Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I am curious why so much needs to be done for HIPPA compliance anytime something is held in electronic form.

What if you have a computer, unconnected to the internet, simply sitting in a doctors office with billing information on it.... does this system need more 'protection' and regulation than the one it replaced of paper files, and sticky notes?



There are many layers of HIPAA outside of of just electronic data security. You must train your staff on security protocols (e.g not sniffing for celebrity records, etc).

I am pretty sure even if your office is all paper charts you still fall under certain HIPAA guidelines such as notifying patients if there was a breach (e.g physically stealing records from the office). This happened in Rocklin, CA a few years ago.

http://www.cda.org/news-events/burglary-leads-to-lengthy-hip...


Yes. Thats the role of regulation, to entrench the incumbent and stifle acceptable innovation.

Plus add to what you mentioned that you need strong disk encryption and some physical security. Else an external key logger and its over.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: