards. Some of these <br />standards in turn include implementation specifications <br />designed to further the standard. <br />2. The Health Plan must consider, evaluate, and document <br />its assessment, including recommendations for <br />improvement. Such documentation shall be reflected in <br />a dated memo attached to and made part of the HIPAA <br />Security Policies and Procedures. <br />3. The Administrative Safeguards standards apply in <br />addition to the HIPAA Privacy Policies and Procedures <br />where the PHI involved is ePHI. <br />