4 ms·
In a sense the name says it all: HIPAA's about Portability and Accountability, less about security. I worked on a few security consulting projects in healthcar
by sjbase 11y ago
In a sense the name says it all: HIPAA's about Portability and Accountability, less about security.
I worked on a few security consulting projects in healthcare. The HIPAA security rule is way more vague about actual controls than a rational person would assume; much more than analogous regulations on financial data (e.g. PCI-DSS). The HITECH amendment added a lot of breadth regarding which parties must comply, but did little to proscribe specific controls. Most providers, contractors, etc. use a framework called HITRUST that attempts to identify and map actual security controls to HIPAA, but even that is not super actionable.
One of the hardest problems to solve is the immediate criticality of patient data. You absolutely cannot have someone die because a nurse or doctor forgot their password and couldn't look up medical history. Makes practitioners resist adoption, and you end up with "break the glass" (emergency security bypass) functionality on a lot of sensitive systems/data.
- dragonwriter 11y ago> The HITECH amendment added a lot of breadth regarding which parties must comply, but did little to proscribe specific controls. I think you mean "prescribe", rather than "proscribe".
- jamra 11y agoHIPAA does require the data to be stored in a secured way. It also requires a certain level of security to get to the data. Don't let the name fool you. Your second point is extremely valid. You can't really restrict a medical professional from looking up health information. It could cause loss of life. Mostly, a large organization can't be expected to lock down the data of an individual. What you can do is log the access (GxP regulations). This means that you will know who accessed the data after the fact.
- dragonwriter 11y ago> HIPAA does require the data to be stored in a secured way. But its extremely unspecific about what that means. > It also requires a certain level of security to get to the data. Less so than you probably think. It has vague high level standards, under which are lower-level implementation specifications (which still tend to be somewhat vague) which may be required or "addressable", which basically means that organizations are required to review whether they are appropriate; the only technical implementation specifications that are required in the security rule are having unique user IDs and having emergency access procedures.