HIPAA Handbooks

  • Privacy and security training for new and seasoned staff
  • 11 staff/setting focus areas
  • Education on protecting PHI
  • HITECH Act updates
  • Discounts on bulk purchases

More»

E-learning

  • Role-based training using real-life case scenarios
  • Test-your-knowledge exercises with remediation
  • Post-course test to document staff participation

More»

Other HIPAA Resources

  • Hot-topic audio conferences
  • CD-Rom, books on privacy and security
  • Business associate training
  • Videos with real-life HIPAA scenarios

More»

Nov
25

Expert: Encryption best way to go

Email This Post Print This Post

It seems as if everyone is talking about encryption these days, and that is certainly the case on our HIPAA Update blog.

HHS added encryption layers in its interim final rule on breach notification to specify the technologies and methods that render PHI “unusable, unreadable, or indecipherable to unauthorized individuals.” Some of these layers were not specified in draft guidance
HHS released in April.

“You now need to really consider encryption,” says Jeff Drummond, HIPAA blogger and health law partner in the Dallas office of Jackson Walker, LLP. “That’s sort of your first opportunity to avoid breach notification. You can’t do much about your paper records other than destroying them, which eliminates their utility. But for electronic data, you can keep it and use it, but should encrypt so it is considered ‘secured’ under HIPAA.”

In the interim final rule, the definitions for acceptable encryption include:

Comments

  1. Alex Golimbievsky says:

    Great resources, thanks Dom!

  2. Dom Nicastro says:

    No problem!

    Just let us know if you ever want to “start a conversation” on the blog or have any inquiries on HIPAA compliance.

    It’s a crucial couple of months we’ve got coming up.

Leave a Reply

Spam protection by WP Captcha-Free