What is HIPAA Security?
I thought HIPAA was all over! The HIPAA Security Rule specifically focuses on the safeguarding of electronic protected health information (EPHI). Make no mistake; there are some technical requirements for your electronic systems. There are also requirements for internal operations, both physical and administrative. All covered entities under HIPAA must comply with the HIPAA Security Rule by April 21, 2005. Amongst other requirements, the Security Rule requires health care practitioners to follow good password practices, have a clear process for any security incident, and put a risk management process in place. Risk Management is the least understood of the Security Rule provisions, but is potentially the biggest source of problems. In upcoming communications, we will define a risk management process that is suitable for small organizations. For more information on the requirements for covered entities, you can refer directly to the Federal Register for the Final Security Rule: (http://