CMS has now posted a document entitled
Sample - Interview and Document Request for HIPAA Security Onsite Investigations and Compliance Reviews. The document closely mirrors the information that surfaced after the Piedmont audit last year. What is also notable is that there are things in the information request document that are not addressed at all in the HIPAA Security Rule, such as wireless network usage, and "mechanisms to ensure the integrity of data during transmission - including portable media transmission (i.e. laptops, cell phones, blackberries, thumb drives)".
HIPAA being one of the more mature compliance
regulations, wireless access and the USB storage security concern were not yet common when the HIPAA Security Rule came into being.
Time will tell if we are seeing the start of "scope creep" in HIPAA security standards, as has been experienced with GLBA by financial organizations (where the FFIEC has added an enormous amount of detail further defining what affected institutions have to do to comply).
Also on the HIPAA enforcement front, as reported on
Rebecca Herold's blog, a HIPAA violation was prosecuted in Oklahoma City. The individual prosecuted was convicted of providing personally identifiable health information to other individuals, apparently in an insider identity theft.
Jim
Jim Hietala
Jim Hietala, GSEC, GCFW and CISSP, is the principal of Compliance Research Group, providing research, analysis, and consulting services in the areas of compliance, risk management, and IT security. Jim has provided consulting services to organizations such as SANS, The Open Group Security Forum, Logical Security, and a number of IT security and compliance vendors. He is a frequent speaker at industry conferences, and he recently authored a comprehensive course on IT risk management. He participates in the SANS Analyst/Expert program, having written several whitepapers and participated in several webcasts for SANS. He has also published numerous articles on information security, risk management, and compliance topics in publications including The ISSA Journal, Bank Accounting & Finance, Risk Factor, and others. He holds a B.S. in Marketing from Southern Illinois University.
Editorial focus: Compliance, Risk Management, IT Security, IT-GRC software, HIPAA, GLBA, Privacy
Jim can be reached at: jim@compliancefocus.com