Orange County NC Website
Policy 32: Policy on Security Incident Management <br /> North State Medical Transport <br /> Policy on Security Incident Management <br /> Purpose <br /> The Health Insurance Portability and Accountability Act ("HIPAA") requires North State <br /> Medical Transport to track and appropriately respond to all incidents that could compromise <br /> our electronic protected health information ("e-PHI"). This policy establishes North State <br /> Medical Transport's procedures for reporting a security incident and the steps that will be <br /> taken by North State Medical Transport to investigate and take action when a potential or <br /> actual security incident occurs. <br /> Scope <br /> This policy applies to all North State Medical Transport staff members who utilize the <br /> electronic information system. Everyone at North State Medical Transport is responsible to <br /> know what to do when confronted with a security incident. The Security/Breach Incident <br /> Reporting Form should be used in conjunction with this policy. <br /> Procedure <br /> Security Incident Defined <br /> A "security incident" is an attempted or successful unauthorized entry, breach or attack on the <br /> electronic information system that we use to create, receive, maintain or transmit e-PHI. <br /> Security incidents include unauthorized probing and browsing of the files, a disruption of <br /> service in our information system and incidents where e-PHI has been improperly altered or <br /> destroyed. Security incidents also include things such as a virus, hacking attempt or incident, <br /> "phishing" incident, malware installation, corrupt data or other similar incident involving North <br /> State Medical Transport's information system. <br /> Reporting a Security Incident <br /> 1. All staff members are responsible for immediately reporting a suspected security <br /> incident immediately to the HIPAA Compliance Officer or an immediate supervisor. <br /> 2. When a suspected security incident occurs,the HIPAA Compliance Officer shall have the <br /> reporting staff member and other members with knowledge of the incident complete <br /> North State Medical Transport's "Internal Breach/Security Incident Reporting Form." <br /> 3. The HIPAA Compliance Officer will be responsible for initiating an immediate <br />