Product Security
HIPAA Rule
Product Security
|
What is Product Security?
|
|
Product Security is a combination of technical product features, administrative policies, and physical safeguards used to ensure safe and effective use of medical devices as well as to ensure the confidentiality, availability, and integrity of the information created, maintained, and transmitted by medical devices.
|
|
|
Back to top
|
|
Can customers download security patches or third-party software to their Philips devices?
|
|
ONLY Philips-authorized changes may be made to Philips Healthcare products, either by Philips personnel, or under Philips explicit, published direction. Philips subjects all patches and software to rigorous testing to ensure patient and operator safety standards are not compromised before authorizing any software - including anti-virus software - or patches for download, by either its customers or authorized Philips personnel. Unauthorized alteration of any medical device, including downloading non-validated or unauthorized patches, may void or breach existing service agreements and warranties. For additional information, contact your Philips service representative.
|
|
|
Back to top
|
|
What is a security breach?
|
|
A security breach is one or both of the following: - Philips software, or data that is managed by a Philips Healthcare product, is suspected of being maliciously altered, misused, or lost, including viruses, worms, hackers, etc.
- A Philips system or component has a customer-reported security vulnerability or breach that could result in alteration, misuse, or loss of patient data.
Generally, an event begins as a security breach that is then examined by a security expert to determine if this event is an applicable vulnerability or an actual breach of a product's confidentiality, integrity, or availability. The terms security breach, security event, and security incident can be used interchangeably. If you suspect a security breach, contact your local Philips Field Service representative as soon as possible.
|
|
|
Back to top
|
HIPAA Rule
|
What is HIPAA?
|
|
HIPAA is a US legislative part of product security that stands for the Health Insurance Portability and Accountability Act. The Act was designed to protect the privacy and security of an individual’s healthcare information against unauthorized access.
|
|
|
Back to top
|
|
What is the Electronic Transactions & Code Sets Rule?
|
|
The Electronic Transactions and Code Sets Rule (TCS) established a standardized format for exchanging electronic data between Covered Entities to improve efficiency in the healthcare industry.
|
|
|
Back to top
|
|
What is the HIPAA Privacy Rule?
|
|
The HIPAA Privacy Rule created standards and requirements specific to procedural policies that Covered Entities must follow to ensure the privacy of PHI, such as: - Notifying patients about their privacy rights and how their information can be used.
- Adopting and implementing privacy procedures.
- Training employees to understand privacy procedures.
- Securing patient records.
|
|
|
Back to top
|
|
What is the HIPAA Security Rule?
|
|
The Security Rule was developed specific to technical procedures so Covered Entities would ensure the confidentiality, integrity, and availability of all electronic PHI they create, maintain, receive, or transmit. To meet these requirements, Covered Entities must implement administrative, physical, and technical safeguards. This Rule applies only to information in electronic form.
|
|
|
Back to top
|
|
What is a Covered Entity?
|
|
Covered Entities are organizations subject to the HIPAA Privacy Rule. They are: Health Plans, Healthcare Providers, and Healthcare Clearinghouses. Covered Entities are allowed to disclose PHI to other organizations or individuals to perform functions on their behalf.
|
|
|
Back to top
|
|
What is a Business Associate?
|
|
Under the HIPAA rules, Business Associates are defined as companies or persons contracted to perform certain functions on behalf of Covered Entities involving the use or disclosure of PHI.
|
|
|
Back to top
|
|
Is Philips a Business Associate?
|
|
At times, Philips could be considered a Business Associate. Service and support activities of a medical device manufacturer, such as Philips Healthcare, may create a Business Associate relationship and may require a Business Associate Agreement as determined by a Covered Entity.
|
|
|
Back to top
|
|
What is PHI?
|
|
PHI, protected health information, refers to any individually identifiable health information, including demographic data, that is transmitted or maintained in electronic form, or in any other form or medium.
|
|
|
Back to top
|
|
What is ePHI?
|
|
Electronic, protected health information.
|
|
|
Back to top
|
|
|
|