On August 25, 2020, OCR as part of its quarterly cybersecurity newsletter, provided outstanding guidance regarding HIPAA and IT Asset Inventories. As part of the risk assessment process at Colington Consulting, this is a critical area we address with all of our clients. We want to ensure there is a detailed asset inventory of all software, hardware, network or computing component that creates, receives, maintains, or transmits electronic protected health information (ePHI). Sometimes we find this information scattered into various documents or not centrally maintained. Our goal is to make sure there is a comprehensive list for software and hardware for these vital components throughout an organization.
Here are some helpful sections from the newsletter:
“The HIPAA Security Rule requires covered entities and business associates to ensure the confidentiality, integrity, and availability of all electronic protected health information (ePHI) that it creates, receives, maintains, or transmits. Conducting a risk analysis, which is an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI held by an organization, is not only a Security Rule requirement, but also is fundamental to identifying and implementing safeguards that comply with and carry out the Security Rule standards and implementation specifications. However, despite this long-standing HIPAA requirement, OCR investigations frequently find that organizations lack sufficient understanding of where all of the ePHI entrusted to their care is located. Although the Security Rule does not require it, creating and maintaining an up-to-date, information technology (IT) asset inventory could be a useful tool in assisting in the development of a comprehensive, enterprise-wide risk analysis, to help organizations understand all of the places that ePHI may be stored within their environment, and improve their HIPAA Security Rule compliance.”
How to Create an IT Asset Inventory
“An enterprise-wide IT asset inventory is a comprehensive listing of an organizationโs IT assets with corresponding descriptive information, such as data regarding identification of the asset (e.g., vendor, asset type, asset name/number), version of the asset (e.g., application or OS version), and asset assignment (e.g., person accountable for the asset, location of the asset). When creating an IT asset inventory, organizations can include:
- Hardware assets that comprise physical elements, including electronic devices and media, which make up an organizationโs networks and systems. This can include mobile devices, servers, peripherals, workstations, removable media, firewalls, and routers.
- Software assets that are programs and applications that run on an organizationโs electronic devices. Well-known software assets include anti-malware tools, operating systems, databases, email, administrative and financial records systems, and electronic medical/health record systems. Though lesser known,there are other programs important to IT operations and security such as backup solutions, virtual machine managers/hypervisors, and other administrative tools that should be included in an organizationโs inventory.
- Data assets that include ePHI that an organization creates, receives, maintains, or transmits on its network, electronic devices, and media.”
As part of this inventory process, we always recommend organizations have an accurate and up-to-date list of all vendors in which you have signed Business Associate Agreements in place with. You may also want to include a list of all types of physical, hard copy medical records, billing records, or any other paper documentation containing protected health information.
All these asset inventory lists must be reviewed and confirmed during the risk assessment process.
Not One and Done
This should not be considered a “one and done” process. It is important to remember whoever is assigned this task, whether it is an individual or a department, that is an ongoing process. Lists must be updated as new equipment or software is added and legacy systems or devices are removed.
Take Action Now
If HIPAA compliance assistance is needed for your organization, we specialize in putting compliance programs in place or assessing your current program. We provide a full range of services that include conducting the required HIPAA Risk Assessment, ensuring critical asset inventory lists are in place, writing and customizing a HIPAA Risk Management Plan (HIPAA Policies and Procedures) for your organization, and providing your entire staff annual required HIPAA Security Awareness & Privacy Training through our web-based platform. Our fees are based on what specifically your organization will need to meet regulatory requirements and reasonably priced to accommodate any budget.
At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.