Orange County NC Website
•• Policies and procedures (written and unwritten)that involve the creation, use, or access <br /> to e-PHI; and <br /> • Vendors, billing companies, clearinghouses and others who create, receive, maintain or <br /> transmit PHI for North State Medical Transport. <br /> Procedure <br /> The HIPAA Compliance Officer will utilize North State Medical Transport's HIPAA Risk <br /> Analysis Tool to identify all current and potential risks and vulnerabilities to PHI at North State <br /> Medical Transport and to develop a plan to manage those risks. <br /> Annual Risk Analysis <br /> North State Medical Transport will, on an annual basis, undertake a risk analysis that <br /> includes the following: <br /> 1. Identifying and documenting all places where the physical (paper) PHI and e-PHI is <br /> stored, received, maintained or transmitted at North State Medical Transport (i.e., all <br /> sources of PHI at North State Medical Transport whether on or off-site). <br /> 2. Identifying and documenting all current and potential risks to the confidentiality, <br /> security, integrity and availability of all PHI sources identified at North State Medical <br /> Transport. <br /> 3. Assessing the likelihood of each identified risk and assigning the risk to a "risk level" and <br /> "potential impact" category. <br /> 4. Identifying and documenting any measures that North State Medical Transport currently <br /> has in place to address each identified risk, including any policies, procedures, <br /> hardware/software, security devices, etc. Then, identifying any methods that are not <br /> currently in place that may eliminate or mitigate the risk. <br /> 5. Providing recommendations to North State Medical Transport that might remedy <br /> identified risks and vulnerabilities and improve the security, integrity and availability of <br /> all PHI sources identified at North State Medical Transport. <br /> 6. Implementing methods that might remedy identified risks and vulnerabilities and <br /> improve the security, integrity and availability of all PHI sources identified at North State <br /> Medical Transport. <br /> Implementation Specifications <br />