The Healthcare Insurance Portability and Accountability
Act (HIPAA) was passed in 1996 in response to concerns about the privacy
and security of medical records. Portions of HIPAA require healthcare
organizations to conduct a thorough information technology (IT) risk
assessment as well as develop and implement a plan for improving and
maintaining security.
Contact Us
Select any of the services below for more information.
To design a more comprehensive compliance solution for your business,
contact VeriSign at 650-426-5310 or enterprise_security@verisign.com.
Requirements
The following solutions can help address certain
HIPAA requirements.
Key Controls |
Applies To |
How VeriSign Helps |
- Requires a regular
risk assessment (assumed to be annually).
- Requires that major
infrastructure changes undergo technical and non-technical evaluations.
|
All systems storing, transmitting or processing
regulated data: electronic Protected Health Information (ePHI) |
Enterprise
Consulting Assessments |
Requires logging of all
access to personal information (by a person or user to view, read,
write, or delete) |
Applications, servers, databases, and network
devices with ePHI |
Log
Management Service |
Requires encryption of
data at rest and in transmission, access to PHI, and integrity controls. |
ePHI in storage and in transmission. |
|
Best Practices
These solutions address industry best practices
that can augment the above required controls.
Best Practice |
Applies To |
How VeriSign Helps |
Periodic vulnerability scanning
|
All systems storing, transmitting or processing
ePHI. |
Vulnerability
Management Service |
Monitoring and intrusion detection
to identify and respond to security incidents. |
All network segments and systems storing, transmitting
or processing ePHI. |
Intrusion
Detection Management Service (IDS) |
Two-factor authentication
|
Useful for high level of compliance to requirements
for remote access/VPN, Web applications and security device authentication |
Unified
Authentication |
Firewall protection |
Network access to segments that transmit, store
or process ePHI. |
Firewall
Management Service |
Learn More