For chiropractic practices that use electronic systems to handle patient information, regularly reviewing security risks is an important part of HIPAA compliance. This includes more than electronic health records. For example, electronic billing and insurance transactions, practice management systems, remote access, and other technology used to store or exchange patient information may all be part of a practice’s security review.
Help Available from HHS to Review HIPAA Security Risks
To help healthcare practices with this process, the U.S. Department of Health and Human Services (HHS) has released Version 3.7 of its Security Risk Assessment (SRA) Tool. This free tool helps small and medium-sized healthcare practices identify potential risks to electronic protected health information (ePHI) and review the safeguards they have in place.
A security risk assessment can also give practices a practical way to review how they use technology and identify areas that may need attention. In particular, a new assessment may be helpful after a practice changes software, adds devices, introduces remote access, or changes how staff access patient information.
What’s New in Version 3.7?
HHS updated Version 3.7 to address several areas of today’s healthcare technology environment. Updates include:
- New questions and guidance about the scope of a security risk assessment
- Updated questions and guidance related to remote access and telework
- Revised information about system activity logging
- Expanded examples of technology and other assets that practices should consider
- Software updates addressing bugs and vulnerabilities
- Revised reports that allow practices to capture additional details and comments
The SRA Tool is available as both a Windows application and an Excel workbook.
In addition, HHS states that the Windows version stores information locally on the user’s computer. HHS does not collect, view, store, or transmit the information entered into the tool.
Download the HHS Security Risk Assessment Tool v3.7
Learn More During a Free HHS Webinar
HHS is also offering two live webinars to introduce Version 3.7. During the sessions, experts will demonstrate the updated features, walk through the reports, and answer questions.
Tuesday, September 15 at 12:00 p.m. ET
Register for the September 15 webinar
Wednesday, September 16 at 3:00 p.m. ET
Register for the September 16 webinar
Practices that have not reviewed their security risk assessment recently may find the updated tool a useful place to start. Likewise, practices that have recently changed their technology, remote access, or other systems may want to review whether those changes affect their existing security safeguards.
Additional Compliance Support for NYSCA Members
NYSCA members can find additional tools and guidance through our Compliance and Professional Requirements resources.
In addition, eligible members have access to the NYSCA Compliance Dashboard at no additional cost. The dashboard helps practices organize and track requirements related to HIPAA, OSHA, ADA, employment, and other areas of practice compliance. Learn more about the NYSCA Compliance Dashboard.
For additional updates on regulatory and practice requirements, visit NYSCA Compliance News.