Outpatient Facility Coding Alert - 2019 Issue 7
Reader Question: Beware HIPAA Compliance Claims
Subscribe or sign in to view the full article.
Article Overview
This reader Q&A addresses common vendor marketing language around healthcare encryption products and clarifies the difference between product-level alignment with HIPAA encryption guidance and an organization’s broader compliance responsibilities. It is relevant to healthcare providers, privacy and security staff, compliance teams, and administrators who evaluate safeguards for electronic protected health information. The article discusses the HIPAA Security Rule’s encryption-related standard, the concept of an addressable implementation specification, and the organizational factors that should be considered when assessing whether a safeguard is reasonable and appropriate.
Why This Topic Matters
Organizations handling electronic protected health information need to understand that a product claim is not a substitute for a complete compliance assessment. The article helps readers frame vendor statements accurately and reinforces the importance of documentation and internal controls.
What You Will Learn
- How to interpret vendor claims about HIPAA-compliant encryption
- How encryption relates to HIPAA privacy and security expectations
- What it means for an encryption safeguard to be addressable
- Which organizational factors are considered when evaluating encryption safeguards
- Why documentation and internal checks and balances matter for compliance
Who Should Read This
- Healthcare providers
- Compliance officers
- Privacy officers
- Security officers
- Practice administrators
- Healthcare IT staff
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com