Security and Privacy
 

HIPAA Information

The Security and Privacy provisions of the Health Insurance Portability and Accountability Act (HIPAA) define standards for protecting and safeguarding individually identifiable health information. Such information may include a person’s name, address, telephone number and social security number. The law recognizes that healthcare organizations need to use this information to provide care, arrange for coordination of services within the healthcare continuum and perform activities to monitor and improve the quality of care. HIPAA provides standards for sharing of protected health information (PHI) for purposes of conducting health care operations between hospitals and their business associates. It is a requirement of the law for hospitals and other covered organizations to have contractual agreements with their business associates or partners that sets forth relative rights and responsibilities with respect to confidential information.

IT HealthTrack (ITH) Agreements and Policies include the following:

  • Our HIPAA Compliance Committee is comprised of a Privacy Officer and representative from each area of operations who has developed and implemented a strategic plan for compliance with the standards;

  • The contractual agreements made between our company and customers specifies that we receive only the minimal amount of information required to fulfill our obligations;

  • We are prohibited from using PHI for any other purposes except fulfilling the obligations of our agreements;

  • We must protect information from unauthorized disclosure to any third party and secure information against loss or damage;

  • Our employees sign confidentiality agreements and must comply with same restrictions that we do as a corporation;

  • ITH meets reporting and record keeping practices required under the law;

For detailed information about HIPAA, you may download the Federal Register at:
http://www.hhs.gov/ocr/hipaa/
 

Technological Methods
  All individually identifiable health information communicated or provided to IT HealthTrack is deemed protected health information and protected electronically;
  • All data are transferred via FTP between IT HealthTrack and facilities by using 128 bit Secure Socket Layer (SSL) data encryption;
  • ITH’s internal network is protected by a triple firewall;
  • We use 128 bit internal password encryption;
  • It is our policy not to transmit passwords or PHI unencrypted (in the clear) over the internet;
  • All administrative passwords are kept off site in a safety deposit box accessible only by the CIO and Privacy Officer;
  • Disaster recovery data is backed up and kept off-site in a data certified fire-proof safe;
  • Physical access to our data center is controlled by a security system, monitored 24 hours a day and kept locked;
  • Access rights to data are controlled at the user file and directory level- adequate, but minimal privileges are granted according to employee role and responsibility;
  • Passwords are required at all user levels;
  • Complex passwords are required and changed every 30 days;
  • No one but the CIO and Privacy Officer has direct access to server console log-ins;
  • Full transaction logs for all hosts are maintained for audit and security tracking;
  • Reports and research databases contain only de-identified health information.

6500 Main St., Suite 3 • Williamsville, NY  14221 • Phone: 716.630.0063 • Fax: 716.630.6403

© IT HealthTrack All Rights Reserved