HIPAA
Overview
The goal of the Health Insurance Portability and Accountability Act (HIPAA) is to simplify the administrative processes of the healthcare system and to protect patients' privacy. Information security considerations are involved throughout the guidelines and play a major role in the Privacy Rule of HIPAA compliance. The purpose of this rule is to protect personally identifiable information (PII) as it moves through the healthcare system. Healthcare organizations, including providers, payers and clearinghouses, must comply with the Privacy Rule.
Importance of Adhering to HIPAA Compliance
To help healthcare organizations comply with the Privacy Rule, Security Standards have been created to help organizations protect PII. These standards encompass administrative procedures, technical security mechanisms and services, and physical safeguards. Security standards compliance and overall HIPAA compliance outlined by the Act is imperative to the ongoing business operations of healthcare companies. Failure to comply may not only result in regulatory actions, such as fines, but also direct business loss from lawsuits, damage to reputation and degradation of the public's trust.
Key Benefits
COE Security LLC offers a full breadth of services to help healthcare organizations address HIPAA compliance Security Standards. We have extensive experience partnering with healthcare providers and we can help you improve your security and compliance posture while reducing costs. As described below, our Enterprise Security Services and Professional Services align directly with many components of the HIPAA Security Standards.
Methodology
| ADMINISTRATIVE SAFEGUARDS | ||
| Standard | Summary of Requirements | Solutions |
|---|---|---|
A. Security Management Process |
Implement policies and procedures to prevent, detect, contain and correct security violations. Specifications include: Risk analysis (1A) Risk management (1B) Sanction policy (1C) Information system activity review (1D |
Security and Risk Consulting includingEnterprise Risk Assessment and Analysis |
B. Workforce Security |
Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information (EPHI) and to prevent those workforce members who do not have access from obtaining access to electronic protected health information. |
Security and Risk Consulting including Policies, Standards, and Security Baseline development and Security Awareness program development |
C. Information Access Management |
Implement policies and procedures for authorizing access to EPHI. |
Security and Risk Consulting including Corporate Information Security Program Development and Enterprise Security Architecture and Standards Development |
D. Security Awareness and Training |
Implement a security awareness and training program for all members of its workforce including management. |
Security and Risk Consulting including Policies, Standards, and Security Baseline development and Security Awareness program development |
E. Security Incident Procedures |
Implement policies and procedures to address security incidents. |
Security and Risk Consulting including GLBA Compliance and Incident Response Program Development |
F. Contingency Plan |
Establish (and implement as needed) policies and procedures for responding to an emergency or other occurrence that damages systems that contain EPHI. |
Security and Risk Consulting including GLBA Compliance and Incident Response Program Development |
G. Evaluation |
Perform a periodic technical and non-technical evaluation that establishes the extent to which an entity's security policies and procedures meet the above administrative safeguard requirements. |
Vulnerability ScanningincludingPenetration Testing |
| PHYSICAL SAFEGUARDS | ||
| Standard | Summary of Requirements | Solutions |
A. Facility Access Controls |
Implement policies and procedures to limit physical access to its electronic information systems while ensuring that properly authorized access is allowed. |
Vulnerability Scanning Security and Risk Consulting includingPenetration Testing and Web Application Testing |
B. Workstation Use |
Implement policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of a specific workstation or class of workstation that can access EPHI. |
Security and Risk Consulting including Corporate Information Security Program Development and Enterprise Security Architecture and Standards Development |
C. Workstation Security |
Implement physical safeguards for all workstations that access EPHI, to restrict access to authorized users. |
Security and Risk Consulting including Corporate Information Security Program Development and Enterprise Security Architecture and Standards Development |
d.Device and Media Controls |
Implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain EPHI into and out of a facility, and the movement of these items within the facility.
Specifications include: |
Security and Risk Consulting including Corporate Information Security Program Development and Enterprise Security Architecture and Standards Development |
| TECHNICAL SAFEGUARDS | ||
| Standard | Summary of Requirements | Solutions |
A. Access Control |
Implement technical policies and procedures for electronic information systems that maintain EPHI to allow access only to those persons or software programs that have been granted access rights. |
• Security policy and procedure development |
B.Audit Controls |
Implement hardware, software and/or procedural mechanisms that record and examine activity in information systems that contain or use EPHI. |
Security and Risk Consulting including Corporate Information Security Program Development and Enterprise Security Architecture and Standards Development |
C.Transmission Security |
Implement technical security mechanisms to guard against unauthorized access to EPHI that is being transmitted over an electronic communications network.
This includes both: |
Security and Risk Consulting including Corporate Information Security Program Development and Enterprise Security Architecture and Standards Development |
![]()
"To lift the functionality and visibility of the Central Blood Register, the Community Relations Centre of BNH hospital was looking for a partner who could reliably secure our web-based application system and support our life saving and sensitive data. In COE Security we found support going beyond our expectations. We appreciate their professionalism and flexibility!"
Udo Kim
Community Relations Executive
![]()
Request a Quote
Lets our representative contact you.
Pilot Project
Let we demonstrate our solution delivery
Live Meeting Request
For live meeting request
Corporate Training
For various training requirements
Contact Us
Reach our global representatives.
A code-level security review of applications can validate the strength of your application security at the lowest layer
A code-level security review of applications can validate the strength of your application security at the lowest layer

