global
Variáveis
Utilitários
ESTILOS PERSONALIZADOS

What Is HIPAA Security? (The HIPAA Law)

The main HIPAA security requirements are quite precise and aim to guarantee the confidentiality of patients' data and studies.

By Eden Experts

We analyze what this HIPAA law entails, which ensures the protection of medical data and information. We will look at how it adapts to current needs when sharing confidential information through digital channels.

The digital era increasingly envelops the world. An important element of this new reality is the security of the information sent across different networks. This becomes even more important when it comes to confidential content, which must remain exclusively in the hands of experts, as is the case with patient information.

This information is governed by the provisions of the HIPAA law. When a PACS system is implemented to manage and store clinical images, one of the goals is for these studies to be transmitted through communication networks to various operational areas of a healthcare facility, through intrahospital networks, with other physicians, and with patients themselves.1 An important point in this exchange of information is that it be done securely.

How Do PACS Systems Guarantee Security?

In pursuit of this security, PACS systems for medical images commonly work with two network systems that make it possible for these studies to be handled with privacy, integrity, and authenticity. The first system corresponds to the connections shared with the hospital's Central Network Authority (CNA), which has its own regulations, maintenance, and management.2

The second system is the PACS network itself, in which cables and terminals are also safeguarded in hubs that support information security. Only authorized personnel working with these systems and medical specialists can access the medical images backed up by the software, ensuring control over the use and exchange of information.2

But who oversees compliance with the proper management of medical images?

Preventing the leakage and manipulation of information can be complex, and this is why HIPAA, the Health Insurance Portability and Accountability Act, was created in the United States. This law seeks to protect and secure patients' healthcare information so that it can be disclosed to interested parties, by enforcing a series of requirements on healthcare facilities.2

Now, the DICOM standard used for medical images across different modalities also establishes security criteria for information exchange policies.2 

For all these reasons, when choosing a PACS system, make sure it complies with HIPAA.

What Requirements Does HIPAA Specify?

Some of the most important requirements established by this law for the secure communication of medical information are:

  • All patients undergoing medical studies have the right to see their results and obtain a copy of them. The medical history must also be made available to assess the progression of a condition.3
  • Professionals with legal certification can access patients' medical information for the purpose of making diagnoses and decisions regarding them.3
  • Every healthcare professional working at a facility in this sector must know the institution's policies for ensuring the confidentiality of its patients.3 
  • Commercializing patient information is a crime carrying significant legal penalties (criminal and civil)4 and is prohibited. This information may only be shared with the healthcare facility's internal staff3 in order to respond to the patient.

It is worth noting that in certain cases, disclosure of information may be required without the patient's authorization, for example in the case of a contagious condition, incidents of violence or abuse, when organ donations are required, or when the law warrants it.4

How Can a Healthcare Facility Comply with HIPAA?

HIPAA's main requirements are quite precise, but they do not impose a single way of guaranteeing the confidentiality of patients' data and studies. What matters is that each healthcare facility create standards that protect this information, including clinical images, so that they are not altered or disclosed to unauthorized individuals.4

To achieve the above, it is essential that every medical facility use systems sufficiently protected against cyberattacks or the misuse of electronic data (even through carelessness) that could leak confidential information. 

This is why quality PACS systems comply with these HIPAA guidelines.

Does Eden PACS Comply with HIPAA?

Among the benefits of Eva PACS for the management, transmission, and cloud storage of radiological images is the full guarantee of electronic security protocols and confidential data protection.

Eden PACS complies with the electronic requirements of the HIPAA law. As an added value, patients will also be able to securely access their studies through digital channels. Finally, only authorized personnel will have access to patient information within the Eva system.

References

1 Centro Nacional de Excelencia Tecnológica en Salud (National Center for Technological Excellence in Health) (2009). Systems for image archiving and communication. Mexico, Secretaría de Salud (Ministry of Health).

2 Huang, H. K. (2004). PACS AND IMAGING INFORMATICS BASIC PRINCIPLES AND APPLICATIONS. University of California, Los Angeles. P.: 691

3 Merck Manual. Confidentiality and HIPAA (Health Insurance Portability and Accountability Act in the United States). Retrieved from https://www.merckmanuals.com/es-us/hogar/fundamentos/asuntos-legales-y-%C3%A9ticos/la-confidencialidad-y-la-hipaa-ley-de-portabilidad-y-responsabilidad-de-seguros-de-salud-en-estados-unidos 4 Centers for Disease Control and Prevention. Health Insurance Portability and Accountability Act of 1996 (HIPAA). Retrieved from https://www.cdc.gov/phlp/publications/topic/hipaa.html