Resources

Become EPCS Certified

Certify your EHR or ePrescribing Application as Electronic Prescriptions for Controlled Substances. Learn more »

Determine If Your Healthcare Security Product Is Ready for HHS Breach Safe Harbor Certification

Use our free SecureEHR Online Product Profile to assess whether your Healthcare product qualifies for HHS Safe Harbor from Breach Reporting. Learn More »

Understand InfoGard's EHR Certification Process

cert_seal_sm.png

Use InfoGard's ONC-ATCB Process for decrypting technical language and guiding you through the procedures for becoming EHR certified.
Learn More »

The HITECH Act requires notification and allows for significant monetary and administrative penalties when a breach of the HIPAA Privacy Rule occurs.

Under the HIPAA Privacy Rule, a breach is defined as “the unauthorized acquisition, access, use, or disclosure of protected health information which compromises the security or privacy of such information…”

HHS provides guidance for rendering electronically protected health information (ePHI) unusable, unreadable, or indecipherable to unauthorized individuals. Covered entities and business associates do not have to comply with the breach notification requirements if their data are protected in accordance with the guidelines because no unsecured PHI has been accessible to unauthorized individuals.

The HHS Guidelines for securing ePHI are in addition to the to the Privacy and Security requirements of the Stage 1 certification for Meaningful Use Criteria stated in 45 CFR 170.210 Standards for health information technology to protect electronic health information created, maintained, and exchanged. The Guidelines require the use of specific technologies and methodologies approved by the National Institute of Standards and Technology (NIST) to secure ePHI while at rest, in motion, or at destruction.

Compliance with the HHS/NIST data at rest guidelines eliminates the risk of unsecured data breaches associated with stolen or inadvertently disclosed media. Compliance with the HHS/NIST data in motion guidelines will protect data movement within and between provider organizations and is an enabler for interoperability between organizations and products.

InfoGard offers SecureEHR services to ensure organizations that handle electronically protected health information (ePHI) are knowledgeable as to where they stand in appropriately securing and safeguarding ePHI against breach, according to HIPAA Privacy Rule and the HITECH Act.