Find White Papers
Home
About Us
List Your Papers
    
> Imprivata > The Value of Enterprise SSO to HIPAA Compliance

The Value of Enterprise SSO to HIPAA Compliance

White Paper Published By: Imprivata

When the U.S. Congress passed the Health Insurance Portability and Accountability Act (HIPAA) of 1996, among the law's many provisions was the establishment of formal regulations designed to protect the confidentiality and security of patient information. In addition to mandating new policies and procedures, the HIPAA security regulations require mechanisms for controlling access to patient data on healthcare providers' information technology (IT) systems.



Tags : 
password management, enterprise single sign on, enterprise single sign-on, single sign on, single sign-on, esso, sso, hipaa

Imprivata
Published:  Aug 21, 2009
Type:  White Paper
Length:  12 pages

The Value of Enterprise SSO
to HIPAA Compliance
A resource guide compiled and edited by:Gregg LaRocheDirector of Product Management, Healthcare Division,Imprivata, Inc.
May, 2005
TABLE OF CONTENTS
Executive Summary....................................................................................................................... 2
Ways in Which the Right ESSO Solutions Satisfies HIPAA Security Requirements.................. 3
HIPAA Security Standards............................................................................................................. 3
Other Advantages ESSO Should Deliver to Healthcare Providers............................................. 5
Imprivata OneSign's Advantages for HIPAA Compliance........................................................... 5
How OneSign Works...................................................................................................................... 6
The Advantages of OneSign Over Other ESSO Solutions.......................................................... 7
Beyond HIPPA Compliance............................................................................................................. 82 The Value of Enterprise SSO to HIPPA Compliance
Executive Summary
When the U.S. Congress passed the Health Insurance Portability and Accountability Act (HIPAA) of1996, among the law's many provisions was the establishment of formal regulations designed to protect the confidentiality and security of patient information. Congress set a series of deadlines for healthcare institutions to comply with the new regulations, including an April 2005 deadline for the security requirements.
In addition to mandating new policies and procedures, the HIPAA security regulations require mechanisms for controlling access to patient data on healthcare providers' information technology(IT) systems. As the April 2005 deadline draws closer, meeting these IT security and access manage-ment requirements is proving to be a challenge for many institutions, for a number of reasons,including: . Complex IT environments: Most hospitals' IT environments include a diverse assortment of legacy, PC and Web applications, both internal and external. Any access control methods they employ must address all applications and platforms in their environments.. Complex legacy applications: Many healthcare institutions still rely heavily on legacy systems for which the software code has grown increasingly complex over time. In many cases, institutions lack the resources to modify application code written years or decades earlier.. Unchartered Territory: While the government body responsible for enforcing the HIPAA regulations, the Office of Civil Rights in the U.S. Department of Health and Human Services, has published the requirements for HIPAA compliance, it has left it to the discretion of healthcare providers to determine how best to meet those requirements.. Overburdened IT departments and help desks: As the number of internal and external applications grows, so does the number of passwords that employees must remember. Every time an employee forgets a password, IT departments and help desks, already strained from budget cuts and reduced staffing, must devote time and resources to resolving the problem. At the same time, user frustration intensifies, and productivity drops.. Cost: Many healthcare IT organizations lack the funding to undertake any HIPAA-related projects that would require large capital outlays. . Time: Development and deployment of enterprise-wide access control mechanisms can often require months or years of effort, thus precluding the possibility of organizations meeting the April 2005 compliance deadline.. User cooperation: Many access control methods, such as strong password policies, can put much of the burden of compliance on application users by requiring them to memorize multiple complex passwords and change them frequently. Institutions are likely to encounter increased help desk calls regarding forgotten passwords, as well as resistance from physicians and hospital staff if the user requirements of HIPAA compliance are perceived as too onerous.
Copyright ® 2005 Imprivata, Inc.The Value of Enterprise SSO to HIPPA Compliance 3
To compound these challenges, a number of vendors have made false or exaggerated claims thattheir software solutions are "HIPAA-c... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search