My WebLink
|
Help
|
About
|
Sign Out
Home
Agenda - Council - 08/22/2006
Ramsey
>
Public
>
Agendas
>
Council
>
2006
>
Agenda - Council - 08/22/2006
Metadata
Thumbnails
Annotations
Entry Properties
Last modified
3/19/2025 3:48:49 PM
Creation date
8/18/2006 2:05:08 PM
Metadata
Fields
Template:
Meetings
Meeting Document Type
Agenda
Meeting Type
Council
Document Date
08/22/2006
Jump to thumbnail
< previous set
next set >
There are no annotations on this page.
Document management portal powered by Laserfiche WebLink 9 © 1998-2015
Laserfiche.
All rights reserved.
/
299
PDF
Print
Pages to print
Enter page numbers and/or page ranges separated by commas. For example, 1,3,5-12.
After downloading, print the document using a PDF reader (e.g. Adobe Reader).
View images
View plain text
Relationship to Privacy Officer <br />Workforce Sanctions <br />(required) <br />Information System Activity <br />Review <br />(required) <br />References: <br />45 C.F.R. § 164.308(a)(2). <br />City of Ramsey HIPAA Security Policy <br />Assigned Security Responsibility <br />[Administrative Safeguard] <br />Standard <br />A Security Officer must be identified and shall be responsible for the development and implementation of <br />the Security Policies and Procedures. <br />Interpretation and Implementation Specifications <br />Security Management Process <br />[Administrative Safeguard] <br />Standard <br />The Health Plan must implement policies and procedures to prevent, detect, contain, and correct security <br />violations. <br />Interpretation and Implementation Specifications <br />1. The HIPAA Security Officer can be, but is not required to <br />be, the same individual as the HIPAA Privacy Officer. <br />Should the HIPAA Security Officer be a different <br />individual than the HIPAA Privacy Officer, the HIPAA <br />Privacy Officer includes overall responsibility for <br />protected health information (PHI), including electronic <br />protected health information (ePHI). <br />Risk Analysis 1. The Health Plan shall conduct an accurate and <br />(required) thorough assessment of the potential risks and <br />vulnerabilities to the confidentiality, integrity, and <br />availability of ePHI held by the covered entity. For <br />this purpose, "held by" includes ePHI that is housed <br />other than by the Health Plan (e.g., third party <br />administrators). <br />Risk Management 2. The Health Plan shall implement security measures <br />(required) sufficient to reduce risks and vulnerabilities to a <br />reasonable and appropriate level to comply <br />3. The Health Plan shall apply appropriate sanctions <br />against workforce members who fail to comply with <br />the Security Policies and Procedures. <br />4. The Health Plan shall implement procedures to <br />regularly review records of information system <br />activity, such as audit logs, access reports, and <br />security incident tracking reports. <br />
The URL can be used to link to this page
Your browser does not support the video tag.