HHS's Office for Civil Rights (OCR) has recently released its latest cybersecurity newsletter to remind HIPAA-covered entities, which include employer-sponsored health plans, and business associates (collectively, “regulated entities”), that physical security measures such as facility access controls are essential for HIPAA Security Rule compliance. These measures help prevent unauthorized access to electronic protected health information (ePHI) as the incidences of cyberattacks and breaches of ePHI are increasing.
The newsletter highlights the importance of implementing proper physical safeguards, including facility access controls. It notes that OCR received over 50 large breach reports (i.e., breaches of unsecured PHI involving 500 or more individuals), affecting over 1,000,000 individuals attributable to stolen equipment and devices containing ePHI from 2020 to 2023. These breaches involved equipment and devices such as workstations, servers, laptops, external hard drives, backup devices, flash drives, smartphones, and medical devices. Regulated entities should ensure that they have proper physical safeguards in place to deter and prevent unauthorized access.
The Facility Access Controls standard of the HIPAA Security Rule consists of four implementation specifications that must be considered when assessing the sufficiency of facility access controls:
The newsletter reminds regulated entities that the failure to implement facility access controls can result in a breach of PHI and potential enforcement actions by OCR.
Plan sponsors and fiduciaries should regularly evaluate their facility access controls standards to make sure that they include reasonable and appropriate contingency operations, facility security plans, access controls, policies and procedures, maintenance of records, and training of their workforce members on the facility security plan.
August 2024 OCR Cybersecurity Newsletter
PPI Benefit Solutions does not provide legal or tax advice. Compliance, regulatory and related content is for general informational purposes and is not guaranteed to be accurate or complete. You should consult an attorney or tax professional regarding the application or potential implications of laws, regulations or policies to your specific circumstances.
Sign up to have it delivered straight to your inbox.
Sign up