I'm trying to understand all rules for HIPAA compliant software.
I have found a great article about that How do I become HIPAA compliant? but I don't clearly understand some of these points.
For example Technical Safeguards:
2. Access Control - Emergency Access Procedure (required): Establish
(and implement as needed) procedures for obtaining necessary ePHI during an emergency.
What does it mean ? Is it something like forgot password functionality or something else ?
4. Access Control - Encryption and Decryption (addressable):
Implement a mechanism to encrypt and decrypt ePHI.
Should I encrypt all ePHI at database level, even when using AWS RDS( HIPAA-eligible services) ?
5. Audit Controls (required): Implement hardware, software, and/or
procedural mechanisms that record and examine activity in information
systems that contain or use ePHI.
Where the logs should be stored and in what form (database, files, encrypted)? Who is allowed to view this information ?
8. Transmission Security - Integrity Controls (addressable):
Implement security measures to ensure that electronically
transmitted ePHI is not improperly modified without detection until disposed of.
9. Transmission Security - Encryption (addressable):
Implement a mechanism to encrypt ePHI whenever deemed appropriate.
Is it enough to use HTTPS protocol for interprocess communication between all services of the system ?
Aucun commentaire:
Enregistrer un commentaire