|   |
|
|
Home » Articles & News » HIPAA Email Security Management in Email Communications
HIPAA Email Security Management in Email CommunicationsBy Brenda K. Burton and Erik Kangas, PhDRelated Information (PDF Downloads)
• HIPAA Email Security Management in Email Communications
• LuxSci PDF Portfolio
open all sections | close all sections
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Standard: ADMINISTRATIVE SAFEGUARDS | Sections | Implementation Specification | Required or Addressable |
| Security Management Process | 164.308(a)(1) | Risk Analysis | R |
| Risk Management | R | ||
| Sanction Policy | R | ||
| Information System Activity Review | R | ||
| Assigned Security Responsibility | 164.308(a)(2) | R | |
| Workforce Security | 164.308(a)(3) | Authorization and/or Supervision | A |
| Workforce Clearance Procedures | R | ||
| Termination Procedures | A | ||
| Information Access Management | 164.308(a)(4) | Isolating Health Care Clearinghouse Function | R |
| Access Authorization | A | ||
| Access Establishment and Modification | A | ||
| Security Awareness and Training | 164.310(a)(5) | Security Reminders | A |
| Protection from Malicious Software | A | ||
| Log-in Monitoring | A | ||
| Password Management | A | ||
| Security Incident Procedures | 164.308(a)(6) | Response and Reporting | R |
| Contingency Plan | 164.308(a)(7) | Data Backup Plan | R |
| Disaster Recovery Plan | R | ||
| Emergency Mode Operation Plan | R | ||
| Testing and Revision Procedure | A | ||
| Applications and Data Criticality Analysis | A | ||
| Evaluation | 164.308(a)(8) | R | |
| Business Associates Contracts and Other Arrangement. | 164.308(b)(1) | Written Contract or Other Arrangement | R |
| Standard: PHYSICAL SAFEGUARDS | Sections | Implementation Specification | Required or Addressable |
| Facility Access Controls | 164.310(a)(1) | Contingency Operations | A |
| Facility Security Plan | A | ||
| Access Control and Validation Procedures | A | ||
| Maintenance Records | A | ||
| Audit Controls | 164.312(b) | R | |
| Integrity | 164.312(c)(1) | Mechanism to Authenticate EPHI | A |
| Workstation Use | 164.310(b) | R | |
| Workstation Security | 164.310(c) | R | |
| Device and Media Controls | 164.310(d) | Disposal | R |
| Media Re-use | R | ||
| Accountability | A | ||
| Data Backup and Storage | A |
The security risks for email commonly include unauthorized interception of messages en route to recipient and messages being delivered to unauthorized recipients. These risks in using the Internet are addressed in the Security Rule's technical safeguards section, particularly:
Each healthcare organization using email services must determine, based on technologies used for electronic transmission of protected health information, how the Security standards are met.
Addressable specifications include automatic logoff, encryption, and decryption. Covered entities must also assess organizational risks to determine if the implementation of transmission security which includes integrity controls to ensure electronically-transmitted PHI is not improperly modified without detection is applicable. Encryption of ePHI is also addressable and not a requirement under HIPAA regulations, however, a heightened emphasis has been placed on encryption due to the risks and vulnerabilities of the Internet.
Ultimately, according to the Department of Health and Human Services, a covered entity can exercise one of the following options in regard to addressable specifications:
Reasonable and appropriate relate to each organization's technical environment and the security measures already in place.
When your organization is responsible for critical data such as protected health information, choosing an email provider is more than a matter of trust. Does the email service provider build on the administrative, physical and technical safeguards while delivering to its customers:
Lux Scientiae (LuxSci for short) offers secure, premium email services including extensive security features, Spam and virus filtering, robustness, and superior customer service. Their offerings are scalable to any size healthcare organization. With consistent management on LuxSci's part, your small practice or large organization will experience true security. Take a look at the table below to see examples of how LuxSci is able to meet HIPAA's requirements for protecting electronic communications in your organization.
| Standard: TECHNICAL SAFEGUARDS | Sections | Implementation Specification | R/A? |
| Access Control | 164.312(a)(1) | Unique User Identification | R |
| HIPAA COMPLIANT SOLUTION from LuxSci | |||
|
The Rule States: "Assign a unique name and/or number for
identifying and tracking user identity." Solution: Use of unique usernames and passwords for all distinct user accounts. | |||
| Standard: TECHNICAL SAFEGUARDS | Sections | Implementation Specification | R/A? |
| Emergency Access Procedure | R | ||
| HIPAA COMPLIANT SOLUTION from LuxSci | |||
| The Rule States: "Establish (and implement as needed)
procedures for obtaining necessary electronic protected health information
during an emergency" Solution: PHI in email communications can be accessed from any location via the Internet. There are also mechanisms for authorized administrative access to account data. | |||
| Standard: TECHNICAL SAFEGUARDS | Sections | Implementation Specification | R/A? |
| Automatic Logoff | A | ||
| HIPAA COMPLIANT SOLUTION from LuxSci | |||
| The Rule States: "Implement electronic
procedures that terminate an electronic session after a predetermined time
of inactivity." Solution: An organization can set screen savers on their desktops to log users out. Additionally, WebMail automatically logs off all users after a predetermined amount of time; this session time is user- and account-configurable. | |||
| Standard: TECHNICAL SAFEGUARDS | Sections | Implementation Specification | R/A? |
| Encryption and Decryption | A | ||
| HIPAA COMPLIANT SOLUTION from LuxSci | |||
| The Rule States: Implement a mechanism to
encrypt and decrypt electronic protected health information. Solution: All usernames, passwords, and all other authentication data can be encrypted during transmission to and from LuxSci's servers and our clients. Additionally, SecureLine permits end-to-end encrypted email communications with anyone on the Internet. | |||
| Standard: TECHNICAL SAFEGUARDS | Sections | Implementation Specification | R/A? |
| Audit Controls | 164.312(b) | R | |
| HIPAA COMPLIANT SOLUTION from LuxSci | |||
| The Rule States: "Implement hardware, software, and/or
procedural mechanisms that record and examine activity in information
systems that contain or use electronic protected health
information." Solution: Detailed audit trails of logins to all POP, IMAP, SMTP, LDAP, SecureLine,and WebMail services are available to users and administrators. These include the dates, times, and the IP addresses from which the logins were made. Auditing of all sent and received email messages is also available. SecureLine also permits auditing of when messages have been read. | |||
| Standard: TECHNICAL SAFEGUARDS | Sections | Implementation Specification | R/A? |
| Integrity | 164.312(c)(1) | Mechanism to Authenticate EPHI | A |
| HIPAA COMPLIANT SOLUTION from LuxSci | |||
| The Rule States: "Implement policies and procedures to
protect electronic protected health information from improper alteration or
destruction." "Implement electronic mechanisms to corroborate that electronic protected health information has not been altered or destroyed in an unauthorized manner." Solution: To prevent unauthorized alteration or destruction of PHI, the use of SSL and SecureLine will verify message integrity. | |||
| Standard: TECHNICAL SAFEGUARDS | Sections | Implementation Specification | R/A? |
| Person or Entity Authentication | 164.312(d) | R | |
| HIPAA COMPLIANT SOLUTION from LuxSci | |||
| The Rule States: "Implement
procedures to verify that a person or entity seeking access to electronic
protected health information is the one claimed." Solution: Username and Password are used for access control; strict control is given over who can access user's accounts. LuxSci's privacy policy strictly forbids any access of email data without explicit permission of the user (unless there are extenuating circumstances). Also, use of SecureLine end-to-end encryption in email and document storage ensures that only the intended recipient(s) of messages or stored documents can ever access them. | |||
| Standard: TECHNICAL SAFEGUARDS | Sections | Implementation Specification | R/A? |
| Transmission Security | 164.312(e)(1) | Integrity Controls | A |
| HIPAA COMPLIANT SOLUTION from LuxSci | |||
| The Rule States:
"Implement technical security measures to guard against unauthorized
access to electronic protected health information that is being
transmitted over an electronic communications network." "Implement security measures to ensure that electronically transmitted electronic protected health information is not improperly modified without detection until disposed of" Solution: SSL-based encryption during the transmission of data to/from our clients for WebMail, POP, IMAP, SMTP, and document storage services is provided. TLS-based encryption of inbound email at LuxSci ensures that all email sent internally at LuxSci meets "Transmission Security" guidelines and allows you to securely receive email from other companies whose servers also support TLS. LuxSci also provides SecureLine for true end-to-end encryption of messages to/from non-clients. | |||
| Standard: TECHNICAL SAFEGUARDS | Sections | Implementation Specification | R/A? |
| Encryption | A | ||
| HIPAA COMPLIANT SOLUTION from LuxSci | |||
|
The Rule States: "Implement a mechanism to encrypt electronic
protected health information whenever deemed appropriate." Solution: SSL encryption for WebMail, POP, IMAP and SMTP services is provided. Additional services, such as encrypted document and data storage and SecureLine for end-to-end security are also available. | |||
| Standard: TECHNICAL SAFEGUARDS | Sections | Implementation Specification | R/A? |
| Device and Media Controls | 164.310(d) | Data Backup and Storage | R |
| HIPAA COMPLIANT SOLUTION from LuxSci | |||
| The Rule States: "Create a retrievable, exact copy of
electronic protected health information, when needed, before movement of
equipment." Solution: Daily on-site and weekly off-site backups ensure exact copies of all PHI are available. Live data is stored on redundant RAID-5 disk arrays for added protection. Furthermore, Premium Email Archival provides permanent, immutable storage on servers in three geographic locations, with weekly backups to optical media stored in vaults. | |||
| Standard: TECHNICAL SAFEGUARDS | Sections | Implementation Specification | R/A? |
| Data Disposal | R | ||
| HIPAA COMPLIANT SOLUTION from LuxSci | |||
| The Rule States: "Implement policies and procedures to address the final disposition of electronic protected health information, and/or the hardware or electronic media on which it is stored." Solution: Clients can delete their data whenever desired. Additional security comes in automatic expiration of data backups (cease to exist after 1 month). Alternate expiration plans are available for large clients. | |||
Healthcare staff using LuxSci can send and receive email from anywhere in the world using existing or new email clients or web browsers. Meet HIPAA's Security Standards with fierce firewalls and intrusion detection. A comprehensive solution for a complex law - managed by your account administrators in-house or remotely by our company. Risk assessments for potential HIPAA violations can be performed by administrators through the use of audit trails. Reliability and cost effective solutions are the backbone of LuxSci - even for extremely large client organizations. And, count on the physical security of our servers (the same server location the U.S. Olympic Committee employed in Salt Lake City!).
If you are interested in specific services at LuxSci and would like to know exactly which of the HIPAA rules each service meets, the following charts will assist you. Please contact LuxSci for more information.
| HIPAA Rule | 1. View Email with Secure WebMail, POP, or IMAP | 2. Send Email with Secure WebMail or SMTP | 3. End-to-End Encryption with SecureLine combined with 1 and 2 | 4. Secure Collaboration (WebAides) |
| Access Control - Unique User Identification | ![]() |
![]() |
![]() |
![]() |
| Access Control - Emergency Access | ![]() |
![]() |
(a) |
(a) |
| Access Control - Automatic Logoff | ![]() |
![]() |
![]() |
![]() |
| Audit Controls | ![]() |
![]() |
![]() |
![]() |
| Integrity | ![]() |
![]() |
(b) |
(b) |
| Person or Entity Authentication | ![]() |
![]() |
(b) |
(b) |
| Transmission Security > Integrity Controls | (c) |
(c) |
![]() |
![]() |
| Transmission Security > Encryption | (c) |
(c) |
![]() |
![]() |
| Device and Media Controls > Data Backups | ![]() |
![]() |
![]() |
![]() |
| Device and Media Controls > Data Disposal | ![]() |
![]() |
![]() |
![]() |
(a) Our secure document storage service and use of SecureLine for communications may assume that the recipients have special passwords for their "Secure data access certificates" (PGP or S/MIME). These passwords are may be stored in "Escrow" in a special secure password database if the users so choose. In these cases, passwords can be retrieved in case of emergency or in case of loss.(b) Our secure document storage service and use of SecureLine for communications encrypts data so that only the intended recipient(s) can ever view the data. The encryption process also allows the recipient(s) to verify that the data was not altered since it was sent or stored.
(c) SSL/TLS solutions encrypt the message during transport to and from LuxSci's servers and your personal computer. Email sent from LuxSci to external addresses is not necessarily secured without the use of SecureLine (Solution #3).
Solutions #3 provides complete transport layer and end-to-end email security compatible with any email user anywhere, no matter what software s/he may have.
Health Insurance Reform: Security Standards - Federal Register, Vol. 68, No. 34, 45 CFR Parts 160, 162, 164.
|
|
|
|
Listen to Our Clients:"I wanted to congratulate you on your service; the reduction in Spam is incredible, and the speed of delivery is stunning. I am recommending you to all of my friends and associates! You can quote me on that!" Victor Pikula, CTO of Mobile Media International |
about us |
services |
quotes & orders |
privacy |
contact us |
site map |
login |
xpress
Copyright © 2004-2008 Lux Scientiae®, Incorporated