Hipaa Encryption Compliance

Every business owner in the country knowsfor their own gain, which is why HIPAA specifically
about HIPAA and HIPAA Encryption Compliance. Amentions it.
law introduced in the 1990s and updated in 2003HIPAA encryption compliance isnt voluntary, its
to cover the use and protection of protectedmandatory, and there are stiff penalties for
medical information or PHI. Although the legislationtransgression. There are two pertinent parts of
has been around for a while, a 2006 survey ofthe HIPAA that relates to email encryption, The
healthcare providers found only half werePrivacy Rule and the Security Rule.
completely compliant with the requirements ofThe Privacy Rule gives individuals the right to
HIPAA.request that a covered entity correct any
With personal information being traded across theinaccurate PHI. It also requires covered entities to
world for both legal and nefarious reasons, youtake reasonable steps to ensure the confidentiality
need to protect your details as much as possible.of communications with individuals.
You dont have to be a well-known figure,This Rule specifies that every effort must be
celebrity or top businessman to want to protecttaken to protect PHI when its stored, used,
your information, company or otherwise.viewed and transmitted. The use of email
Of course if you run a company that hasencryption is mandatory for any body that has
employees with medical insurance, or process oraccess to or deals with PHI.
any way deal with medical records or insurance,The security rule is very specific.
you have no choice but to protect yourself.Covered Entities must maintain reasonable and
HIPAA encryption compliance specifies that anyappropriate administrative, physical, and technical
electronic correspondence that has PHI included insafeguards to protect the confidentiality, integrity,
it must be encrypted. It also specifies that theand availability of their EPHI against any
correspondence should also be securely archived,reasonably anticipated risks.
time-stamped, indexed, tamper-proof and beThis includes the use of email encryption.
available when requested.Fortunately it isnt as difficult, or as cumbersome
Many hospitals, doctors and clinics consult by email.as it used to be. There are now specific programs
Medical records are also transmitted via email, asthat sit alongside, or within email clients and
are insurance details. We do most of our businessservers that encrypt email before its sent. This
over the internet and email, medicine too. This canautomatic process allows companies to fully
make people a little uncomfortable, knowing theircomply with HIPAA while not having to spend
information is out there somewhere floatingextra time administering it.
around the ether. Even on a short trip, an email isThere is now no real excuse for a business that
copied at least a couple of times by each emaildeals in PHI to not be fully compliant. The means
server it transits. Someone with the access andare there, the cost has reduced, it just takes the
ability could easily get that information and use itwill of business to adopt it.