Ah yes, copiers, the workhorse of American healthcare covered entities, business associates and subcontractors — your insurance card, your drivers’ license, your lab reports, your meds, etc, etc.. Do you happen to know if you are storing Protected Health Information on your copiers? Surprise! You probably are!
The HIPAA Security Final Rule as strengthened by The HITECH Act, requires that a Risk Analysis be conducted:
45 C.F.R. §164.308(a)(1)(ii) (A) – Risk analysis (Required). Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity.
Most organizations fail to include digital copiers in their inventory of information assets that create, receive, maintain or transmit protected health information.
- View this information CBS Reports news clip on the risks of what information can be found on copiers.
- Learn How to Conduct a HIPAA Security Risk Analysis by attending one of our webinars.
- Review our acclaimed HIPAA Security Risk Analysis ToolKit™ to help you complete the process.
Keep us in mind if we may be of any assistance.
Latest posts by Bob Chaput (see all)
- HIPAA Risk Analysis Tip – Part 5 – Questions & Answers from May 3rd Conversation with Former OCR Director Leon Rodriguez - June 5, 2017
- HIPAA Risk Analysis Tip – Part 4 – Questions & Answers from May 3rd Conversation with Former OCR Director Leon Rodriguez - May 29, 2017
- HIPAA Risk Analysis Tip – Part 3 – Questions & Answers from May 3rd Conversation with Former OCR Director Leon Rodriguez - May 21, 2017