I am curious why so much needs to be done for HIPPA compliance anytime something is held in electronic form.
What if you have a computer, unconnected to the internet, simply sitting in a doctors office with billing information on it.... does this system need more 'protection' and regulation than the one it replaced of paper files, and sticky notes?
There are many layers of HIPAA outside of of just electronic data security. You must train your staff on security protocols (e.g not sniffing for celebrity records, etc).
I am pretty sure even if your office is all paper charts you still fall under certain HIPAA guidelines such as notifying patients if there was a breach (e.g physically stealing records from the office). This happened in Rocklin, CA a few years ago.
What if you have a computer, unconnected to the internet, simply sitting in a doctors office with billing information on it.... does this system need more 'protection' and regulation than the one it replaced of paper files, and sticky notes?