164.308(a)(1)(ii)(A)Risk Analysis
You have worked out where health information lives in your systems and what could go wrong with it, and written that down.
Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the organisation.
Required - there is no alternative route to satisfying this one.
164.308(a)(1)(ii)(B)Risk Management
You have acted on what the risk assessment found, rather than filing it and moving on.
Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.
Required - there is no alternative route to satisfying this one.
164.308(a)(1)(ii)(C)Sanction Policy
Your team knows what happens if someone ignores the security rules, and it is written down before it is needed.
Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the organisation.
Required - there is no alternative route to satisfying this one.
164.308(a)(1)(ii)(D)Information System Activity Review
Someone reads your access logs and security reports on a regular schedule, rather than only after something has gone wrong.
Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.
Required - there is no alternative route to satisfying this one.
164.308(a)(2)Assigned Security Responsibility
One named person is responsible for security here, and everyone knows who that is. It can be a part-time role, but it cannot be nobody.
Identify the security official who is responsible for the development and implementation of the policies and procedures required of the organisation by the Security Rule.
Required - there is no alternative route to satisfying this one.
164.308(a)(3)(ii)(A)Authorization and/or Supervision
Nobody starts working with health information without being approved for it, or supervised by someone who already is.
Implement procedures for the authorisation and/or supervision of workforce members who work with electronic protected health information or in locations where it might be accessed.
Addressable - you may implement an equivalent measure, and must document why.
164.308(a)(3)(ii)(B)Workforce Clearance Procedure
Before you give someone access to health records, you check that their job actually needs it.
Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate.
Addressable - you may implement an equivalent measure, and must document why.
164.308(a)(3)(ii)(C)Termination Procedures
When someone leaves, their access to health information goes the same day, and you work from a checklist so nothing is missed.
Implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends.
Addressable - you may implement an equivalent measure, and must document why.
164.308(a)(4)(ii)(A)Isolating Health Care Clearinghouse Functions
If part of your business is a health care clearinghouse, its health information is walled off from the rest of the company. Most organisations are not clearinghouses, and for them this one does not apply.
If a health care clearinghouse is part of a larger organisation, the clearinghouse must implement policies and procedures that protect its electronic protected health information from unauthorised access by the larger organisation.
Required - there is no alternative route to satisfying this one.
164.308(a)(4)(ii)(B)Access Authorization
Someone approves each person's access to health records before it is granted, and you can say who approved what.
Implement policies and procedures for granting access to electronic protected health information, for example through access to a workstation, transaction, program, process, or other mechanism.
Addressable - you may implement an equivalent measure, and must document why.
164.308(a)(4)(ii)(C)Access Establishment and Modification
You review who has access to health information from time to time, and you change it when someone's job changes.
Implement policies and procedures that, based upon the organisation's access authorisation policies, establish, document, review, and modify a user's right of access to a workstation, transaction, program, or process.
Addressable - you may implement an equivalent measure, and must document why.
164.308(a)(5)(ii)(A)Security Reminders
Your team hears about security more than once a year, in short reminders they actually read.
Provide periodic security updates to members of the workforce as part of the security awareness and training programme.
Addressable - you may implement an equivalent measure, and must document why.
164.308(a)(5)(ii)(B)Protection from Malicious Software
Your computers are protected against malware, and your team knows who to tell when something looks wrong.
Implement procedures for guarding against, detecting, and reporting malicious software.
Addressable - you may implement an equivalent measure, and must document why.
164.308(a)(5)(ii)(C)Log-in Monitoring
You would notice a run of failed log-in attempts on an account that reaches health information, and someone would look into it.
Implement procedures for monitoring log-in attempts and reporting discrepancies.
Addressable - you may implement an equivalent measure, and must document why.
164.308(a)(5)(ii)(D)Password Management
You have rules for how passwords are created and kept safe, and people are not sharing one login between them.
Implement procedures for creating, changing, and safeguarding passwords.
Addressable - you may implement an equivalent measure, and must document why.
164.308(a)(6)(ii)Response and Reporting
When something goes wrong you act on it, limit the damage, and write down what happened and what you did about it.
Identify and respond to suspected or known security incidents; mitigate, to the extent practicable, harmful effects of security incidents that are known to the organisation; and document security incidents and their outcomes.
Required - there is no alternative route to satisfying this one.
164.308(a)(7)(ii)(A)Data Backup Plan
You keep backups of your health information, and you could get an exact copy back if the original were lost.
Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information.
Required - there is no alternative route to satisfying this one.
164.308(a)(7)(ii)(B)Disaster Recovery Plan
You have written down how you would restore lost health information, so the steps are not being invented on a bad day.
Establish (and implement as needed) procedures to restore any loss of electronic protected health information data.
Required - there is no alternative route to satisfying this one.
164.308(a)(7)(ii)(C)Emergency Mode Operation Plan
You know how you would keep looking after people, and keep their information safe, while your main systems were down.
Establish (and implement as needed) procedures to enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode.
Required - there is no alternative route to satisfying this one.
164.308(a)(7)(ii)(D)Testing and Revision Procedures
You have tested your recovery plan rather than assuming it works, and you updated it with what the test showed.
Implement procedures for periodic testing and revision of contingency plans.
Addressable - you may implement an equivalent measure, and must document why.
164.308(a)(7)(ii)(E)Applications and Data Criticality Analysis
You know which systems and records you would need back first, and which ones could wait a week.
Assess the relative criticality of specific applications and data in support of other contingency plan components.
Addressable - you may implement an equivalent measure, and must document why.
164.308(a)(8)Evaluation
You check on a regular schedule whether your safeguards still match how you work now, and you write down what you found.
Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under the Security Rule and subsequently in response to environmental or operational changes affecting the security of electronic protected health information, that establishes the extent to which the organisation's security policies and procedures meet the requirements of the Security Rule.
Required - there is no alternative route to satisfying this one.
164.308(b)(3)Written Contract or Other Arrangement
Every outside company that touches your health information has signed a business associate agreement, and you can put your hands on the signed copy.
Document the satisfactory assurances required of a business associate, or of a subcontractor, through a written contract or other arrangement that meets the applicable requirements of 45 CFR 164.314(a). This is the single implementation specification of the business associate standard at 45 CFR 164.308(b)(1) and (b)(2).
Required - there is no alternative route to satisfying this one.