Home > Security News > HIPAA security rules apply to firms with healthcare plans
Security News:
EMAIL THIS LICENSING & REPRINTS

HIPAA security rules apply to firms with healthcare plans

By Bill Brenner, News Writer
15 Mar 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

If your business isn't healthcare, then HIPAA's security rules don't affect you, right?

Think again.
HIPAA is great at telling you what to do, but not how to do it.
Ryan Hunter
sr. technology consultant, Watson Wyatt

According to Ryan Hunter, senior technology consultant and data manager for Washington D.C.-based Watson Wyatt, the rules must be observed by any enterprise that offers its employees a healthcare plan. His job is to help Fortune 500 businesses operate their health plans and benefits enrollment the HIPAA way.

"HIPAA has wide implications from hospitals to insurance companies to outside businesses," Hunter said. "HIPAA security is about protecting healthcare information electronically and companies rely on different vendors that make up components of their health plan."

When an enterprise does business with these vendors, he said, "They need to make sure that when an employee's personal health information is passed among vendors that it's protected." Businesses also have a responsibility to make sure their vendors have all the proper HIPAA procedures in place, Hunter said. That's a tall order for many of them.

"They need to know where their data is coming from and going to, and benefits enrollment data is a part of this," Hunter said. "It's a big challenge, and they need to have their own policies and procedures in place to handle it."
HIPAA data security rules:

HIPAA rules force health insurers to secure sensitive data: HIPAA is forcing a majority of health insurance companies ensure the security of sensitive data.

HIPAA security rules broken down: The HIPAA security requirements have been described by the Department of Health and Human Services, ArticSoft, HIPAAacademy.net and the Centers for Medicare & Medicaid Services (CMS).

HIPAA security rules essential to protect data, say experts. The HIPAA security rules force healthcare firms to protect sensitive healthcare information. The security rules could guard against identity theft and data security breaches, say IT pros and industry experts.

HIPAA security rules apply to firms with healthcare plans.Companies that offer healthcare plans are affected by the HIPAA security rules.

Hunter said his job starts with a data flow analysis that identifies areas where data must be better protected at rest and in transit.

"HIPAA is great at telling you what to do but not how to do it," Hunter said. "It says you need encryption, but doesn't say how to implement and manage it. There's always that interpretation challenge."

Most of the companies Hunter deals with aren't technologically oriented. "The human resources department is not going to understand the technical requirements of encryption and access control," he said. "We come in and try to help the different departments come together and have a process: to triangulate."

Hunter said it's surprising how many companies are turning to outside organizations for help. Despite the challenges, he thinks Watson Wyatt's clients will be on target for April 21. "Every one of them will at least have the pieces in place," he said. "The problem will be that ongoing interpretation challenge."

The good news is that the interpretation issue gives companies leeway to do things in a way they can best afford, he said.

Sound Off! -   Post your comments |  See others' comments (1)


Tags: HIPAAVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts