US Codex
C.F.R.
Browse by date
Notes

§164.306. Security standards: General rules. — Inbound Citations

45 C.F.R. § 164.306

Cited by 9 regulations in release Current.

Citations to 45 U.S.C. § 164.306 as a whole

  • (a) A covered entity or business associate must, in accordance with § 164.306:
    (i) Implement policies and procedures to prevent, detect, contain, and correct security violations.
    (A) Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate.
    (B) Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with § 164.306(a).
    (C) Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity or business associate.
    (D) Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.
    (2) Identify the security official who is responsible for the development and implementation of the policies and procedures required by this subpart for the covered entity or business associate.
    (i) Implement policies and procedures to ensure that all members of its workforce have appropriate access to electronic protected health information, as provided under paragraph (a)(4) of this section, and to prevent those workforce members who do not have access under paragraph (a)(4) of this section from obtaining access to electronic protected health information.
    (A) Implement procedures for the authorization and/or supervision of workforce members who work with electronic protected health information or in locations where it might be accessed.
    (B) Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate.
    (C) Implement procedures for terminating access to electronic protected health information when the employment of, or other arrangement with, a workforce member ends or as required by determinations made as specified in paragraph (a)(3)(ii)(B) of this section.
    (i) Implement policies and procedures for authorizing access to electronic protected health information that are consistent with the applicable requirements of subpart E of this part.
    (A) If a health care clearinghouse is part of a larger organization, the clearinghouse must implement policies and procedures that protect the electronic protected health information of the clearinghouse from unauthorized access by the larger organization.
    (B) Implement policies and procedures for granting access to electronic protected health information, for example, through access to a workstation, transaction, program, process, or other mechanism.
    (C) Implement policies and procedures that, based upon the covered entity's or the business associate's access authorization policies, establish, document, review, and modify a user's right of access to a workstation, transaction, program, or process.
    (i) Implement a security awareness and training program for all members of its workforce (including management).
    (ii) Implement:
    (A) Periodic security updates.
    (B) Procedures for guarding against, detecting, and reporting malicious software.
    (C) Procedures for monitoring log-in attempts and reporting discrepancies.
    (D) Procedures for creating, changing, and safeguarding passwords.
    (i) Implement policies and procedures to address security incidents.
    (ii) Identify and respond to suspected or known security incidents; mitigate, to the extent practicable, harmful effects of security incidents that are known to the covered entity or business associate; and document security incidents and their outcomes.
    (i) Establish (and implement as needed) policies and procedures for responding to an emergency or other occurrence (for example, fire, vandalism, system failure, and natural disaster) that damages systems that contain electronic protected health information.
    (A) Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information.
    (B) Establish (and implement as needed) procedures to restore any loss of data.
    (C) Establish (and implement as needed) procedures to enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode.
    (D) Implement procedures for periodic testing and revision of contingency plans.
    (E) Assess the relative criticality of specific applications and data in support of other contingency plan components.
    (8) Perform a periodic technical and nontechnical evaluation, based initially upon the standards implemented under this rule and, subsequently, in response to environmental or operational changes affecting the security of electronic protected health information, that establishes the extent to which a covered entity's or business associate's security policies and procedures meet the requirements of this subpart.
  • A covered entity or business associate must, in accordance with § 164.306:
  • A covered entity or business associate must, in accordance with § 164.306:
  • A covered entity or business associate must, in accordance with § 164.306:

Citations to §164.306(a)

Citations to §164.306(b)(2)(i)

  • (a) Implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements of this subpart, taking into account those factors specified in § 164.306(b)(2)(i), (ii), (iii), and (iv). This standard is not to be construed to permit or excuse an action that violates any other standard, implementation specification, or other requirements of this subpart. A covered entity or business associate may change its policies and procedures at any time, provided that the changes are documented and are implemented in accordance with this subpart.

Citations to §164.306(b)(2)(ii)

  • (a) Implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements of this subpart, taking into account those factors specified in § 164.306(b)(2)(i), (ii), (iii), and (iv). This standard is not to be construed to permit or excuse an action that violates any other standard, implementation specification, or other requirements of this subpart. A covered entity or business associate may change its policies and procedures at any time, provided that the changes are documented and are implemented in accordance with this subpart.

Citations to §164.306(b)(2)(iii)

  • (a) Implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements of this subpart, taking into account those factors specified in § 164.306(b)(2)(i), (ii), (iii), and (iv). This standard is not to be construed to permit or excuse an action that violates any other standard, implementation specification, or other requirements of this subpart. A covered entity or business associate may change its policies and procedures at any time, provided that the changes are documented and are implemented in accordance with this subpart.

Citations to §164.306(b)(2)(iv)

  • (a) Implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements of this subpart, taking into account those factors specified in § 164.306(b)(2)(i), (ii), (iii), and (iv). This standard is not to be construed to permit or excuse an action that violates any other standard, implementation specification, or other requirements of this subpart. A covered entity or business associate may change its policies and procedures at any time, provided that the changes are documented and are implemented in accordance with this subpart.