HIPAA Compliance News

Is Zoom a HIPAA Compliant Video and Web Conferencing Platform?

Zoom is a popular video and web conferencing platform that has been adopted by more than 750,000 businesses, but is the service suitable for use by healthcare organizations for sharing PHI. Is Zoom HIPAA compliant?  

What is Zoom?

Zoom is a cloud-based video and web conferencing platform that allows workers across multiple locations to take part in meetings, share files, and collaborate. The platform supports webinars and includes a business IM service.

Zoom has already been adopted by many healthcare organizations around the globe who use the platform to consult with other providers and communicate with patients. However, in the United States, healthcare providers must comply with HIPAA Rules.

Any software solution must incorporate a host of security protections to ensure protected health information (PHI) is safeguarded. Further, cloud-based platform providers are classed as a business associates and are also required to comply with HIPAA Rules if their platforms are to be used in conjunction with PHI.

Zoom and HIPAA Compliance

As a business associate, Zoom would be required to enter into a contract with a HIPAA covered entity before its service can be used with ePHI. That contract – a Business Associate Agreement – serves as a confirmation that Zoom is aware of its responsibilities with regards to the privacy and security of PHI.

Zoom is prepared to sign a business associate agreement with healthcare organizations and has ensured that its platform incorporates all of the necessary security controls to meet the strict requirements of HIPAA.

In April 2017 Zoom announced that it had launched the first scalable cloud-based telehealth service for the healthcare industry. Zoom for Telehealth allows enterprises and providers to communicate easily with other organizations, care teams, and patients in a HIPAA compliant manner.

The service incorporates access and authentication controls, all communications are secured with end-to-end AES-256 bit encryption, and the platform integrates with the Epic electronic health record system to support healthcare workflows.

This year Zoom announced that it has partnered with a global telehealth integrator and that its platform has been further enhanced to support full enterprise healthcare workflows.

Is Zoom HIPAA Compliant?

Zoom is a HIPAA compliant web and video conferencing platform that is suitable for use in healthcare, provided a HIPAA-covered entity enters into a business associate agreement with Zoom prior to using the platform.

It is still possible for HIPAA Rules to be violated using the platform so users must be aware of their responsibilities with respect to patient privacy, and must only share or communicate PHI with individuals authorized to receive the information. It is the responsibility of the covered entity to ensure Zoom is used correctly and HIPAA Rules are always followed.

The post Is Zoom a HIPAA Compliant Video and Web Conferencing Platform? appeared first on HIPAA Journal.

Is WebEx HIPAA Compliant?

Is WebEx HIPAA compliant? Is the online meeting and web conferencing platform suitable for use by healthcare organizations or should the service be avoided? In this post we assess the security controls and features of the platform and determine whether use of WebEx could be considered a HIPAA violation.

What is WebEx?

WebEx is a web and video conferencing and collaboration platform that helps businesses connect with remote workers and partners as if they are in the same room.

With tools such as WebEx, healthcare organizations can communicate quickly and easily with the workforce, no matter where employees are located. Regional operational meetings can be conducted, medical education can take place online, and healthcare employees can be trained on new processes and procedures. These platforms can also potentially be used for communicating with patients.

However, before any collaboration tools can be used in connection with protected health information (PHI), healthcare organizations must be certain that the tools support HIPAA compliance. So how does WebEx fare in this regard? Is WebEx HIPAA compliant or should the platform be avoided by HIPAA-covered entities?

WebEx Security

Cisco has implemented a host of security controls to ensure all communications take place securely and information cannot be intercepted. Any information sent from a WebEx application to the WebEx cloud occurs through an encrypted channel which supports TLS 1.0, 1.1 and 1.2 protocols and uses high strength ciphers such as AES-256. Media packets are encrypted using AES 128. There is also the option of end-to-end encryption, which if applied, means Cisco will not decrypt any media streams.

All media streams can be recorded for future reference and meet HIPAA audit requirements. Data is also protected at rest with encryption and audio, video, and data streams are stored separately.

Administrators can configure the platform to provide the desired level of security, including rate limiting on login attempts, the automatic deactivation of accounts after a defined period of inactivity, password policies can be enforced, 2-factor authentication can be used, and strict access controls set to carefully control who has access to the platform.

Cisco also provides full documentation on functionality, technology, and security to help healthcare organizations with their risk assessments.

Cisco will also sign a business associate agreement with HIPAA covered entities and their business associates.

Is WebEx HIPAA Compliant?

WebEx incorporates administrative and technical safeguards that meet HIPAA requirements; however, it is up to covered entities to ensure the platform is configured correctly and that it is used in a manner compliant with HIPAA Rules.

Provided that is the case, and a business associate agreement has been entered into with Cisco covering the use of WebEx for Healthcare, WebEx is HIPAA compliant and can be used by healthcare organizations.

The post Is WebEx HIPAA Compliant? appeared first on HIPAA Journal.

Is Amazon CloudFront HIPAA Compliant?

Is Amazon CloudFront HIPAA compliant and can the web service be used by HIPAA covered entities without violating HIPAA Rules? In this post we determine whether Amazon CloudFront supports HIPAA compliance or if it should be avoided by HIPAA-covered entities.

What is Amazon CloudFront?

Amazon CloudFront is a web service that allows users to speed up web content delivery over the Internet. Typically, when a website is accessed, the visitor experiences some latency accessing static and dynamic content.

The reason for this is visitors will not make a direct connection to the content, instead they will be routed through a path to reach the server where the content can be accessed. The path can involve many routing points, will inevitably have an impact on the speed at which content can be accessed. By using a content delivery network such as Amazon CloudFront, it is possible to reduce latency and improve reliability and availability of web content.

By delivering content via a network of data centers (edge locations), users are routed to the nearest location with the least latency, thus speeding up their connection. The service also offers a level of protection against DDoS attacks and other cyberthreats that can be harmful to web services.

Is Amazon CloudFront HIPAA Compliant?

In order for any cloud service to be used in conjunction with protected health information, HIPAA-covered entities must enter into a business associate agreement with the service provider. Therefore, before Amazon CloudFront can be deployed, a HIPAA-compliant business associate agreement must be obtained.

Recently, Amazon has updated its HIPAA compliance program and CloudFront has now been included as a HIPAA-eligible service. CloudFront is now included in the list of services covered by the business associate agreement provided for AWS. If you have already executed a BAA for AWS, it is possible to use CloudFront to deliver content containing PHI. However, make sure you check that your BAA specifically states CloudFront is covered.

The service should also be configured to log CloudFront usage data for auditing purposes for HIPAA-compliant workloads. Access logs should be enabled on the platform and requests sent to the CloudFront API should be captured.

Provided a BAA has been obtained for AWS – that includes CloudFront – and the solution is configured correctly, Amazon CloudFront is HIPAA compliant and can be used by healthcare organizations without violating HIPAA Rules.

The post Is Amazon CloudFront HIPAA Compliant? appeared first on HIPAA Journal.

Is Citrix ShareFile HIPAA Compliant?

ShareFile was bought by Citrix Systems in 2011 and the platform is marketed as a suitable data sync, file sharing, and collaboration tool for the healthcare industry, but is Citrix ShareFile HIPAA compliant?

What is Citrix ShareFile?

Citrix ShareFile is a secure file sharing, data storage and collaboration tool that allows large files to be easily shared within a company, with remote workers, and with external partners. The solution allows any authorized individual to instantly access stored documents via desktops and mobile devices.

For healthcare organizations this means the solution can be used to share large files such as DICOM images with researchers, remote healthcare workers, and business associates. The ShareFile patient portal can also be used to share PHI with patients.

Is Citrix ShareFile HIPAA Compliant?

Citrix will sign a business associate agreement with HIPAA covered entities and their business associates that covers the use of FileShare, although it is the responsibility of the covered entity to ensure that the solution is configured correctly and is used in a manner that does not violate HIPAA Rules.

The solution satisfies HIPAA requirements for data security, with appropriate access and authentication controls. Users connect to the solution via an encrypted secure SSL/TLS connection and data is protected at rest with AES 256-bit encryption. The solution also supports encryption on mobile devices. An audit trail is maintained with access logs recording who accessed files, when, and for how long and application errors and events are also logged.

So is Citrix ShareFile HIPAA compliant? The safeguards incorporated into the solution mean the solution does supports HIPAA compliance.

Where HIPAA Covered Entities Must Exercise Caution

Many firms advertise their platforms and software as HIPAA compliant, but that does not mean use does not carry risks. Software solution providers can only build in security and administrative controls that allow their solution to be used in a HIPAA compliant manner. It is the responsibility of users to make sure the solution is configured correctly and HIPAA Rules are not violated.

To avoid HIPAA violations:

  • Ensure a business associate agreement has been obtained prior to the solution being used for storing, syncing, or sharing ePHI
  • Covered entities must perform a risk analysis to determine any potential risks to the confidentiality, integrity, and availability of PHI
  • Ensure encryption is used when sending files to third parties
  • Policies and procedures (administrative safeguards) must be developed covering the use of the solution and staff must be trained
  • Access and authentication controls must be set to restrict access to PHI to only those individuals who are authorized to access information
  • Any PHI shared with third parties must be limited to the minimum necessary data for tasks to be performed
  • Appropriate security controls should be implemented on devices to ensure that in case of theft or loss, the devices cannot be used to gain access to PHI

Citrix offers guidance for covered entities on aspects of HIPAA Rules, how they apply to FileShare, and assistance to ensure HIPAA compliance while using the platform. The information can be accessed on this link.

The post Is Citrix ShareFile HIPAA Compliant? appeared first on HIPAA Journal.

Is eFileCabinet HIPAA Compliant?

eFileCabinet is a document management and storage solution for businesses that offers on-site and cloud storage, but is the service suitable for the healthcare industry? Is eFileCabinet HIPAA compliant or will using the platform be considered a violation of HIPAA Rules?

What are Document Management Systems?

Document management systems allow organizations to carefully manage electronic documents and store them securely in one location. With huge volumes of documents being created, such systems take the stress out of document management and can help HIPAA covered entities share documents containing ePHI securely and avoid HIPAA violations.

There are many document management systems on the market, but not all support HIPAA compliance, so what about eFileCabinet? Is eFileCabinet HIPAA compliant?

eFileCabinet Security and Privacy Controls

Security controls include the encryption of data in transit and at rest with 256-bit encryption. Sensitive data can be securely shared with third-parties and remote employees via the company’s SecureDrawer feature. SecureDrawer allows files to be shared without having to send documents beyond the protection of the firewall. The files remain in the eFileCabinet system and are accessed through a secure, encrypted portal.

eFileCabinet allows user and role-based permissions to be set to limit access to sensitive information as well as restrict what users and user groups can do with documents containing ePHI. Controls can be set with varying levels of user authentication, from simple passwords to voice prints and facial recognition. Users are also automatically logged off after a period of inactivity.

Automated file retention satisfies HIPAA integrity control requirements, data backups are performed, and an audit trail is maintained with records kept of user access, what users have done with documents, and whether documents have been copied or downloaded.

Will eFileCabinet Sign a BAA with HIPAA Covered Entities and their Business Associates?

Privacy and security controls are only one part of HIPAA compliance. Even with all appropriate controls in place, a document management system is not a ‘HIPAA compliant’ service unless a business associate agreement (BAA) has entered into with the service provider. By providing a BAA, the service provider is confirming they have implemented all appropriate controls to ensure data security and are aware of their responsibilities with respect to HIPAA.  eFileCabinet is prepared to sign a BAA with HIPAA covered entities and their business associates.

However, it is up to the covered entity to ensure that all controls made available through eFileCabinet to support HIPAA compliance are configured correctly. Fail to set access controls appropriately, for example, and HIPAA Rules would be violated.

Is eFileCabinet HIPAA Compliant?

In our opinion, eFileCabinet has all the necessary security, access, and audit controls to ensure it can be used by healthcare organizations in a manner compliant with HIPAA Rules. eFileCabinet will also sign a business associate agreement with HIPAA covered entities and their business associates.

So, is eFileCabinet HIPAA compliant? Provided a business associate agreement has been entered into prior to the platform being used for storing or sharing ePHI, eFileCabinet can be considered a HIPAA compliant document management system.

The post Is eFileCabinet HIPAA Compliant? appeared first on HIPAA Journal.

$100,000 Settlement Shows HIPAA Obligations Don’t End When a Business Closes

HIPAA covered entities and their business associates must abide by HIPAA Rules, yet when businesses closes the HIPAA obligations do not end. The HHS’ Office for Civil Rights (OCR) has made this clear with a $100,000 penalty for FileFax Inc., for violations that occurred after the business had ceased trading.

FileFax is a Northbrook, IL-based firm that offers medical record storage, maintenance, and delivery services for HIPAA covered entities. The firm ceased trading during the course of OCRs investigation into potential HIPAA violations.

An investigation was launched following an anonymous tip – received on February 10, 2015 – about an individual that had taken documents containing protected health information to a recycling facility and sold the paperwork.

That individual was a “dumpster diver”, not an employee of FileFax. OCR determined that the woman had taken files to the recycling facility on February 6 and 9 and sold the paperwork to the recycling firm for cash. The paperwork, which included patients’ medical records, was left unsecured at the recycling facility. In total, the records of 2,150 patients were included in the paperwork.

OCR determined that between January 28, 2015 and February 14, 2015, FileFax had impermissibly disclosed the PHI of 2,150 patients as a result of either: A) Leaving the records in an unlocked truck where they could be accessed by individuals unauthorized to view the information or; B) By granting permission to an individual to remove the PHI and leaving the unsecured paperwork outside its facility for the woman to collect.

Since FileFax is no longer in business – the firm was involuntarily dissolved by the Illinois Secretary of State on August 11, 2017 – the HIPAA penalty will be covered by the court appointed receiver, who liquidated the assets of FileFax and is holding the proceeds of that liquidation.

A corrective action plan has also been issued that requires the receiver to catalogue all remaining medical records and ensure the records are stored securely for the remainder of the retention period. Once that time period has elapsed, the receiver must ensure the records are securely and permanently destroyed in accordance with HIPAA Rules.

The settlement has been agreed with no admission of liability.

HIPAA Retention Requirements and Disposal of PHI

There are no HIPAA retention requirements – Covered entities and their business associates are not required to keep medical records after their business has ceased trading. However, that does not mean medical records and PHI can be disposed of immediately. Businesses are bound by state laws, which do require documents to be retained for a set period of time. For instance, in Florida, physicians must maintain medical records for 5 years after the last patient contact and in North Carolina hospitals must maintain records for 11 years following the last date of discharge.

During that time, HIPAA requires appropriate administrative, technical, and physical safeguards to be implemented to ensure those records are secure and remain confidential. After the retention period is over, all PHI must be disposed of in a compliant manner.

In the case of paper records, disposal typically means shredding, burning, pulping, or pulverization. Whatever method chosen must render the documents indecipherable and incapable of reconstruction.

This HIPAA breach is similar to several others that have occurred over the past few years. Businesses have ceased trading and paper records containing the protected health information of patients have been dumped, abandoned, or left unsecured. There have also been cases where businesses have moved location and left paperwork behind, only for contractors performing a cleanup or refurb of the property to find the paperwork and dispose of it with regular trash.

The failure to secure PHI during the retention period and the incorrect disposal of records after that retention period is over are violations of HIPAA Rules that can attract a significant financial penalty.

“The careless handling of PHI is never acceptable,” said OCR Director Roger Severino in a press release about the latest HIPAA settlement. “Covered entities and business associates need to be aware that OCR is committed to enforcing HIPAA regardless of whether a covered entity is opening its doors or closing them. HIPAA still applies.”

The post $100,000 Settlement Shows HIPAA Obligations Don’t End When a Business Closes appeared first on HIPAA Journal.

Is Box HIPAA Compliant?

Is Box HIPAA compliant? Can Box be used by healthcare organizations for the storage of documents containing protected health information or would doing so be a violation of HIPAA Rules? An assessment of the security controls of the Box cloud storage and content management service and its suitability for use in healthcare.

What is Box?

Box is a cloud storage and content management service that supports collaboration and file-sharing. Users can share files, invite others to view, edit or upload content. Box can be used for personal use; however, businesses need to sign up for either a business, enterprise, or elite account.

Is Box Covered by the Conduit Exception Rule?

The HIPAA conduit exception rule was introduced to allow HIPAA covered entities to use certain communications channels without having to obtain a business associate agreement. The conduit exception rule applies to telecoms companies and Internet service providers that act as conduits through which data flows. Cloud storage services are not covered under the HIPAA conduit exception rule, even if those entities claim they never access any data uploaded to their cloud service. Therefore, cloud storage services can only be used if a business associate agreement is entered into with the service provider.

Box and the HIPAA Business Associate Agreement

Box is confident it has put appropriate security controls in place to ensure all customers’ data is secured, both in transit to Box and while stored in the cloud. The company was formed in 2004, although it took nine years for the company to make its move into the healthcare sphere. In April 2013, Box started signing business associate agreements with HIPAA covered entities and their business associates. Box only offers a BAA to HIPAA covered entities if they have an enterprise or elite account.

Box for Healthcare Launched

In addition to agreeing to sign a BAA and having its service verified as supporting HIPAA compliance by an independent auditor, the company has now launched its Box for Healthcare service. The Box for Healthcare service has been developed to integrate seamlessly with top healthcare vendors such as IBM, Microsoft, Apple, TigerText, eHealth Technologies, and EDCO Health apps. The service helps healthcare organizations coordinate care, collaborate with research organizations, and share information securely with third parties outside the protection of the firewall.

The service includes all the necessary security controls to comply with the HIPAA Security Rule including data encryption at rest and in transit, audit controls, and configurable administrative controls that allow customers to monitor access, usage and document edits by employees and third parties, and set appropriate access and authentication controls.

Is Box HIPAA Compliant?

Any cloud service can be used in a manner that violates HIPAA Rules, as HIPAA compliance is more about the people that use a product or service rather than the product or service itself. That said, Box has implemented a wide range of safeguards and controls to ensure data privacy and security. So, is Box HIPAA compliant?

Provided a BAA has been obtained before the platform is used to store documents containing PHI, Box can be considered a HIPAA compliant cloud storage provider. However, it is the responsibility of the covered entity to ensure that the service is configured correctly and HIPAA Rules are followed.

The post Is Box HIPAA Compliant? appeared first on HIPAA Journal.

Timothy Noonan Becomes OCR’s Top HIPAA Enforcer, Replacing Deputy Director Iliana Peters

After just 4 months in the position of deputy director for health information privacy at the Department of Health and Human Services’ Office for Civil Rights, Iliana Peters has departed for the private sector.

Peters took over as deputy director following the departure of acting deputy director Deven McGraw in November, only to leave the post on February 2 to join the healthcare team at law firm Polsinelli.

This is the third major change of staff at the Department of Health and Human Services in a little over four months. First, there was the departure of HHS Secretary Tom Price in late September, McGraw left in October to join health tech startup Citizen, and now Iliana Peters has similarly quit for the private sector.

Peters has been working at the Office for Civil Rights for the past 12 years, including 5 years as a senior advisor. During her time at OCR Peters has worked closely with regional offices helping them enforce HIPAA Rules and has been instrumental in building up OCR’s HIPAA enforcement program.

Peters has trained regional OCR staff on HIPAA enforcement and the handling of cases and played a key role in OCR’s latest enforcement actions – the $3.5 million settlement with Fresenius Medical Care North America over five data breaches reported to OCR in 2012 and the $2.3 million settlement with 21st Century Oncology over its 2015 cyberattack.

Peters has also trained state attorneys general on HIPAA policies and played a key role in the development of OCR’s second phase of HIPAA compliance audits, as well helping with the development of guidance for HIPAA covered entities on HIPAA Privacy and Security Rules.

Now, instead of helping OCR punish organizations for HIPAA violations, Peters will be working on the other side and will be helping healthcare organizations avoid HIPAA violations and OCR penalties.

Peters has become a shareholder at Polsinelli and will be based at its Health Care Operations practice in Washington D.C. According to a February 7 Polsinelli press release. Peters will be helping to develop the law firm’s healthcare presence in DC.

“Iliana brings key insights into the government’s investigation, enforcement, and settlement processes and will enhance our ability to guide our clients in responding to ever-changing threats and risks,” said Polsinelli Health Care Department Chair Matt Murer. “We know that our clients look forward to having Iliana as a strategic member of their privacy and security teams.”

OCR’s southeast regional manager Timothy Noonan was appointed as acting deputy director for health information privacy at OCR on January 29, 2018. Noonan has spent the past four years working as the Southeast regional manager and has served as acting associate deputy director for regional operations and OCR’s acting director for centralized case management operations.

While the loss of Peters will certainly be felt at OCR, there is unlikely to be any easing of OCR’s HIPAA enforcement efforts. OCR’s regional offices have been well trained and will continue to ensure that HIPAA Rules are being followed and action is taken over serious violations of HIPAA Rules.

The post Timothy Noonan Becomes OCR’s Top HIPAA Enforcer, Replacing Deputy Director Iliana Peters appeared first on HIPAA Journal.

What is HIPAA Authorization?

We are often asked to clarify certain elements of HIPAA Rules. One recent question relates to disclosures of protected health information (PHI) and medical records – ‘What is HIPAA authorization?’

What is HIPAA Authorization?

The HIPAA Privacy Rule (effective since April 14, 2003) introduced standards covering allowable uses and disclosures of health information, including to whom information can be disclosed and under what circumstances protected health information can be shared.

The HIPAA Privacy Rule permits the sharing of health information by healthcare providers, health plans, healthcare clearinghouses, business associates of HIPAA-covered entities, and other entities covered by HIPAA Rules under certain circumstances. In general terms, permitted uses and disclosures are for treatment, payment, or health care operations.

HIPAA authorization is consent obtained from a patient or health plan member that permits a covered entity or business associate to use or disclose PHI to an individual/entity for a purpose that would otherwise not be permitted by the HIPAA Privacy Rule. Without HIPAA authorization, such a use or disclosure of PHI would violate HIPAA Rules and could attract a severe financial penalty and may even be determined to be a criminal act.

When is HIPAA Authorization Required?

45 CFR §164.508 details the uses and disclosures of PHI that require an authorization to be obtained from a patient/plan member before information can be shared or used. HIPAA authorization is required for:

  • Use or disclosure of PHI otherwise not permitted by the HIPAA Privacy Rule
  • Use or disclosure of PHI for marketing purposes except when communication occurs face to face between the covered entity and the individual or when the communication involves a promotional gift of nominal value.
  • Use or disclosure of psychotherapy notes other than for specific treatment, payment, or health care operations (see 45 CFR §164.508(a)(2)(i) and (a)(2)(ii))
  • Use or disclosure of substance abuse and treatment records
  • Use or disclosure of PHI for research purposes
  • Prior to the sale of protected health information

What Must Be Included on a HIPAA Authorization Form?

A HIPAA authorization is a detailed document in which specific uses and disclosures of protected health are explained in full.

By signing the authorization, an individual is giving consent to have their health information used or disclosed for the reasons stated on the authorization. Any use or disclosure by the covered entity or business associate must be consistent with what is stated on the form.

The authorization form must be written in plain language to ensure it can be easily understood and as a minimum, must contain the following elements:

  • Specific and meaningful information, including a description, of the information that will be used or disclosed
  • The name (or other specific identification) of the person or class of persons authorized to make the requested use or disclosure
  • The name(s) or other specific identification of the person or class of persons to whom information will be disclosed
  • A description of the purpose of the requested use or disclosure. In cases where a statement of the purpose is not provided, “at the request of the individual” is sufficient
  • A specific time frame for the authorization including an expiration date. In the case of uses and disclosures related to research, “at the end of the study” can be used or ‘none’ in the case of the creation of a research database or research repository
  • A date and signature from the individual giving the authorization. If the authorization is being given by an individual’s authorized representative, a description of the person’s authority to act on behalf of the individual must be detailed.

Statements must also be included on the HIPAA authorization to notify the individual of:

The right to revoke the authorization in writing and either:

  1. Exceptions to the right to revoke and a description of how the right to revoke can be exercised; or
  2. The extent to which the information in A) is included in the organization’s notice of privacy practices

The ability or inability to condition treatment, payment, enrollment, or eligibility for benefits on the authorization by stating either:

  1. That the covered entity may not condition treatment, payment, enrollment or eligibility for benefits on whether the individual signs the authorization; or
  2. The consequences of a refusal to sign the authorization when the covered entity is permitted to condition treatment, enrollment in the health plan, or eligibility for benefits on a failure to obtain authorization.

The individual providing consent must be provided with a copy of the authorization form for their own records.

The post What is HIPAA Authorization? appeared first on HIPAA Journal.