<img src="https://ws.zoominfo.com/pixel/4CagHYMZMRWAjWFEK36G" width="1" height="1" style="display: none;">
Request Demo

How Healthcare IT Teams Can Unify HIPAA Security and Privacy Regulations Using NIST

down-arrow

The Health Insurance Portability and Accountability Act (HIPAA) seeks to ensure that patients’ data, protected health information (PHI), is reasonably protected from both a privacy and security perspective. As we have shifted into the digital age, healthcare providers have had to account for the rise of electronic protected health information (EPHI) and the wealth of new technologies available to both enhance the patient experience and improve patient outcomes. While these technologies have made great strides to their respective ends, they have also opened up a wealth of new opportunities for bad actors to attack organizations that store some of the most intimate information people can imagine.

The HIPAA Privacy Rule

According to the Department of Health and Human Services: The Rule requires appropriate safeguards to protect the privacy of personal health information, and sets limits and conditions on the uses and disclosures that may be made of such information without patient authorization. The Rule also gives patients rights over their health information, including rights to examine and obtain a copy of their health records, and to request corrections.

In short, the Privacy Rule seeks to protect the confidentiality of PHI that a covered entity handles.

The HIPAA Security Rule

The DHHS states: The HIPAA Security Rule establishes national standards to protect individuals’ electronic personal health information that is created, received, used, or maintained by a covered entity. The Security Rule requires appropriate administrative, physical and technical safeguards to ensure the confidentiality, integrity, and security of electronic protected health information.

The Security Rule seeks to ensure that electronic PHI has the necessary security measures protecting it to ensure that patient information is protected from outside actors.

How Do HIPAA Security and Privacy Rules Differ

The difference between the HIPAA Security and Privacy Rules comes down to the empiric difference between privacy and security. Thinking of EPHI like a house, security may be able to put bars on the windows, but that does not mean that people cannot see in. That’s where privacy (the curtains in this analogy) come into play. When effectively harmonized, security and privacy work together to enable the safety of patient information while also granting patients the ability to control who within and outside the organization has access.

Where the security rule mandates covered organizations to put administrative safeguards in place, as well as physical security and technical controls, the privacy rule applies more guidelines to protect patient anonymity both within the organization (i.e. health care professionals not working on a given case) as well as outside the organization (i.e.a specialist at a different hospital or worse, a bad actor who gained access to the system).

Using the NIST CSF and Privacy Frameworks to Align HIPAA Security and Privacy Teams and More

In January of 2020, the National Institute of Standards and Technology (NIST) introduced its much-anticipated Privacy Framework. The Privacy Framework built on the success of their wildly popular Cybersecurity Framework and enables organizations roll privacy program management alongside security and risk management using the CSF and Risk Management Framework. As we have discussed in this post, privacy and security are two sides of the same coin. If we think of security as a rectangle and privacy as a square - in the same way that all squares are rectangles but not all rectangles are squares, privacy programs inherently call upon security but not all security programs are inherently secure. Especially as it relates to HIPAA compliance, ensuring harmonization across security and privacy efforts is critical. However, catering to regulations (in this case HIPAA) and not preparing for the future and addressing risks and threats that have emerged since the Security and Privacy Rules were updated is equally as critical. As a result, leveraging outcomes, risk-based frameworks like the CSF and Privacy Framework enables organizations to meet compliance while also ensuring that their information systems are truly secure and prepared for the future.

The CyberStrong integrated risk management platform benchmarks all assessments against the NIST CSF as well as supports both HIPAA and the NIST Privacy Framework. To learn more about the CyberStrong platform, give us a call at 1 800 NIST CSF, or click, here, to schedule a conversation.

You may also like

New Gartner Report Identifies ...
on September 15, 2021

With a variety of risks growing out of the pandemic, cybersecurity control failures was listed as the top executive concern during Q1 2021. According to the Gartner Emerging Risks ...

Why IOT in the Commercial ...
on September 14, 2021

Every month there seems to be a new device that changes the way we travel, communicate, conduct business, and live our personal lives. The transformation promises efficiency and ...

Why the Chemical Sector is ...
on September 1, 2021

The chemical sector encompasses more than 70,000 diverse products that are critical to the modern global infrastructure. Several thousand chemical facilities ship, manufacture, ...

Kyndall Elliott
What Does the Future of Risk ...
on August 31, 2021

Cyber risk is the top concern for water and wastewater systems. With government intelligence confirming cyber attacks staged by Russia and Iran, utilities need strong risk ...

What Threatens Other Critical ...
on August 24, 2021

Everyone knows that one person that likes to say that they’re not addicted to their phone. In 2021, it’s difficult to find a way to socialize, work, access vital services, and be ...

Is the Energy Sector Paving the ...
on August 13, 2021

It’s difficult to imagine a day in which the products and services we use are not connected back to the energy sector. How we heat or cool our homes to how we remotely work are ...