Regardless of what happens with the current NPRM, the HIPAA Security Rule still stands, just like it has since 2005. I feel as though the OCR has clearly demonstrated that their focus on compliance with the Security Rule, particularly in regard to a comprehensive Security Risk Analysis, is not a passing fancy. So, treat your policies and procedures like your Owner’s Manual – a rulebook that applies to everyone in the organization.
Avoid falling into the very bad habit of adopting policies but not the procedures that define how the policies get implemented. Far too often, policies are stored on a shared drive, reviewed once a year to update the review date, but without active implementation, how effective are they?
Depending on what role people have in the organization, they may have more, or fewer, or different roles to follow in implementing the rules. For example – there might be different roles in implementing information system access for employees; hiring managers; human resources staff; information technology staff; and information security leaders. Then train accordingly, because you cannot expect people to follow rules that they don’t know.
Pro Tip: Socialize Your Owner’s Manual Rules
You can do this as part of onboarding and as annual refresher training. Employee Handbooks are a great place to address high-level, all-employee rules. Employees should review organizational Acceptable Use policies at least annually and attest that they understand what’s allowed and what isn’t.
The ways that tasks are accomplished change routinely, especially in technology. Review your procedures—your owner’s manual rules—regularly to make sure they still fit how you do business.
Finally, trust but verify. Many organizations might issue prohibitions on some employee actions. For example, no information may be saved to a USB drive. Without putting a technical prohibition in place to enforce the ban (like disabling USB drives in this example), your organization’s policy is worth no more than the paper it prints on.
Leadership’s Role
As a rule, our firm always recommends that leadership, particularly those in information security management roles, be heavily engaged in the development and updating of policies and procedures that deal with access control from a security perspective. So, when developing that Owner’s Manual, consider:
- Who in the organization needs to have access to the EMR, and why? Are different positions in the organization assigned different levels of access?
- How is access assignment tracked, and who approves it?
- What if an employee changes jobs, or leaves the organization? How quickly is EMR access changes or shut down entirely?
- Does employee access get reviewed for continuing appropriateness? If so, by whom and how often?
- Who decides if third parties are allowed EMR access? How is that access tracked and reviewed?
While information security management leaders or departmental managers may not be the final decision-makers on these questions, their group/department certainly has a role to play in discussions of what should happen.
Are you ready to review your organization’s Owner’s Manual aka Policies and Procedures? Give us a call.