(a) A covered entity must, in accordance with § 164.306:
(4)(i) Standard: Information access management. Implement policies and procedures for authorizing access to electronic protected health information that are consistent with the applicable requirements of subpart E of this part.
The information access management standard has three(3) implementation specifications:
- (A) Isolating health care clearinghouse functions (Required).
- (B) Access authorization (Addressable).
- (C) Access establishment and modification (Addressable).
Latest posts by Michelle Caswell (see all)
- What to Know About OCR Pre-Audit Questionnaires - June 3, 2016
- HIPAA and Firearms. Balancing privacy with public safety. - February 1, 2016
- Cornell Faces Heavy Fines with Latest OCR Resolution Agreement - May 4, 2015