§170.210. Standards for health information technology to protect electronic health information created, maintained, and exchanged. — Inbound Citations
45 C.F.R. § 170.210
Statutory Authority
Cited by 25 regulations in release Current.
Citations to 45 U.S.C. § 170.210 as a whole
-
(1) Sections 3.29—2.43, Revision 7.0, August 10, 2010, IBR approved for § 170.205(p).
Citations to §170.210(a)
-
(3) [Reserved]
Citations to §170.210(a)(1)
Citations to §170.210(a)(2)
-
(i) the Health IT Module encrypts stored authentication credentials in accordance with standards adopted in § 170.210(a)(2).
Citations to §170.210(c)
-
(4) FIPS PUB 180-4, Secure Hash Standard (August 2015), IBR approved for § 170.210(c).
Citations to §170.210(c)(1)
Citations to §170.210(c)(2)
-
(i) Create a message digest in accordance with the standard specified in § 170.210(c)(2).
Citations to §170.210(d)
-
(11) Record disclosures made for treatment, payment, and health care operations in accordance with the standard specified in § 170.210(d).
Citations to §170.210(e)
-
(3) Enable a user to create an audit report for a specific time period and to sort entries in the audit log according to each of the data specified in the standards in § 170.210(e).
Citations to §170.210(e)(1)
-
(i) By default, be set to record actions related to electronic health information in accordance with the standard specified in § 170.210(e)(1).
Citations to §170.210(e)(2)
-
(B) Record the audit log status (enabled or disabled) in accordance with the standard specified in § 170.210(e)(2) unless it cannot be disabled by any user; and
Citations to §170.210(e)(3)
-
(C) Record the encryption status (enabled or disabled) of electronic health information locally stored on end-user devices by technology in accordance with the standard specified in § 170.210(e)(3) unless the technology prevents electronic health information from being locally stored on end-user devices (see paragraph (d)(7) of this section).
Citations to §170.210(f)
Citations to §170.210(g)
-
(ii) The date and time must be recorded in accordance with the standard specified at § 170.210(g).
-
(A) When any of the capabilities included in paragraphs (e)(1)(i)(A) through (C) of this section are used, the following information must be recorded and made accessible to the patient (or his/her authorized representative):(1) The action(s) (i.e., view, download, transmission) that occurred;(2) The date and time each action occurred in accordance with the standard specified in § 170.210(g);(3) The user who took the action; and(4) Where applicable, the addressee to whom an ambulatory summary or inpatient summary was transmitted.
Citations to §170.210(h)
-
(i) The audit log must record the information specified in sections 7.1.1 and 7.1.2 and 7.1.6 through 7.1.9 of the standard specified in § 170.210(h) and changes to user privileges when health IT is in use.
-
(1) ASTM E2147-18 Standard Specification for Audit and Disclosure Logs for Use in Health Information Systems, approved May 1, 2018, IBR approved for § 170.210(h).