SlideShare a Scribd company logo
1 of 21
Download to read offline
Decoding HIPAA for Developers!
Jason Wang!
Founder & CEO, TrueVault!
1996 - HIPAA
!!
1996 - HIPAA!
1996 – HIPAA!
!
2009 – HITECH!
!
2013 – Final Omnibus Rule Update!
HIPAA Acronyms!
PHI – Protected Health Information!
!
CE – Covered Entities!
BA – Business Associates!
BAA – Business Associate Agreement!
HIPAA	
  
Privacy	
  Rule	
  Security	
  Rule	
  
Administra6ve	
  
Safeguards	
  
Technical	
  
Safeguards	
  
Physical	
  
Safeguards	
  
Enforcement	
  
Rule	
  
Breach	
  
No6fica6on	
  Rule	
  
HIPAA	
  
Privacy	
  Rule	
  Security	
  Rule	
  
Administra6ve	
  
Safeguards	
  
Technical	
  
Safeguards	
  
Physical	
  
Safeguards	
  
Enforcement	
  
Rule	
  
Breach	
  
No6fica6on	
  Rule	
  
If	
  you’re	
  a	
  developer	
  trying	
  to	
  understand	
  the	
  
scope	
  of	
  the	
  build,	
  then	
  you	
  need	
  to	
  focus	
  on	
  
the	
  Technical	
  and	
  Physical	
  Safeguards	
  spelled	
  
out	
  in	
  the	
  Security	
  Rule;	
  these	
  two	
  sec6ons	
  
comprise	
  the	
  majority	
  of	
  your	
  to-­‐do	
  list.	
  
	
  
Who Needs to be HIPAA Compliant?
If you handle PHI then you need to be HIPAA
compliant.!
!
The HIPAA rules apply to both Covered
Entities and their Business Associates!
!
Who Certifies HIPAA Compliance?
The short answer is no one.!
“required” vs. “addressable”!
Some implementation specifications are “required” and others are
“addressable.” Required implementation specifications must be
implemented. Addressable implementation specifications must be
implemented if it is reasonable and appropriate to do so; your choice
must be documented.!
!
It is important to remember that an addressable implementation
specification is not optional. !
!
When in doubt, you should just implement the addressable
implementation specifications. Most of them are best practices anyway.!
Addressable does NOT mean optional!
Technical Safeguards!
1.  Access Control - Unique User Identification (required):
Assign a unique name and/or number for identifying and
tracking user identity.!
!
2.  Access Control - Emergency Access Procedure (required):
Establish (and implement as needed) procedures for
obtaining necessary ePHI during an emergency.!
3.  Access Control - Automatic Logoff (addressable):
Implement electronic procedures that terminate an electronic
session after a predetermined time of inactivity.!
!
4.  Access Control - Encryption and Decryption (addressable):
Implement a mechanism to encrypt and decrypt ePHI.!
Technical Safeguards
5.  Audit Controls (required): Implement hardware, software, and/or
procedural mechanisms that record and examine activity in information
systems that contain or use ePHI.!
6.  Integrity - Mechanism to Authenticate ePHI (addressable):
Implement electronic mechanisms to corroborate that ePHI has not
been altered or destroyed in an unauthorized manner.!
7.  Authentication (required): Implement procedures to verify that a
person or entity seeking access to ePHI is the one claimed.!
!
8.  Transmission Security - Integrity Controls (addressable): Implement
security measures to ensure that electronically transmitted ePHI is not
improperly modified without detection until disposed of.!
!
9.  Transmission Security - Encryption (addressable): Implement a
mechanism to encrypt ePHI whenever deemed appropriate.!
Physical Safeguards
1.  Facility Access Controls - Contingency Operations (addressable):
Establish (and implement as needed) procedures that allow facility
access in support of restoration of lost data under the disaster
recovery plan and emergency mode operations plan in the event of an
emergency.!
2.  Facility Access Controls - Facility Security Plan (addressable):
Implement policies and procedures to safeguard the facility and the
equipment therein from unauthorized physical access, tampering, and
theft.!
3.  Facility Access Controls - Access Control and Validation
Procedures (addressable): Implement procedures to control and
validate a person’s access to facilities based on their role or function,
including visitor control, and control of access to software programs for
testing and revision.!
HIPAA Compliant Hosting Providers can take care of some of the Physical Safeguards for you.!
Physical Safeguards
4.  Facility Access Controls - Maintenance Records (addressable):
Implement policies and procedures to document repairs and
modifications to the physical components of a facility which are
related to security (e.g. hardware, walls, doors, and locks).!
5.  Workstation Use (required): Implement policies and procedures that
specify the proper functions to be performed, the manner in which
those functions are to be performed, and the physical attributes of the
surroundings of a specific workstation or class of workstation that can
access ePHI.!
6.  Workstation Security (required): Implement physical safeguards for
all workstations that access ePHI, to restrict access to authorized
users.!
HIPAA Compliant Hosting Providers can take care of some of the Physical Safeguards for you.!
Physical Safeguards
7.  Device and Media Controls - Disposal (required): Implement policies
and procedures to address the final disposition of ePHI, and/or the
hardware or electronic media on which it is stored.!
!
8.  Device and Media Controls - Media Re-Use (required): Implement
procedures for removal of ePHI from electronic media before the
media are made available for re-use.!
!
9.  Device and Media Controls - Accountability (addressable): Maintain
a record of the movements of hardware and electronic media and any
person responsible therefore.!
!
10.  Device and Media Controls - Data Backup and Storage
(addressable): Create a retrievable, exact copy of ePHI, when
needed, before movement of equipment.!
HIPAA Compliant Hosting Providers can take care of some of the Physical Safeguards for you.!
What Else?
•  Emails, texts, voicemails!
•  3rd party tools (MixPanel, Loggly, New Relic, etc)!
•  Administrative Safeguards!
•  Building a HIPAA compliant infrastructure!
Q&A Time!
Shameless Promotions:!
!
•  TrueVault is hiring Developers, DevOps Engineers in San Francisco !
•  Join our iOS SDK beta list – Be the first to release an iOS app leveraging Health Book!
http://go.truevault.com/ios8!
!
Thank	
  you!	
  
Jason	
  Wang	
  
Founder	
  &	
  CEO,	
  TrueVault	
  
May	
  29,	
  2014	
   Confiden6al	
  -­‐	
  Not	
  for	
  
What is Protected Health Information (PHI)?

PHI	
  is	
  any	
  informa6on	
  in	
  a	
  medical	
  record	
  that	
  can	
  be	
  used	
  to	
  iden6fy	
  
an	
  individual,	
  and	
  that	
  was	
  created,	
  used,	
  or	
  disclosed	
  in	
  the	
  course	
  of	
  
providing	
  a	
  healthcare	
  service,	
  such	
  as	
  a	
  diagnosis	
  or	
  treatment.	
  
	
  
PHI	
  is	
  informa6on	
  in	
  your	
  medical	
  records,	
  including	
  conversa6ons	
  
between	
  your	
  doctors	
  and	
  nurses	
  about	
  your	
  treatment.	
  PHI	
  also	
  
includes	
  your	
  billing	
  informa6on	
  and	
  any	
  medical	
  informa6on	
  in	
  your	
  
health	
  insurance	
  company's	
  computer	
  system.	
  
	
  
This	
  includes	
  any	
  individually	
  iden6fiable	
  health	
  informa6on	
  collected	
  
from	
  an	
  individual	
  by	
  a	
  healthcare	
  provider,	
  employer	
  or	
  plan	
  that	
  
includes	
  name,	
  social	
  security	
  number,	
  phone	
  number,	
  medical	
  
history,	
  current	
  medical	
  condi6on,	
  test	
  results	
  and	
  more.	
  
	
  
Electronic	
  Protected	
  Health	
  Informa3on	
  (EPHI)	
  
All	
  individually	
  iden6fiable	
  health	
  informa6on	
  that	
  is	
  created,	
  
maintained,	
  or	
  transmiZed	
  electronically.	
  
	
  
May	
  29,	
  2014	
   Confiden6al	
  -­‐	
  Not	
  for	
  
Covered Entity (CE)
Anyone	
  who	
  provides	
  treatment,	
  payment	
  and	
  opera6ons	
  
in	
  healthcare.	
  	
  
	
  
It	
  could	
  include	
  a	
  doctor’s	
  office,	
  dental	
  office,	
  clinics,	
  
psychologist,	
  nursing	
  home,	
  pharmacy,	
  hospital	
  or	
  home	
  
healthcare	
  agency.	
  	
  
	
  
This	
  also	
  includes	
  health	
  plans,	
  health	
  insurance	
  
companies,	
  HMOs,	
  company	
  health	
  plans	
  and	
  government	
  
programs	
  that	
  pay	
  for	
  health	
  care.	
  	
  
	
  
Health	
  clearing	
  houses	
  are	
  also	
  considered	
  covered	
  
en66es.	
  
	
  
May	
  29,	
  2014	
   Confiden6al	
  -­‐	
  Not	
  for	
  
Business Associate
Anyone	
  who	
  has	
  access	
  to	
  pa6ent	
  informa6on,	
  whether	
  directly,	
  indirectly,	
  
physically	
  or	
  virtually.	
  	
  
	
  
Addi6onally,	
  any	
  organiza6on	
  that	
  provides	
  support	
  in	
  the	
  treatment,	
  
payment	
  or	
  opera6ons	
  is	
  considered	
  a	
  business	
  associate,	
  i.e.	
  an	
  IT	
  company	
  
or	
  a	
  mHealth	
  applica6on	
  that	
  provides	
  secure	
  photo-­‐sharing	
  for	
  physicians.	
  
	
  
Other	
  examples	
  include	
  a	
  document	
  destruc6on	
  company,	
  a	
  telephone	
  
service	
  provider,	
  accountant,	
  or	
  lawyer.	
  	
  
	
  
The	
  business	
  associates	
  also	
  have	
  the	
  responsibility	
  to	
  achieve	
  and	
  maintain	
  
HIPAA	
  compliance	
  in	
  terms	
  of	
  all	
  of	
  the	
  internal,	
  administra6ve,	
  and	
  technical	
  
safeguards.	
  	
  
	
  
A	
  business	
  associate	
  does	
  not	
  work	
  under	
  the	
  covered	
  en6ty’s	
  workforce,	
  but	
  
instead	
  performs	
  some	
  type	
  of	
  service	
  on	
  their	
  behalf.	
  
	
  

More Related Content

What's hot

EHR meaningful use security risk assessment sample document
EHR meaningful use security risk assessment sample documentEHR meaningful use security risk assessment sample document
EHR meaningful use security risk assessment sample documentdata brackets
 
Business Associates: How to become HIPAA compliant, increase revenue, and gai...
Business Associates: How to become HIPAA compliant, increase revenue, and gai...Business Associates: How to become HIPAA compliant, increase revenue, and gai...
Business Associates: How to become HIPAA compliant, increase revenue, and gai...Compliancy Group
 
HIPAA Solutions on Cloud Foundry
HIPAA Solutions on Cloud FoundryHIPAA Solutions on Cloud Foundry
HIPAA Solutions on Cloud FoundryJim Shingler
 
Security White Paper From Paychex
Security White Paper From PaychexSecurity White Paper From Paychex
Security White Paper From Paychexcboston
 
Web Werks Data Center Achieves HIPAA Compliance Certification
Web Werks Data Center Achieves HIPAA Compliance CertificationWeb Werks Data Center Achieves HIPAA Compliance Certification
Web Werks Data Center Achieves HIPAA Compliance CertificationWeb Werks Data Centers
 
Security & Privacy - Lecture E
Security & Privacy - Lecture ESecurity & Privacy - Lecture E
Security & Privacy - Lecture ECMDLearning
 
FRSecure Sales Deck
FRSecure Sales DeckFRSecure Sales Deck
FRSecure Sales DeckEvan Francen
 
How to Secure Your Medical Devices
How to Secure Your Medical DevicesHow to Secure Your Medical Devices
How to Secure Your Medical DevicesSecurityMetrics
 
Meaningful Use and Security Risk Analysis
Meaningful Use and Security Risk AnalysisMeaningful Use and Security Risk Analysis
Meaningful Use and Security Risk AnalysisEvan Francen
 
Norris, t week 1 discussion 2
Norris, t week 1 discussion 2Norris, t week 1 discussion 2
Norris, t week 1 discussion 2Tina Norris
 
HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations OnRamp
 
Security Crossroads of Healthcare reforms and IoT enabled E-health
Security Crossroads of Healthcare reforms and IoT enabled E-healthSecurity Crossroads of Healthcare reforms and IoT enabled E-health
Security Crossroads of Healthcare reforms and IoT enabled E-healthRajesh Vargheese
 
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)U.S. News Healthcare of Tomorrow
 
Security in electronic health records
Security in electronic health recordsSecurity in electronic health records
Security in electronic health recordssamuelerie
 

What's hot (17)

EHR meaningful use security risk assessment sample document
EHR meaningful use security risk assessment sample documentEHR meaningful use security risk assessment sample document
EHR meaningful use security risk assessment sample document
 
Ecfirstbiz
EcfirstbizEcfirstbiz
Ecfirstbiz
 
Business Associates: How to become HIPAA compliant, increase revenue, and gai...
Business Associates: How to become HIPAA compliant, increase revenue, and gai...Business Associates: How to become HIPAA compliant, increase revenue, and gai...
Business Associates: How to become HIPAA compliant, increase revenue, and gai...
 
HIPAA Solutions on Cloud Foundry
HIPAA Solutions on Cloud FoundryHIPAA Solutions on Cloud Foundry
HIPAA Solutions on Cloud Foundry
 
Security White Paper From Paychex
Security White Paper From PaychexSecurity White Paper From Paychex
Security White Paper From Paychex
 
Web Werks Data Center Achieves HIPAA Compliance Certification
Web Werks Data Center Achieves HIPAA Compliance CertificationWeb Werks Data Center Achieves HIPAA Compliance Certification
Web Werks Data Center Achieves HIPAA Compliance Certification
 
Security & Privacy - Lecture E
Security & Privacy - Lecture ESecurity & Privacy - Lecture E
Security & Privacy - Lecture E
 
FRSecure Sales Deck
FRSecure Sales DeckFRSecure Sales Deck
FRSecure Sales Deck
 
How to Secure Your Medical Devices
How to Secure Your Medical DevicesHow to Secure Your Medical Devices
How to Secure Your Medical Devices
 
Meaningful Use and Security Risk Analysis
Meaningful Use and Security Risk AnalysisMeaningful Use and Security Risk Analysis
Meaningful Use and Security Risk Analysis
 
Norris, t week 1 discussion 2
Norris, t week 1 discussion 2Norris, t week 1 discussion 2
Norris, t week 1 discussion 2
 
HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations
 
Confidentiality
ConfidentialityConfidentiality
Confidentiality
 
Security Crossroads of Healthcare reforms and IoT enabled E-health
Security Crossroads of Healthcare reforms and IoT enabled E-healthSecurity Crossroads of Healthcare reforms and IoT enabled E-health
Security Crossroads of Healthcare reforms and IoT enabled E-health
 
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)
Safeguarding Patient Privacy in a Digital Age (Meredith Phillips)
 
Security in electronic health records
Security in electronic health recordsSecurity in electronic health records
Security in electronic health records
 
Common Security Framework Summary
Common Security Framework SummaryCommon Security Framework Summary
Common Security Framework Summary
 

Viewers also liked

HXR 2016: Designing for Addiction and Recovery -Mary Beth Schoening, Behavior...
HXR 2016: Designing for Addiction and Recovery -Mary Beth Schoening, Behavior...HXR 2016: Designing for Addiction and Recovery -Mary Beth Schoening, Behavior...
HXR 2016: Designing for Addiction and Recovery -Mary Beth Schoening, Behavior...HxRefactored
 
HXR 2016: New Models for Care Delivery -Andrew Schutzbank, Iora Health
HXR 2016: New Models for Care Delivery -Andrew Schutzbank, Iora HealthHXR 2016: New Models for Care Delivery -Andrew Schutzbank, Iora Health
HXR 2016: New Models for Care Delivery -Andrew Schutzbank, Iora HealthHxRefactored
 
HIPAA Compliance for Developers
HIPAA Compliance for DevelopersHIPAA Compliance for Developers
HIPAA Compliance for DevelopersTrueVault
 
HXR 2016: Sustainable Design -Jen Briselli, James Christie, Mad*Pow
HXR 2016: Sustainable Design -Jen Briselli, James Christie, Mad*PowHXR 2016: Sustainable Design -Jen Briselli, James Christie, Mad*Pow
HXR 2016: Sustainable Design -Jen Briselli, James Christie, Mad*PowHxRefactored
 
A LOMCE para profes, nais e pais.
A LOMCE para profes, nais e pais.A LOMCE para profes, nais e pais.
A LOMCE para profes, nais e pais.castrexo33
 
22560 luz mila galvis valbuena
22560  luz mila galvis valbuena22560  luz mila galvis valbuena
22560 luz mila galvis valbuena2015andes
 
Ciclo vital de la informacion y fases
Ciclo vital de la informacion y fasesCiclo vital de la informacion y fases
Ciclo vital de la informacion y fasesNatalia Areiza
 
Designing for the iPad
Designing for the iPadDesigning for the iPad
Designing for the iPadusabilitynj
 
Contabilidade respostas 025
Contabilidade respostas 025Contabilidade respostas 025
Contabilidade respostas 025geral contabil
 
Formación de el núcleo familiar
Formación de el núcleo familiarFormación de el núcleo familiar
Formación de el núcleo familiarjenifferselena
 

Viewers also liked (20)

Aduana12
Aduana12Aduana12
Aduana12
 
HXR 2016: Designing for Addiction and Recovery -Mary Beth Schoening, Behavior...
HXR 2016: Designing for Addiction and Recovery -Mary Beth Schoening, Behavior...HXR 2016: Designing for Addiction and Recovery -Mary Beth Schoening, Behavior...
HXR 2016: Designing for Addiction and Recovery -Mary Beth Schoening, Behavior...
 
HXR 2016: New Models for Care Delivery -Andrew Schutzbank, Iora Health
HXR 2016: New Models for Care Delivery -Andrew Schutzbank, Iora HealthHXR 2016: New Models for Care Delivery -Andrew Schutzbank, Iora Health
HXR 2016: New Models for Care Delivery -Andrew Schutzbank, Iora Health
 
HIPAA Compliance for Developers
HIPAA Compliance for DevelopersHIPAA Compliance for Developers
HIPAA Compliance for Developers
 
HXR 2016: Sustainable Design -Jen Briselli, James Christie, Mad*Pow
HXR 2016: Sustainable Design -Jen Briselli, James Christie, Mad*PowHXR 2016: Sustainable Design -Jen Briselli, James Christie, Mad*Pow
HXR 2016: Sustainable Design -Jen Briselli, James Christie, Mad*Pow
 
Diario guido 9 12 pag - 2013
Diario guido 9   12 pag - 2013Diario guido 9   12 pag - 2013
Diario guido 9 12 pag - 2013
 
Unidad II
Unidad IIUnidad II
Unidad II
 
Planeacion de un_wiki_icagra
Planeacion de un_wiki_icagraPlaneacion de un_wiki_icagra
Planeacion de un_wiki_icagra
 
Erp
ErpErp
Erp
 
A LOMCE para profes, nais e pais.
A LOMCE para profes, nais e pais.A LOMCE para profes, nais e pais.
A LOMCE para profes, nais e pais.
 
communication
communicationcommunication
communication
 
22560 luz mila galvis valbuena
22560  luz mila galvis valbuena22560  luz mila galvis valbuena
22560 luz mila galvis valbuena
 
Seminario5
Seminario5Seminario5
Seminario5
 
Adviento
AdvientoAdviento
Adviento
 
Ciclo vital de la informacion y fases
Ciclo vital de la informacion y fasesCiclo vital de la informacion y fases
Ciclo vital de la informacion y fases
 
Designing for the iPad
Designing for the iPadDesigning for the iPad
Designing for the iPad
 
Contabilidade respostas 025
Contabilidade respostas 025Contabilidade respostas 025
Contabilidade respostas 025
 
Formación de el núcleo familiar
Formación de el núcleo familiarFormación de el núcleo familiar
Formación de el núcleo familiar
 
Guia 10
Guia 10Guia 10
Guia 10
 
6A- Vigilancia sindrómica
6A- Vigilancia sindrómica6A- Vigilancia sindrómica
6A- Vigilancia sindrómica
 

Similar to HxRefactored - TrueVault - Jason Wang

HIPAA Compliance Testing In Software Applications.pdf
HIPAA Compliance Testing In Software Applications.pdfHIPAA Compliance Testing In Software Applications.pdf
HIPAA Compliance Testing In Software Applications.pdfZoe Gilbert
 
HIPAA Compliance For Small Practices
HIPAA Compliance For Small PracticesHIPAA Compliance For Small Practices
HIPAA Compliance For Small PracticesNisos Health
 
Cain and AbelOphcrackStart H.docx
Cain and AbelOphcrackStart H.docxCain and AbelOphcrackStart H.docx
Cain and AbelOphcrackStart H.docxRAHUL126667
 
how to really implement hipaa presentation
how to really implement hipaa presentationhow to really implement hipaa presentation
how to really implement hipaa presentationProvider Resources Group
 
Healthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTHealthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTControlCase
 
Hipaa privacy and security real world cases and breach determinations
Hipaa privacy and security   real world cases and breach determinationsHipaa privacy and security   real world cases and breach determinations
Hipaa privacy and security real world cases and breach determinationsCompliance Trainings
 
The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act Kartheek Kein
 
Cyb 610 Education Organization-snaptutorial.com
Cyb 610 Education Organization-snaptutorial.comCyb 610 Education Organization-snaptutorial.com
Cyb 610 Education Organization-snaptutorial.comrobertlesew8
 
Cyb 610 Believe Possibilities / snaptutorial.com
Cyb 610  Believe Possibilities / snaptutorial.comCyb 610  Believe Possibilities / snaptutorial.com
Cyb 610 Believe Possibilities / snaptutorial.comDavis12a
 
Cyb 610Education Specialist / snaptutorial.com
Cyb 610Education Specialist / snaptutorial.comCyb 610Education Specialist / snaptutorial.com
Cyb 610Education Specialist / snaptutorial.comMcdonaldRyan80
 
Securing Mobile Healthcare Application
Securing Mobile Healthcare ApplicationSecuring Mobile Healthcare Application
Securing Mobile Healthcare ApplicationCitiusTech
 
C427 Technology Applications in Healthcare Performance Assessment.docx
C427 Technology Applications in Healthcare Performance Assessment.docxC427 Technology Applications in Healthcare Performance Assessment.docx
C427 Technology Applications in Healthcare Performance Assessment.docxwrite22
 
C427 Technology Applications in Healthcare Performance Assessment.docx
C427 Technology Applications in Healthcare Performance Assessment.docxC427 Technology Applications in Healthcare Performance Assessment.docx
C427 Technology Applications in Healthcare Performance Assessment.docxwrite31
 
Homework AssignmentShort Answer Responses.1. Describe the fiv.docx
Homework AssignmentShort Answer Responses.1.  Describe the fiv.docxHomework AssignmentShort Answer Responses.1.  Describe the fiv.docx
Homework AssignmentShort Answer Responses.1. Describe the fiv.docxadampcarr67227
 
CYB 610 Exceptional Education - snaptutorial.com
CYB 610   Exceptional Education - snaptutorial.comCYB 610   Exceptional Education - snaptutorial.com
CYB 610 Exceptional Education - snaptutorial.comDavisMurphyA98
 
Cst 610 Believe Possibilities / snaptutorial.com
Cst 610  Believe Possibilities / snaptutorial.comCst 610  Believe Possibilities / snaptutorial.com
Cst 610 Believe Possibilities / snaptutorial.comDavis10a
 
CYB 610 Effective Communication - snaptutorial.com
CYB 610 Effective Communication - snaptutorial.comCYB 610 Effective Communication - snaptutorial.com
CYB 610 Effective Communication - snaptutorial.comdonaldzs9
 

Similar to HxRefactored - TrueVault - Jason Wang (20)

HIPAA Compliance Testing In Software Applications.pdf
HIPAA Compliance Testing In Software Applications.pdfHIPAA Compliance Testing In Software Applications.pdf
HIPAA Compliance Testing In Software Applications.pdf
 
HIPAA Compliance For Small Practices
HIPAA Compliance For Small PracticesHIPAA Compliance For Small Practices
HIPAA Compliance For Small Practices
 
Cain and AbelOphcrackStart H.docx
Cain and AbelOphcrackStart H.docxCain and AbelOphcrackStart H.docx
Cain and AbelOphcrackStart H.docx
 
how to really implement hipaa presentation
how to really implement hipaa presentationhow to really implement hipaa presentation
how to really implement hipaa presentation
 
HIPAA AND IT AUDITS.pdf
HIPAA AND IT AUDITS.pdfHIPAA AND IT AUDITS.pdf
HIPAA AND IT AUDITS.pdf
 
Healthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTHealthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUST
 
HIPAA and How it Applies to You
HIPAA and How it Applies to YouHIPAA and How it Applies to You
HIPAA and How it Applies to You
 
Hipaa privacy and security real world cases and breach determinations
Hipaa privacy and security   real world cases and breach determinationsHipaa privacy and security   real world cases and breach determinations
Hipaa privacy and security real world cases and breach determinations
 
web-MINImag
web-MINImagweb-MINImag
web-MINImag
 
The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act The Health Insurance Portability and Accountability Act 
The Health Insurance Portability and Accountability Act 
 
Cyb 610 Education Organization-snaptutorial.com
Cyb 610 Education Organization-snaptutorial.comCyb 610 Education Organization-snaptutorial.com
Cyb 610 Education Organization-snaptutorial.com
 
Cyb 610 Believe Possibilities / snaptutorial.com
Cyb 610  Believe Possibilities / snaptutorial.comCyb 610  Believe Possibilities / snaptutorial.com
Cyb 610 Believe Possibilities / snaptutorial.com
 
Cyb 610Education Specialist / snaptutorial.com
Cyb 610Education Specialist / snaptutorial.comCyb 610Education Specialist / snaptutorial.com
Cyb 610Education Specialist / snaptutorial.com
 
Securing Mobile Healthcare Application
Securing Mobile Healthcare ApplicationSecuring Mobile Healthcare Application
Securing Mobile Healthcare Application
 
C427 Technology Applications in Healthcare Performance Assessment.docx
C427 Technology Applications in Healthcare Performance Assessment.docxC427 Technology Applications in Healthcare Performance Assessment.docx
C427 Technology Applications in Healthcare Performance Assessment.docx
 
C427 Technology Applications in Healthcare Performance Assessment.docx
C427 Technology Applications in Healthcare Performance Assessment.docxC427 Technology Applications in Healthcare Performance Assessment.docx
C427 Technology Applications in Healthcare Performance Assessment.docx
 
Homework AssignmentShort Answer Responses.1. Describe the fiv.docx
Homework AssignmentShort Answer Responses.1.  Describe the fiv.docxHomework AssignmentShort Answer Responses.1.  Describe the fiv.docx
Homework AssignmentShort Answer Responses.1. Describe the fiv.docx
 
CYB 610 Exceptional Education - snaptutorial.com
CYB 610   Exceptional Education - snaptutorial.comCYB 610   Exceptional Education - snaptutorial.com
CYB 610 Exceptional Education - snaptutorial.com
 
Cst 610 Believe Possibilities / snaptutorial.com
Cst 610  Believe Possibilities / snaptutorial.comCst 610  Believe Possibilities / snaptutorial.com
Cst 610 Believe Possibilities / snaptutorial.com
 
CYB 610 Effective Communication - snaptutorial.com
CYB 610 Effective Communication - snaptutorial.comCYB 610 Effective Communication - snaptutorial.com
CYB 610 Effective Communication - snaptutorial.com
 

More from HxRefactored

HXR 2017: Denise Gosnell, Pokitdok: Blockchain: The Now and The Future:
HXR 2017: Denise Gosnell, Pokitdok: Blockchain: The Now and The Future: HXR 2017: Denise Gosnell, Pokitdok: Blockchain: The Now and The Future:
HXR 2017: Denise Gosnell, Pokitdok: Blockchain: The Now and The Future: HxRefactored
 
HXR 2017: Susan Hunt Stevens, WeSpire: Holistic Wellbeing
HXR 2017: Susan Hunt Stevens, WeSpire: Holistic WellbeingHXR 2017: Susan Hunt Stevens, WeSpire: Holistic Wellbeing
HXR 2017: Susan Hunt Stevens, WeSpire: Holistic WellbeingHxRefactored
 
HXR 2017: John Weiss, Human Design: Building a Culture of Health
HXR 2017: John Weiss, Human Design: Building a Culture of HealthHXR 2017: John Weiss, Human Design: Building a Culture of Health
HXR 2017: John Weiss, Human Design: Building a Culture of HealthHxRefactored
 
HXR 2017: Juhan Sonin, GoInvo
HXR 2017: Juhan Sonin, GoInvoHXR 2017: Juhan Sonin, GoInvo
HXR 2017: Juhan Sonin, GoInvoHxRefactored
 
HXR 2017: Heather Patrick, Carrot Sense: Motivation and Health Behavior Change
HXR 2017: Heather Patrick, Carrot Sense: Motivation and Health Behavior ChangeHXR 2017: Heather Patrick, Carrot Sense: Motivation and Health Behavior Change
HXR 2017: Heather Patrick, Carrot Sense: Motivation and Health Behavior ChangeHxRefactored
 
HXR 2017: Casey Quinlan: the Price is Right
HXR 2017: Casey Quinlan: the Price is RightHXR 2017: Casey Quinlan: the Price is Right
HXR 2017: Casey Quinlan: the Price is RightHxRefactored
 
HXR 2017: Bakul Patel: How the FDA Is Promoting Innovation and Protecting the...
HXR 2017: Bakul Patel: How the FDA Is Promoting Innovation and Protecting the...HXR 2017: Bakul Patel: How the FDA Is Promoting Innovation and Protecting the...
HXR 2017: Bakul Patel: How the FDA Is Promoting Innovation and Protecting the...HxRefactored
 
HXR 2017: Jay Gupta, RxRelax: RxRelax to Reverse Polypharmacy Trends
HXR 2017: Jay Gupta, RxRelax: RxRelax to Reverse Polypharmacy TrendsHXR 2017: Jay Gupta, RxRelax: RxRelax to Reverse Polypharmacy Trends
HXR 2017: Jay Gupta, RxRelax: RxRelax to Reverse Polypharmacy TrendsHxRefactored
 
HXR 2017: Kathleen Howland, Berklee College of Music: Music Therapy in Health...
HXR 2017: Kathleen Howland, Berklee College of Music: Music Therapy in Health...HXR 2017: Kathleen Howland, Berklee College of Music: Music Therapy in Health...
HXR 2017: Kathleen Howland, Berklee College of Music: Music Therapy in Health...HxRefactored
 
HXR 2017: Center for Health Experience Design Announcement
HXR 2017: Center for Health Experience Design Announcement HXR 2017: Center for Health Experience Design Announcement
HXR 2017: Center for Health Experience Design Announcement HxRefactored
 
HXR 2017: Paul Kahn, Mad*Pow: Lessons Learned from a Bill you can understand
HXR 2017: Paul Kahn, Mad*Pow: Lessons Learned from a Bill you can understandHXR 2017: Paul Kahn, Mad*Pow: Lessons Learned from a Bill you can understand
HXR 2017: Paul Kahn, Mad*Pow: Lessons Learned from a Bill you can understandHxRefactored
 
HXR 2017: Design Challenge Announcement!
HXR 2017: Design Challenge Announcement!HXR 2017: Design Challenge Announcement!
HXR 2017: Design Challenge Announcement!HxRefactored
 
HXR 2017: Aneesh Chopra, NavHealth: Call to Action: All Hands on Deck to Brin...
HXR 2017: Aneesh Chopra, NavHealth: Call to Action: All Hands on Deck to Brin...HXR 2017: Aneesh Chopra, NavHealth: Call to Action: All Hands on Deck to Brin...
HXR 2017: Aneesh Chopra, NavHealth: Call to Action: All Hands on Deck to Brin...HxRefactored
 
HXR 2017: Amy Cueva, Mad*Pow: Purpose Driven Design
HXR 2017: Amy Cueva, Mad*Pow: Purpose Driven DesignHXR 2017: Amy Cueva, Mad*Pow: Purpose Driven Design
HXR 2017: Amy Cueva, Mad*Pow: Purpose Driven DesignHxRefactored
 
HXR 2016: Addressing the Opioid Crisis
HXR 2016: Addressing the Opioid CrisisHXR 2016: Addressing the Opioid Crisis
HXR 2016: Addressing the Opioid CrisisHxRefactored
 
HXR 2016: New Models for Care Delivery -Ethan Berke, Dartmouth-Hitchcock
HXR 2016: New Models for Care Delivery -Ethan Berke, Dartmouth-HitchcockHXR 2016: New Models for Care Delivery -Ethan Berke, Dartmouth-Hitchcock
HXR 2016: New Models for Care Delivery -Ethan Berke, Dartmouth-HitchcockHxRefactored
 
HXR 2016: Human Focused Innovation in a Clinical Setting -Lesley Solomon, Bri...
HXR 2016: Human Focused Innovation in a Clinical Setting -Lesley Solomon, Bri...HXR 2016: Human Focused Innovation in a Clinical Setting -Lesley Solomon, Bri...
HXR 2016: Human Focused Innovation in a Clinical Setting -Lesley Solomon, Bri...HxRefactored
 
HXR 2016: Human Focused Innovation in a Clinical Setting -Jennie Kung, UCLA H...
HXR 2016: Human Focused Innovation in a Clinical Setting -Jennie Kung, UCLA H...HXR 2016: Human Focused Innovation in a Clinical Setting -Jennie Kung, UCLA H...
HXR 2016: Human Focused Innovation in a Clinical Setting -Jennie Kung, UCLA H...HxRefactored
 
HXR 2016: Human Focused Innovation in a Clinical Setting -Dr. Nancy Hanrahan,...
HXR 2016: Human Focused Innovation in a Clinical Setting -Dr. Nancy Hanrahan,...HXR 2016: Human Focused Innovation in a Clinical Setting -Dr. Nancy Hanrahan,...
HXR 2016: Human Focused Innovation in a Clinical Setting -Dr. Nancy Hanrahan,...HxRefactored
 
HXR 2016: Human Focused Innovation in a Clinical Setting -Marnie de Mooij, Ma...
HXR 2016: Human Focused Innovation in a Clinical Setting -Marnie de Mooij, Ma...HXR 2016: Human Focused Innovation in a Clinical Setting -Marnie de Mooij, Ma...
HXR 2016: Human Focused Innovation in a Clinical Setting -Marnie de Mooij, Ma...HxRefactored
 

More from HxRefactored (20)

HXR 2017: Denise Gosnell, Pokitdok: Blockchain: The Now and The Future:
HXR 2017: Denise Gosnell, Pokitdok: Blockchain: The Now and The Future: HXR 2017: Denise Gosnell, Pokitdok: Blockchain: The Now and The Future:
HXR 2017: Denise Gosnell, Pokitdok: Blockchain: The Now and The Future:
 
HXR 2017: Susan Hunt Stevens, WeSpire: Holistic Wellbeing
HXR 2017: Susan Hunt Stevens, WeSpire: Holistic WellbeingHXR 2017: Susan Hunt Stevens, WeSpire: Holistic Wellbeing
HXR 2017: Susan Hunt Stevens, WeSpire: Holistic Wellbeing
 
HXR 2017: John Weiss, Human Design: Building a Culture of Health
HXR 2017: John Weiss, Human Design: Building a Culture of HealthHXR 2017: John Weiss, Human Design: Building a Culture of Health
HXR 2017: John Weiss, Human Design: Building a Culture of Health
 
HXR 2017: Juhan Sonin, GoInvo
HXR 2017: Juhan Sonin, GoInvoHXR 2017: Juhan Sonin, GoInvo
HXR 2017: Juhan Sonin, GoInvo
 
HXR 2017: Heather Patrick, Carrot Sense: Motivation and Health Behavior Change
HXR 2017: Heather Patrick, Carrot Sense: Motivation and Health Behavior ChangeHXR 2017: Heather Patrick, Carrot Sense: Motivation and Health Behavior Change
HXR 2017: Heather Patrick, Carrot Sense: Motivation and Health Behavior Change
 
HXR 2017: Casey Quinlan: the Price is Right
HXR 2017: Casey Quinlan: the Price is RightHXR 2017: Casey Quinlan: the Price is Right
HXR 2017: Casey Quinlan: the Price is Right
 
HXR 2017: Bakul Patel: How the FDA Is Promoting Innovation and Protecting the...
HXR 2017: Bakul Patel: How the FDA Is Promoting Innovation and Protecting the...HXR 2017: Bakul Patel: How the FDA Is Promoting Innovation and Protecting the...
HXR 2017: Bakul Patel: How the FDA Is Promoting Innovation and Protecting the...
 
HXR 2017: Jay Gupta, RxRelax: RxRelax to Reverse Polypharmacy Trends
HXR 2017: Jay Gupta, RxRelax: RxRelax to Reverse Polypharmacy TrendsHXR 2017: Jay Gupta, RxRelax: RxRelax to Reverse Polypharmacy Trends
HXR 2017: Jay Gupta, RxRelax: RxRelax to Reverse Polypharmacy Trends
 
HXR 2017: Kathleen Howland, Berklee College of Music: Music Therapy in Health...
HXR 2017: Kathleen Howland, Berklee College of Music: Music Therapy in Health...HXR 2017: Kathleen Howland, Berklee College of Music: Music Therapy in Health...
HXR 2017: Kathleen Howland, Berklee College of Music: Music Therapy in Health...
 
HXR 2017: Center for Health Experience Design Announcement
HXR 2017: Center for Health Experience Design Announcement HXR 2017: Center for Health Experience Design Announcement
HXR 2017: Center for Health Experience Design Announcement
 
HXR 2017: Paul Kahn, Mad*Pow: Lessons Learned from a Bill you can understand
HXR 2017: Paul Kahn, Mad*Pow: Lessons Learned from a Bill you can understandHXR 2017: Paul Kahn, Mad*Pow: Lessons Learned from a Bill you can understand
HXR 2017: Paul Kahn, Mad*Pow: Lessons Learned from a Bill you can understand
 
HXR 2017: Design Challenge Announcement!
HXR 2017: Design Challenge Announcement!HXR 2017: Design Challenge Announcement!
HXR 2017: Design Challenge Announcement!
 
HXR 2017: Aneesh Chopra, NavHealth: Call to Action: All Hands on Deck to Brin...
HXR 2017: Aneesh Chopra, NavHealth: Call to Action: All Hands on Deck to Brin...HXR 2017: Aneesh Chopra, NavHealth: Call to Action: All Hands on Deck to Brin...
HXR 2017: Aneesh Chopra, NavHealth: Call to Action: All Hands on Deck to Brin...
 
HXR 2017: Amy Cueva, Mad*Pow: Purpose Driven Design
HXR 2017: Amy Cueva, Mad*Pow: Purpose Driven DesignHXR 2017: Amy Cueva, Mad*Pow: Purpose Driven Design
HXR 2017: Amy Cueva, Mad*Pow: Purpose Driven Design
 
HXR 2016: Addressing the Opioid Crisis
HXR 2016: Addressing the Opioid CrisisHXR 2016: Addressing the Opioid Crisis
HXR 2016: Addressing the Opioid Crisis
 
HXR 2016: New Models for Care Delivery -Ethan Berke, Dartmouth-Hitchcock
HXR 2016: New Models for Care Delivery -Ethan Berke, Dartmouth-HitchcockHXR 2016: New Models for Care Delivery -Ethan Berke, Dartmouth-Hitchcock
HXR 2016: New Models for Care Delivery -Ethan Berke, Dartmouth-Hitchcock
 
HXR 2016: Human Focused Innovation in a Clinical Setting -Lesley Solomon, Bri...
HXR 2016: Human Focused Innovation in a Clinical Setting -Lesley Solomon, Bri...HXR 2016: Human Focused Innovation in a Clinical Setting -Lesley Solomon, Bri...
HXR 2016: Human Focused Innovation in a Clinical Setting -Lesley Solomon, Bri...
 
HXR 2016: Human Focused Innovation in a Clinical Setting -Jennie Kung, UCLA H...
HXR 2016: Human Focused Innovation in a Clinical Setting -Jennie Kung, UCLA H...HXR 2016: Human Focused Innovation in a Clinical Setting -Jennie Kung, UCLA H...
HXR 2016: Human Focused Innovation in a Clinical Setting -Jennie Kung, UCLA H...
 
HXR 2016: Human Focused Innovation in a Clinical Setting -Dr. Nancy Hanrahan,...
HXR 2016: Human Focused Innovation in a Clinical Setting -Dr. Nancy Hanrahan,...HXR 2016: Human Focused Innovation in a Clinical Setting -Dr. Nancy Hanrahan,...
HXR 2016: Human Focused Innovation in a Clinical Setting -Dr. Nancy Hanrahan,...
 
HXR 2016: Human Focused Innovation in a Clinical Setting -Marnie de Mooij, Ma...
HXR 2016: Human Focused Innovation in a Clinical Setting -Marnie de Mooij, Ma...HXR 2016: Human Focused Innovation in a Clinical Setting -Marnie de Mooij, Ma...
HXR 2016: Human Focused Innovation in a Clinical Setting -Marnie de Mooij, Ma...
 

Recently uploaded

Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Dipal Arora
 
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋TANUJA PANDEY
 
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...tanya dube
 
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...astropune
 
Lucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel roomLucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel roomdiscovermytutordmt
 
Top Rated Hyderabad Call Girls Erragadda ⟟ 6297143586 ⟟ Call Me For Genuine ...
Top Rated  Hyderabad Call Girls Erragadda ⟟ 6297143586 ⟟ Call Me For Genuine ...Top Rated  Hyderabad Call Girls Erragadda ⟟ 6297143586 ⟟ Call Me For Genuine ...
Top Rated Hyderabad Call Girls Erragadda ⟟ 6297143586 ⟟ Call Me For Genuine ...chandars293
 
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service AvailableCall Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escorts
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore EscortsCall Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escorts
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escortsvidya singh
 
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Gwalior Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...parulsinha
 
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...jageshsingh5554
 
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...astropune
 
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...aartirawatdelhi
 
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...Arohi Goyal
 
Call Girls Tirupati Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Tirupati Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Bangalore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...Genuine Call Girls
 
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Kochi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 

Recently uploaded (20)

Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
 
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
 
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Bhubaneswar Just Call 9907093804 Top Class Call Girl Service Avail...
 
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
 
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
♛VVIP Hyderabad Call Girls Chintalkunta🖕7001035870🖕Riya Kappor Top Call Girl ...
 
Lucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel roomLucknow Call girls - 8800925952 - 24x7 service with hotel room
Lucknow Call girls - 8800925952 - 24x7 service with hotel room
 
Top Rated Hyderabad Call Girls Erragadda ⟟ 6297143586 ⟟ Call Me For Genuine ...
Top Rated  Hyderabad Call Girls Erragadda ⟟ 6297143586 ⟟ Call Me For Genuine ...Top Rated  Hyderabad Call Girls Erragadda ⟟ 6297143586 ⟟ Call Me For Genuine ...
Top Rated Hyderabad Call Girls Erragadda ⟟ 6297143586 ⟟ Call Me For Genuine ...
 
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service AvailableCall Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
 
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escorts
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore EscortsCall Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escorts
Call Girls Horamavu WhatsApp Number 7001035870 Meeting With Bangalore Escorts
 
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Gwalior Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 9907093804 Top Class Call Girl Service Available
 
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
 
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
VIP Service Call Girls Sindhi Colony 📳 7877925207 For 18+ VIP Call Girl At Th...
 
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...
Best Rate (Hyderabad) Call Girls Jahanuma ⟟ 8250192130 ⟟ High Class Call Girl...
 
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Cuttack Just Call 9907093804 Top Class Call Girl Service Available
 
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
 
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
 
Call Girls Tirupati Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Tirupati Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Bangalore Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Bangalore Just Call 9907093804 Top Class Call Girl Service Available
 
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
 
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Kochi Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Kochi Just Call 9907093804 Top Class Call Girl Service Available
 

HxRefactored - TrueVault - Jason Wang

  • 1. Decoding HIPAA for Developers! Jason Wang! Founder & CEO, TrueVault!
  • 4. 1996 – HIPAA! ! 2009 – HITECH! ! 2013 – Final Omnibus Rule Update!
  • 5. HIPAA Acronyms! PHI – Protected Health Information! ! CE – Covered Entities! BA – Business Associates! BAA – Business Associate Agreement!
  • 6. HIPAA   Privacy  Rule  Security  Rule   Administra6ve   Safeguards   Technical   Safeguards   Physical   Safeguards   Enforcement   Rule   Breach   No6fica6on  Rule  
  • 7. HIPAA   Privacy  Rule  Security  Rule   Administra6ve   Safeguards   Technical   Safeguards   Physical   Safeguards   Enforcement   Rule   Breach   No6fica6on  Rule   If  you’re  a  developer  trying  to  understand  the   scope  of  the  build,  then  you  need  to  focus  on   the  Technical  and  Physical  Safeguards  spelled   out  in  the  Security  Rule;  these  two  sec6ons   comprise  the  majority  of  your  to-­‐do  list.    
  • 8. Who Needs to be HIPAA Compliant? If you handle PHI then you need to be HIPAA compliant.! ! The HIPAA rules apply to both Covered Entities and their Business Associates! !
  • 9. Who Certifies HIPAA Compliance? The short answer is no one.!
  • 10. “required” vs. “addressable”! Some implementation specifications are “required” and others are “addressable.” Required implementation specifications must be implemented. Addressable implementation specifications must be implemented if it is reasonable and appropriate to do so; your choice must be documented.! ! It is important to remember that an addressable implementation specification is not optional. ! ! When in doubt, you should just implement the addressable implementation specifications. Most of them are best practices anyway.! Addressable does NOT mean optional!
  • 11. Technical Safeguards! 1.  Access Control - Unique User Identification (required): Assign a unique name and/or number for identifying and tracking user identity.! ! 2.  Access Control - Emergency Access Procedure (required): Establish (and implement as needed) procedures for obtaining necessary ePHI during an emergency.! 3.  Access Control - Automatic Logoff (addressable): Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity.! ! 4.  Access Control - Encryption and Decryption (addressable): Implement a mechanism to encrypt and decrypt ePHI.!
  • 12. Technical Safeguards 5.  Audit Controls (required): Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.! 6.  Integrity - Mechanism to Authenticate ePHI (addressable): Implement electronic mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner.! 7.  Authentication (required): Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed.! ! 8.  Transmission Security - Integrity Controls (addressable): Implement security measures to ensure that electronically transmitted ePHI is not improperly modified without detection until disposed of.! ! 9.  Transmission Security - Encryption (addressable): Implement a mechanism to encrypt ePHI whenever deemed appropriate.!
  • 13. Physical Safeguards 1.  Facility Access Controls - Contingency Operations (addressable): Establish (and implement as needed) procedures that allow facility access in support of restoration of lost data under the disaster recovery plan and emergency mode operations plan in the event of an emergency.! 2.  Facility Access Controls - Facility Security Plan (addressable): Implement policies and procedures to safeguard the facility and the equipment therein from unauthorized physical access, tampering, and theft.! 3.  Facility Access Controls - Access Control and Validation Procedures (addressable): Implement procedures to control and validate a person’s access to facilities based on their role or function, including visitor control, and control of access to software programs for testing and revision.! HIPAA Compliant Hosting Providers can take care of some of the Physical Safeguards for you.!
  • 14. Physical Safeguards 4.  Facility Access Controls - Maintenance Records (addressable): Implement policies and procedures to document repairs and modifications to the physical components of a facility which are related to security (e.g. hardware, walls, doors, and locks).! 5.  Workstation Use (required): Implement policies and procedures that specify the proper functions to be performed, the manner in which those functions are to be performed, and the physical attributes of the surroundings of a specific workstation or class of workstation that can access ePHI.! 6.  Workstation Security (required): Implement physical safeguards for all workstations that access ePHI, to restrict access to authorized users.! HIPAA Compliant Hosting Providers can take care of some of the Physical Safeguards for you.!
  • 15. Physical Safeguards 7.  Device and Media Controls - Disposal (required): Implement policies and procedures to address the final disposition of ePHI, and/or the hardware or electronic media on which it is stored.! ! 8.  Device and Media Controls - Media Re-Use (required): Implement procedures for removal of ePHI from electronic media before the media are made available for re-use.! ! 9.  Device and Media Controls - Accountability (addressable): Maintain a record of the movements of hardware and electronic media and any person responsible therefore.! ! 10.  Device and Media Controls - Data Backup and Storage (addressable): Create a retrievable, exact copy of ePHI, when needed, before movement of equipment.! HIPAA Compliant Hosting Providers can take care of some of the Physical Safeguards for you.!
  • 16. What Else? •  Emails, texts, voicemails! •  3rd party tools (MixPanel, Loggly, New Relic, etc)! •  Administrative Safeguards! •  Building a HIPAA compliant infrastructure!
  • 17. Q&A Time! Shameless Promotions:! ! •  TrueVault is hiring Developers, DevOps Engineers in San Francisco ! •  Join our iOS SDK beta list – Be the first to release an iOS app leveraging Health Book! http://go.truevault.com/ios8! !
  • 18. Thank  you!   Jason  Wang   Founder  &  CEO,  TrueVault  
  • 19. May  29,  2014   Confiden6al  -­‐  Not  for   What is Protected Health Information (PHI)? PHI  is  any  informa6on  in  a  medical  record  that  can  be  used  to  iden6fy   an  individual,  and  that  was  created,  used,  or  disclosed  in  the  course  of   providing  a  healthcare  service,  such  as  a  diagnosis  or  treatment.     PHI  is  informa6on  in  your  medical  records,  including  conversa6ons   between  your  doctors  and  nurses  about  your  treatment.  PHI  also   includes  your  billing  informa6on  and  any  medical  informa6on  in  your   health  insurance  company's  computer  system.     This  includes  any  individually  iden6fiable  health  informa6on  collected   from  an  individual  by  a  healthcare  provider,  employer  or  plan  that   includes  name,  social  security  number,  phone  number,  medical   history,  current  medical  condi6on,  test  results  and  more.     Electronic  Protected  Health  Informa3on  (EPHI)   All  individually  iden6fiable  health  informa6on  that  is  created,   maintained,  or  transmiZed  electronically.    
  • 20. May  29,  2014   Confiden6al  -­‐  Not  for   Covered Entity (CE) Anyone  who  provides  treatment,  payment  and  opera6ons   in  healthcare.       It  could  include  a  doctor’s  office,  dental  office,  clinics,   psychologist,  nursing  home,  pharmacy,  hospital  or  home   healthcare  agency.       This  also  includes  health  plans,  health  insurance   companies,  HMOs,  company  health  plans  and  government   programs  that  pay  for  health  care.       Health  clearing  houses  are  also  considered  covered   en66es.    
  • 21. May  29,  2014   Confiden6al  -­‐  Not  for   Business Associate Anyone  who  has  access  to  pa6ent  informa6on,  whether  directly,  indirectly,   physically  or  virtually.       Addi6onally,  any  organiza6on  that  provides  support  in  the  treatment,   payment  or  opera6ons  is  considered  a  business  associate,  i.e.  an  IT  company   or  a  mHealth  applica6on  that  provides  secure  photo-­‐sharing  for  physicians.     Other  examples  include  a  document  destruc6on  company,  a  telephone   service  provider,  accountant,  or  lawyer.       The  business  associates  also  have  the  responsibility  to  achieve  and  maintain   HIPAA  compliance  in  terms  of  all  of  the  internal,  administra6ve,  and  technical   safeguards.       A  business  associate  does  not  work  under  the  covered  en6ty’s  workforce,  but   instead  performs  some  type  of  service  on  their  behalf.