(a)(1) Standard: Access control. Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights as specified in § 164.308(a)(4).
The Access control standard includes four (4) implementation specifications:
- (i) Unique user identification (Required).
- (ii) Emergency access procedure (Required).
- (iii) Automatic logoff (Addressable).
- (iv) Encryption and decryption (Addressable).
Latest posts by Michelle Caswell (see all)
- What to Know About OCR Pre-Audit Questionnaires - June 3, 2016
- HIPAA and Firearms. Balancing privacy with public safety. - February 1, 2016
- Cornell Faces Heavy Fines with Latest OCR Resolution Agreement - May 4, 2015