Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

Simplify HIPAA Compliance with PKWARE

PKWARE

By PKWAREProductivity Protected

Share on social media

Download

The Health Insurance Portability and Accountability Act (HIPAA) requires that protected health information (PHI) remain private and secure at all times. It also gives patients control over their data and outlines processes for handling patient complaints and reporting data breaches. If your organization is a health plan, healthcare provider or clearinghouse, or any other company that creates, handles, or processes health care data, you may be required to comply with HIPAA.

PKWARE can help your organization protect all PHI throughout the data lifecycle—regardless of how or where it is stored or used—supporting your compliance with HIPAA’s privacy and security rules and other requirements for compliance. Download our solution overview to learn more.

What HIPAA Protects

The Health Insurance Portability and Accountability Act of 1996 established security standards protecting the confidentiality of Protected Health Information, defined as any information that identifies an individual and relates to their health condition, their care, or payment for that care.

That definition is wider than medical records. It covers prescription details and ordinary personal information wherever those sit alongside a health context, which is why PHI turns up in systems nobody classified as clinical.

What HITECH Added in 2009

The Health Information Technology for Economic and Clinical Health Act strengthened HIPAA in two ways that changed how organizations behave.

It raised the fines for non-compliance, and it required covered entities to notify regulators, the individuals affected and in some cases the media following a breach involving PHI. The second is the one that made health data breaches public events rather than internal ones.

Who Has to Comply

The two laws apply to any entity, and to its business associates, that accesses, maintains, retains, modifies, records, stores, destroys, holds, uses or discloses PHI.

Health plans, providers and clearinghouses are the obvious cases. The business associate clause is the one that surprises people, because it reaches vendors, processors and service providers who never thought of themselves as healthcare organizations.

What Enforcement Has Actually Cost

As of 31 March 2021, the Department of Health and Human Services recorded 99 HIPAA violation cases resulting in a combined $135,298,482 in fines.

The figure is worth reading alongside the breach notification requirement. The financial penalty is frequently the smaller consequence next to the disclosure obligation and what follows it.

Where PHI Escapes

PHI moves constantly between doctors’ offices, laboratories, hospitals and billing departments, and each handoff is a copy. The risk is rarely the clinical system itself; it is the extract taken from it, the report built on it, and the message that carried it.

Discovery and protection working together are what address that, by locating PHI wherever it has been copied and applying protection according to policy rather than according to where the data was supposed to stay.

Analytics Without Exposure

Healthcare organizations need to analyze the same data they are obliged to protect, and refusing access is not a workable answer for a sector whose improvement depends on it.

De-identification and masking resolve that. A dataset stripped of the elements that identify a patient supports the analysis while removing the obligation attached to the original, which is a materially better position than a strict access policy nobody can work within.

The same reasoning applies to test and development environments, where realistic data improves the work and real PHI creates an obligation nobody intended to take on. Masked copies satisfy both halves of that requirement.

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.