Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 37 guests and 1 member online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Compliance, Regulations & Standardsarrow HIPAA Security Training
EH-Net
May 21, 2013, 06:43:39 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: HIPAA Security Training  (Read 7955 times)
0 Members and 1 Guest are viewing this topic.
Dengar13
Sr. Member
****
Offline Offline

Posts: 380



View Profile
« on: June 18, 2010, 06:17:42 AM »

OK folks, here is my dilemma:  we have a requirement to have employees take a HIPAA security test for HIPAA training and am not sure how it applies to temporary employees.   One scenario that was brought to me was what if there is a temporary employee who works for one day, a couple of days or one week; do they need to take this training?  HIPAA guidelines are not very clear and concise in my opinion. 

I just want to make sure that we are covered and fulfill the HIPAA requirements for security training.  Has anyone been in this situation before?

Thanks all!
Logged

A+, Net+, MCP, CEH
MCSE: Security/Messaging
MCSA: Security/Messaging
Former U.S. Marine and damn proud of it!
ziggy_567
Sr. Member
****
Offline Offline

Posts: 361


View Profile
« Reply #1 on: June 18, 2010, 09:49:16 AM »

I don't know if it is applicable to the private sector, but when I was  in the National Guard, the only people that had to be HIPAA certified were the one handling HIPAA protected information. We basically had only senior enlisted and officers go through the training.

Logged

--
Ziggy


eCPPT - GSEC - GCIH - GCUX - RHCE - SCSecA - Security+ - Network+
yatz
Full Member
***
Offline Offline

Posts: 222


View Profile WWW
« Reply #2 on: June 18, 2010, 10:20:08 AM »

My company does HIPAA-related stuff but I've never had to be certified for anything.  Maybe this is something that needs investigating...
Logged

"Live as though you would die tomorrow, learn as though you would live forever."

CCNA, MCSA, MCTS, Sec+, Net+, Linux+, CEH
vekarman
Newbie
*
Online Online

Posts: 28



View Profile
« Reply #3 on: June 21, 2010, 09:01:32 AM »

I have also not heard of any HIPAA training. But following are my views on such trainings.

All regulations like HIPAA, SarbOx, PCI-DSS etc are based on Best Practices in relevant industries. You can organize a formal training about user awareness for the employees who are handling and processing HIPAA records and infrastructure also. I understand majority of the people in a company who are HIPAA compliant will be desktop operators who are accessing HIPAA records. They should be trained about the best practices like password protection, clear screen policy etc.. You might be having some IT infra people who are maintaining hardware and network processing HIPAA records. They should be trained about the security of the hardware and network from leaking of HIPAA records. Application developers need to be trained about incorporating security into applications which process HIPAA records. and so on...

You have to segregate people in various groups based on their job roles and train them on best practices.

Few cents from me.

Kishore
Logged

CISSP
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #4 on: June 22, 2010, 01:21:32 PM »

Look into:

http://www.hipaaacademy.net/

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
tux633k
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #5 on: June 30, 2010, 07:11:37 PM »

The keywords when it comes to HIPAA is reasonable and appropriate.  If it is not reasonable to train a temporary employee that only stays with you for one day then training shouldn't be a requirement for those employees.

When an employee is given the test is there an acknowledgment form that is signed by them and returned to HR or the security office?  You may want to consider creating a 1 page document that simply covers Compliance, Security and Privacy in very general terms (Ex. employees should not... based on XYZ Policy) and have temp employees read and sign that form for documentation purposes so that you can prove that you are doing your due diligence if it came to that.
Logged

CEH, MCP, CSCS, CHP
Compliance
Newbie
*
Offline Offline

Posts: 2


View Profile
« Reply #6 on: July 06, 2010, 03:00:24 AM »

HIPAA requires employees to be trained based on their job role. Even if you employee is temporary employee. Based on the job role of the person, you will ask them to take necessary training. If you want them to take the basic training, you can ask them to do the Certified HIPAA Privacy Associate (CHPA) training http://hipaatraining.net/hipaa-certification/certified-hipaa-privacy-associate-chpa.htm  which includes HIPAA security overview. If you want them to have comprehensive HIPAA security training then you want them to go through the Certified HIPAA Security Expert (CHSE) http://hipaatraining.net/hipaa-certification/certified-hipaa-Security-Expert-chse.htm 

All consultants or companies providing temp staff are the business associate of covered entity. All BA have to comply with the HIPAA regulation. If you have temporary employee, they are still part of your organization and your organization will be responsible if there is HIPAA violation caused due to their action. The key is that the person has to be trained based on their job role.

If you are covered entity, download this questionnaire of  HIPAA compliance status of the business associates. This helps you to ensure that BA meets the HIPAA standards.  http://www.compliancehome.com/whitepapers/HIPAA/abstract11982.html

Feel free to ask if you have any other questions.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.083 seconds with 24 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.