<?xml version="1.0" encoding="iso-8859-1"?>
<?xml-stylesheet type="text/css" href="http://www.hipaastore.com/includes/templates/theme078/css/rss.css" media="screen"?>
<!-- generator="Zen-Cart RSS Feed/"v 2.1.4 14.02.2008 15:26 -->
<rss version="2.0" 
xmlns:g="http://base.google.com/ns/1.0"
xmlns:c="http://base.google.com/cns/1.0"
xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>The HIPAA Store : RSS Product Feed :: HIPAA Policies for Business Associates</title>
    <link>http://www.hipaastore.com/</link>
    <description></description>
    <atom:link href="http://www.hipaastore.com/" rel="self" type="application/rss+xml" />
    <language>en</language>
    <copyright>Copyright (c) 2010 HIPAA Group, Inc.</copyright>
    <managingEditor>sales@hipaastore.com (HIPAA Group, Inc.)</managingEditor>
    <webMaster>sales@hipaastore.com (HIPAA Group, Inc.)</webMaster>
    <lastBuildDate>Mon, 18 Jan 2010 08:47:22 -0800</lastBuildDate>
    <generator>Zen-Cart v. v 2.1.4 14.02.2008 15:26 RSS 2.0 Feed</generator>
    <ttl>1440</ttl>
    <item>
      <title>HIPAA Policies for Business Associates</title>
      <link>http://www.hipaastore.com/hipaa-policies-for-business-associates-p-25.html</link>
      <comments>http://www.hipaastore.com/index.php?main_page=product_reviews&amp;products_id=25</comments>
      <description><![CDATA[ <a href="http://www.hipaastore.com/hipaa-policies-for-business-associates-p-25.html"><img src="http://www.hipaastore.com/bmz_cache/c/cf2ad6ea6c910c0b96aa98492e83425b.image.107x132.jpg" alt="HIPAA Policies for Business Associates" title=" HIPAA Policies for Business Associates " width="107" height="132" style="float: left; margin: 0px 8px 8px 0px;" style="position:relative" onmouseover="showtrail('bmz_cache/8/8cfe00d7e3a653f2f14a9fb34c984fc5.image.107x132.jpg','HIPAA Policies for Business Associates',107,132,107,132,this,0,0,107,132);" onmouseout="hidetrail();"  /></a><p><img src="images/new_digital_dwnload_icon_3.jpg" alt="" /></p>
<h2><br />
A Complete Set of HIPAA Policy and Procedure Templates<br />
for Business Associates of All Types and Sizes.</h2>
<p>Fully updated for the HITECH Act, these editable Policy and Procedure templates are ready to be customized for your specific needs. Fifty-five templates covering every area required by HIPAA are fully compliant with HIPAA and the recent HITECH Act changes to HIPAA. This template collection is specially designed for HIPAA Business Associates, and is perfect for any Business Associate to meet their compliance obligations under HIPAA.</p>
<p>A complete set of Policies and Procedures is mandatory for HIPAA compliance. If you are ever investigated for or changed with a HIPAA violation, your Polices and Procedures are the first thing investigators will want to see. Make sure you are ready!</p>
<p>HIPAA requires certain Policies and Procedures for Business Associates. However, HIPAA has no specific requirements as to how long or short P&Ps must be, the form or format they must have, or the language that must be in them. Customize the templates in this product for your own unique needs and save thousands on attorney fees with this legally-valid template collection.</p>
<p>Policy and Procedure templates included in this collection require editing before use. You can easily edit these templates to align each one with your unique business and policy positions. All items included in this product are in Microsoft Word format.</p>
<h4><span style="color: rgb(0, 0, 255);">Complete instructions and an editing guide are included with this product.</span></h4>
<h3 style="text-align: left; margin-left: 40px;">This product contains the following Policies and Procedures<br />
 </h3>
<div align="left">
<table width="623" cellspacing="0" border="1" bordercolordark="#000080" bordercolorlight="#000080" class="valign">
    <tbody>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>1</h4>
            </td>
            <td style="text-align: center;"><b>General HIPAA <br />
            Compliance Policy</b></td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.104<br />
            </font><font size="1" face="Tahoma">164.306<br />
            <font size="1" face="Tahoma">HITECH 13041</font></font></td>
            <td><font size="1" face="Tahoma">Covered Entities and Business Associates, as defined in HIPAA and HITECH, must comply with all required parts and subparts of the regulations that apply to each type of Entity.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>2</h4>
            </td>
            <td style="text-align: center;"><b>Policies & Procedures <br />
            General Requirement</b></td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.306<br />
            </font><font size="1" face="Tahoma">164.312(b)(1)<br />
            </font><font size="1" face="Tahoma">164.530(i)</font></td>
            <td><font size="1" face="Tahoma">Implement reasonable and appropriate P&Ps to comply with all standards, implementation specifications, or other requirements. P&P changes must be appropriately documented.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>3</h4>
            </td>
            <td style="text-align: center;"><b>Documentation Requirement</b></td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.530(j)(1)(ii)<font size="1" face="Tahoma">164.530(j)(1)(iii)</font><font size="1" face="Tahoma">164.312(b)(2)(i)</font></font></td>
            <td><font size="1" face="Tahoma">Maintain all P&Ps in written (may be electronic) form. If an action, activity or assessment must be documented, maintain written (may be electronic) records of all.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>4</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Documentation Retention<br />
            </b>Requirement</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.312(b)(2)(ii)</font></td>
            <td><font size="1" face="Tahoma">Retain all required documentation for 6 years from the date of its creation or the date when it last was in effect, whichever is later.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>5</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Documentation Availability<br />
            </b>Requirement</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.312(b)(2)(iii)</font></td>
            <td><font size="1" face="Tahoma">Make documentation available to those persons responsible for implementing the Policies and/or Procedures to which the documentation pertains.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>6</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Documentation Updates<br />
            </b>Requirement</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.312(b)(2)(iii)</font></td>
            <td><font size="1" face="Tahoma">Review documentation periodically and update as needed, in response to environmental or operational changes affecting the security of PHI.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>7</h4>
            </td>
            <td style="text-align: center;"><b>HHS Investigations Policy</b></td>
            <td style="text-align: center;"><font size="1" face="Tahoma">160.103</font></td>
            <td><font size="1" face="Tahoma">CEs and BAs must implement policies & procedures to assure compliance with HHS investigation & recordkeeping requirements.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>8</h4>
            </td>
            <td style="text-align: center;"><b>Breach Notification Policy</b></td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.400 to<br />
            </font><font size="1" face="Tahoma">164.414</font></td>
            <td><font size="1" face="Tahoma">Requires CEs and BAs to comply with all Breach Notification requirements: risk analysis; determination of potential harm; notifications.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>9</h4>
            </td>
            <td style="text-align: center;"><b>Assign Privacy Official Policy</b></td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.530(a)</font></td>
            <td><font size="1" face="Tahoma">CEs and BA must assign an individual for all Privacy-related activities and compliance efforts; and to accept and process complaints.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>10</h4>
            </td>
            <td style="text-align: center;"><b>State Law Preemption Policy</b></td>
            <td style="text-align: center;"><font size="1" face="Tahoma">160.201 to<br />
            <font size="1" face="Tahoma">160.205</font></font></td>
            <td><font size="1" face="Tahoma">CEs and BAs must analyze and assess state law requirements related to data privacy & security; and HIPAA preemption impacts of state laws.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>11</h4>
            </td>
            <td style="text-align: center;"><b>HIPAA Training Policy</b></td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.530(b)</font></td>
            <td><font size="1" face="Tahoma">CEs and BAs must train all affected workforce members on their Policies & Procedures, as well as the basics of HIPAA, as needed.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>12</h4>
            </td>
            <td style="text-align: center;"><b>PHI Uses & Disclosures Policy</b></td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.502 to<br />
            <font size="1" face="Tahoma">164.514</font></font></td>
            <td><font size="1" face="Tahoma">CEs and BAs must establish methods and procedures to assure that all PHI uses & disclosures are in accord with HIPAA regs.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>13</h4>
            </td>
            <td style="text-align: center;"><b>Patient Rights Policy</b></td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.520 to 164.528</font></td>
            <td><font size="1" face="Tahoma">CEs (and BAs optionally) must implement policies & procedures to assure the lawful provision of Patient Rights as called for in HIPAA regs.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>14</h4>
            </td>
            <td style="text-align: center;"><b>Complaints Policy</b></td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.530(d)<br />
            <font size="1" face="Tahoma">164.530(a)</font></font></td>
            <td><font size="1" face="Tahoma">CEs and BAs must establish methods and procedures to assure the proper handling of, and response to, all complaints received.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>15</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Risk Management <br />
            Process Policy</b><br />
            Required</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.302<br />
            <font size="1" face="Tahoma">164.306</font></font></td>
            <td><font size="1" face="Tahoma">Establishes the overall Risk Management process that CEs and BAs must implement to meet Privacy & Security Rule compliance requirements.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>16</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Risk Analysis</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Conduct assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the entity.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>17</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Risk Management</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with Sec. 164.306(a).</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>18</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Sanction Policy</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>19</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Information System<br />
            Activity Review</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Implement procedures to regularly review information system activity: audit logs; access reports; and security incident reports; etc.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>20</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Assigned Security Responsibility</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(2)</font></td>
            <td><font size="1" face="Tahoma">Assign security responsibility. Identify Security Official responsible for development and implementation of required P&Ps.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>21</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Authorization & Supervision Procedures</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(3)</font></td>
            <td><font size="1" face="Tahoma">Implement procedures for authorization and/or supervision of workers who work with ePHI or in locations where it might be accessed.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>22</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Workforce Clearance Procedures</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(3)</font></td>
            <td><font size="1" face="Tahoma">Implement procedures to determine that the access of a workforce member to ePHI is appropriate.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>23</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Termination Procedures</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(3)</font></td>
            <td><font size="1" face="Tahoma">Implement procedures for terminating access to ePHI when the employment ends or as required by (a)(3)(ii)(B) of this section.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>24</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Access Authorization</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(4)</font></td>
            <td><font size="1" face="Tahoma">Implement policies and procedures for granting access to ePHI, for workstations, transactions, programs, processes, or other mechanisms.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>25</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Access Establishment <br />
            and Modification</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(4)</font></td>
            <td><font size="1" face="Tahoma">Implement P&Ps, based on Access Authorization policies, to establish, document, review, and modify user's rights of access to workstations, transactions, programs, or processes.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>26</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Security Reminders</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(5)</font></td>
            <td><font size="1" face="Tahoma">Implement periodic reminders of security and information safety best practices.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>27</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Protection from<br />
            Malicious Software</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(5)</font></td>
            <td><font size="1" face="Tahoma">Implement Procedures for guarding against, detecting, and reporting malicious software.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>28</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Log-in Monitoring</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(5)</font></td>
            <td><font size="1" face="Tahoma">Implement Procedures for monitoring and reporting log-in attempts and discrepancies.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>29</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Password Management</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(5)</font></td>
            <td><font size="1" face="Tahoma">Implement Procedures for creating, changing, and safeguarding appropriate passwords.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>30</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Security Incident Procedures</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(6)</font></td>
            <td><font size="1" face="Tahoma">Identify and respond to suspected or known security incidents. Mitigate harmful effects. Document security incidents and their outcomes.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>31</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Data Backup Plan</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(7)</font></td>
            <td><font size="1" face="Tahoma">Establish and implement procedures to create and maintain retrievable, exact copies of ePHI during unexpected negative events.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>32</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Disaster Recovery Plan</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(7)</font></td>
            <td><font size="1" face="Tahoma">Establish (and implement as needed) procedures to restore any loss of data.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>33</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Emergency Mode<br />
            Operation Plan</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(7)</font></td>
            <td><font size="1" face="Tahoma">Establish (and implement as needed) procedures to enable continuation of critical business processes for protection of ePHI while operating in emergency mode.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>34</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Testing and Revision Procedures</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(7)</font></td>
            <td><font size="1" face="Tahoma">Implement procedures for periodic testing and revision of contingency and emergency plans.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>35</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Applications and Data<br />
            Criticality Analysis</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(7)</font></td>
            <td><font size="1" face="Tahoma">Assess the relative criticality of specific applications and data in support of other contingency plan components.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>36</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Evaluation Policy</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(a)(8)</font></td>
            <td><font size="1" face="Tahoma">Perform periodic technical & nontechnical evaluations, to establish how well security P&Ps meet the requirements of this subpart.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>37</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Business Associate Contracts and Other Arrangements</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.308(b)(1)</font></td>
            <td><font size="1" face="Tahoma">CE&rsquo;s must obtain, and BA&rsquo;s must provide, written satisfactory assurances that all ePHI and PHI will be appropriately safeguarded.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>38</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Contingency Operations Procedures</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.310(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Establish (and implement as needed) procedures that allow facility access to support restoration of lost data in the event of an emergency.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>39</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Facility Security Plan</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.310(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Implement P&P&rsquo;s to safeguard the facility and the equipment therein from unauthorized physical access, tampering, and theft.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>40</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Access Control and<br />
            Validation Procedures</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.310(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Implement procedures to control and validate individual access to facilities based on role or function; including visitor control, and access control for software testing and revision.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>41</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Maintenance Records</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.310(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Implement P&Ps to document repairs and changes to physical elements of a facility related to security (hardware, walls, doors, locks, etc.).</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>42</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Workstation Use</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.310(b)</font></td>
            <td><font size="1" face="Tahoma">Implement P&Ps that specify the proper functions, procedures, and appropriate environments of workstations that access ePHI.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>43</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Workstation Security</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.310(c)</font></td>
            <td><font size="1" face="Tahoma">Implement physical safeguards for all workstations that access ePHI, to restrict access to authorized users.</font></td>
        </tr>
        <tr valign="top">
            <td height="36">
            <h4>44</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Media Disposal & Disposition</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.310(d)(1)</font></td>
            <td><font size="1" face="Tahoma">Implement P&Ps to address the final disposition of ePHI, and/or the hardware or electronic media on which it is stored.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>45</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Media Re-use</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.310(d)(1)</font></td>
            <td><font size="1" face="Tahoma">Implement procedures for removal of ePHI from electronic media before the media are made available for re-use.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>46</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Hardware & Media <br />
            Accountability</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.310(d)(1)</font></td>
            <td><font size="1" face="Tahoma">Maintain records of the movements of hardware and electronic media, and any person responsible therefore.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>47</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Data Backup and Storage</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.310(d)(1)</font></td>
            <td><font size="1" face="Tahoma">The Data Backup Plan defines what data is essential for continuity after damage or destruction of data, hardware, or software. Risk Analysis determines what to backup.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>48</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Unique User Identification</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.312(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Assign a unique name and/or number for identifying and tracking user identity.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>49</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Emergency Access Procedure</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.312(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Establish (and implement as needed) procedures for obtaining necessary ePHI during an emergency.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>50</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Automatic Logoff</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.312(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>51</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Encryption and Decryption</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.312(a)(1)</font></td>
            <td><font size="1" face="Tahoma">Implement an appropriate mechanism to encrypt and decrypt ePHI.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>52</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Audit Controls</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.312(b)</font></td>
            <td><font size="1" face="Tahoma">Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>53</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Integrity Controls Policy</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.312(c)(1)</font></td>
            <td><font size="1" face="Tahoma">Implement electronic mechanisms to corroborate that ePHI has not been altered or destroyed in an unauthorized manner.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>54</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Person or Entity <br />
            Authentication</b><br />
            Required Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.312(d)</font></td>
            <td><font size="1" face="Tahoma">Implement procedures to verify that a person or entity seeking access to ePHI is the one claimed.</font></td>
        </tr>
        <tr valign="top">
            <td height="36" style="text-align: center;">
            <h4>55</h4>
            </td>
            <td>
            <p style="text-align: center;"><b>Integrity Controls Procedures</b><br />
            Addressable Standard</p>
            </td>
            <td style="text-align: center;"><font size="1" face="Tahoma">164.312(e)(1)</font></td>
            <td><font size="1" face="Tahoma">Implement security measures to ensure that electronically transmitted ePHI is not improperly modified without detection until disposed of.</font></td>
        </tr>
    </tbody>
</table>
</div>
<p> </p>
<br /><br /><a href="https://www.hipaastore.com/index.php?main_page=shopping_cart&products_id=25&action=buy_now" target="_blank"><img src="http://www.hipaastore.com/includes/templates/theme078/buttons/english/button_buy_now.gif" alt="Buy Now" title=" Buy Now " width="83" height="18" /></a> ]]></description>
      <author>sales@hipaastore.com (HIPAA Group, Inc.)</author>
      <enclosure url="http://www.hipaastore.com/images/pnpLG.jpg" length="103044" type="image/jpeg" />
      <guid isPermaLink="true">http://www.hipaastore.com/hipaa-policies-for-business-associates-p-25.html</guid>
      <pubDate>Mon, 18 Jan 2010 08:47:22 -0800</pubDate>
      <g:price>298.00</g:price>
      <g:currency>USD</g:currency>
      <g:id>25</g:id>
      <g:quantity>1001</g:quantity>
      <g:rating>1</g:rating>
      <g:image_link>http://www.hipaastore.com/images/large/pnpLG_LRG.jpg</g:image_link>
    </item>
  </channel>
</rss>
