Use of intranets / extranets for HIPAA compliance
Collaboration among healthcare professionals, particularly incircumstances that require the sharing of confidential patientinformation, requires an intranet or extranet that offersenhanced security features.The Health Insurance Portability and Accountability Act (HIPAA)has three major requirements:* Protect the privacy of individual health information * Providethe necessary security to protect the privacy of individualhealth information * Provide standardization of electronic datainterchange in health care transactionsAddressing this need, intranets and extranets are now availablethat meet these security requirements. As you consider theimplementation of an intranet or extranet, look for thefollowing security features:* Secure web server with 128bit SSL encryption * Servermonitoring * Secure IDs and passwords * Defined authority levels* Viewing permission controls * Session time out after 30minutes * The ability to disable user-specific cookies, * Theability of users to change their own password, * The ability tocreate strong passwords. * Complete, un-editable activity logfor security auditsChoosing a web-based solutionTo speed the implementation of an intranet or extranet withthese features, an increasingly popular approach is to use anApplication Service Provider (ASP).In addition to providing an immediate solution that has theappropriate security features in-place, the advantages of aweb-based ASP include a lower cost of entry, a proventrack-record of performance and no need to install intranetsoftware or extranet software.Laura Schwiker writes extensively on the use of technology bybusinesspeople and is an evangelist for onlinecollaboration and collaboration software.
|