• DocumentCode
    624238
  • Title

    Analyzing the relationship between CCHIT certification criteria and HIPAA

  • Author

    Ragland, Ashley ; Xiaohong Yuan ; Jones, B.

  • Author_Institution
    Dept. of Comput. Sci., North Carolina A&T State Univ., Greensboro, NC, USA
  • fYear
    2013
  • fDate
    4-7 April 2013
  • Firstpage
    1
  • Lastpage
    5
  • Abstract
    In the health field, there is an immense amount of personal data that is collected, stored and transmitted from providers to patients, within the electronic health systems, to insurance companies, etc. Important law and regulations, such as Health Information Portability and Accountability Act (HIPAA), have been adopted and enforced as national standards for the protection of health information. The Certification Commission for Health Information Technology (CCHIT), an organization that certifies and tests electronic health record (EHR) modules, has designed test scripts and certification criteria to certify EHR modules. This paper analyzes CCHIT certification criteria and its relationship with HIPAA´s Privacy and Security rules. This analysis discloses to what degree CCHIT certification criteria covers the testing of compliance of the HIPAA rules. The analysis results could provide useful information for improving the CCHIT certification criteria.
  • Keywords
    conformance testing; data privacy; medical information systems; personal information systems; security of data; CCHIT certification criteria; Certification Commission for Health Information Technology; EHR modules; HIPAA; Health Information Portability and Accountability Act; compliance testing; electronic health record modules; electronic health systems; health information protection; insurance companies; personal data; privacy rules; security rules; test scripts; Certification; Information technology; Medical services; Privacy; Security; Standards organizations; CCHIT; Certification Criteria; Electronic Health Record; Electronic Protected Health Information; HIPAA; Health Informatics;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Southeastcon, 2013 Proceedings of IEEE
  • Conference_Location
    Jacksonville, FL
  • ISSN
    1091-0050
  • Print_ISBN
    978-1-4799-0052-7
  • Type

    conf

  • DOI
    10.1109/SECON.2013.6567455
  • Filename
    6567455