OCR Guidance Underscores Importance of Authentication under HIPAA

By and on November 17, 2016

In its tenth OCR Cyber Awareness Newsletter of the year (Newsletter), the Office for Civil Rights (OCR) reminded HIPAA-covered entities and business associates of the importance of selecting an appropriate authentication method to protect electronic protected health information (ePHI). Authentication is the process used to “verify whether someone or something is who or what it purports to be and keeps unauthorized people or programs from gaining access to information.” The Newsletter notes that the health care sector has been a significant target of cybercrime and that some incidents result from weak authentication methods.

Authentication methods can consist of one or more factors and are often described as: (1) something you know, such as a password; (2) something you are, such as a fingerprint; or (3) something you have, such as a mobile device or smart card. Single-factor authentication requires use of only one of the methods. Multifactor authentication requires use of two or more methods (for example, a password prompt followed by an additional prompt to a mobile device).

The selection of an authentication method should be tied to the results of a covered entity’s or business associate’s required security risk assessment, which can uncover “the vulnerabilities of current authentication methods, the threats that can exploit the weakness, the likelihood of a breach occurring. . . .” Based on the probability of potential risks and vulnerabilities to the ePHI, business associates and covered entities should select a form of authentication that is “reasonable and appropriate” for the size, complexity, technical infrastructure, hardware and software capabilities of the organization.

OCR’s Cyber Awareness Newsletter was launched in February 2016 in order “to assist the regulated community to become more knowledgeable about the various security threats and vulnerabilities that currently exist in the healthcare sector, to understand what security measures can be taken to decrease the possibility of being exposed by these threats; and how to reduce breaches of ePHI.” Past issues of the Newsletter are available on the OCR website and have covered various security topics, including ransomware, malware and medical devices, business associate preparedness for a security incident, vulnerabilities in third-party application software, inter-organizational information sharing, and file transfer protocol vulnerabilities.

Amanda Enyeart
  Amanda Enyeart maintains a general health industry and regulatory practice, focusing on fraud and abuse, information technology and digital health matters. Amanda advises health care industry clients in all aspects of software licenses and other agreements for the acquisition electronic health record (EHR) systems and other mission critical health IT.  Amanda’s health care IT transactional experience also includes advising clients with respect to software development, maintenance, service and outsourced hosting arrangements, including cloud-computing transactions. Read Amanda Enyeart's full bio.

Ryan S. Higgins
Ryan S. Higgins focuses his practice on representing hospitals, health systems, private equity firms and platform companies, and other health care organizations in corporate and transactional matters, including mergers, acquisitions, joint ventures and management arrangements. He also devotes a significant portion of his practice to representing health care organizations in matters involving health information privacy and security and Health Insurance Portability and Accountability Act (HIPAA) compliance. Ryan serves on the Chicago's office Pro Bono Committee and is heavily involved in pro bono matters. Read Ryan Higgins' full bio.




2021 Chambers USA top ranked firm
U.S. News Law Firm of the Year 2022 Health Care Law
U.S. News Law Firm of the Year 2022 Health Care Law