164.312 Technical safeguards
A covered entity must, in accordance with [164.306]:
-
- 164.312(a)(1)
(1) Standard: Access control. Implement technical policies
and procedures for electronic information systems that
maintain electronic protected health information to allow
access only to those persons or software programs that
have been granted access rights as specified in [164.308(a)(4)].
-
(2) Implementation specifications:
- 164.312(a)(1)(i)
(i) Unique user identification (Required). Assign a
unique name and/or number for identifying and tracking
user identity.
- 164.312(a)(2)(ii)
(ii) Emergency access procedure (Required). Establish
(and implement as needed) procedures for obtaining
necessary electronic protected health information
during an emergency.
- 164.312(a)(2)(iii)
(iii) Automatic logoff (Addressable). Implement
electronic procedures that terminate an electronic
session after a predetermined time of inactivity.
- 164.312(a)(2)(iv)
(iv) Encryption and decryption
(Addressable). Implement a mechanism to encrypt and
decrypt electronic protected health information.
- 164.312(b)
(b) Standard: Audit controls. Implement hardware, software,
and/or procedural mechanisms that record and examine activity
in information systems that contain or use electronic
protected health information.
-
(c)
- 164.312(c)(1)
(1) Standard: Integrity. Implement policies and procedures
to protect electronic protected health information from
improper alteration or destruction.
- 164.312(c)(2)
(2) Implementation specification: Mechanism to
authenticate electronic protected health information
(Addressable). Implement electronic mechanisms to
corroborate that electronic protected health information
has not been altered or destroyed in an unauthorized
manner.
- 164.312(d)
(d) Standard: Person or entity authentication. Implement
procedures to verify that a person or entity seeking access to
electronic protected health information is the one claimed.
-
(e)
- 164.312(e)(1)
(1) Standard: Transmission security. Implement technical
security measures to guard against unauthorized access to
electronic protected health information that is being
transmitted over an electronic communications network.
-
(2) Implementation specifications:
- 164.312(e)(2)(i)
(i) Integrity controls (Addressable). Implement
security measures to ensure that electronically
transmitted electronic protected health information is
not improperly modified without detection until
disposed of.
- 164.312(e)(2)(ii)
(ii) Encryption (Addressable). Implement a mechanism
to encrypt electronic protected health information
whenever deemed appropriate.