Laserfiche WebLink
• <br />and procedures to protect a covered entity's electronic information systems and related buildings and <br />equipment, from natural and environmental hazards, and unauthorized intrusion." <br />Policy Interpretation and Implementation <br />Standards and Implementation <br />Specifications <br />Approach <br />Coordination with Privacy <br />Policies and Procedures <br />References: <br />45 C.F.R. § 164.310(a). <br />Facility Access Controls <br />[Physical Safeguard] <br />Standard <br />The first standard under the Physical Safeguards section is Facility Access Control. It requires the Health <br />Plan to "implement policies and procedures to limit physical access to its electronic information systems <br />and the facility or facilities in which they are housed, while ensuring that properly authorized access is <br />allowed." <br />Interpretation and Implementation Specifications <br />Contingency Operations <br />(addressable) <br />Facility Security Plan <br />(addressable) <br />1. The Physical Safeguards portion of the Security Rules <br />consists of four standards. Some of these standards in <br />turn include implementation specifications designed to <br />further the standard. <br />2. The Health Plan must consider, evaluate, and document <br />its assessment, including recommendations for <br />improvement. Such documentation shall be reflected in <br />a dated memo attached to and made part of the <br />Security Policies and Procedures. <br />3. The Physical Safeguards standards apply in addition to <br />the HIPAA Privacy Policies and Procedures where the <br />PHI involved is ePH-I. <br />1. The Health Plan shall "establish (and implement as <br />needed) procedures that allow facility access in support <br />of restoration of lost data under the disaster recovery <br />plan and emergency mode operations plan in the event <br />of an emergency." <br />2. The Health Plan shall "implement policies and <br />procedures to safeguard the facility and the equipment <br />therein from - unauthorized physical access, tampering, <br />and theft." <br />Access Control and Validation 3. The Health Plan shall "implement policies and <br />Procedures procedures to control and validate a person's access to <br />City of Ramsey HIPAA Security Policy - 15 - <br />