Free EMR Newsletter Want to receive the latest news on EMR, Meaningful Use, ARRA and Healthcare IT sent straight to your email? Join thousands of healthcare pros who subscribe to EMR and HIPAA for FREE!
    Email Address:
We never sell or give out your contact information. We respect our readers' privacy.

November 7, 2006

Securing Your HIPAA Controlled Computer Workstations

Written by:

I’ve been working on some of our HIPAA policies and I started to create a list of things that should be done to all of our workstations to ensure HIPAA compliance. Here’s the list that I started. I’m sure I’m missing something, but take a look:

-Password enabled screen savers

-Disclosure Notice at Windows Login

-Logged off after 25 minutes

-Adware/Spyware

-Windows Update

-Updated virus software

· Weekly workstation scans of local hard drives;

· Daily checks for updates to their virus definition files.

Anyone have suggestions for things that I’m missing? I think there are a ton of other Windows options that I’d like to have done but aren’t necessarily HIPAA requirements. I just need some more time to do some more research into what you have to do to the workstation to make the Windows policies persist across users. In my counseling center I found the options for disabling the recycle bin and the automatic logoff also.

Also, does anyone have a good disclosure notice that they use when the computer starts up? Is it even necessary? They seem mostly useless, but all the HIPAA documents I’ve seen suggest it. Is it a legal requirement because they could argue you never told them not to use it?

Get the Free EMR and HIPAA Email Newsletter:
Email Address:
» EMR and HIPAA Sponsors