Laserfiche WebLink
Relationship to Privacy Officer <br />Workforce Sanctions <br />(required) <br />Information System Activity <br />Review <br />(required) <br />References: <br />45 C.F.R. § 164.308(a)(2). <br />City of Ramsey HIPAA Security Policy <br />Assigned Security Responsibility <br />[Administrative Safeguard] <br />Standard <br />A Security Officer must be identified and shall be responsible for the development and implementation of <br />the Security Policies and Procedures. <br />Interpretation and Implementation Specifications <br />Security Management Process <br />[Administrative Safeguard] <br />Standard <br />The Health Plan must implement policies and procedures to prevent, detect, contain, and correct security <br />violations. <br />Interpretation and Implementation Specifications <br />1. The HIPAA Security Officer can be, but is not required to <br />be, the same individual as the HIPAA Privacy Officer. <br />Should the HIPAA Security Officer be a different <br />individual than the HIPAA Privacy Officer, the HIPAA <br />Privacy Officer includes overall responsibility for <br />protected health information (PHI), including electronic <br />protected health information (ePHI). <br />Risk Analysis 1. The Health Plan shall conduct an accurate and <br />(required) thorough assessment of the potential risks and <br />vulnerabilities to the confidentiality, integrity, and <br />availability of ePHI held by the covered entity. For <br />this purpose, "held by" includes ePHI that is housed <br />other than by the Health Plan (e.g., third party <br />administrators). <br />Risk Management 2. The Health Plan shall implement security measures <br />(required) sufficient to reduce risks and vulnerabilities to a <br />reasonable and appropriate level to comply <br />3. The Health Plan shall apply appropriate sanctions <br />against workforce members who fail to comply with <br />the Security Policies and Procedures. <br />4. The Health Plan shall implement procedures to <br />regularly review records of information system <br />activity, such as audit logs, access reports, and <br />security incident tracking reports. <br />