Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Guidelines for HIPAA compliance in the works

A non-profit group is working to devise guidelines for implementing HIPAA security policies

November 24, 2003 12:00 PM ET

Computerworld - Health care organizations looking for more information on how to comply with HIPAA security mandates may soon get more help.
URAC, a nonprofit accreditation agency for the health care industry, along with the Workgroup for Electronic Data Interchange and the National Institute of Standards and Technology, is developing guidelines for implementing HIPAA security policies.
The Healthcare Security Workgroup, which the three organizations created earlier this year, met in Washington last week to discuss how to consolidate industry best practices and security standards into a set of easily implemented instructions. The goal is to give organizations subject to the Health Insurance Portability and Accountability Act something they can use to ensure compliance with the law's security requirements by the April 15, 2005, deadline, said Adam Stone, a member of the workgroup. The group aims to deliver the guidelines by the middle of next year.
"No standard measures exist in the health care industry" to implement HIPAA's security requirements, Stone said. "One of the major problems with the rule is that it is so broad. There are a million different ways to approach it in terms of compliance."
The workgroup will study how it can adopt and adapt NIST's more general security specifications for federal information systems in the health care sector, said Lisa Gallagher, senior vice president of Washington-based URAC. Similarly, the workgroup will gather information on best practices, case studies and other standards efforts by organizations such as the Healthcare Information and Management Systems Society.
"We are going to gather all this information and make it available on a national basis," Gallagher said, by means of white papers and a portal site.
The community feedback that's being collected by the workgroup is also useful in adapting NIST standards for the health care industry, said Arnold Johnson, a NIST program manager in Washington.
"Real standards are very, very [much] needed," said Roger Brown, a senior IT auditor at Jefferson Health System, a $2 billion health care organization in Radnor, Pa. "Only the economically strong [companies] will comply with the intent of the law. Most will spend the absolute minimum they think they can get away with." Standards will provide a formal yardstick for measuring compliance, he said.

HIPAA HIPAA Hooray
The Healthcare Security Workgroup's objectives are to:

BRING TOGETHER key stakeholders from the public and private sectors to facilitate communication and consensus on best practices for information security in health care.
PROMOTE the implementation of a uniform approach to security practices and assessments.


Source: URAC, Washington







Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

Best Practices in Protecting the Technology Systems Revolutionizing Healthcare
With technology infiltrating every aspect of healthcare, traditional approaches to power protection no longer suffice. This paper introduces a new hospital power protection...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

Accelerate SSL Encrypted Applications
The amount of SSL traffic is growing in the enterprise. Because it is encrypted, it cannot be properly controlled and accelerated. Blue Coat...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

ESG Lab Field Audit
Many companies have successfully implemented Riverbed WAN optimization solutions within their Cisco networks. This ESG Lab Field Audit document explores the success that...  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....

Shape Your Apps Strategy to Reflect New SaaS Licensing and Pricing Trends
Why are smart companies choosing software-as-a-service? Find out in the complimentary Forrester Research report...  

Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...

Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....  

Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....