|
|
Article: HIPAA Regulatory Alert - Security rule guidance issued to covered entities.
- Article from:
- Healthcare Risk Management
- Article date:
- November 1, 2004
CopyrightCOPYRIGHT 2004 A Thomson Healthcare Company. This material is published under license from the publisher through the Gale Group, Farmington Hills, Michigan. All inquiries regarding rights should be directed to the Gale Group. (Hide copyright information)
|
HIPAA Regulatory Alert
Security rule guidance issued to covered entities
Entities covered under the HIPAA security rule are not required to certify compliance with provisions of the rule, according to guidance issued by the Centers for Medicare & Medicaid Services. The security rule does, however, require covered entities to periodically perform evaluations to establish the extent to which technological and nontechnological security policies and procedures meet the requirements, the agency says.
The evaluation can be performed internally by the covered entity, the guidance says. There are also external organizations that provide evaluations or ...