HHS Signals Continued Focus on Health Plan Privacy and Cybersecurity
Privacy and security are enforcement priorities for government regulators following HHS's restructuring of its Office for Civil Rights.
Questions about your benefits? Contact your HR administrator.
First introduced in 2014 and recently updated in 2023, the SRA Tool is a free, downloadable desktop application designed to assist organizations in conducting comprehensive...
First introduced in 2014 and recently updated in 2023, the SRA Tool is a free, downloadable desktop application designed to assist organizations in conducting comprehensive security risk assessments. These assessments are a core requirement under the HIPAA Security Rule, which mandates safeguarding electronic protected health information (ePHI).
The tool focuses on critical aspects of security, including:
Importantly, the SRA Tool operates offline, storing input securely on the user’s computer. This ensures that no data is transmitted to HHS or any external entity, offering complete confidentiality for users.
The SRA Tool is primarily tailored for small and medium-sized healthcare providers. However, its associated User Guide emphasizes that health plans and business associates are also required to conduct risk analyses and implement safeguards to protect ePHI. These safeguards span technical, physical, and administrative measures, all of which are covered comprehensively by the tool and therefore can be used by these organizations also.
The SRA Tool walks users through a structured series of multiple-choice questions. Based on the responses, the tool identifies areas where corrective actions may be necessary to align with the HIPAA Security Rule.
The assessment process is divided into seven sections:
The latest version of the tool introduces new and enhanced questions, improved guidance, and references to the NIST Cybersecurity Framework 2.0. Additional content highlights strategies for mitigating organizational threats, addressing vulnerabilities, and managing cybersecurity risks within the supply chain.
HHS highlights the growing prevalence of hacking and ransomware breaches as a key motivator for updating the tool. These enhancements align with the agency’s ongoing efforts to bolster cybersecurity and ensure compliance with HIPAA standards. By improving their cybersecurity posture, covered entities and business associates can better safeguard the confidentiality, integrity, and availability of ePHI.
The updated SRA Tool is a valuable resource for groups seeking to navigate the complexities of HIPAA compliance. By systematically addressing vulnerabilities and implementing robust safeguards, organizations can protect their data, mitigate risks, and avoid costly breaches.
To access the latest version of the SRA Tool and its accompanying resources, visit HealthIT.gov.
Benefit Allocation Systems (BAS) provides online solutions for: Employee Benefits Enrollment; COBRA; Flexible Spending Accounts (FSAs); Health Reimbursement Accounts (HRAs); Leave of Absence Premium Billing (LOA); Affordable Care Act Record Keeping, Compliance & IRS Reporting (ACA); Group Insurance Premium Billing; Property & Casualty Premium Billing; and Payroll Integration.
MyEnroll360 integrates with major insurance carriers for enrollment eligibility management (e.g., Blue Cross, Blue Shield, Aetna, United Health Care, Kaiser, CIGNA and others), and with leading payroll platforms for enrollment deduction management (e.g., Workday, ADP, Paylocity, PayCor, UKG, and others).
This article is for informational purposes only and is not intended as legal, tax, or benefits advice. Readers should not rely on this information for taking (or not taking) any action relating to employment, compliance, or benefits. Always consult with a qualified professional before making decisions based on this content.