control, and governance
August 2006
Enhancing HIPAA Security Rule Compliance Efforts
Achieving compliance with the U.S. Health Insurance Portability and Accountability Act's Security Rule can be a daunting task. Internal auditors can play an instrumental role during the compliance process by helping organizations gain the most from their HIPAA security audits.
Gary Swindon, CISM, CHS-III
Chief Operating Officer
RiskWatch Inc.
Protecting and securing medical information is a major concern for private, public, and government organizations in the health-care industry. Internal auditors are equally aware of this importance: Ensuring health-care records and other sensitive information do not fall into the wrong hands is of special concern. Auditors must determine whether or not the organization has taken the necessary steps to prevent the inappropriate exposure, damage, or loss of confidential data.
Since 1996, the U.S. Health Insurance Portability and Accountability Act (HIPAA) has provided organizations in the United States with guidance regarding the proper ways to protect personal health information through the act's Privacy and Security rules. While HIPAA's Privacy Rule provides information to help organizations regulate how they use and disclose personal health information, its Security Rule lists 42 standards companies need to implement to ensure the confidentiality, integrity, and availability of digital personally identifiable health information. Although both rules should be used together, the Security Rule is of special importance to IT departments, because it identifies how organizations can protect personal health information from external and internal security threats, such as e-mail attacks and password compromises.
Internal auditors can help organizations prepare for the IT component of the HIPAA security audit by focusing management's attention on key compliance considerations, such as the organization's IT governance structure; helping IT departments identify how the Security Rule's 42 standards will affect the organization's current IT environment; and comparing each of the report's findings to IT guidance provided in the Security Rule. This will enable auditors to help organizations gain the most from their HIPAA security audits.
SECURITY RULE COMPLIANCE CONSIDERATIONS
HIPAA compliance audits should be based on three things:
In the case of HIPAA's Security Rule, audits should be based on the rule's provisions or standards (i.e., safeguards and outcomes specified in the body of the regulation, as opposed to industry best practices) and be supplemented by the organization's chosen governance model. Understanding the organization's IT governance model is important, because it enables auditors to determine which standards the company views as appropriate and should be used in the conduct of the audit. The IT governance model also helps auditors frame audit findings and recommendations pertaining to IT controls and identify whether these controls are effective based on HIPAA compliance requirements. If the firm has no adopted IT governance model, the use of generally accepted IT industry standards to conduct the audit would be appropriate, such as ISO's 17799 and 27001 standards, CobiT, or the National Institute of Standard and Technology's Security Self-Assessment Guide for Information Technology Systems.
The findings of the audit should help to confirm or call into question the governance model chosen. Audit results that indicate a clear pattern of noncompliance with rules and regulations should warn executives that the company's governance model may not be appropriate.
Traditional screenings or checklists identify required compliance elements that will be reviewed during the audit, such as key items to be addressed, personnel to be interviewed, and new or existing policies. These checklists are important, because they enable the auditor to provide a list of the different areas that need to be improved or implemented for compliance to take place.
Finally, an identification of the master rules or conditions required by the regulation based on the organization's type is important, especially in situations where the company chooses to meet other standards as a demonstration of its good intentions. A good example of this is when a private nonprofit organization adopts IT controls outlined in Section 404 of the U.S. Sarbanes-Oxley Act of 2002, even though the company is exempt from Sarbanes-Oxley compliance. HIPAA's Security Rule identifies four minimum requirements or master conditions that all implemented IT measures and controls need to meet (refer to "HIPAA Security Rule Master Conditions" for more information).
THE AUDIT PROCESS
The Security Rule allows auditors to construct their audit plans more effectively by expressing desired outcomes under three safeguard categories — administrative, physical, and technical. Each of these safeguards is divided into a number of standards — 42 total — which are then categorized as required or addressable. These outcomes can be found in a matrix that has been incorporated into the final Security Rule. Although required standards must be implemented as outlined in the Security Rule, addressable standards can be structured by the entity to suit its particular needs as long as the outcome conforms to those found in the Security Rule. This process is outlined in Figure 1.
|
|
|
Figure 1: HIPAA Security Rule audit process |
HIPAA security audits require the auditor to pay attention to the prevailing general conditions or stipulations that may impact the audit plan, as well as how existing controls and methods address each of the 42 security standards. In terms of IT, auditors need to review the organization's use of appropriate controls to ensure the protection of personally identifiable health information. The following list provides useful information auditors should keep in mind during Security Rule audits:
|
HIPAA Security Rule Master Conditions The Security Rule outlines four master conditions or minimum requirements that apply to business controls and processes used to address the rule's 42 standards. These minimum requirements state that all selected controls must be:
During Security Rule compliance reviews, internal auditors need to identify how companywide IT measures and controls meet each of the four requirements. |
Prior to releasing audit findings, internal auditors should be able to answer questions regarding the report's IT recommendations. To do this, auditors can compare each of the report's findings to IT guidance provided in the Security Rule. The following questions can help auditors identify how current IT controls compare to IT guidance provided in the Security Rule, as well as determine whether existing controls meet compliance requirements:
LEVERAGING AUDIT RECOMMENDATIONS
Although the information above focuses primarily on the IT aspect of Security Rule compliance, these basic recommendations can be used for overall HIPAA compliance audits. These recommendations also can be applied to other regulations, particularly Sarbanes-Oxley and the U.S. Graham-Leach-Bliley Act (GLBA) of 1999. For instance, HIPAA, Sarbanes-Oxley, and GLBA share many common requirements, such as the need for companies to conduct regular risk assessments or the need to achieve cost effectiveness and stay within the company's IT capability. Furthermore, the blending of implemented audit compliance requirements from different regulations and the organization's adopted governance model can highlight the potential need for changes in the way the company views IT risks and uses IT resources.
For more information about HIPAA, visit:
Gary Swindon is the chief operating officer for RiskWatch Inc., a security risk assessment company. Prior to RiskWatch, Swindon held senior positions in both public and private organizations, including Orlando Regional Healthcare, where he was the hospital group's chief information security officer; WebMD, where he served as chief security and privacy officer; and the state of Michigan, where he was responsible for consolidating more than 20 data centers. He also has served as a director for the ISACA CISM certification board.
Internal Auditor is pleased to provide you an opportunity to share your thoughts about the articles posted on this site. Some comments may be reprinted elsewhere, online, or offline. We encourage lively, open discussion and only ask that you refrain from personal comments and remarks that are off topic. Internal Auditor reserves the right to edit/remove comments.