In 1996 Congress passed the Health Insurance Portability and Accountability Act (HIPAA). The purpose of this Act was to improve the efficiency and effectiveness of the healthcare system through the development of established health data standards and requirements for the transmission and storage of electronic health information. HIPAA is the first national regulation on medical privacy and is the most far-reaching federal legislation affecting the use, release and transmission of medical data.
MyDoctorsNotes.com products and services have been designed to fully comply with HIPAA requirements.
Administrative:
- Password Aging and Complexity Policy
- PC Usage Policy for all Surgical Notes employees
- Encryption Policies for all transmission of patient data
- VPN Policy
- 180 day Data Retention Policy
- Disaster Recovery Plan
- Employee HIPAA awareness training
- Dedicated security officer to stay abreast of and constantly evaluate our business practices as they relate to HIPAA compliance
Physical:
- All Business critical systems co-located with Internap, providing best in class in terms of speed, redundancy and security
- Bio-metric access control systems to the Internap facility
Technical:
- Security Audit performed monthly by Maximum Network Security
- Checkpoint Firewall securing the perimeter of the Surgical Notes public and private networks
- 3DES, IKE/IPSEC2 encryption, VPN and SSL 128 bit secure, web enabled portal
- Separate internal LAN and DMZ networks
- Server auditing
- Unique username/password required for all data access
- RAID 5 disk configuration of all business critical systems
- Redundant data storage solutions