---
title: Protecting Patient Information w/ HIPAA Electronic Security Standards
description: Establish HIPAA electronic security standards to protect patient information and confidentiality in your medical practice.
image: https://info.pmimd.com/hubfs/patientsecurity300.jpg
---

[![pmi-logo-white-on-blue](https://info.pmimd.com/hs-fs/hubfs/pmi-logo-white-on-blue.png?width=174&name=pmi-logo-white-on-blue.png "pmi-logo-white-on-blue")](https://www.pmimd.com/)

- [About PMI](https://www.pmimd.com/about/)
- [Online Training Center](https://www.pmimd.com/onlinetraining/)
- [Instructors](https://www.pmimd.com/instructors.php)
- [Contact Us](https://www.pmimd.com/contact.asp)

# Protecting Patient Information w/ HIPAA Electronic Security Standards

Posted by [Practice Management Institute](https://info.pmimd.com/blog/author/practice-management-institute) on Aug 11, 2019, 4:55:48 PM

![Practice Management Institute](https://info.pmimd.com/hubfs/pmilogo-1.gif)

- [Tweet](https://twitter.com/share)

HIPAA Compliance can be a complex issue. Especially with advancements in technology and the rising prominence of social media and online reviews. However, there is a degree of solace in knowing that you are not alone in your quest to successfully navigate HIPAA requirements. Medical office managers across the country must be able to effectively understand the federal regulations that deal with [protected health information](https://www.hipaajournal.com/what-is-protected-health-information/) (PHI).

The regulations safeguarding PHI is covered under the Health Insurance Portability and Accountability Act. Originally enacted in 1996, it set national standards and laid down the law for how physician offices, hospitals, and business associates are to protect sensitive and confidential health information. Commissioned with the task of writing the regulation, the U.S. Department of Health and Human Services (HHS) broke it down into two rules: the [privacy rule](https://www.hhs.gov/hipaa/for-professionals/privacy/index.html) and the [security rule.](https://www.hhs.gov/hipaa/for-professionals/security/index.html)

## **HIPAA’s Security Rule**

*Addressable vs Required specifications*

In 2003 HHS published a final security rule, which protects the confidentiality, integrity and availability of electronic PHI. The rule specifically outlines a series of required administrative, technical, and physical security procedures for [covered entities and business associates.](https://www.hhs.gov/hipaa/for-professionals/covered-entities/index.html) The standard also established two types of implementation specifications—required and addressable. To better understand the difference, let’s take a look at their definitions and how it relates to your organization’s HIPAA compliance.

Required - Just how it sounds. If an implementation specification is deemed required then under HIPAA it must be implemented.

Addressable -This is where it gets a little less straightforward. HHS developed addressable implementation specifications to give covered entities flexibility when complying with its security standards. Here’s how it works:

- Covered entities must assess and analyze whether a specification is a reasonable and appropriate safeguard for its environment.
- Determining factors such as the size and capability of the organization as well as the practicality of the specification can play a key role in the decision process.
- An organization has the right to reject compliance if it is not an appropriate answer to their security needs. However, to comply with HIPAA standards you must rectify the issue by: 
    1. Implementing another equivalent specification, or;
    2. Not implement one at all. However, keep in mind that documenting the rationale behind the decision is a HIPAA requirement. Failure to submit proper documentation will result in a violation and is subject to monetary penalties.

## **Protecting Your Organization Against Cyber-Attacks and Ransomware**

Safeguarding PHI from cyber-attacks is of utmost importance. One such threat in today’s society is ransomware. This malicious software created by hackers encrypts information so that it is no longer accessible. To remove the encryption the hacker demands ransom for a decryption key that results in the unlocking of the files. To keep your organization’s information breach-free HIPAA requires the following measures:

- Implement a security management process that includes conducting a comprehensive risk analysis identifying threats and vulnerabilities to the organization’s electronic data.
- Perform security measures to mitigate or remediate any identified risks.
- Implement procedures to guard against and detect malicious software.
- Provide users with malicious software training to assist in detection and arm them with the proper procedures to report a cyber-attack should it occur.
- Put controls in place to limit access to individuals and software programs that need to have the information as required for the job at hand.

## **Stay Current on HIPAA Violations**

With instances of [data breaches on the rise](https://www.hipaajournal.com/largest-healthcare-data-breaches-of-2018/) all organizations that handle PHI must take the necessary steps to protect sensitive information and avoid a HIPAA violation. With routine HIPAA updates, it is necessary to ensure that your practice stays up to date on all HIPAA regulations. Our new [HIPAA Compliance ebook](https://info.pmimd.com/ebook-hipaa-compliance?utm_source=Website&utm_medium=homepage+banner&utm_term=Download+now&utm_content=Img+Text+CTA&utm_campaign=Ebook++HIPAA+compliance) provides best practices to help protect your office. Download it today.

[![Download Ebook](https://no-cache.hubspot.com/cta/default/2430152/ccf02c12-8b28-46b5-918b-8b6f12f78685.png)](https://cta-redirect.hubspot.com/cta/redirect/2430152/ccf02c12-8b28-46b5-918b-8b6f12f78685)

 

 

 

 Topics: [Practice management](https://info.pmimd.com/blog/tag/practice-management), [medical office compliance](https://info.pmimd.com/blog/tag/medical-office-compliance), [HIPAA compliance](https://info.pmimd.com/blog/tag/hipaa-compliance), [HIPAA](https://info.pmimd.com/blog/tag/hipaa)

### Subscribe Here!

### Recent Posts

### Posts by Tag

- [Practice management (50)](https://info.pmimd.com/blog/tag/practice-management)
- [medical office manager topics (43)](https://info.pmimd.com/blog/tag/medical-office-manager-topics)
- [CMOM (35)](https://info.pmimd.com/blog/tag/cmom)
- [medical practice issues (33)](https://info.pmimd.com/blog/tag/medical-practice-issues)
- [medical coding (28)](https://info.pmimd.com/blog/tag/medical-coding)
- [Certified Medical Office Manager (25)](https://info.pmimd.com/blog/tag/certified-medical-office-manager)
- [cmom certification (25)](https://info.pmimd.com/blog/tag/cmom-certification)
- [PMI Certification (24)](https://info.pmimd.com/blog/tag/pmi-certification)
- [Insider (21)](https://info.pmimd.com/blog/tag/insider)
- [medical office staff (20)](https://info.pmimd.com/blog/tag/medical-office-staff)
- [medical office compliance (18)](https://info.pmimd.com/blog/tag/medical-office-compliance)
- [medical billing (17)](https://info.pmimd.com/blog/tag/medical-billing)
- [medical office certification (17)](https://info.pmimd.com/blog/tag/medical-office-certification)
- [medical office training (16)](https://info.pmimd.com/blog/tag/medical-office-training)
- [financial management (14)](https://info.pmimd.com/blog/tag/financial-management)
- [medical office (13)](https://info.pmimd.com/blog/tag/medical-office)
- [physician relations (12)](https://info.pmimd.com/blog/tag/physician-relations)
- [medical office leadership (11)](https://info.pmimd.com/blog/tag/medical-office-leadership)
- [patient billing (11)](https://info.pmimd.com/blog/tag/patient-billing)
- [staff recruiting (10)](https://info.pmimd.com/blog/tag/staff-recruiting)
- [Practice cash flow (8)](https://info.pmimd.com/blog/tag/practice-cash-flow)
- [partnerships (8)](https://info.pmimd.com/blog/tag/partnerships)
- [administrative burdens (7)](https://info.pmimd.com/blog/tag/administrative-burdens)
- [patient relations (6)](https://info.pmimd.com/blog/tag/patient-relations)
- [personnel management (6)](https://info.pmimd.com/blog/tag/personnel-management)
- [time management (6)](https://info.pmimd.com/blog/tag/time-management)
- [workplace violence (6)](https://info.pmimd.com/blog/tag/workplace-violence)
- [HIPAA compliance (5)](https://info.pmimd.com/blog/tag/hipaa-compliance)
- [carrier contract guidelines (5)](https://info.pmimd.com/blog/tag/carrier-contract-guidelines)
- [emergency preparedness (5)](https://info.pmimd.com/blog/tag/emergency-preparedness)
- [medicare compliance (5)](https://info.pmimd.com/blog/tag/medicare-compliance)
- [patient engagement (5)](https://info.pmimd.com/blog/tag/patient-engagement)
- [HIPAA (4)](https://info.pmimd.com/blog/tag/hipaa)
- [medical fraud (4)](https://info.pmimd.com/blog/tag/medical-fraud)
- [medical office administration (4)](https://info.pmimd.com/blog/tag/medical-office-administration)
- [payer contract (4)](https://info.pmimd.com/blog/tag/payer-contract)
- [Client Relations (3)](https://info.pmimd.com/blog/tag/client-relations)
- [Medical Front Office (3)](https://info.pmimd.com/blog/tag/medical-front-office)
- [Medical entry-level (3)](https://info.pmimd.com/blog/tag/medical-entry-level)
- [medical practice benchmarking (3)](https://info.pmimd.com/blog/tag/medical-practice-benchmarking)
- [osha (3)](https://info.pmimd.com/blog/tag/osha)
- [patient satisfaction (3)](https://info.pmimd.com/blog/tag/patient-satisfaction)
- [quality assurance (3)](https://info.pmimd.com/blog/tag/quality-assurance)
- [value proposition (3)](https://info.pmimd.com/blog/tag/value-proposition)
- [CMOM FAQs (2)](https://info.pmimd.com/blog/tag/cmom-faqs)
- [Care Management (2)](https://info.pmimd.com/blog/tag/care-management)
- [E/M coding (2)](https://info.pmimd.com/blog/tag/e-m-coding)
- [Medical Office Management (2)](https://info.pmimd.com/blog/tag/medical-office-management)
- [Medicare fraud (2)](https://info.pmimd.com/blog/tag/medicare-fraud)
- [Opioid Addiction (2)](https://info.pmimd.com/blog/tag/opioid-addiction)
- [Pain Management (2)](https://info.pmimd.com/blog/tag/pain-management)
- [Practice debt (2)](https://info.pmimd.com/blog/tag/practice-debt)
- [Practice safety (2)](https://info.pmimd.com/blog/tag/practice-safety)
- [carrier contract (2)](https://info.pmimd.com/blog/tag/carrier-contract)
- [change management (2)](https://info.pmimd.com/blog/tag/change-management)
- [diversity and inclusion (2)](https://info.pmimd.com/blog/tag/diversity-and-inclusion)
- [hazard communication (2)](https://info.pmimd.com/blog/tag/hazard-communication)
- [medical identity theft (2)](https://info.pmimd.com/blog/tag/medical-identity-theft)
- [medicare (2)](https://info.pmimd.com/blog/tag/medicare)
- [patient collections (2)](https://info.pmimd.com/blog/tag/patient-collections)
- [psr (2)](https://info.pmimd.com/blog/tag/psr)
- [CMOM training courses (1)](https://info.pmimd.com/blog/tag/cmom-training-courses)
- [COVID (1)](https://info.pmimd.com/blog/tag/covid)
- [Crisis Leadership (1)](https://info.pmimd.com/blog/tag/crisis-leadership)
- [Desk of the President Series (1)](https://info.pmimd.com/blog/tag/desk-of-the-president-series)
- [Heidi Kocher (1)](https://info.pmimd.com/blog/tag/heidi-kocher)
- [auditing (1)](https://info.pmimd.com/blog/tag/auditing)
- [budget planning (1)](https://info.pmimd.com/blog/tag/budget-planning)
- [claims (1)](https://info.pmimd.com/blog/tag/claims)
- [cmom assessment (1)](https://info.pmimd.com/blog/tag/cmom-assessment)
- [contract negotiation (1)](https://info.pmimd.com/blog/tag/contract-negotiation)
- [difficult personalities (1)](https://info.pmimd.com/blog/tag/difficult-personalities)
- [evaluation and management (1)](https://info.pmimd.com/blog/tag/evaluation-and-management)
- [insurance (1)](https://info.pmimd.com/blog/tag/insurance)
- [leadership (1)](https://info.pmimd.com/blog/tag/leadership)
- [medical insurance (1)](https://info.pmimd.com/blog/tag/medical-insurance)
- [sexual harassment (1)](https://info.pmimd.com/blog/tag/sexual-harassment)
- [value-based care (1)](https://info.pmimd.com/blog/tag/value-based-care)
- [workplace safety (1)](https://info.pmimd.com/blog/tag/workplace-safety)

See all

![pmi-logo-white-on-blue](https://info.pmimd.com/hs-fs/hubfs/pmi-logo-white-on-blue.png?width=174&name=pmi-logo-white-on-blue.png "pmi-logo-white-on-blue")

Explore our site

- [Home](https://www.pmimd.com/)
- [About PMI](https://www.pmimd.com/about/)
- [Online Training Center](https://www.pmimd.com/onlinetraining/)
- [Instructors](https://www.pmimd.com/instructors.php)

Our Office

10223 McAllister Fwy.  
Suite 104  
San Antonio, TX 78216

Contact Us

T: 210-691-8900

F: (210) 691-8972

[info@pmimd.com](mailto:info@pmimd.com)

© CPT is a registered trademark of the American Medical Association. All rights reserved. © 2024 Practice Management Institute® | All rights reserved.