The InfraWare HIPAA Advantage:


Core System Facilities

  • Located at SAS-70 Type II Compliant Data Center
  • Controlled access via biometric hand scanners, electronic keycard, and keyed server racks
  • Monitored and staffed 24 hours a day, 365 days a year
  • Redundant power supplied at one facility by two separate power companies and on-site generators
  • Redundant networking with automatic failover

Equipment

  • Enterprise class HP and Cisco equipment
  • Monitored Cisco firewall to secure network
  • Enterprise class HP Storage Area Network equipment with fully redundant fabric
  • Enterprise class HP servers with fully redundant and fault tolerant components

Physical Access

  • Systems are accessible only by select senior engineers
  • Isolated production network
  • All internal access is logged and reviewed

InfraWare Education and Administration

  • All staff has received HIPAA training
  • A HIPAA compliance officer has been designated
  • An internal HIPAA policies and procedures guide has been published

Software

  • Jobs are encrypted and stored securely throughout InfraWare’s platform
  • Communication with the InfraWare platform is secured using High-grade 128bit SSL encryption
  • User actions on the InfraWare platform are logged and available for administrative review
  • A comprehensive audit trail is maintained for each job on the InfraWare platform
  • User-specific roles and access rights provide granular settings for administrators



Helpful Resources

Regulations and Compliance

Bricker.com - Ohio law firm website with links to HIPAA related statutes, regulations, and interpretations.

OCR - The Office for Civil Rights (OCR) is within the U.S. Department of Health & Human Services and serves as the official interpreter, investigator, and enforcer for the HIPAA Privacy and Security Rules.

McKenna Long & Aldridge - International law firm website with Business Associate compliance advice.

Online Education

HIPAA Store - Site operated by a consultancy called The HIPAA Group that offers online training courses, HIPAA forms, and policy and procedures templates.

HIPAA Training - Another HIPAA consultancy site offering training and supplies.

Articles

Fierce Health IT - February 16, 2010 – fiercehealthit – “Security officers have new motivation to protect healthcare data”

American Medical News - May 4, 2009 – amednews.com – “Stimulus package alters HIPAA rules for business associates”