Share on LinkedInShare on LinkedIn

ARTICLE · 26 FEBRUARY 2003

Final HIPAA Security Standards Published

United StatesFood, Drugs, Healthcare, Life Sciences
Dean Harvey
Dean Harvey

Pursuant to the Health Insurance Portability and Accountability Act ("HIPAA"), the U.S. Department of Health and Human Services published a final rule adopting standards for the security of electronic protected health information on February 20, 2003. (68 Federal Register 8333). The implementation standards in the final rule are framed to allow covered entities to meet their requirements through various approaches and technologies. The final rule contains some significant variations from the proposed rule that was published on August 12, 1998, including the elimination of the requirements that a covered entity: (a) certify that the appropriate security has been implemented; (b) enter into chain of trust partner agreements with third parties processing data for the covered entity; (c) have a formal mechanism for processing records and documented policies and procedures for the routine and non-routine receipt, manipulation, storage, dissemination, transmission, and/or disposal of health information; and (d) implement measures, practices and procedures regarding security configuration management, which would have included documentation, hardware/software installation and maintenance review, inventory procedures, security testing and virus checking (other standards in the final rule, however, address these measures and practices). Under the final rule a covered entity is required to: (1) periodically evaluate its security safeguards, both the technical and non-technical components, to demonstrate and document their compliance with its security policies and security standards; (2) assess the need for a new evaluation based on changes to its security environment since its last evaluation, for example, new technology adopted or responses to newly recognized risks to the security of its information; (3) enter into contracts with persons that meet the definition of business associate as that term has been defined in previously published HIPAA rules and obtain satisfactory assurances from the business associate that the business associate will appropraitely safeguard the information in accordance with the security standards.

This material is not intended to create, and does not create, an attorney-client relationship between you and Vinson & Elkins L.L.P., and you should not act or rely on any of this information. As legal advice must be tailored to the specific circumstances of each case, nothing provided herein should be used as a substitute for advice of competent counsel. These materials do not constitute legal advice, do not necessarily reflect the opinions of Vinson & Elkins L.L.P. or any of its attorneys or clients, and are not guaranteed to be correct, complete, or up-to-date.

Vinson & Elkins L.L.P. assumes no liability for the use or interpretation of information contained herein. This publication is provided "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. Unless otherwise indicated, V&E attorneys listed are: not Certified by the Texas Board of Legal Specialization. None of the attorneys listed on this website is certified as an "expert" or "specialist" pursuant to any authority governing the practice of law in New York. Vinson & Elkins is a registered limited liability partnership. Principal office-Houston.

See more popular content from