(a) A covered entity must, in accordance with § 164.306:
(4)(i) Standard: Information access management. Implement policies and procedures for authorizing access to electronic protected health information that are consistent with the applicable requirements of subpart E of this part.
The information access management standard has three(3) implementation specifications:
- (A) Isolating health care clearinghouse functions (Required).
- (B) Access authorization (Addressable).
- (C) Access establishment and modification (Addressable).
Latest posts by admin (see all)
- $100,000 Fine in Case Involving Defunct Records Storage Firm - February 14, 2018
- Clearwater CEO Bob Chaput Shares Expertise on Insuring Hospital Cyber Risks Through Captives - February 13, 2018
- Partnership Brings Focus on Cyber Security Solutions to Texas Hospitals - February 5, 2018