{"id":1087,"date":"2017-03-21T17:45:01","date_gmt":"2017-03-21T14:45:01","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=1087"},"modified":"2021-06-24T20:21:51","modified_gmt":"2021-06-24T17:21:51","slug":"hipaa-basics-and-the-role-of-dlp-in-meeting-compliance","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/hipaa-basics-and-the-role-of-dlp-in-meeting-compliance\/","title":{"rendered":"HIPAA Basics and The Role of DLP in Meeting Compliance"},"content":{"rendered":"<p>Health-related data is moving more and more from paper to electronic records, determining changes in how healthcare organizations or other industries processing healthcare records are managing and protecting their data today. Businesses that are involved in any way with the use or management of PHI (personal health information) of individuals, need to ensure that they secure their sensitive data against\u00a0loss or leakage, by following security guidelines, like HIPAA, in order to avoid penalties.<\/p>\n<h2>What is HIPAA<\/h2>\n<p>Health Insurance Portability and Accountability Act of 1996, HIPAA, provides data privacy and security measures for protecting medical information. The legislation is designed to protect the ePHI (electronic protected health information) of individuals, like Social Security Numbers, medical ID numbers, credit card numbers, drivers\u2019 license numbers, home address, telephone numbers, medical records,\u00a0and other critical data.<br \/>\nIn 2009, the legislation was updated with HITECH (Health Information Technology for Economic and Clinical Health), that brings additional compliance standards to businesses linked to healthcare.<\/p>\n<h2>What organizations\u00a0are affected by HIPAA<\/h2>\n<p>The\u00a0organizations\u00a0affected by HIPAA are those that create, store, process, transmit or touch protected health information of individuals.<br \/>\nThis legislation does not only apply to healthcare companies, but also to businesses that are associated with them, like attorney firms, IT companies, accounting firms, billing companies, health insurance companies, community health management information systems, etc.<\/p>\n<blockquote><p>Read our\u00a0<a href=\"https:\/\/www.endpointprotector.com\/resources\/case-studies\/spectrum-of-hope-usa-en\" target=\"_blank\" rel=\"noopener noreferrer\">Case Study<\/a>\u00a0on a healthcare provider\u00a0that\u00a0managed to meet the strict HIPAA laws for protecting patient data\u00a0with Endpoint Protector DLP.<\/p><\/blockquote>\n<h2>The HIPAA key points<\/h2>\n<p>The three rules of HIPAA: Privacy, Security, and Breach Notification\u00a0are meant to protect the privacy and security of health information and provide individuals with certain rights to their health\u00a0records.<\/p>\n<p>According to\u00a0<a href=\"https:\/\/www.cms.gov\/\" target=\"_blank\" rel=\"noopener noreferrer\">cms.gov<\/a>:<\/p>\n<h3><em>The Privacy Rule<\/em><\/h3>\n<p><em>It sets national standards for when protected health information (PHI) may be used and disclosed.<\/em><br \/>\n<em>PHI includes information related to:<\/em><\/p>\n<ul>\n<li><em>The individual\u2019s past, present, or future physical or mental health or condition<\/em><\/li>\n<li><em>The provision of healthcare to the individual<\/em><\/li>\n<li><em>The past, present or future payment for the provision of healthcare to the individual<\/em><\/li>\n<li><em>PHI includes many common identifiers, such as name, address, birth date, and Social Security number.<\/em><\/li>\n<\/ul>\n<h3><em>The Security Rule<\/em><\/h3>\n<p><em>It specifies safeguards that covered entities and their business associates must implement to protect the confidentiality, integrity, and availability of electronic protected health information (ePHI).<\/em><br \/>\n<em>Covered entities must:<\/em><\/p>\n<ul>\n<li><em>Ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain or transmit<\/em><\/li>\n<li><em>Identify and protect against reasonably anticipated threats to the security or integrity of the ePHI<\/em><\/li>\n<li><em>Protect against reasonably anticipated, impermissible uses or disclosures<\/em><\/li>\n<li><em>Ensure compliance by their workforce<\/em><\/li>\n<\/ul>\n<h3><em>The Breach Notification Rule<\/em><\/h3>\n<p><em>It requires covered entities to notify affected individuals, U.S. Department of Health &amp; Human Services (HHS), and in some cases, the media of a breach of unsecured PHI.<\/em><br \/>\n<em>Most notifications must be provided no later than 60 days after the discovery of a breach. Notifications of smaller breaches affecting fewer than 500 individuals may be submitted to HHS annually.<\/em><\/p>\n<h2>Data Breaches and Penalties<\/h2>\n<p>A recent\u00a0<a href=\"https:\/\/ocrportal.hhs.gov\/ocr\/breach\/breach_report.jsf\" target=\"_blank\" rel=\"noopener noreferrer\">study<\/a>\u00a0shows that 2016 was the year with the all-time highest number of HIPAA violation cases, since 2009. The most causes of the data breaches were bad security policies or the lack of interest in data security issues. Phishing e-mails, credit card data breach, stolen laptops, patient data leakage, etc., are just a few examples of last year\u2019s main causes of data breaches in healthcare.<br \/>\nPenalties for HIPAA non-compliance can reach from $50K to $1.5 million per year.<\/p>\n<h2>How DLP helps\u00a0meeting HIPAA compliance<\/h2>\n<p>In the healthcare industry, it\u2019s absolutely necessary to ensure that the information is secured and it can only be accessed on a \u201cneed to know\u201d basis.\u00a0Healthcare and personal records mustn&#8217;t leave the health provider&#8217;s or associated companies&#8217; premises unless it is encrypted or transmitted to secure, authorized channels.\u00a0<a href=\"https:\/\/www.endpointprotector.com\/solutions\/healthcare\" target=\"_blank\" rel=\"noopener noreferrer\">Data Loss Prevention solutions<\/a>\u00a0are a big help in that direction.<\/p>\n<p>DLP\u00a0allows organizations\u00a0to monitor and control data movement.\u00a0It\u00a0can scan documents before\u00a0they are being transferred and block them in case they contain sensitive information, such as Health Insurance Numbers, Social Security Numbers, Addresses, etc.<br \/>\nWith a DLP solution,\u00a0IT Administrators can detect and prevent\u00a0users\u00a0from sending e-mails that could contain PHI, detect and prevent from copying\u00a0PHI on\u00a0portable\u00a0storage devices, get reports with detected incidents, and many other actions.<\/p>\n<p>Here&#8217;s a breakdown of policies performed by\u00a0<a href=\"https:\/\/www.endpointprotector.com\/products\/endpoint-protector\" target=\"_blank\" rel=\"noopener noreferrer\">Endpoint Protector<\/a>\u00a0DLP with regards to healthcare sensitive data:<\/p>\n<ul>\n<li>Tracking and blocking of transfers of documents containing FDA recognized drugs, pharmaceutical firms, ICD-10 and ICD-9 codes and diagnosis lexicon<\/li>\n<li>Monitoring and blocking transfers of information containing Personally Identifiable Information: e-mail, address, phone number, Social Security Number (SSN), driver license, tax ID, passport number, and others<\/li>\n<li>Detecting and blocking HIPAA protected information in e-mail body (Outlook, Mozilla Thunderbird, IBM Lotus Notes) and attachment (Outlook, Mozilla Thunderbird, IBM Lotus, Windows Live Mail, Opera Mail, and other e-mail clients)<\/li>\n<li>Scanning documents and content for specific healthcare keywords added by IT Administrators in dictionaries and stopping transfers in case confidential data is found<\/li>\n<li>Using report-only policies to monitor users&#8217; activity related to data transfers and restrict transfers based on discovered information<\/li>\n<li>Creating whitelists based on file, file location, network share, e-mail domain and URL name so employees can conduct their daily tasks without interruptions<\/li>\n<li>Including in HIPAA policies other exit channels besides e-mail such as: web-browsers, cloud file sharing, instant messaging, social media, portable storage devices, network shares, copy\/paste, printers or print screens<\/li>\n<\/ul>\n<p>Besides Data Loss Prevention solutions,\u00a0organizations in\u00a0the\u00a0healthcare industry,\u00a0but not limited\u00a0to this, must have a layered protection,\u00a0using\u00a0multiple security\u00a0tools,\u00a0starting from antivirus software, firewalls, to encryption,\u00a0<a href=\"https:\/\/www.endpointprotector.com\/products\/mobile-device-management\" target=\"_blank\" rel=\"noopener noreferrer\">Mobile Device Management<\/a>, and others.\u00a0Above all these, periodical risk assessments and audits (preferably with external auditors) must be performed, not only to assess the level of compliance, but also the efficiency of implemented security solutions.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Health-related data is moving more and more from paper to electronic records, determining changes in how healthcare organizations or other industries processing healthcare records are managing and protecting their data today. Businesses that are involved in any way with the use or management of PHI (personal health information) of individuals, need to ensure that they &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/hipaa-basics-and-the-role-of-dlp-in-meeting-compliance\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;HIPAA Basics and The Role of DLP in Meeting Compliance&#8221;<\/span><\/a><\/p>\n","protected":false},"author":8,"featured_media":1088,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[115,1,161],"tags":[],"class_list":["post-1087","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","category-data-loss-prevention","category-healthcare","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/1087","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=1087"}],"version-history":[{"count":8,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/1087\/revisions"}],"predecessor-version":[{"id":3356,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/1087\/revisions\/3356"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/1088"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=1087"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=1087"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=1087"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}