Category: HIPAA Security
Responsible Office: UBIT HIPAA Compliance
Responsible Executive: Vice President and Chief Information Officer (VPCIO)
Approved By (Name/Title): J. Brice Bible, VPCIO
CATEGORY: Administrative Safeguards
TYPE: Required implementation Specification for Security Management Process Standard
CITATION: 45 CFR 164.308(a)(1)(ii)(B)
The University at Buffalo Information Technology (UBIT) operates as a covered entity as defined by the U.S. Department of Health and Human Services Office of Civil Rights (OCR). HIPAA Regulation Text 45 CFR Part 164.308(a)(1)(i) requires a covered entity to implement policies and procedures to prevent, detect, contain, and correct security violations.
UBIT implements security measures sufficient to reduce risks and vulnerabilities to ePHI to a reasonable and appropriate level.
This policy applies to all UBIT workforce members.
Workforce members: Adhere to all policies and procedures as written.
HIPAA Security and Privacy Officer: Implements security measures to reduce the risks to ePHI to a reasonable and appropriate level.
Compliance Officer: Participates in ensuring the security of ePHI is enforced and is effective. Performs this duty in conjunction with the HIPAA Security and Privacy Officer.
Date Approved: 12/6/2017