Integrity of e-PHI Procedures, v1.0

Specifies that a health care related organization must implement procedures to protect electronic protected health information from improper alteration or destruction and must implement electronic mechanisms to corroborate that electronic protected health information has not been altered or destroyed in an unauthorized manner.

Assessment Step

1
Procedures to Protect e-PHI from Alteration or Destruction (ProcedurestoProtecte-PHIfromAlterationorDestruction)
Does the covered entity or business associate implement procedures to protect electronic protected health information from improper alteration or destruction? Implement electronic mechanisms to corroborate that electronic protected health information has not been altered or destroyed in an unauthorized manner?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

Procedures to Protect e-PHI from Alteration or Destruction
The covered entity or business associate must implement procedures to protect electronic protected health information from improper alteration or destruction and must implement electronic mechanisms to corroborate that electronic protected health information has not been altered or destroyed in an unauthorized manner.
Citations
HIPAA-Security-Rule
45 CFR Section 164.312(c)(1)
HIPAA-Security-Rule
45 CFR Section 164.306