Demo environment — fictional staff and data. Do not enter PHI.

Evelyn Marchetti-Sung

Quality Assurance Director · QCR-0057

Back to library
HIP-002HIPAA Security Rule Safeguardsv3.1EffectiveEffective Jan 12, 2026HIPAA Compliance
0% read Signed

1. Purpose

To establish the administrative, physical and technical safeguards that protect the confidentiality, integrity and availability of electronic protected health information at Quillbrook.

2. Scope

Applies to all workforce members and to every device, system, network, application and physical location that creates, receives, maintains or transmits electronic protected health information, including personally owned devices approved for work use.

3. Responsibilities

  • IT Director & HIPAA Security Officer: Owns the security programme, risk analysis, access control, audit log review and incident technical response.
  • HIPAA Privacy Officer: Coordinates privacy and security policy, training content and incident assessment.
  • Information Security Analyst: Monitors alerts, reviews audit logs, and maintains vulnerability and patch records.
  • All Workforce Members: Protect credentials and devices, use only approved systems, and report suspected incidents immediately.

4. Definitions

Electronic protected health information (ePHI)
Protected health information created, received, maintained or transmitted in electronic form.
Risk analysis
The documented assessment of potential risks and vulnerabilities to the confidentiality, integrity and availability of ePHI.
Business associate agreement (BAA)
The contract required before a vendor may create, receive, maintain or transmit PHI on behalf of the covered entity.
Automatic logoff
A technical control that terminates an electronic session after a predetermined period of inactivity.

5. Procedure

  1. Conduct and document an enterprise risk analysis at least annually and after any significant change in systems, facilities or services, and maintain a prioritised risk management plan.
  2. Maintain written security policies and procedures, review them annually, and retain them and all required documentation for at least six years from creation or last effective date.
  3. Assign every workforce member a unique user identification and authenticate with a strong password plus multi-factor authentication for all remote and administrative access; never share or reuse credentials.
  4. Apply role-based access with least privilege: grant access to ePHI only for the systems and records the person's role requires, on documented authorisation from the system owner.
  5. Review user access rights at least quarterly, remove unnecessary privileges, and terminate all access on the same business day a workforce member departs or changes role.
  6. Enforce automatic logoff after no more than fifteen minutes of inactivity on workstations and applications that access ePHI, and require a password-protected screen lock.
  7. Encrypt ePHI at rest on all laptops, desktops, servers, mobile devices and removable media using full-disk or file-level encryption, and prohibit storage of ePHI on unencrypted media.
  8. Encrypt ePHI in transit: use TLS for all application traffic, an encrypted email gateway or secure portal for any email containing PHI, and approved secure file transfer for data exchange; never use personal email or consumer cloud storage.
  9. Secure the physical environment: badge-controlled entry to areas holding ePHI, locked cabinets for paper records, visitor logging and escort, and a maintenance record for physical security repairs.
  10. Position and shield workstations so displays are not visible to visitors or subjects, use privacy filters in shared areas, lock screens whenever leaving a workstation, and never leave records unattended.
  11. Maintain an inventory of all hardware and media that store ePHI, track movement, and sanitise or destroy media before reuse or disposal using approved methods with documented certificates.
  12. Enable audit logging in every system holding ePHI, protect logs from alteration, retain them for at least six years, and review them at a documented frequency of at least monthly for inappropriate access.
  13. Maintain malware protection, centralised patch management with defined remediation timelines by severity, network segmentation and firewall rules, and document exceptions with compensating controls.
  14. Maintain a contingency plan including data backup, disaster recovery, emergency mode operation, and an applications and data criticality analysis, and test restoration at least annually.
  15. Execute a business associate agreement before any vendor, laboratory, courier, sponsor service provider or cloud platform creates, receives, maintains or transmits PHI on the site's behalf, and track expiry dates.
  16. Apply sanctions consistently for workforce members who violate security policy, document the sanction, and record it per the sanction policy.
  17. Complete security awareness training at hire and annually, including phishing recognition, and document completion per TRN-001.
  18. Report any suspected security incident to the HIPAA Security Officer immediately and process it under HIP-003.

6. References

  • 45 CFR Part 164, Subpart C — Security Standards for the Protection of ePHI
  • 45 CFR 164.308 — Administrative safeguards
  • 45 CFR 164.310 — Physical safeguards
  • 45 CFR 164.312 — Technical safeguards
  • 45 CFR 164.316 — Policies, procedures and documentation
  • 21 CFR Part 11 — Electronic Records; Electronic Signatures
  • HIP-003 Privacy & Security Incident Response and Breach Notification

7. Revision History

  • v2.0 · Oct 17, 2022 — Added multi-factor authentication and quarterly access reviews.
  • v3.0 · Nov 05, 2024 — Added patch management timelines and annual restoration testing.
  • v3.1 · Jan 12, 2026 — Clarified email encryption and workstation security requirements.

— End of document —

Document control
OwnerGideon Mbeki-Turner
ApproverAna Lucía Restrepo
EffectiveJan 12, 2026
Next reviewJan 12, 2027
Estimated read14 minutes
Applies toAll departments
My statusSigned
Signed this version (49)

Devan Ramaswamy

Read and understood · Aug 01, 2026, 09:57 AM UTC

Ingrid Halvorsen, MD

Read and understood · Sep 04, 2026, 02:57 PM UTC

Cornelius Abara, MD

Read and understood · Jul 29, 2026, 02:57 PM UTC

Rosalind Achterberg, DO

Read and understood · Sep 17, 2026, 10:57 AM UTC

Fatoumata Diallo, MD

Read and understood · Jul 12, 2026, 01:57 PM UTC

Noor Al-Rashidi, NP

Read and understood · Jul 20, 2026, 11:57 AM UTC

Beatrix Calloway

Read and understood · Jul 21, 2026, 09:57 AM UTC

Emeka Nwachukwu

Read and understood · Sep 27, 2026, 08:57 AM UTC

Sunniva Lindqvist, RN

Read and understood · Jul 20, 2026, 02:57 PM UTC

Rafael Quintanilla

Read and understood · Sep 15, 2026, 12:57 PM UTC

Meredith Sowande

Read and understood · Aug 27, 2026, 02:57 PM UTC

Jozef Kaminski

Read and understood · Sep 15, 2026, 02:57 PM UTC

Lucinda Ferreira-Mota

Read and understood · Jul 18, 2026, 01:57 PM UTC

Hattie Vandenberg, RN

Read and understood · Jun 22, 2026, 10:57 AM UTC

Renzo Palacios, RN

Read and understood · Sep 26, 2026, 01:57 PM UTC

Ingeborg Strand, RN

Read and understood · Jul 17, 2026, 09:57 AM UTC

Delphine Rousseau

Read and understood · Jun 17, 2026, 03:57 PM UTC

Yusra Abdalla

Read and understood · Jul 22, 2026, 12:57 PM UTC

Milo Ferrante

Read and understood · Sep 23, 2026, 10:57 AM UTC

Saoirse MacLochlainn, RN

Read and understood · Aug 19, 2026, 02:57 PM UTC

Anneliese Brummer

Read and understood · Aug 15, 2026, 08:57 AM UTC

Jamal Whitfield

Read and understood · Sep 20, 2026, 08:57 AM UTC

Auberon Castellanos

Read and understood · Aug 02, 2026, 11:57 AM UTC

Nikolai Petrosyan

Read and understood · Sep 16, 2026, 02:57 PM UTC

Chiamaka Eze

Read and understood · Jul 12, 2026, 02:57 PM UTC

Sebastián Duarte

Read and understood · Aug 30, 2026, 12:57 PM UTC

Harriet Oyelaran

Read and understood · Jul 03, 2026, 09:57 AM UTC

Viktor Salminen

Read and understood · Jun 17, 2026, 10:57 AM UTC

Rosalie Beauchamp

Read and understood · Jun 15, 2026, 02:57 PM UTC

Tallulah Winthrop

Read and understood · Sep 19, 2026, 11:57 AM UTC

Georgi Dimitrov

Read and understood · Sep 25, 2026, 12:57 PM UTC

Bartholomew Ng'ang'a, PharmD

Read and understood · Jul 21, 2026, 10:57 AM UTC

Solveig Aune, PharmD

Read and understood · Sep 14, 2026, 02:57 PM UTC

Rashida Karimova

Read and understood · Aug 03, 2026, 02:57 PM UTC

Marisol Echeverría

Read and understood · Aug 19, 2026, 02:57 PM UTC

Desmond Achebe

Read and understood · Aug 31, 2026, 08:57 AM UTC

Ingrid Bäckström

Read and understood · Sep 17, 2026, 11:57 AM UTC

Evelyn Marchetti-Sung

Read and understood · Jul 01, 2026, 08:57 AM UTC

Obadiah Lindgren

Read and understood · Sep 09, 2026, 12:57 PM UTC

Ana Lucía Restrepo

Approved · Jul 08, 2026, 08:57 AM UTC

Farrukh Tashkentov

Read and understood · Aug 12, 2026, 03:57 PM UTC

Coretta Blanchard

Read and understood · Sep 05, 2026, 09:57 AM UTC

Ravi Choudhury

Read and understood · Jul 25, 2026, 10:57 AM UTC

Birgitta Sjöberg

Read and understood · Aug 02, 2026, 02:57 PM UTC

Winston Ferraro-Kline

Read and understood · Aug 17, 2026, 11:57 AM UTC

Jasper Lindholm

Read and understood · Sep 10, 2026, 12:57 PM UTC

Gideon Mbeki-Turner

Authored · Jun 14, 2026, 01:57 PM UTC

Philippa Nkemdirim

Read and understood · Aug 30, 2026, 02:57 PM UTC

Miriam Sandoval-Reyes

Read and understood · Sep 15, 2026, 08:57 AM UTC