DEPARTMENT OF HEALTH AND HUMAN SERVICES
Office of the Secretary
45 CFR Parts 160,
162, and 164
[CMS-0049-F]
RIN 0938-AI57
Health Insurance Reform:
Security Standards
AGENCY:
Centers for Medicare & Medicaid Services (CMS), HHS.
ACTION:
Final rule.
Table of Contents
I. Background
II. General Overview of the Provisions of the Proposed Rule
III. Analysis of, and Responses to, Public Comments on the Proposed Rule
A. General Issues
1. Security Rule and Privacy Rule Distinctions
2. Level of Detail
3. Implementation Specifications
4. Examples
B. Applicability (§ 164.302)
C. Transition to the Final Rule
1. Covered Entity (§ 160.103)
2. Health Care and Medical Care (§ 160.103)
3. Health Information and Individually Identifiable Health Information (§
160.103)
4. Protected Health Information (§ 160.103)
5. Breach (§ 164.304)
6. Facility (§ 164.304)
7. Security Incident (§ 164.304)
8. System (§ 164.304)
9. Workstation (§ 164.304)
10. Definitions Not Adopted
D. General Rules (§ 164.306)
1. Scope of Health Information Covered by the Rule (§ 164.306(a))
2. Technology-Neutral Standards
3. Miscellaneous Comments
E. Administrative Safeguards (§ 164.308)
1. Security Management Process (§ 164.308(a)(1)(i))
2. Assigned Security Responsibility (§ 164.308(a)(2))
3. Workforce Security (§ 164.308(a)(3)(i))
4. Information Access Management (§ 164.308(a)(4))
5. Security Awareness and Training (§ 164.308(a)(5)(i))
6. Security Incident Procedures (§ 164.308(a)(6))
7. Contingency Plan (§ 164.308(a)(7)(i))
8. Evaluation (§ 164.308(a)(8))
8. Business Associate Contracts or Other Arrangements (§ 164.308(b)(1))
(sic)
9. Proposed Requirements Not Adopted in This Final Rule
F. Physical Safeguards (§ 164.310)
1. General Comments
2. Facility Access Controls (§ 164.310(a)(1))
3. Workstation Use (§ 164.310(b))
4. Workstation Security (§ 164.310(c))
5. Device and Media Controls (§ 164.310(d)(1))
G. Technical
Safeguards (§ 164.312)
1. Access Control (§ 164.312(a)(1))
2. Audit Controls (§ 164.312(b))
3. Integrity (§ 164.312(c)(1))
4. Person or Entity Authentication (§ 164.312(d))
5. Transmission Security (§ 164.312(e)(1))
6. Proposed Requirements Not Adopted in This Final Rule
H. Requirements (§ 164.314)
1. Health Care Clearinghouses
2. Business Associate Contracts and Other Arrangements
I. Policies and Procedures and Documentation Requirements (§ 164.316)
J. Compliance Dates for Initial Implementation (§ 164.318)
K. Appendix
L. Miscellaneous Issues
1. Preemption
2. Enforcement
3. Comment Period
M. Proposed Impact Analysis
IV. Provisions of the Final Regulation
V. Collection of Information Requirements
Section 164.306 Security Standards: General Rules
Section 164.308 Administrative Safeguards
Section 164.310 Physical Safeguards
Section 164.314 Organizational Requirements
Section 164.316 Policies and Procedures and Documentation Requirements
IV. Regulatory Impact Analysis (sic)
A. Overall Impact
B. Anticipated Effects
C. Changes From the 1998 Impact Analysis
1. Changes in Technology
2. Synchronizing Standards
3. Relationship to Privacy Standards
4. Sensitivity to Security Concerns as a Result of September 11, 2001
D. Guiding Principles for Standard
E. Affected Entities
1. Health Care Providers
2. Health Plans
3. Clearinghouses
4. System Vendors
F. Factors in Establishing the Security Standard
1. General Effect
2. Complexity of Conversion
3. Cost of Conversion
G. Alternatives Considered
V. Federalism (sic)
List of Subjects
45 CFR Part 160
45 CFR Part 162
45 CFR Part 164
PART 160—GENERAL ADMINISTRATIVE REQUIREMENTS
§ 160.103 Definitions
PART 162—ADMINISTRATIVE REQUIREMENTS
§ 162.103 [Amended]
PART 164—SECURITY AND PRIVACY
§ 164.103 Definitions
§ 164.104 Applicability
§ 164.105 Organizational
Requirements
Subpart C—Security Standards for the Protection of Electronic Protected Health Information
§ 164.302 Applicability
§ 164.304 Definitions
§ 164.306 Security standards: General rules
§ 164.308 Administrative safeguards
§ 164.310 Physical safeguards
|