The HIPAA law defines very specific procedures for workstation password management for an office to be HIPAA compliant.
For example, each employee is required to have their own login to workstations that give them access to electronic patient health information (ePHI). While it is possible for each member of the staff to have their own accounts on every PC they use, HIPAA also requires that password be changed as part of periodic security updates (§164.308(5)(ii)).
Implementing this policy presents a unique challenge in that if staff members use multiple computers, maintaining a password for each PC, even if they are the same, becomes difficult. As workstations are added and removed from the office, the password update cycle for each PC will change and it becomes hard to keep the login information synchronized between all the computers an employee uses.
Our solution to managing user passwords is to use a domain server, which gives your office a central place to administer user login information. Users are created once on the domain server with their own unique passwords that they can use to login to any of the office computers to which they have been given access. When a password needs changing, it is updated on the server and the change is propagated out to all the office workstations without any additional work.
User accounts can also be easily added and removed from the domain for new hires and those leaving the organization, respectively, without making any changes on individual PCs. In addition, a domain server fulfills other requirements of HIPAA such as log-in monitoring.
In addition to running a domain, a server can also host your practice management software and images, as well as shared documents that need to be accessed by multiple staff members. The added benefit for doing this is that there aren’t multiple copies of the same document, which can sometimes create confusion as to which is the current version.
To discuss fulfilling the password management requirement of HIPAA and gain the other benefits of getting a domain server for your office, please give us a call at 707-523-5915.