Comprehensive database of HIPAA controls, requirements, and implementation guidance to help you achieve and maintain compliance.
Implement policies and procedures to prevent, detect, contain, and correct security violations.
Identify the security official who is responsible for the development and implementation of the policies and procedures.
Implement policies and procedures to ensure that all members of the workforce have appropriate access to ePHI.
Implement policies and procedures for authorizing access to ePHI that are consistent with the applicable requirements.
Implement a security awareness and training program for all members of the workforce.
Implement policies and procedures to limit physical access to electronic information systems.
Implement policies and procedures that specify the proper functions to be performed by workstations.
Implement physical safeguards for all workstations that access ePHI.
Implement policies and procedures that govern the receipt and removal of hardware and electronic media.
Implement technical policies and procedures for electronic information systems that maintain ePHI.
Implement hardware, software, and/or procedural mechanisms that record and examine activity.
Implement policies and procedures to protect ePHI from improper alteration or destruction.
Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed.
Implement technical security measures to guard against unauthorized access to ePHI during transmission.
HIPAA controls are organized into three main categories of safeguards.
Policies, procedures, and administrative actions to manage the selection, development, implementation, and maintenance of security measures.
Physical measures, policies, and procedures to protect electronic information systems and related buildings and equipment.
Technology and the policy and procedures for its use that protect ePHI and control access to it.
Our experts can help you implement these controls and achieve full HIPAA compliance.