What is HIPAA?
HIPAA is a United States Act for organizations dealing with electronic healthcare transactions and PIIs in the healthcare and healthcare insurance industries.
These are the main HIPAA security rules:
- Administrative Safeguards
- Physical Safeguards
- Technical Safeguards
- Organizational, Policies and Procedures and Documentation Requirements
- Basics of Risk Analysis and Risk Management
Here are some best practices to implement:
- Encrypt all healthcare information, while in transit (using TLS 1.2) or at rest (using the AES 256 algorithm).
- Enable an audit log for any information related to healthcare data.
- Authenticate and authorize any request to access healthcare data.
- Follow the principle of least privilege (POLP) when accessing healthcare data.
- Conduct penetration testing for systems that contain healthcare data.
- Keep all systems up to date (enforce patch management).
- Enable backups for any system that contains...