Laserfiche WebLink
Policy Interpretation and Implementation <br />Standards and Implementation <br />Specifications <br />Approach <br />Coordination with Privacy <br />Policies and Procedures <br />References: <br />45 C.F.R. § 164.312. <br />Interpretation and Implementation Specifications <br />"Access" Defined <br />Unique User Identification <br />(required) <br />Emergency Access Procedure <br />(required) <br />Automatic Logoff <br />City of Ramsey HIPAA Security Policy <br />1. The Technical Safeguards portion of the Security Rules <br />consists of five standards: <br />• Access Control, <br />• Audit Control, <br />• Integrity, <br />• Personal or Entity Authentication, and <br />• Transmission Security. <br />Some of these standards in turn include implementation <br />specifications designed to further the standard. <br />2. The Health Plan must consider, evaluate, and document <br />its assessment, including recommendations for <br />improvement. Such documentation shall be reflected in <br />a dated memo attached to and made part of the HIPAA <br />Security Policies and Procedures. <br />The Technical Safeguards apply in addition to the HIPAA <br />Privacy Policies and Procedures where the PHI involved <br />is ePHI. <br />Access Control <br />[Technical Safeguard] <br />Standard <br />The Health Plan shall implement technical procedures to restrict access to electronic information systems <br />maintaining ePHI to allow access only to authorized persons and /or software programs. <br />1. "The ability or the means necessary to read, write, <br />modify, or communicate data /information or otherwise <br />use any system resource." <br />2. The Health Plan shall "assign a unique name and /or <br />number for identifying and tracking user identity." <br />3. The Health Plan shall "establish (and implement as <br />needed) procedures for obtaining necessary [ePHI] • <br />during an emergency." <br />4. The Health Plan shall "implement electronic procedures <br />- 12 - <br />• <br />