Technical Safeguards Defined
Technical safeguards under the HIPAA Security Rule refer to the technology and related policies and procedures that protect electronic protected health information and control access to it. These safeguards work alongside administrative and physical safeguards to form a comprehensive security program.
Access Control
The access control standard requires technical policies and procedures that allow only authorized persons to access ePHI. Required implementation specifications include assigning a unique user identifier to track each individual's system activity, establishing emergency access procedures for obtaining necessary ePHI during an emergency, and addressable specifications for automatic logoff and encryption of stored data.
Audit Controls
Audit control mechanisms record and examine activity in information systems containing or using ePHI, capturing hardware, software, and procedural mechanisms that log access and activity. Regular review of audit logs helps detect unauthorized access, unusual access patterns such as employees viewing records of patients they are not treating, and potential security incidents.
Integrity Controls
Integrity controls protect ePHI from improper alteration or destruction, whether intentional or accidental. Implementation approaches include checksums, digital signatures, and error-correcting mechanisms that verify data has not been altered during storage or transmission.
Authentication
Person or entity authentication verifies that a person seeking access to ePHI is the one claimed. Common authentication methods include passwords, PINs, biometric identifiers, and multi-factor authentication combining something the user knows with something the user has or is.
Transmission Security
Transmission security standards require measures to guard against unauthorized access to ePHI transmitted over electronic networks. Implementation specifications address integrity controls to ensure transmitted data is not improperly modified and encryption to protect data confidentiality during transmission, particularly important as more health information moves across networks for health information exchange and telehealth.
Encryption's Role
While encryption is an addressable rather than strictly required specification under several safeguards, it is widely considered a best practice and often serves as a safe harbor from breach notification requirements when encrypted data is lost or stolen, since properly encrypted data is not considered unsecured PHI.