In our series on the HIPAA Administrative Simplification Security Rule, this is the second implementation specification for the Technical Safeguard Standard, Access Control. This implementation specification is required. As we noted in earlier postings on HIPAA.com, business associates of covered entities will be required to comply with the Security Rule safeguard standards, beginning February 17, 2010. This requirement is one of the HITECH Act provisions of the American Recovery and Reinvestment Act (ARRA), signed by President Obama on February 17, 2009.
What to Do
Establish and implement as needed procedures for obtaining necessary electronic protected health information during an emergency.
How to Do It
Emergency access refers to loss of data and systems containing electronic protected health information due to an emergency. Emergencies may include, but are not limited to, fire, vandalism, terrorism, system failure, or natural disaster. In an emergency situation, delay in accessing vital information could result in danger to someone’s health.
As part of its risk analysis, a covered entity should identify emergency situations that would warrant immediate access to electronic protected health information. The Security Official of the covered entity should prepare a written inventory of such situations. The covered entity should coordinate policies and procedures for this technical safeguard standard implementation specification with the policies and procedures developed for the Facility Access Physical Safeguard Standard implementation specification: Contingency Operations.
The covered entity should work with its electronic information system and software vendors to establish emergency access procedures to accommodate the emergency situations identified in the risk analysis. Such procedures should include offsite backup of electronic protected health information. In addition, a covered entity should consider “alarm” procedures to respond to an emergency, including the use of a special user password by the Security Official and one other designated workforce member who would have full access to electronic protected health information and who would be accountable for their actions. Finally, a covered entity should document emergency response procedures and distribute them to workforce members, and maintain a special audit log of responses to emergencies.