Publications

Home 9 Publication 9 Summary of HIPAA Final Security Rule

Summary of HIPAA Final Security Rule

October 12, 2004


On February 20, 2003, the Department of Health and Human Services (“HHS”) published the final HIPAA security standards, Health Insurance Reform: Security Standards; Final Rule, 45 CFR Parts 160, 162 and 164, 68 Fed. Reg. 8333. These standards establish a security management framework for the protection of Electronic Protected Health Information (EPHI). Significantly, this final Security Rule applies only to protected health information in electronic form and, unlike the earlier Privacy Rule, does not cover paper copies of documents or oral information. The standards established in the Security Rule are necessarily intertwined with the requirements of the Privacy Rule. Specifically, the Privacy Rule requires the use of reasonable administrative, physical and technical safeguards to protect privacy, and the new Security Rule provides guidance for interpreting the reasonableness of such safeguards. Most covered entities must be in compliance with the Security Rule by April 21, 2005.

Resources

Firm Highlights