• Home
  • Blog
  • Contact
HIPAA ComplianceHIPAA Compliance
HIPAA ComplianceHIPAA Compliance
  • Home
  • Blog
  • Contact

Three Key Properties of HIPAA Privacy and Security of Protected Health Information

September 11, 2009 Health IT and HITECH, HIPAA Law, Privacy, Security No Comments

HIPAA.com has received from its readers requests for information on topics related to HIPAA Administrative Simplification Privacy and Security Rules and to updates to those rules reflected in the HITECH Act provisions of the American Recovery and Reinvestment Act of 2009, signed by President Obama on February 17, 2009.  Recently, HIPAA.com answered the question of particular interest to several readers:  what exactly is protected health information (PHI)?  In this posting, we answer the question:  what are the fundamental properties that underlie privacy and security of protected health information?

Three Key Properties

The three key properties that underpin privacy and security under the Health Insurance Portability and Accountability Act (HIPAA) are availability, confidentiality, and integrity.

Availability is the property that data or information is accessible and useable upon demand by an authorized person.

Confidentiality is the property that data or information is not made available or disclosed to unauthorized persons or processes.

Integrity is the property that data or information have not been altered or destroyed in an unauthorized manner.

These definitions appear in 45 CFR § 164.304, where CFR is Code of Federal Regulations.  Part 164 covers Security and Privacy.  These definitions fall into Subpart C, which covers Security Standards for the Protection of Electronic Protected Health Information.  These properties also underpin the “Guidance Specifying the Technologies and Methodologies that Render Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals’ that appears in the Interim Final Rule:  Breach Notification for Unsecured Protected Health Information, issued by the Office of Civil Rights (OCR) of the U.S. Department of Health and Human Services (HHS) and published in the Federal Register on August 24, 2009.

Tags: Administrative SimplificationAmerican Recovery and Reinvestment ActAugust 24authorized personavailabilityBreach NotificationCode of Federal RegulationsconfidentialityFebruary 17Federal RegisterguidanceHEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACTHHSHIPAAHIPAA PrivacyHIPAA securityHITECH ActindecipherableintegrityInterim Final Rulekey propertiesOCROffice of Civil RightsPHIPresident Obamaprotected health informationSecurity StandardsU.S. Department of Health and Human Servicesunauthorized individualsunauthorized personsunauthorized processesunreadableunsecured protected health informationunusable
No Comments
Share
0

You also might be interested in

HIPAA Final Rule: More on Uses and Disclosures of Protected Health Information of Decedents

Mar 14, 2013

Today, we continue going through the HIPAA Privacy Rule, section[...]

Access Control: Emergency Access Procedure-What to Do and How to Do It

Jun 4, 2009

In our series on the HIPAA Administrative Simplification Security Rule,[...]

HIPAA Final Rule: Prohibited Uses and Disclosures–Sale of Protected Health Information

Mar 7, 2013

March 7, 2013.  Today, we continue going through the HIPAA[...]

Leave a Reply Cancel Reply

Categories

  • 5010
  • American Recovery and Reinvestment Act
  • Enforcement
  • GINA
  • Health Care Reform
  • Health IT and HITECH
  • HIPAA Law
  • Identifiers
  • Meaningful Use
  • Privacy
  • Red Flags Rules
  • Security
  • Transactions & Code Sets
  • Uncategorized

Recent Posts

  • Contracting with Vendors that are NOT HIPAA Business Associates: Best Practices
  • HIPAA Breach: Who You Gonna Call?
  • Can I Be Sued for a HIPAA Violation?
  • Business Associate Agreements – a First Look at Indemnification
  • Gmail, Google Apps for Business HIPAA Business Associate Agreements

Archives

Contact Us

We're currently offline. Send us an email and we'll get back to you, asap.

Send Message
HIPAA- Health Insurance Portability Accountability Act

© 2023 · hipaa.com

Prev Next