" Hipaa | LuxSci FYI - Part 3 hipaa « LuxSci FYI
Secure Email, Web and Form Solutions     +1 800.441.6612
LuxSciLuxSci
Secure Email,
Web and Form Solutions
Call: 800-441-6612
Int'l: +1 814-870-9250
sales@luxsci.com
support@luxsci.com

Posts Tagged ‘hipaa’

HIPAA Compliance Seal for your Web Site or Email

Thursday, February 11th, 2010

LuxSci customers who require HIPAA Compliance to safeguard electronic protected health information (ePHI) that is stored in or transmitted through their accounts can now display a “HIPAA Compliance Seal” on their web sites or in their email signatures/tag lines/disclaimers.

For example, your compliance seal may look like (click on it to see an example verification page):

Read the rest of this post »

HIPAA HITECH Business Associate Agreement and LuxSci Account Requirements

Saturday, January 30th, 2010

Changes to HIPAA as a result of HITECH provisions in the American Recovery and Reinvestment Act are going into effect on February 17, 2010.  These changes seriously impact the requirements on Business Associates and impose significant liability penalties on HIPAA violations.  For a discussion of these and how they relate to email and web services, see: HITECH 2010: HITECH Impact on Email and Web Outsourcing.

In response to these changes and to ensure that both LuxSci and its HIPAA customers are HIPAA-compliant:

  • Old BAA Void: All Business Associate Agreements (BAA), formerly known as Medical Privacy Agreements, that current LuxSci customers have by virtue of the old BAA being incorporated automatically in LuxSci’s Master Services Agreement are VOID as of February 17th, 2010.
  • New BAA Required: Any LuxSci Customer who is using or plans to use LuxSci for ePHI (electronic protected health information) of any kind (i.e. email, web sites, WebAides, databases, etc) must explicitly sign our new BAA and ARA (Account Restrictions Agreement) before LuxSci will consider itself a Business Associate and the customer’s LuxSci account HIPAA compliant.

LuxSci will be contacting customers that it believes might need to sign a BAA and ARA during the month of February.  However, as LuxSci does not know which customers are using their account(s) for storage or transmission of ePHI, it is up to our customers to contact LuxSci to establish a BAA.

See:

Read the rest of this post »

Security and HIPAA Changes Coming Soon to LuxSci

Wednesday, January 20th, 2010

On January 30th, 2010, LuxSci will be releasing a set of software updates that add new security features and enhance existing security features.  Additionally, LuxSci is introducing a new Business Associate Agreement for HIPAA customers — one that complies with the new HITECH provisions of HIPAAThese changes will impact some existing and future customers, as described in this notice.

Read the rest of this post »

HIPAA 2010: HITECH Impact on Email and Web Outsourcing

Wednesday, January 20th, 2010

Surprise!  HIPAA has changed, gotten bigger, and grown teeth.

The American Recovery and Reinvestment Act (ARRA, or The Obama Stimulus Bill), signed into law in February 2009, includes new, more comprehensive provisions for HIPAA. These provisions are in a section of the bill known as the Health Information Technology for Economic and Clinical Health Act (HITECH).

For organizations that are already required to abide by HIPAA (i.e. the “Covered Entities” of HIPAA), HITECH adds the following requirements:

Read the rest of this post »

Premium High Volume Outbound Email Service

Monday, June 1st, 2009

High Volume EmailLuxSci’s High Volume Outbound Email Sending Service, released earlier this year, has been a notable success.  Our service permits the sending of legitimate bulk email messages and also provides reliable “smarthost” services.  However, the offering is restricted to SMTP services and does not include the many outbound email processing tools present in LuxSci’s Premium Email service.  I.e. see  LuxSci Outbound Email: 5 Sending Options Compared!

Since High Volume Mail was offered, we have had many requests to send HIPAA-compliant bulk outbound email, i.e. newsletters and notices that contain protected health information (PHI) .  In such cases, SecureLine should be used to encrypt the outbound email in a way that can be opened by any recipient, but which is still secure.  Unfortunately, integration with SecureLine is not a feature of our Basic High Volume service.

LuxSci has responded by releasing Premium High Volume Outbound Email Service.  This is essentially Premium Email hosting with:

Read the rest of this post »

Does sending email using BCC make it HIPAA Compliant?

Thursday, April 9th, 2009

HIPAA Email SecurityPeople have asked us if sending an email to someone via BCC (Blind Carbon Copy) is HIPAA-compliant.  For example, a doctor’s office sending a newsletter to its patients via BCC.  The presumption is that because when a message is sent via BCC, the recipient’s email address is not visible in the message that there is no way to identify the individual(s) to whom the message was sent and thus the messages do not contain any “personally identifiable health information” that is protected by HIPAA.

The short answer is “BCC is not good enough“.  For the long answer, read on.

Read the rest of this post »

Recipe: Completely Secure Collection of Web Form Data using SSL and PGP or S/MIME

Tuesday, March 17th, 2009

The situation: your organization needs to collect information from clients through from(s) on your web site, but that information is sensitive. So, you need to be absolutely sure that the information is transferred from the users of your web site to you in as secure a fashion as possible. This means that

  1. no one but you (or optionally your authorized staff) can intercept or read the information,
  2. the information is never stored insecurely anywhere
  3. the information cannot be modified without your knowledge

Why would this high level of security and privacy be necessary? There are many cases where they are essential; some of these include:

Read the rest of this post »

What HIPAA Says about Email Security

Monday, March 16th, 2009

Performing daily business transactions through electronic technologies is an accepted, reliable and necessary tool across the nation’s healthcare sectors. Therefore, electronic communications have become a standard in the healthcare industry as a way to conduct business activities that commonly include:

  • Interacting with web-savvy patients;
  • Real time authorizations for medical services;
  • Transcribing, accessing and storing health records;
  • Appointment scheduling; and
  • Submitting claims to health plan payers for payment of the services provided.

Read the rest of this post »

Is a FAX document HIPAA-Secure?

Friday, March 6th, 2009

LuxSci offers solutions for secure and HIPAA compliant email and web services,  so we are often asked about secure FAXing.

Many organizations, especially in the healthcare industry, have an urgent need to send important and sensitive information, like protected health information (PHI), to  organizations via facsimile. Why?  Because this is how it has always been done, and everyone is “set up” to be able to handle FAXes quickly and efficiently.

However, with HIPAA security regulations ever-present, our clients are concerned that their use of FAX is compliant, similar to making sure that their email and web sites meet HIPAA security standards.

Update – for electronic FAXing options, see: HIPAA Faxing: How to Send and Receive FAXes i na Secure and Compliant Way.

Can data sent via FAX be “secure enough” for HIPAA?

Read the rest of this post »

Receive Secure Emails from Anyone

Monday, February 9th, 2009

Secure SendGuaranteeing that information sent via email remains confidential can be a tricky business. Whether you’re in health care governed by HIPAA, education, or commerce, your customers and correspondents must be able to quickly and easily send your messages and attachments securely — no matter what email service they may have.

Solution?

With the LuxSci’s SecureLine SecureSend Portal, anyone with an email address can easily send any LuxSci SecureLine user secure emails for free.

Read the rest of this post »

Security Certifications TRUSTe EU Safe Harbor Thawte Extended Validation SSL Certificate McAfee Secure Authorize.net Merchant