all-in-one privacy solution":["Proton Unlimited ist eine All-in-One-Datenschutzlösung"],"Black Friday":["Black Friday"],"No ads. Privacy by default.":["Keine Werbung. Privatsphäre als Standard."],"People before profits":["Menschen sind uns wichtiger als Gewinne"],"Security through transparency":["Sicherheit durch Transparenz"],"The best Proton Mail ${ BLACK_FRIDAY } deals":["Die besten Proton Mail-Angebote zum ${ BLACK_FRIDAY }"],"The world’s only community- supported email service":["Der weltweit einzige von der Community unterstützte E-Mail-Dienst"]},"specialoffer:limited":{"${ hours } hour":["${ hours } Stunde","${ hours } Stunden"],"${ hoursLeft }, ${ minutesLeft } and ${ secondsLeft } left":["Nur noch ${ hoursLeft }, ${ minutesLeft } und ${ secondsLeft }"],"${ minutes } minute":["${ minutes } Minute","${ minutes } Minuten"],"${ seconds } second":["${ seconds } Sekunde","${ seconds } Sekunden"],"Limited time offer":["Zeitlich befristetes Angebot"]},"specialoffer:listitem":{"Create multiple addresses":["Erstelle mehrere Adressen"],"Hide-my-email aliases":["Hide-my-email-Aliase"],"Quickly unsubscribe from newsletters":["Newsletter schnell abbestellen"],"Use your own domain name":["Verwende deine eigene Domain"]},"specialoffer:logos":{"As featured in":["Vorgestellt in"]},"specialoffer:metadescription":{"Get an encrypted email that protects your privacy":["Nutze einen verschlüsselte E-Mail-Dienst, der deine Privatsphäre schützt"]},"specialoffer:metatitle":{"Proton Mail Black Friday Sale - Up to 40% off":["Proton Mail Black Friday-Angebot – Bis zu 40 % Rabatt"]},"specialoffer:newmetadescription":{"Get up to 40% off Proton Mail subscriptions this Black Friday. Find great deals on our secure end-to-end encrypted email plans.":["Erhalte an diesem Black Friday bis zu 40 % Rabatt auf Proton Mail-Abonnements. Mache tolle Schnäppchen bei unseren sicheren, Ende-zu-Ende-verschlüsselten E-Mail-Abonnements."]},"specialoffer:newmetatitle":{"Proton Mail Black Friday sale | Up to 40% off secure email":["Proton Mail-Black-Friday-Angebot | Bis zu 40 % Rabatt auf sichere E-Mails"]},"specialoffer:note":{"* Billed at ${ TOTAL_SUM } for the first year":["* Zum Preis von ${ TOTAL_SUM } im ersten Jahr"],"*Billed at ${ TOTAL_SUM } for the first 2 years":["*Zum Preis von ${ TOTAL_SUM } in den ersten zwei Jahren"],"30-day money-back guarantee":["30-tägige Geld-zurück-Garantie"],"Billed at ${ TOTAL_SUM } for the first 2 years":["Zum Preis von ${ TOTAL_SUM } in den ersten zwei Jahren"],"Billed at ${ TOTAL_SUM } for the first year":["Zum Preis von ${ TOTAL_SUM } im ersten Jahr"],"You save ${ SAVE_SUM }":["Du sparst ${ SAVE_SUM }"]},"specialoffer:off":{"${ PERCENT_OFF } off":["− ${ PERCENT_OFF }"]},"specialoffer:testimonial":{"I love my ProtonMail":["Ich liebe mein ProtonMail"],"My favorite email service":["Mein Lieblings-E-Mail-Dienst"],"Thanks Proton for keeping us all safe in the complicated internet universe.":["Danke Proton, dass du uns alle im komplizierten Internet-Universum beschützt."],"You get what you pay for. In the case of big tech, if you pay nothing, you get used. I quit using Gmail and switched to @ProtonMail":["Du bekommst, wofür du bezahlst. Wenn du nichts bezahlst, wirst du bei der Nutzung von Big Tech ausgenutzt. Ich habe Gmail aufgegeben und bin zu @ProtonMail gewechselt"]},"specialoffer:time":{"Days":["Tage"],"Hours":["Stunden"],"Min":["Min."]},"specialoffer:title":{"And much more":["Und vieles mehr"],"Safe from trackers":["Sicher vor Trackern"],"Stay organized":["Ordnung halten"],"Black Friday email deals":["E-Mail-Angebote zum Black Friday"],"Don’t just take our word for it":["Verlasse dich nicht nur auf unser Wort"],"Make your inbox yours":["Passe deinen Posteingang an"],"Our story":["Unsere Geschichte"],"Transfer your data from Google in one click":["Übertrage deine Daten von Google mit einem Klick"]},"specialoffer:tooltip":{"Access blocked content and browse privately. Includes ${ TOTAL_VPN_SERVERS }+ servers in ${ TOTAL_VPN_COUNTRIES }+ countries, connect up to 10 devices, access worldwide streaming services, malware and ad-blocker, and more.":["Greife auf blockierte Inhalte zu und surfe privat. Umfasst ${ TOTAL_VPN_SERVERS } Server in über ${ TOTAL_VPN_COUNTRIES } Ländern, die Verbindung \nvon bis zu 10 Geräten, weltweite Streaming-Dienste, Malware- und Werbeblocker und mehr."],"Easily share your calendar with your family, friends or colleagues, and view external calendars.":["Teile deinen Kalender ganz einfach mit Verwandten, Freunden oder Kollegen und rufe externe Kalender auf."],"Includes support for 1 custom email domain, 10 email addresses, 10 hide-my-email aliases, calendar sharing, and more.":["Beinhaltet Unterstützung für eine eigene E-Mail-Domain, 10 E-Mail-Adressen, 10 „hide-my-email“-Aliasse, Kalenderfreigabe und mehr."],"Includes support for 3 custom email domains, 15 email addresses, unlimited hide-my-email aliases, calendar sharing, and more.":["Beinhaltet Unterstützung für 3 benutzerdefinierte E-Mail-Domänen, 15 E-Mail-Adressen, unbegrenzte „hide-my-email“-Aliase, Kalenderfreigabe und mehr."],"Manage up to 25 calendars, mobile apps, secured with end-to-end encryption, 1-click calendar import from Google, and more.":["Verwalte bis zu 25 Kalender, Ende zu Ende verschlüsselte mobile Apps, 1-Klick-Kalenderimporte von Google und vieles mehr."]},"Status banner":{"Learn more":["Mehr erfahren"],"Please note that at the moment we are experiencing issues with the ${ issues[0] } service.":["Bitte beachte, dass wir im Moment Probleme mit dem Dienst ${ issues[0] } haben."],"We are experiencing issues with one or more services at the moment.":["Im Moment gibt es Probleme mit einem oder mehreren Diensten."]},"Status Banner":{"At the moment we are experiencing issues with the Proton VPN service":["Im Moment gibt es Probleme mit dem Proton VPN-Dienst"],"Learn more":["Mehr erfahren"]},"steps":{"Step":["Schritt"]},"suggestions":{"Suggestions":["Vorschläge"]},"Support":{"Sub category":["Unterkategorie","Unterkategorien"]},"Support article":{"${ readingTime } min":["${ readingTime } Min.","${ readingTime } Min."],"Category":["Kategorie","Kategorien"],"Didn’t find what you were looking for?":["Hast du nicht gefunden, wonach du gesucht hast?"],"General contact":["Allgemeiner Kontakt"],"Get help":["Hilfe erhalten"],"Legal contact":["Kontakt für Rechtliches"],"Media contact":["Kontakt für Medien"],"Partnerships contact":["Kontakt für Partnerschaften"],"Reading":["Lesen"]},"Support Form Platform option":{"VPN for Android TV":["VPN für Android TV"],"VPN for Apple TV":["VPN für Apple TV"],"VPN for Chromebook":["VPN für Chromebook"]},"Support troubleshooting":{"App version":["App-Version"],"Browser":["Browser"],"Check if this helps":["Schau, ob das hilft."],"Choose a product":["Produkt auswählen"],"Did this solve your issue?":["Hat dies dein Problem gelöst?"],"Faster assistance is just a few clicks away":["Schnellere Hilfe ist nur ein paar Klicks entfernt"],"How can we help?":["Wie können wir dir helfen?"],"No, contact support":["Nein, Support kontaktieren"],"Please fill out one field after another":["Bitte fülle ein Feld nach dem anderen aus"],"Please make your selections":["Bitte triff deine Auswahl"],"Proton account":["Proton-Konto"],"Proton for Business":["Proton for Business"],"Thank you for your feedback":["Danke für dein Feedback"],"What can we help with?":["Wobei können wir dir helfen?"],"Yes":["Ja"]},"support_modal_search_query":{"Search query":["Anfrage suchen"]},"support_search_button":{"Search":["Suchen"]},"support_search_i_am_looking_for":{"I'm looking for":["Ich suche"]},"SupportForm":{"For a faster resolution, please report the issue from the Bridge app: Help > Report a problem.":["Damit das Problem schneller gelöst werden kann, melde es bitte über die Bridge-App: Help > Report a problem (Hilfe > Problem melden)."],"Information":["Informationen"]},"SupportForm:option":{"Account Security":["Kontosicherheit"],"Contacts":["Kontakte"],"Custom email domain":["Benutzerdefinierte E-Mail-Domain"],"Email delivery and Spam":["E-Mail-Zustellung und Spam"],"Encryption":["Verschlüsselung"],"Login and password":["Anmeldung und Passwort"],"Merge aliases and accounts":["Zusammenführung von Aliassen und Konten"],"Migrate to Proton":["Migration zu Proton"],"Notifications":["Benachrichtigungen"],"Other":["Sonstiges"],"Plans and billing":["Abonnements und Abrechnung"],"Proton for Business":["Proton for Business"],"Sign up":["Registrierung"],"Storage":["Speicher"],"Users, addresses, and identities":["Benutzer, Adressen und Identitäten"]},"SupportForm:optionIntro":{"Select a topic":["Thema auswählen"]},"Testimonial":{"Awards":["Auszeichnungen"],"Customers":["Kunden"],"Featured":["Empfohlen"],"Go to testimonial source":["Zur Referenzquelle wechseln"],"Open source of award":["Quelle der Auszeichnung öffnen"],"Open source of quote":["Quelle des Zitats öffnen"],"Reviews":["Bewertungen"],"Videos":["Videos"],"Watch on TikTok":["Auf TikTok ansehen"],"Watch on YouTube":["Auf YouTube ansehen"]},"TestimonialCategory":{"Awards":["Auszeichnungen"],"Customers":["Kunden"],"Featured":["Empfohlen"],"Media":["Medien"],"Reviews":["Bewertungen"],"Videos":["Videos"]},"Text":{"If you need help, check out our ${ supportLink }.":["Hilfe erhältst du in unserem ${ supportLink }."],"The page you’re looking for might have been removed, or it could be an\nold link.":["Die von dir gesuchte Seite wurde möglicherweise entfernt, oder es könnte sich um einen alten Link handeln."],"Your question may already have an answer in our knowledge base:":["Vielleicht gibt es bereits eine Antwort auf deine Frage in unserer Wissensdatenbank:"]},"Title":{"On this page":["Auf dieser Seite"],"Related articles":["Verwandte Artikel"],"Share ${ thisPage }":["${ thisPage } teilen"],"Switch to Proton Pass - Contact us":["Zu Proton Pass wechseln – Kontaktiere uns"],"Thank you!":["Vielen Dank!"],"this page":["diese Seite"]},"tooltip_vpn":{"Access blocked content and browse privately. Includes ${ TOTAL_VPN_SERVERS }+ servers in ${ TOTAL_VPN_COUNTRIES }+ countries, highest VPN speed, ${ TOTAL_VPN_CONNECTIONS } VPN connections, worldwide streaming services, malware and ad-blocker, and more.":["Greife auf blockierte Inhalte zu und surfe privat. Enthält über ${ TOTAL_VPN_SERVERS } Server in mehr als ${ TOTAL_VPN_COUNTRIES } Ländern, höchste VPN-Geschwindigkeiten, ${ TOTAL_VPN_CONNECTIONS } VPN-Verbindungen, weltweite Streaming-Dienste, Malware- und Werbeblocker und mehr."]},"vpn_servers":{"Get Proton VPN Plus":["Proton VPN Plus holen"]},"wallet_signup_2024:Action":{"Get Proton Wallet":["Hol dir Proton Wallet"]},"wallet_signup_2024:Homepage hero product link title":{"Wallet":["Wallet"]},"wallet_signup_2024:Homepage product navigation bar":{"Wallet":["Wallet"]},"wallet_signup_2024:menu item":{"Bitcoin guide":["Bitcoin-Leitfaden"],"Proton Wallet news":["Proton Wallet-Neuigkeiten"],"Proton Wallet support":["Proton Wallet-Support"]},"wallet_signup_2024:Pricing":{"Includes everything in Proton Unlimited and":["Umfasst alles, was in Proton Unlimited enthalten ist und"],"Limited availability":["Begrenzte Verfügbarkeit"],"The easiest way to securely own, send, and receive Bitcoin":["Der einfachste Weg, Bitcoin sicher aufzubewahren, zu senden und zu empfangen"]},"wallet_signup_2024:ProductRange":{"Discover Proton Wallet":["Proton Wallet entdecken"],"Store and transact Bitcoin privately with an encrypted self-custody wallet.":["Bewahre Bitcoins auf und überweise sie auf private Weise mit einer verschlüsselten, selbstverwahrenden Wallet."]},"wallet_signup_2024:wallet bitcoin":{"Learn about Bitcoin, the Internet's value network.":["Erfahre mehr über Bitcoin, das Wertnetzwerk des Internets."]},"wallet_signup_2024:wallet overview":{"Ensure you're always in control of your Bitcoin.":["Stelle sicher, dass du immer die Kontrolle über deine Bitcoins behältst."]},"wallet_signup_2024:wallet security":{"The encrypted, open-source wallet that puts you in control.":["Die verschlüsselte Open-Source-Wallet, die dir die Kontrolle gibt."]}}},"base":"blog","cdn":{"enabledForAssets":true,"enabledForImages":true,"url":"https://pmecdn.protonweb.com/"},"unleashApi":"https://account.proton.me/api"};
window.frameworkContext = frameworkContext;
const context = frameworkContext.base === '' ? '' : `${frameworkContext.base}/`;
window.__toAssetUrl = (filename) => {
if (frameworkContext.cdn !== undefined && frameworkContext.cdn.enabledForAssets === true) {
return `${frameworkContext.cdn.url}${context}${filename}`;
} else {
return `/${context}${filename}`;
}
};
})();
HIPAA compliance checklist guide for 2022 | Proton
As discussed in our article on HIPAA Compliance, the Health Insurance Portability and Accountability Act (HIPAA) is a collection of closely aligned regulations that protect the medical data of patients in the United States.
In that article, we also discuss who must be HIPAA compliant — covered entities and business associates — which basically means anyone with any access to patients’ protected health information (PHI). Failures in HIPAA compliance are known as HIPAA violations(neues Fenster), and can result in stiff fines.
This article explains the most important measures and best practices that covered entities and business associates must address in order to be HIPAA compliant.
The HSS Office of Inspector General (OIG) offers a Compliance Resource Portal(neues Fenster) that establishes the “seven fundamental elements of an effective compliance program.” These elements are:
Standards, Policies, and Procedures
Compliance Program Administration
Screening and Evaluation of Employees, Physicians, Vendors, and other Agents
Communication, Education, and Training on Compliance Issues
Monitoring, Auditing, and Internal Reporting Systems
Discipline for Non‐Compliance
Investigations and Remedial Measures
A HIPAA compliance checklist
In practical terms, the key measures that must be implemented by all covered entities and business associates that wish to be (and remain) HIPAA compliant can be summarized as:
1. Develop robust standards, policies, and procedures
Covered entities and business associates must develop administrative systems and practices that ensure they meet the HIPAA compliance Rules (discussed here). Staff must be fully and routinely trained in all such standards, policies, and procedures, and are required to attest that they have received this training.
2. Implement strong physical and technical safeguards
In order to be HIPAA compliant, entities must ensure that all data relating to PHI is secure. This includes implementing:
Technical safeguards — such as restricting access to EPHI to authorized personnel only, requiring authorized personnel to verify their identity using unique identification methods (such as physical login tokens), monitoring hardware and software access logs for irregular activity, using strong encryption, implementing auto-logout, clearly specifying emergency access procedures, and using a HIPAA-compliant email(neues Fenster) service.
Physical safeguards — restrictions on who can physically access buildings, offices, and facilities, restrictions on who has access to workstations and electronic media, and procedures for disposing of or otherwise moving workstations and electronic media (such as old hard drives).
3. Perform an annual HIPAA risk assessment
According to the HIPAA Security Rule(neues Fenster), “risk analysis should be an ongoing process, in which a covered entity regularly reviews its records to track access to e-PHI and detect security incidents, periodically evaluates the effectiveness of security measures put in place, and regularly reevaluates potential risks to e-PHI.”
In order to comply with this requirement, HIPAA compliant entities are strongly advised to perform an annual audit to identify problems or gaps in their implementation of the security standards specified in the Security and Privacy Rules. These audits should therefore cover all administrative, physical security, and technical security measures deployed by the company in order to achieve HIPAA compliance.
4. Report data breaches
HIPAA-compliant entities must develop procedures outlining the measures to be taken in the event of a data breach. These include procedures for notifying customers, the HSS OCR, and any other entities required in accordance with the Breach Notification Rule.
5. Investigate violations and implement remedial measures
If a HIPAA violation occurs for any reason (including any violation identified during the annual self-audit) then it must be fully investigated, and a remedial plan developed and then implemented to correct the problem and bring the covered entity or business associate back in line with HIPAA regulations.
6. Document everything
Covered entities and business associates should document everything related to HIPAA compliance. This includes:
All measures taken to become HIPAA compliant.
All contact with other covered entities and business associates that they share PHI with.
All HIPAA violations that occur, plus all measures taken to remedy and report such incidents.
Failure to keep extensive documentation of all matters relating to HIPAA compliance is likely to result in a company failing the HSS OCR audit(neues Fenster) requirements.
A second phase was conducted in 2016, and in 2017 the OCR announced phase 3: on-site audits. This is a major expansion of the audit program and means that the OCR can now show up unannounced to view evidence that an individual or organization is HIPAA compliant.
The main purpose of maintaining a HIPAA compliance checklist could therefore be seen as providing proof of HIPAA compliance in the event of OCR audit. It is in everyone’s interest that covered entities and business associates work hard to maintain HIPAA compliance, however, regardless of whether an OCR audit is performed or not.
Audit Protocol
In order to help entities create checklists that meet HIPAA standards, the OCR has published an Audit Protocol(neues Fenster) which explains all areas that may be assessed during an OCR audit.
The audit protocol lists the different audit types (privacy, security, or breach), and identifies “key activities” that entities must comply with to be deemed HIPAA compliant. The “established performance criteria” needed to meet these standards are explained in detail.
HIPAA checklist FAQ
What is required for HIPAA compliance?
HIPAA compliant entities must appoint a HIPAA Privacy Officer and a HIPAA Security Officer to oversee HIPAA compliance. These can be existing staff members or outside contactors.
Their responsibility is to run risk assessments on the privacy and security systems and standards used by your company to protect PHI. The key areas that must be examined are:
The working practices of all staff members
Physical security measures in place to prevent unauthorized access to PHI
Electronic security measures in place to prevent unauthorized access to PHI
How your company will respond if a HIPAA violation or data breach occurs
Once risks have been identified, effective measures should be put into place to address them. The HIPAA Audit Protocol makes it clear that the OCR values evidence that self-audits are updated on a regular basis to account for changes within the entity, and for changes in the wider privacy and security landscape.
How do you do a HIPAA compliance checklist?
Your HIPAA Privacy and Security Officers should document all the key areas they have examined for potential risks. If existing safeguards are deemed sufficient to address these risks then this should be documented, or if additional safeguards are required then this, along with evidence of implementing the safeguards, should also be documented.
Detailed plans should be made and documented about what to do in the event of a HIPAA violation or data breach, with clear lines of responsibility established for actions that will be taken.
How do I know my documentation is sufficient to pass a HIPAA audit?
The Audit Protocol, which is published on the HSS website, should help identify all areas that your HIPAA compliance checklist should cover. If you are not confident in your entity’s ability to produce sufficient documentation, then there are many companies that offer professional help with HIPAA compliance.
What are desk audits and physical audits?
Desk audits are remote audits, where covered entities and business associates are asked to submit their documentation via the OCR’s secure web portal. Physical audits involve the OCR turning up at your workplace to inspect your HIPAA compliance provisions. They are often made in response to a lack of cooperation when an entity is asked to submit a desk audit, but also include the impromptu phase 3 on-site audits discussed above.
What happens if you fail a HIPAA audit?
If minor issues are found during a desk audit then you will be notified by the HSS. If minor issues are found during a physical audit then you may need to produce evidence of addressing them.
If major issues are found during any HSS audit then you may be subject to the penalties.
Do HIPAA audits only assess how EPHI is stored and transmitted?
No. Although HSA audits were introduced primarily to address an alarming rise in electronic data breaches, they assess all aspects of HIPAA compliance. This includes administrative practices, physical security measures, and planning for the possibility of data breaches, in addition to technical measures used to keep EPHI data safe.