Zum Hauptinhalt springen
DocumentMS

Glossary

HIPAA

Also called: Health Insurance Portability and Accountability Act

HIPAA is the US framework governing protected health information. Its Security Rule sets administrative, physical and technical safeguards, and it is the technical ones — unique user identification, automatic logoff, encryption, audit controls, integrity checks and authentication — that a document management system implements directly.

HIPAA explained

The safeguard that decides it

45 CFR §164.312(b) requires mechanisms that record and examine activity in systems containing protected health information — activity, not merely modification. A system that logs edits but not reads cannot tell you who saw a record before it was disclosed, which is the first question in a breach investigation.

That single requirement disqualifies most general-purpose file stores.

Unique identification

§164.312(a)(2)(i) requires a unique name or number for each user. Shared departmental logins are excluded outright, because a record of "the reception account" opening a file is attributable to nobody and therefore evidences nothing.

Minimum necessary

The Privacy Rule limits uses and disclosures to the minimum needed for the purpose. In practice this requires permissions finer than read and write — a billing clerk confirming a procedure took place does not need the clinical narrative, and preview-only access exists for exactly this case.

Business associate agreements

A vendor storing or transmitting protected health information on a covered entity's behalf is a business associate as a matter of law and must execute an agreement. A vendor that hesitates on that question has answered it.

Retention is not HIPAA's

HIPAA requires six years for compliance documentation such as policies and risk analyses. Clinical record retention is set by state law and varies substantially, with longer clocks for minors — which is the retention question most often misconfigured in healthcare.

FAQ

HIPAA: common questions

Does encryption remove the breach notification duty?

It can. The duty applies to unsecured protected health information, and PHI encrypted to the standard in HHS guidance may fall outside that definition. It does not help if an authorised account is compromised.

Is a signed BAA sufficient assurance?

It is necessary and not sufficient. The agreement allocates responsibility; the controls still have to exist, which is what a security review examines.

Eine 30-minütige Sitzung mit einem Solutions Engineer, mit einer Ordnerstruktur und Freigabekette, die Ihren ähneln — kein allgemeiner Demo-Mandant.