An Important Overview of The Security Rule

By Houeida Saad, General Counsel, Privacy Officer on 12/6/17 2:01 PM

GettyImages-512543170-252115-edited.jpg
Last month, I addressed The Health Insurance Portability and Accountability Act of 1996 (HIPAA)’s Privacy Rule. In addition to the Privacy Rule, Congress mandated through HIPAA that the Secretary of the U.S. Department of Health and Human Services (HHS) publish regulations --
The Security Standards for the Protection of Electronic Protected Health Information (the Security Rule)  which establishes a national set of security standards for protecting certain health information that is held or transferred in electronic form.

The Security Rule operationalizes the protections contained in the Privacy Rule by addressing the technical and non-technical safeguards that organizations called “covered entities” must put in place to secure individuals’ “electronic protected health information” (e-PHI). The Office for Civil Rights (OCR), which is within Health and Human Services (HHS), has responsibility for enforcing the Privacy and Security Rules with voluntary compliance activities and civil money penalties.

The Security Rule, was published February 20, 2003 and specifies a series of administrative, technical, and physical security procedures for covered entities to use to assure the confidentiality, integrity, and availability of e-PHI.  The Security Rule applies to health plans, health care clearinghouses, and to any health care provider who transmits health information in electronic form in connection with a transaction for which the Secretary of HHS has adopted standards under HIPAA (the “covered entities”) and to their business associates.  The Security Rule does not apply to protected health information (PHI) transmitted orally or in writing—that is covered under the Privacy Rule. 

The Security Rule was further expanded when HHS developed regulations relating to business associate obligations and business associate contracts as required by The HITECH Act of 2009.  Now, both covered entities and business associates have obligations under the Security Rule. 

The rule requires Risk Analysis and Management; Administrative Safeguards; Physical Safeguards snf and Technical Safeguards which are set forth in detail for covered entities to follow and those applicable to Business Associates. 

URAC does not receive, store nor accept PHI or electronic-PHI.  URAC maintains all the Business Associate requirements of the Security Rule.  If you have questions, do not hesitate to contact Legal or our IT Department for further questions. 

Comments Policy: We welcome your comments to our articles. Comments not relevant to the posted topic, contain profanity, offensive or abusive language, or that attack a person individually, will be deleted. We reserve the right to delete any comments submitted to this blog without notice.