" hipaa Archives - Page 8 of 21 - LuxSci

Posts Tagged ‘hipaa’

The CMS Interoperability and Patient Access Final Rule

Tuesday, December 22nd, 2020

The Centers for Medicare and Medicaid Services (CMS) Interoperability and Patient Access Final Rule is a mouthful, but it’s also an important step for improving how health data is accessed and shared. While the rule may be beneficial in certain ways, it’s not without its risks. It opens up the door for patient data to be shared with third-party app developers outside of the tight confines of HIPAA regulations, which could lead to more breaches of sensitive data.

CMS Interoperability and Patient Access Final Rule

Read the rest of this post »

Business Associate Agreement: Explained

Monday, October 26th, 2020

If your organization collects, stores or processes electronic protected health information (ePHI) it will need a clear understanding of business associate agreements (BAAs). This also applies to businesses that process ePHI on behalf of other organizations.

Business Associate Agreements

Each business associate agreement stipulates how a company will share its ePHI with the respective business associate, and where the responsibilities lie. Unless your organization is a rare breed that has its own web hosting, email service, lawyers, accountants and every other aspect of its business in-house, then it needs to have these agreements in place with every provider that it shares ePHI with.

Read the rest of this post »

LuxSci Achieves HITRUST CSF Certification

Thursday, October 22nd, 2020

LuxSci announces today that it has achieved the HITRUST CSF Certification, the gold standard and most widely adopted security framework in the healthcare industry.

LuxSci Achieves HITRUST CSF Certification

What is HITRUST CSF Certification and why should it matter?

Today, we are very proud to announce that LuxSci has achieved the HITRUST CSF Certification, the gold standard and most widely adopted security framework in the healthcare industry. The full fleet of LuxSci services, including Secure High Volume HIPAA Compliant Email Sending, HIPAA Marketing, HIPAA Compliant Hosting, Secure Connector for Microsoft 365 and Google Workspace, Secure Forms, Secure Texting, and Secure Web Hosting, were audited by our third-party assessor, Security Compliance Associates, and have earned Certified status for HIPAA and GDPR under HITRUST.

Read the rest of this post »

Is Skype HIPAA Compliant? If not, what is?

Saturday, May 9th, 2020

In recent times we have seen a huge push toward telehealth, so many are wondering, “Is Skype HIPAA compliant?” While Skype is a practical tool that many people have access to, it’s important to consider any regulatory obligations you need to meet before you use it.

If your business collects, stores, transmits or processes electronic protected health information (ePHI), then it is subject to HIPAA regulations. Organizations that process ePHI on behalf of other parties also need to stick within the rules, otherwise they may face heavy fines.

Regardless of whether your organization provides health services through video or it uses video platforms to process ePHI in any other way, it needs to make sure it is using software that abides by the regulations.

Wondering, “Is Skype HIPAA compliant?” is a good starting point, but there are several things to consider before you commit to a video conferencing service.

Do You Need a BAA to Make Skype HIPAA Compliant?

A business associates agreement (BAA) is a contract between your organization and any others that process its data. In essence, these agreements outline how ePHI will be used, what control measures will be in place, and where the responsibilities lie between the two parties.

BAAs are absolutely necessary for HIPAA compliance. Even if your organization and its partner share ePHI with every control and security mechanism imaginable, as well as following all other aspects of the regulations, it would still be violating HIPAA if a signed BAA was not in place.

If your organization is going to be sharing ePHI over a video service, then it needs to be HIPAA-compliant.* However, the only way that it can be HIPAA compliant is if a BAA is in place.

Is Only the Business Version of Skype HIPAA Compliant?

Skype comes in several different versions, but the basic, consumer oriented one is not HIPAA compliant. The only type that offers BAAs and which could be made HIPAA compliant is Skype for Business, which is one of Microsoft Office’s business communication tools.  Note that “Skype for Business” is a completely different service than consumer Skype. 

However, it’s also worth noting that Skype for Business is currently being phased out in favor of Microsoft Teams. If you don’t already have a supported version of Skype for Business, you should look for HIPAA-compliant alternatives instead. Support for Skype for Business Online ends in 2021, while support for Skype for Business Server will be extended until 2025.

With this in mind, it’s probably not worthwhile pursuing any version of Skype for HIPAA compliance. If you use the basic version of Skype, you will be violating the regulations, and even if you can get Microsoft to sign a Skype for Business BAA, you may have to switch your software in 2021 anyway.

HIPAA-Compliant Alternatives to Skype

Considering that Skype for Business doesn’t have much time left and that it is not even the same as “regular Skype,” your organization will be better off finding a HIPAA-compliant alternative. One option is LuxSci’s SecureVideo, which was designed specifically to make it easy to stay within the regulations.

SecureVideo was developed from the ground up with HIPAA compliance in mind, ensuring that it became a practical video calling service that made security and compliance simple. The Zoom for Healthcare-based platform is great for telemedicine and other forms of sharing ePHI.

SecureVideo includes handy features like screen-sharing, file-sharing, and virtual clinics, with a capacity of up to 100 participants. This makes LuxSci’s SecureVideo a convenient and compliant alternative to Skype.

 

* During the Covid-19 pandemic, HHS has waived responsibility for breaches through non-compliant video conferencing services, like Skype. So, while Skype may not be compliant, it is OK to use during the pandemic. However, as the pandemic subsides and this waiver is lifted, you should have transitioned to a service that is actually HIPAA compliant.

Secure & Compliant Remote Work

Thursday, April 16th, 2020

As a result of the pandemic, many businesses have closed their offices and have employees working from home, which is an excellent compromise for keeping operations ongoing and while keeping employees safe.

However, the shift to working from home is a big jump for many companies and their employees, mainly if an existing remote work policy isn’t in place. Organizations need to tread carefully because, with certain exceptions for the public health emergency, coronavirus doesn’t change their security and compliance obligations.

This is especially critical for organizations that process electronic protected health information (ePHI) and for employees that deal with valuable or sensitive data. If the appropriate precautions aren’t taken, companies could breach regulations like HIPAA or PCI DSS and face the significant penalties that come with violations. 

They may also have their sensitive data stolen by cybercriminals or leaked through negligence, which could lead to all kinds of problems, ranging from the theft of intellectual property to blackmail.

How Can Organizations Establish a Secure & Compliant Remote Work Policy

Even in these difficult times, a secure and compliant remote work policy needs to be designed carefully. It needs to meet company requirements and its employees, as well as any legal obligations and the needs of customers.

To address each of these needs, all of these stakeholders should be involved in the process. It’s critical to get legal advice and engage security experts to make sure that the policy and technical measures are adequate for your company’s unique circumstances.

A secure and compliant remote work policy should include:

  • Who is covered, when, and in which situations.
  • What are the organization’s responsibilities and obligations.
  • What are the employee’s responsibilities and obligations.
  • What hardware and software must be used, and in what configurations.
  • What security and privacy measures should be in place.
  • How reliability and availability will be ensured.

Companies may still have specific legal obligations for their remote workers, so a secure and compliant remote work policy needs to take these into account. For example, the company may still need to take measures to ensure that laws such as the Fair Labor Standards Act are followed and that employees are working in a safe environment. 

Once your company has developed its remote work policy, it should have each of its employees sign it so that they are aware of the expectations and committed to following them.

What Security Measures Do Companies Need as Part of Their Remote Work Policies?

The particular measures will vary from situation to situation, depending on a company’s setup, the regulations it is subject to, the data assets it has, as well as how it transmits and stores valuable or sensitive information.

Some measures for remote work, found in the HITRUST and other security guidelines, include:

  • All data should be encrypted when it is transmitted over public networks. FIPS-approved ciphers should be implemented in any of the security protocols used.
  • Wireless access points should be encrypted with AES WPA2 as a minimum security standard.
  • Emails and other digital messages should be protected from end-to-end and sensitive information should never be sent without encryption.
  • Faxes should only be used for protected information if more secure alternatives are not possible.
  • Employees should use VPNs to connect to corporate systems, and all traffic should flow through the VPN. Any access should be remotely logged and monitored. Unauthorized connections should be monitored and reviewed quarterly at a minimum, and appropriate actions should be taken after the review process.
  • Effective authorization systems need to be in place for privileged connections and access to sensitive business information. Remote administration sessions should have heightened security measures in place.
  • The authentication process for remote devices should include additional measures on top of passwords, such as the verification of IP or MAC addresses.
  • Employee use of portable storage devices should be strictly controlled, and the information should be encrypted. 
  • Any data transfers outside of controlled areas require approval, and the details need to be recorded. Cryptographic measures need to be in place to protect the integrity and confidentiality of data when it is transferred.
  • Sensitive or valuable data should not be available to unauthorized individuals or left unattended. This includes leaving the information out on desks, on printers, or viewable by others on computer monitors.
  • External services (such as new SaaS vendors) should not be used to store or transmit information without prior approval.
  • Controls and training should be in place if personal devices are allowed to be used in the workplace.

Solutions for Secure & Compliant Remote Work

In the wake of the rapid spread of coronavirus and the significant changes it has brought, many companies are scrambling to provide secure and compliant remote work solutions to their employees.

This poses a significant challenge because when new systems are implemented abruptly, it can easily lead to mistakes. If these errors involve data leaks or compliance violations, they can have substantial long-term consequences for businesses.

To minimize risk, the best option is to use well-established and specialized solutions like LuxSci’s many offerings. All of our products are designed to be secure and comply with various sets of regulations and optimize our users’ workflows.

These services include our secure and HIPAA-compliant email service, as well as tools like SecureText. The rise of coronavirus may have permanently changed work environments, but adopting LuxSci’s safe and carefully designed tools can help prevent further threats from harming your business in these difficult times.