Keep 4 Categories in Mind for HIPAA Security Issues
Question: We know that any issues that don’t comply with HIPAA regulations are serious, but are there official ways to categorize them?
North Dakota Subscriber
Answer: When a security incident occurs, your best first step is to determine its potential impact. They generally fall into one of four categories:
“All critical incidents must be investigated and documented as incidents,” says Jim Sheldon-Dean, principal and director of compliance services for Lewis Creek Systems, LLC, based in Charlotte, Vt. Moderate or minor incidents require minimal investigation and documentation as incidents, Sheldon-Dean says, “but will receive full investigation and documentation if it is deemed that the incident is unusual and can be learned from so that similar incidents may be prevented in the future.”
You don’t need to conduct a detailed investigation and complete thorough documentation of a suspicious activity. Just remember that you might have to elevate it to a higher level category, depending on the incident specifics.
