Posts: 34
Joined: August 2010
|
|
|
|
Joined: Dec 2009
Posts: 1,208 Likes: 8
Member
|
Member
Joined: Dec 2009
Posts: 1,208 Likes: 8 |
1 ?172.302(o) Access control. Assign a unique name and/or number for identifying and tracking user identity and establish controls that permit only authorized users to access electronic health information.
Each user should have their own Windows account and their own account into whatever software that requires each user to have their own user account outisde of Windows. Users should not share accounts.
2 ?172.302(p) Emergency access. Permit authorized users (who are authorized for emergency situations) to access electronic health information during an emergency.
Subjective. For most of you, the built in Administrator account in Windows will suffice.
3 ?172.302(q) Automatic log-off. Terminate an electronic session after a predetermined time of inactivity.
Set a screen saver in Windows to lock the machine after so much time of inactivity. Set Terminal Servers to disconnect users after so much time of inactivity.
4 ?172.302(r) Audit Log. (1) Record actions. Record actions related to electronic health information in accordance with the standard specified in ? 170.210(b).
Set the Windows Security Event Log to track log on and log off and access to certain files and file shares. EMR's should have their own facilities for this.
(2) Generate audit log. Enable a user to generate an audit log for a specific time period and to sort entries in the audit log according to any of the elements specified in the standard at 170.210(b).
This is what the Administrator account in Windows and Amazing Charts is for.
5 ?172.302(s) Integrity. (1) Create a message digest in accordance with the standard specified in 170.210(c). (2) Verify in accordance with the standard specified in 170.210(c) upon receipt of electronically exchanged health information that such information has not been altered.
If you have an HL7 or other interface, ensure you encrypt the data while en route to it's destination via VPN or other method. Have the necessary business associates agreement in with those you are sending to/receiving from.
(3) Detection. Detect the alteration of audit logs.
If you ever see an event in Windows that says the "Security Event Log has been cleared" then you know the deal.
6 ?172.302(t) Authentication. Verify that a person or entity seeking access to electronic health information is the one claimed and is authorized to access such information.
Again, make sure users are not sharing accounts.
7 ?172.302(u) General encryption. Encrypt and decrypt electronic health information in accordance with the standard specified in ? 170.210(a)(1), unless the Secretary determines that the use of such algorithm would pose a significant security risk for Certified EHR Technology.
Utilize the built-in encryption in Windows to encrypt information from workstation to server (domain based networks only).
8 ?172.302(v) Encryption when exchanging electronic health information. Encrypt and decrypt electronic health information when exchanged in accordance with the standard specified in ? 170.210(a)(2).
Utilize the built-in encryption in Windows to encrypt information from workstation to server (domain based networks only).
How do I accomplish all of this??
A SBS 2011 network with all Windows 7 workstations will handle the majority of this for you with no work on your part save setting up user accounts. A Juniper SRX100 security gateway will handle setting up VPN's with outside entities and security publishing services to the Internet (e.g. Exchange, Terminal Server). Such a network with 5 workstations should cost you less than $10,000 to purchase AND SET UP.
JamesNT
|
|
|
|
Entire Thread
|
Lawyers, Guns and Money.....and Security
|
Boondoc
|
02/08/2012 9:43 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Boondoc
|
02/08/2012 9:49 PM
|
Re: Lawyers, Guns and Money.....and Security
|
ryanjo
|
02/08/2012 10:09 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Bert
|
02/08/2012 11:51 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Boondoc
|
02/09/2012 12:37 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Adam Lauer DO
|
02/11/2012 6:51 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Bert
|
02/09/2012 4:54 AM
|
Re: Lawyers, Guns and Money.....and Security
|
ryanjo
|
02/09/2012 2:15 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Indy
|
02/09/2012 4:53 PM
|
Re: Lawyers, Guns and Money.....and Security
|
ryanjo
|
02/09/2012 10:08 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Indy
|
02/10/2012 5:00 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Boondoc
|
02/09/2012 7:48 PM
|
Re: Lawyers, Guns and Money.....and Security
|
ryanjo
|
02/09/2012 10:50 PM
|
Re: Lawyers, Guns and Money.....and Security
|
donaldphi
|
02/12/2012 6:25 AM
|
Re: Lawyers, Guns and Money.....and Security
|
SoCalRehabDoc
|
02/16/2012 9:04 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Adam Lauer DO
|
02/16/2012 11:20 PM
|
Re: Lawyers, Guns and Money.....and Security
|
DanWatrous
|
02/17/2012 1:16 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Ches
|
02/17/2012 2:24 AM
|
Re: Lawyers, Guns and Money.....and Security
|
DanWatrous
|
02/17/2012 5:03 AM
|
Re: Lawyers, Guns and Money.....and Security
|
DCubed
|
02/12/2012 7:15 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Leslie
|
02/17/2012 12:07 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Adam Lauer DO
|
02/18/2012 1:54 AM
|
Re: Lawyers, Guns and Money.....and Security
|
DocMartin
|
02/18/2012 2:02 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Leslie
|
02/18/2012 11:49 PM
|
Re: Lawyers, Guns and Money.....and Security
|
JBS
|
02/19/2012 12:31 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Steven
|
02/19/2012 12:42 AM
|
Re: Lawyers, Guns and Money.....and Security
|
JamesNT
|
02/19/2012 1:04 AM
|
Re: Lawyers, Guns and Money.....and Security
|
JamesNT
|
02/19/2012 1:43 AM
|
Re: Lawyers, Guns and Money.....and Security
|
dgrauman
|
02/19/2012 2:01 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Bert
|
02/19/2012 3:56 AM
|
Re: Lawyers, Guns and Money.....and Security
|
dgrauman
|
02/19/2012 4:16 AM
|
Re: Lawyers, Guns and Money.....and Security
|
JBS
|
02/19/2012 10:23 AM
|
Re: Lawyers, Guns and Money.....and Security
|
ryanjo
|
02/19/2012 3:26 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Bert
|
02/19/2012 5:05 AM
|
Re: Lawyers, Guns and Money.....and Security
|
dgrauman
|
02/19/2012 6:13 AM
|
Re: Lawyers, Guns and Money.....and Security
|
JamesNT
|
02/19/2012 2:35 PM
|
Re: Lawyers, Guns and Money.....and Security
|
dgrauman
|
02/19/2012 6:05 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Tomastoria
|
02/19/2012 6:41 PM
|
Re: Lawyers, Guns and Money.....and Security
|
dgrauman
|
02/19/2012 8:59 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Bert
|
02/19/2012 10:33 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Leslie
|
02/20/2012 12:10 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Tomastoria
|
02/20/2012 3:06 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Bert
|
02/20/2012 3:07 AM
|
Re: Lawyers, Guns and Money.....and Security
|
JBS
|
02/20/2012 8:16 PM
|
Re: Lawyers, Guns and Money.....and Security
|
dgrauman
|
02/20/2012 8:58 PM
|
Re: Lawyers, Guns and Money.....and Security
|
JamesNT
|
02/21/2012 3:30 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Wayne
|
02/22/2012 4:22 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Wendell365
|
02/22/2012 7:25 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Bert
|
02/22/2012 7:42 PM
|
Re: Lawyers, Guns and Money.....and Security
|
JBS
|
02/22/2012 8:00 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Wendell365
|
02/22/2012 8:34 PM
|
Re: Lawyers, Guns and Money.....and Security
|
dgrauman
|
02/22/2012 9:02 PM
|
Re: Lawyers, Guns and Money.....and Security
|
ryanjo
|
02/22/2012 10:20 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Nephros
|
02/23/2012 2:27 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Wendell365
|
02/23/2012 4:34 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Bert
|
02/23/2012 2:44 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Nephros
|
02/23/2012 5:22 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Wayne
|
02/23/2012 2:26 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Ches
|
02/23/2012 2:51 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Ches
|
02/23/2012 3:00 PM
|
Re: Lawyers, Guns and Money.....and Security
|
dgrauman
|
02/23/2012 4:41 PM
|
Re: Lawyers, Guns and Money.....and Security
|
JBS
|
02/23/2012 5:28 PM
|
Re: Lawyers, Guns and Money.....and Security
|
ryanjo
|
02/23/2012 6:11 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Leslie
|
02/23/2012 6:05 PM
|
Re: Lawyers, Guns and Money.....and Security
|
dgrauman
|
02/23/2012 7:50 PM
|
Re: Lawyers, Guns and Money.....and Security
|
Bert
|
02/24/2012 1:58 AM
|
Re: Lawyers, Guns and Money.....and Security
|
Adam Lauer DO
|
02/24/2012 6:16 AM
|
Re: Lawyers, Guns and Money.....and Security
|
kallis
|
01/23/2013 12:49 PM
|
|
|
0 members (),
113
guests, and
34
robots. |
|
Key:
Admin,
Global Mod,
Mod
|
|
|
|