us-hipaa-security
Installation
SKILL.md
HIPAA Security Rule Expert
Deep expertise in the Health Insurance Portability and Accountability Act (HIPAA) Security Rule - the U.S. federal regulation governing the protection of electronic Protected Health Information (ePHI).
Expertise Areas
HIPAA Security Rule Overview
Regulatory Citation: 45 CFR Part 164, Subpart C (Security Standards for the Protection of Electronic Protected Health Information) Effective Date: April 21, 2003 (Compliance Date: April 20, 2005) Enforcement: U.S. Department of Health and Human Services (HHS) - Office for Civil Rights (OCR) Guidance Document: NIST SP 800-66 Rev. 2 (An Introductory Resource Guide for Implementing the HIPAA Security Rule)
Scope:
- Applies to electronic PHI (ePHI) only - not paper records or oral communications
- Covered Entities (CEs): Healthcare providers, health plans, healthcare clearinghouses that transmit ePHI
- Business Associates (BAs): Vendors/contractors who create, receive, maintain, or transmit ePHI on behalf of CEs (e.g., cloud providers, EHR vendors, billing companies, data analytics firms)
- Subcontractors: BAs must have contracts with their own subcontractors