1. Purpose
To establish the administrative, physical and technical safeguards that protect the confidentiality, integrity and availability of electronic protected health information at Quillbrook.
2. Scope
Applies to all workforce members and to every device, system, network, application and physical location that creates, receives, maintains or transmits electronic protected health information, including personally owned devices approved for work use.
3. Responsibilities
- IT Director & HIPAA Security Officer: Owns the security programme, risk analysis, access control, audit log review and incident technical response.
- HIPAA Privacy Officer: Coordinates privacy and security policy, training content and incident assessment.
- Information Security Analyst: Monitors alerts, reviews audit logs, and maintains vulnerability and patch records.
- All Workforce Members: Protect credentials and devices, use only approved systems, and report suspected incidents immediately.
4. Definitions
- Electronic protected health information (ePHI)
- Protected health information created, received, maintained or transmitted in electronic form.
- Risk analysis
- The documented assessment of potential risks and vulnerabilities to the confidentiality, integrity and availability of ePHI.
- Business associate agreement (BAA)
- The contract required before a vendor may create, receive, maintain or transmit PHI on behalf of the covered entity.
- Automatic logoff
- A technical control that terminates an electronic session after a predetermined period of inactivity.
5. Procedure
- Conduct and document an enterprise risk analysis at least annually and after any significant change in systems, facilities or services, and maintain a prioritised risk management plan.
- Maintain written security policies and procedures, review them annually, and retain them and all required documentation for at least six years from creation or last effective date.
- Assign every workforce member a unique user identification and authenticate with a strong password plus multi-factor authentication for all remote and administrative access; never share or reuse credentials.
- Apply role-based access with least privilege: grant access to ePHI only for the systems and records the person's role requires, on documented authorisation from the system owner.
- Review user access rights at least quarterly, remove unnecessary privileges, and terminate all access on the same business day a workforce member departs or changes role.
- Enforce automatic logoff after no more than fifteen minutes of inactivity on workstations and applications that access ePHI, and require a password-protected screen lock.
- Encrypt ePHI at rest on all laptops, desktops, servers, mobile devices and removable media using full-disk or file-level encryption, and prohibit storage of ePHI on unencrypted media.
- Encrypt ePHI in transit: use TLS for all application traffic, an encrypted email gateway or secure portal for any email containing PHI, and approved secure file transfer for data exchange; never use personal email or consumer cloud storage.
- Secure the physical environment: badge-controlled entry to areas holding ePHI, locked cabinets for paper records, visitor logging and escort, and a maintenance record for physical security repairs.
- Position and shield workstations so displays are not visible to visitors or subjects, use privacy filters in shared areas, lock screens whenever leaving a workstation, and never leave records unattended.
- Maintain an inventory of all hardware and media that store ePHI, track movement, and sanitise or destroy media before reuse or disposal using approved methods with documented certificates.
- Enable audit logging in every system holding ePHI, protect logs from alteration, retain them for at least six years, and review them at a documented frequency of at least monthly for inappropriate access.
- Maintain malware protection, centralised patch management with defined remediation timelines by severity, network segmentation and firewall rules, and document exceptions with compensating controls.
- Maintain a contingency plan including data backup, disaster recovery, emergency mode operation, and an applications and data criticality analysis, and test restoration at least annually.
- Execute a business associate agreement before any vendor, laboratory, courier, sponsor service provider or cloud platform creates, receives, maintains or transmits PHI on the site's behalf, and track expiry dates.
- Apply sanctions consistently for workforce members who violate security policy, document the sanction, and record it per the sanction policy.
- Complete security awareness training at hire and annually, including phishing recognition, and document completion per TRN-001.
- Report any suspected security incident to the HIPAA Security Officer immediately and process it under HIP-003.
6. References
- 45 CFR Part 164, Subpart C — Security Standards for the Protection of ePHI
- 45 CFR 164.308 — Administrative safeguards
- 45 CFR 164.310 — Physical safeguards
- 45 CFR 164.312 — Technical safeguards
- 45 CFR 164.316 — Policies, procedures and documentation
- 21 CFR Part 11 — Electronic Records; Electronic Signatures
- HIP-003 Privacy & Security Incident Response and Breach Notification
7. Revision History
- v2.0 · Oct 17, 2022 — Added multi-factor authentication and quarterly access reviews.
- v3.0 · Nov 05, 2024 — Added patch management timelines and annual restoration testing.
- v3.1 · Jan 12, 2026 — Clarified email encryption and workstation security requirements.
— End of document —
Devan Ramaswamy
Read and understood · Aug 01, 2026, 09:57 AM UTC
Ingrid Halvorsen, MD
Read and understood · Sep 04, 2026, 02:57 PM UTC
Cornelius Abara, MD
Read and understood · Jul 29, 2026, 02:57 PM UTC
Rosalind Achterberg, DO
Read and understood · Sep 17, 2026, 10:57 AM UTC
Fatoumata Diallo, MD
Read and understood · Jul 12, 2026, 01:57 PM UTC
Noor Al-Rashidi, NP
Read and understood · Jul 20, 2026, 11:57 AM UTC
Beatrix Calloway
Read and understood · Jul 21, 2026, 09:57 AM UTC
Emeka Nwachukwu
Read and understood · Sep 27, 2026, 08:57 AM UTC
Sunniva Lindqvist, RN
Read and understood · Jul 20, 2026, 02:57 PM UTC
Rafael Quintanilla
Read and understood · Sep 15, 2026, 12:57 PM UTC
Meredith Sowande
Read and understood · Aug 27, 2026, 02:57 PM UTC
Jozef Kaminski
Read and understood · Sep 15, 2026, 02:57 PM UTC
Lucinda Ferreira-Mota
Read and understood · Jul 18, 2026, 01:57 PM UTC
Hattie Vandenberg, RN
Read and understood · Jun 22, 2026, 10:57 AM UTC
Renzo Palacios, RN
Read and understood · Sep 26, 2026, 01:57 PM UTC
Ingeborg Strand, RN
Read and understood · Jul 17, 2026, 09:57 AM UTC
Delphine Rousseau
Read and understood · Jun 17, 2026, 03:57 PM UTC
Yusra Abdalla
Read and understood · Jul 22, 2026, 12:57 PM UTC
Milo Ferrante
Read and understood · Sep 23, 2026, 10:57 AM UTC
Saoirse MacLochlainn, RN
Read and understood · Aug 19, 2026, 02:57 PM UTC
Anneliese Brummer
Read and understood · Aug 15, 2026, 08:57 AM UTC
Jamal Whitfield
Read and understood · Sep 20, 2026, 08:57 AM UTC
Auberon Castellanos
Read and understood · Aug 02, 2026, 11:57 AM UTC
Nikolai Petrosyan
Read and understood · Sep 16, 2026, 02:57 PM UTC
Chiamaka Eze
Read and understood · Jul 12, 2026, 02:57 PM UTC
Sebastián Duarte
Read and understood · Aug 30, 2026, 12:57 PM UTC
Harriet Oyelaran
Read and understood · Jul 03, 2026, 09:57 AM UTC
Viktor Salminen
Read and understood · Jun 17, 2026, 10:57 AM UTC
Rosalie Beauchamp
Read and understood · Jun 15, 2026, 02:57 PM UTC
Tallulah Winthrop
Read and understood · Sep 19, 2026, 11:57 AM UTC
Georgi Dimitrov
Read and understood · Sep 25, 2026, 12:57 PM UTC
Bartholomew Ng'ang'a, PharmD
Read and understood · Jul 21, 2026, 10:57 AM UTC
Solveig Aune, PharmD
Read and understood · Sep 14, 2026, 02:57 PM UTC
Rashida Karimova
Read and understood · Aug 03, 2026, 02:57 PM UTC
Marisol Echeverría
Read and understood · Aug 19, 2026, 02:57 PM UTC
Desmond Achebe
Read and understood · Aug 31, 2026, 08:57 AM UTC
Ingrid Bäckström
Read and understood · Sep 17, 2026, 11:57 AM UTC
Evelyn Marchetti-Sung
Read and understood · Jul 01, 2026, 08:57 AM UTC
Obadiah Lindgren
Read and understood · Sep 09, 2026, 12:57 PM UTC
Ana Lucía Restrepo
Approved · Jul 08, 2026, 08:57 AM UTC
Farrukh Tashkentov
Read and understood · Aug 12, 2026, 03:57 PM UTC
Coretta Blanchard
Read and understood · Sep 05, 2026, 09:57 AM UTC
Ravi Choudhury
Read and understood · Jul 25, 2026, 10:57 AM UTC
Birgitta Sjöberg
Read and understood · Aug 02, 2026, 02:57 PM UTC
Winston Ferraro-Kline
Read and understood · Aug 17, 2026, 11:57 AM UTC
Jasper Lindholm
Read and understood · Sep 10, 2026, 12:57 PM UTC
Gideon Mbeki-Turner
Authored · Jun 14, 2026, 01:57 PM UTC
Philippa Nkemdirim
Read and understood · Aug 30, 2026, 02:57 PM UTC
Miriam Sandoval-Reyes
Read and understood · Sep 15, 2026, 08:57 AM UTC