" Hipaa | LuxSci FYI - Part 2 hipaa « LuxSci FYI
Secure Email, Web and Form Solutions     +1 800.441.6612
LuxSciLuxSci
Secure Email,
Web and Form Solutions
Call: 800-441-6612
Int'l: +1 814-870-9250
sales@luxsci.com
support@luxsci.com

Posts Tagged ‘hipaa’

Manage HIPAA-Compliant and non-Compliant Domains with One Account!

Friday, April 22nd, 2011

LuxSci has introduced a number of per-domain security features that allow us to offer accounts that contain both HIPAA-complaint domains and non-compliant domains.

Previously, customers could order such a combination of domains, but they were segregated into completely separate accounts.  These new security features benefit our customers because:

Read the rest of this post »

SecureLine Users Can Toggle Between TLS and Escrow Encryption When Sending Messages

Tuesday, March 1st, 2011

LuxSci’s SecureLine end-to-end email security system enables allows customers to enable use of TLS for email delivery, without any further encryption, when TLS is supported by the recipient email servers and the customers’ needs only include transport encryption (i.e. for HIPAA).  This provides security with maximum usability, when available.

However, TLS is not as secure as SecureLine Escrow for email communications.  For cases where enhanced security is desired, even to a recipient whose email servers support TLS, LuxSci’s WebMail email composer now permits users to override the use of “TLS Only” so that “SecureLine Escrow” can be used instead — on a message-by-message basis.  I.e., users can now use Escrow “on demand” to provide enhanced security over TLS.

Additionally, users have a new preference (under “Email Composition > SecureLine” preferences), where they can alter the behavior of WebMail so that “TLS Only” delivery is NOT used for them unless requested — Escrow can be used by default if desired.

These new security settings only apply to SecureLine customers who have “TLS” enabled as a viable secure email delivery method in their account.

MySQL v5.5.x Now Supported

Saturday, February 19th, 2011

LuxSci now supports databases running on MySQL v5.5.x.  Customers have the option of using v5.5.x or v5.0.x when making new databases.  Version 5.5 brings many enhancements that users have been asking for, including:

  • Improved performance
  • Improved InnoDB engines
  • Triggers that can be managed by the end user (i.e. for HIPAA auditing purposes and other reasons)

MySQL v5.5 databases can be added by anyone in a database-supporting account via the “Databases” administrative control. If you have a dedicated server, and would like MySQL v5.5 added to your server, please contact Support.

MySQL v5.5 databases are compatible with LuxSci web hosting accounts, SecureForm database storage, and HIPAA accounts.

LuxSci’s Database Management User Interface has also been updated to allow Account Administrators to change the password to their database on demand.  See the “Change Database Password” tool in this area.

HIPAA Alert: Contacts, Calendar Events and Tasks may contain ePHI!

Friday, January 21st, 2011

When health care organizations review their operations to see where electronic protected health information (ePHI) is being saved, transmitted, and viewed, a great deal of time is spent on the obvious candidates: email, chat, stored files and health records, etc.

Many overlook the fact that ePHI can be embedded in Contacts, Calendars, and Tasks.  Consider for example:

Read the rest of this post »

Protect your mobile data from theft with “Remote Wipe”

Friday, January 14th, 2011

If your mobile device (e.g., iPad or Blackberry) is lost or stolen, then you have no control over who may gain access to:

  • Viewing existing and new email messages
  • All of your contacts
  • Your calendar appointments
  • Sending email as you
  • and more…

This is pretty serious, especially for folks who are subject to regulations and compliance laws.

For example, if a Nurse, using an iPad to manage patient appointments or to communicate via email with remote doctors, were to lose that iPad and it were to be accessed by someone else, then that may become a HIPAA “breach” (an unauthorized disclosure of protected health information) and the Nurse’s organization may be subject to stiff monetary fines and bad publicity.

Read the rest of this post »

Improved HIPAA Certification Seal

Saturday, November 13th, 2010

LuxSci’s HIPAA Certification Seal is an image that HIPAA accounts can place on their web sites and/or include in their email signatures to show that their email and/or web forms are HIPAA compliant.  Clicking on the LuxSci HIPAA Seal takes one to a custom LuxSci page certifying that the customer is using specific LuxSci security services for compliance reasons.

Read the rest of this post »

More and More Companies need HIPAA Compliance due to Changing Regulations

Thursday, July 29th, 2010

In February, 2010, the HITECH changes to HIPAA went into effect.  These required that the Business Associates of HIPAA covered entities also be HIPAA Compliant with respect to the Protected Health Information (PHI) they manage and transmit.  This was a big change with big ramifications … but more changes are coming.

On July 14th, 2010, the US Department of Health and Human Services (HHS) published a series of proposed changes to HIPAA in a notice in the Federal Register.  All comments on these proposed changes are due by September 13th, 2010, and the final rules will likely go into effect shortly thereafter.

With respect to electronic communications, there are several significant changes that will be happening.

Read the rest of this post »

Is Blackberry HIPAA Compliant? What You Need To Know

Tuesday, July 13th, 2010

We are often approached by customers wanting to use their blackberry mobile devices to send and receive email that may contain electronic Protected Health Information (ePHI).  Such customers, when they must abide by the HIPAA and HITECH laws governing medical privacy, must comply with a long set of regulations that covers, among other things, how ePHI may be transmitted over the Internet.

This article deals with the security of sending and receiving email on a Blackberry configured for Internet email services (i.e. it does not apply to those connecting to an Blackberry Enterprise Server and Exchange).

Read the rest of this post »

Video: HIPAA-Compliant Email Services at LuxSci

Friday, July 9th, 2010

If you are in need of HIPAA-compliant email services, this video will answer many of your questions regarding how LuxSci’ secure email services apply to HIPAA and what is needed for a HIPAA-compliant account with LuxSci.

Watch Video: HIPAA-compliant email services at LuxSci


SecureForm: now with SMTP TLS for Secure Form Email Delivery

Friday, April 2nd, 2010

SecureForm is LuxSci’s service that makes it quick and easy to collect data, including files, from web and PDF form posts and have that data emailed to one or more recipients and/or archived in a LuxSci WebAides document storage area.  The “Secure” in SecureForm refers in part to the fact that the emailed form data can be secured using PGP or S/MIME.  This, combined with enforced use of SSL, ensures that the form data is secured from end-to-end … from submission by the end user to the receipt by the web site administrator.  This ensures HIPAA compliance and strong security for that data.

Now, SecureForm supports the option of secure delivery of form data emails to recipients using TLS instead of PGP or S/MIME.  While use of TLS only is less secure than PGP or S/MIME, it is more user friendly — there is no need for certificates or extra steps to decrypt the messages once they arrive.  TLS does provide transport encryption from LuxSci’s servers to the recipients servers and thus still provides HIPAA compliant form data delivery. 

Read the rest of this post »

Security Certifications TRUSTe EU Safe Harbor Thawte Extended Validation SSL Certificate McAfee Secure Authorize.net Merchant