<?xml version="1.0"?>

<rss version="2.0">


<channel>
<title>Home - All Categories - HIPAA Compliance  - Administrative Safeguards  </title>
<link>http://www.compliancewiki.org/category/hipaa-compliance/administrative-safeguards/112/</link>
<description>This RSS Feed contains Articles of Category in the knowledge base. You can click on the title to view its content. Powered by PHPKB (https://www.phpkb.com)</description>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-information-system-activity-review-164-308-a-1-ii-d-437.html</guid>
										<title>HIPAA - Information System Activity Review 164.308&#40;a&#41;&#40;1&#41;&#40;ii&#41;&#40;D&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-information-system-activity-review-164-308-a-1-ii-d-437.html</link>
										<description><![CDATA[Overview:Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports. Action Items:1) Obtain and review policies and procedures related to reviewing...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-access-authorization-164-308-a-4-ii-b-445.html</guid>
										<title>HIPAA - Access Authorization 164.308&#40;a&#41;&#40;4&#41;&#40;ii&#41;&#40;B&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-access-authorization-164-308-a-4-ii-b-445.html</link>
										<description><![CDATA[Overview:Implement policies and procedures for granting access to electronic protected health information, for example, through access to a workstation, transaction, program, process, or other mechanism. Action Items:1) Obtain and review policies and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-security-incident-procedures-164-308-a-6-i-452.html</guid>
										<title>HIPAA - Security Incident Procedures 164.308&#40;a&#41;&#40;6&#41;&#40;i&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-security-incident-procedures-164-308-a-6-i-452.html</link>
										<description><![CDATA[Overview:Implement policies and procedures to address security incidents. Action Items:1) Obtain and review the policies and procedures related to security incidents. Elements to review may include but are not limited to: Identification of what...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-access-establishment-and-modification-164-308-a-4-ii-c-446.html</guid>
										<title>HIPAA - Access Establishment and Modification 164.308&#40;a&#41;&#40;4&#41;&#40;ii&#41;&#40;C&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-access-establishment-and-modification-164-308-a-4-ii-c-446.html</link>
										<description><![CDATA[Overview:Implement policies and procedures that, based upon the covered entity&rsquo;s or the business associate&rsquo;s access authorization policies, establish, document, review, and modify a user&rsquo;s right of access to a workstation,...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-data-backup-plan-164-308-a-7-ii-a-455.html</guid>
										<title>HIPAA - Data Backup Plan 164.308&#40;a&#41;&#40;7&#41;&#40;ii&#41;&#40;A&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-data-backup-plan-164-308-a-7-ii-a-455.html</link>
										<description><![CDATA[Overview:Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information. Action Items:1) Obtain and review policies and procedures related to data back-up plans. Evaluate and determine...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-response-and-reporting-164-308-a-6-ii-453.html</guid>
										<title>HIPAA - Response and Reporting 164.308&#40;a&#41;&#40;6&#41;&#40;ii&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-response-and-reporting-164-308-a-6-ii-453.html</link>
										<description><![CDATA[Overview:Identify and respond to suspected or known security incidents; mitigate, to the extent practicable, harmful effects of security incidents that are known to the covered entity; and document security incidents and their outcomes. Action Items...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-termination-procedures-164-308-a-3-ii-c-442.html</guid>
										<title>HIPAA - Termination Procedures 164.308&#40;a&#41;&#40;3&#41;&#40;ii&#41;&#40;C&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-termination-procedures-164-308-a-3-ii-c-442.html</link>
										<description><![CDATA[Overview:Implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends or as required by determinations made as specified in paragraph (a)(3)(ii)(b)....]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-authorization-and-or-supervision-164-308-a-3-ii-a-440.html</guid>
										<title>HIPAA - Authorization and/or Supervision 164.308&#40;a&#41;&#40;3&#41;&#40;ii&#41;&#40;A&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-authorization-and-or-supervision-164-308-a-3-ii-a-440.html</link>
										<description><![CDATA[Overview:Implement procedures for the authorization and/or supervision of workforce members who work with electronic protected health information or in locations where it might be accessed. Action Items:1) Obtain and review policies and procedures...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-log-in-monitoring-164-308-a-5-ii-c-450.html</guid>
										<title>HIPAA - Log-in Monitoring 164.308&#40;a&#41;&#40;5&#41;&#40;ii&#41;&#40;C&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-log-in-monitoring-164-308-a-5-ii-c-450.html</link>
										<description><![CDATA[Overview:Procedures for monitoring log-in attempts and reporting discrepancies. Action Items:1) Obtain and review procedures (or other vehicle) for monitoring log-in and reporting discrepancies and related training material. Elements to review may...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-isolation-health-clearinghouse-functions-164-308-a-4-ii-a-444.html</guid>
										<title>HIPAA - Isolation Health Clearinghouse Functions 164.308&#40;a&#41;&#40;4&#41;&#40;ii&#41;&#40;A&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-isolation-health-clearinghouse-functions-164-308-a-4-ii-a-444.html</link>
										<description><![CDATA[Overview:If a health care clearinghouse is part of a larger organization, the clearinghouse must implement polices and procedures that protect the electronic protected health information of the clearinghouse from unauthorized access by the larger...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-password-management-164-308-a-5-ii-d-451.html</guid>
										<title>HIPAA - Password Management 164.308&#40;a&#41;&#40;5&#41;&#40;ii&#41;&#40;D&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-password-management-164-308-a-5-ii-d-451.html</link>
										<description><![CDATA[Overview:Procedures for creating, changing, and safeguarding passwords. Action Items:1) Obtain and review password management procedures and training (or other vehicle) for creating, changing, and safeguarding passwords. Elements to review may...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-risk-analysis-164-308-a-1-ii-a-434.html</guid>
										<title>HIPAA - Risk Analysis 164.308&#40;a&#41;&#40;1&#41;&#40;ii&#41;&#40;A&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-risk-analysis-164-308-a-1-ii-a-434.html</link>
										<description><![CDATA[Overview:Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate. Action...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-testing-and-revision-procedures-164-308-a-7-ii-d-458.html</guid>
										<title>HIPAA - Testing and Revision Procedures 164.308&#40;a&#41;&#40;7&#41;&#40;ii&#41;&#40;D&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-testing-and-revision-procedures-164-308-a-7-ii-d-458.html</link>
										<description><![CDATA[Overview:Implement procedures for periodic testing and revision of contingency plans. Action Items:1) Obtain and review policies and procedures related to periodic testing and revision of contingency plans. Elements to review may include but are not...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-workforce-clearance-procedure-164-308-a-3-ii-b-441.html</guid>
										<title>HIPAA - Workforce Clearance Procedure 164.308&#40;a&#41;&#40;3&#41;&#40;ii&#41;&#40;B&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-workforce-clearance-procedure-164-308-a-3-ii-b-441.html</link>
										<description><![CDATA[Overview:Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate. Action Items:1) Obtain and review documentation related to workforce clearance procedures. Evaluate and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-applications-and-data-criticality-analysis-164-308-a-7-ii-e-459.html</guid>
										<title>HIPAA - Applications and Data Criticality Analysis 164.308&#40;a&#41;&#40;7&#41;&#40;ii&#41;&#40;E&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-applications-and-data-criticality-analysis-164-308-a-7-ii-e-459.html</link>
										<description><![CDATA[Overview:Assess the relative criticality of specific applications and data in support of other contingency plan components. Action Items:1) Obtain and review policies and procedures related to identifying critical aplications and data. Evaluate and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-risk-management-164-308-a-1-ii-b-435.html</guid>
										<title>HIPAA - Risk Management 164.308&#40;a&#41;&#40;1&#41;&#40;ii&#41;&#40;B&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-risk-management-164-308-a-1-ii-b-435.html</link>
										<description><![CDATA[Overview:Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with Sec 164.206(a). Action Items:1) Obtain and review policies and procedure related to risk management. Evaluate and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-information-access-management-164-308-a-4-i-443.html</guid>
										<title>HIPAA - Information Access Management 164.308&#40;a&#41;&#40;4&#41;&#40;i&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-information-access-management-164-308-a-4-i-443.html</link>
										<description><![CDATA[Overview:Implement policies and procedures for authorizing access to electronic protected health information that are consistent with the applicable requirements of subpart E of this part. Action Items:1) Obtain and review the policies and procedures...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-workforce-security-164-308-a-3-i-439.html</guid>
										<title>HIPAA - Workforce Security 164.308&#40;a&#41;&#40;3&#41;&#40;i&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-workforce-security-164-308-a-3-i-439.html</link>
										<description><![CDATA[Overview:Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information, as provided under paragraph (a)(4) of this section, and to prevent those workforce members who...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-contingency-plan-164-308-a-7-i-454.html</guid>
										<title>HIPAA - Contingency Plan 164.308&#40;a&#41;&#40;7&#41;&#40;i&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-contingency-plan-164-308-a-7-i-454.html</link>
										<description><![CDATA[Overview:Establish (and implement as needed) policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, and natural disaster) that damages systems that contain electronic protected health...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-security-management-process-164-308-a-433.html</guid>
										<title>HIPAA - Security Management Process 164.308&#40;a&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-security-management-process-164-308-a-433.html</link>
										<description><![CDATA[Overview:A covered entity or business associate must in accordance with 164.306: (1)(i) Implement policies and procedures to prevent, detect, contain, and correct security violations. Action Items:1) Obtain and review policies and procedures related...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-security-reminders-164-308-a-5-ii-a-448.html</guid>
										<title>HIPAA - Security Reminders 164.308&#40;a&#41;&#40;5&#41;&#40;ii&#41;&#40;A&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-security-reminders-164-308-a-5-ii-a-448.html</link>
										<description><![CDATA[Overview:Periodic security updates. Action Items:1) Obtain and review documentation demonstrating how periodic security updates are conducted. Elements to review may include but are not limited to: Frequency of the periodic security updates; Methods...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-emergency-mode-operation-plan-164-308-a-7-ii-c-457.html</guid>
										<title>HIPAA - Emergency Mode Operation Plan 164.308&#40;a&#41;&#40;7&#41;&#40;ii&#41;&#40;C&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-emergency-mode-operation-plan-164-308-a-7-ii-c-457.html</link>
										<description><![CDATA[Overview:Establish (and implement as needed) procedures to enable continuation of critical business processes for protection of the security of electronic protected health information while operation in emergency mode. Action Items:1) Obtain and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-protection-from-malicious-software-164-308-a-5-ii-b-449.html</guid>
										<title>HIPAA - Protection from Malicious Software 164.308&#40;a&#41;&#40;5&#41;&#40;ii&#41;&#40;B&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-protection-from-malicious-software-164-308-a-5-ii-b-449.html</link>
										<description><![CDATA[Overview:Procedures for guarding against, detecting, and reporting malicious software. Action Items:1) Obtain and review documentation demonstrating that the procedures for guarding against, detecting, and reporting malicious software are...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-disaster-recovery-plan-164-308-a-7-ii-b-456.html</guid>
										<title>HIPAA - Disaster Recovery Plan 164.308&#40;a&#41;&#40;7&#41;&#40;ii&#41;&#40;B&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-disaster-recovery-plan-164-308-a-7-ii-b-456.html</link>
										<description><![CDATA[Overview:Establish (and implement as needed) procedures to restore loss of data. Action Items:1) Obtain and review documentation related to a disaster recovery plan. Review and determine if appropriate procedures for restoring any loss of data has...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-evaluation-164-308-a-8-460.html</guid>
										<title>HIPAA - Evaluation 164.308&#40;a&#41;&#40;8&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-evaluation-164-308-a-8-460.html</link>
										<description><![CDATA[Overview:Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under this rule and subsequently, in response to environmental or operational changes affecting the security of electronic protected...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-sanction-policy-164-308-a-1-ii-c-436.html</guid>
										<title>HIPAA - Sanction Policy 164.308&#40;a&#41;&#40;1&#41;&#40;ii&#41;&#40;C&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-sanction-policy-164-308-a-1-ii-c-436.html</link>
										<description><![CDATA[Overview:Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity or business associate. Action Items:1) Obtain and review documentation of the sanction policies and...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-security-awareness-training-164-308-a-5-i-447.html</guid>
										<title>HIPAA - Security Awareness Training 164.308&#40;a&#41;&#40;5&#41;&#40;i&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-security-awareness-training-164-308-a-5-i-447.html</link>
										<description><![CDATA[Overview:Implement a security awareness and training program for all members of its workforce (including management). Action Items:1) Obtain and review policies and procedures for security awareness and training program. Elements to review may...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-assigned-security-responsibility-164-308-a-2-438.html</guid>
										<title>HIPAA - Assigned Security Responsibility 164.308&#40;a&#41;&#40;2&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-assigned-security-responsibility-164-308-a-2-438.html</link>
										<description><![CDATA[Overview:Identify the security official who is responsible for the development and implementation of the policies and procedures required by this subpart for the covered entity or business associate. Action Items:1) Obtain and review documentation of...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-business-associate-contracts-and-other-arrangements-164-308-b-1-461.html</guid>
										<title>HIPAA - Business Associate Contracts and Other Arrangements 164.308&#40;b&#41;&#40;1&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-business-associate-contracts-and-other-arrangements-164-308-b-1-461.html</link>
										<description><![CDATA[Overview:(1) A covered entity, in accordance with Â§ 164.306, may permit a business associate to create, receive, maintain, or transmit electronic protected health information on the covered entity&#039;s behalf only if the covered entity obtains...]]></description>

									</item>
<item>
										<guid>http://www.compliancewiki.org/article/hipaa-written-contract-164-308-b-4-462.html</guid>
										<title>HIPAA - Written Contract 164.308&#40;b&#41;&#40;4&#41;</title>
										<link>http://www.compliancewiki.org/article/hipaa-written-contract-164-308-b-4-462.html</link>
										<description><![CDATA[Overview:Document the satisfactory assurances required by paragraph (b)(1) of this section through a written contract or other arrangement with the business associate that meets the applicable requirements of Â§ 164.314(a). Action Items:1) Obtain and...]]></description>

									</item>

</channel>

</rss>