HIPAA and HL7 Compliance

What is HIPAA?

HIPAA (Health Information Portability and Accountability Act) is a federal law that protects health information. Federal standards are now in place that ensures patients have access to their own medical records while adding new responsibilities to those charged with protecting this information.

For those in the business of providing access to information, these regulations are the proverbial double-edged sword. If patients now have expanded access to their own medical data, the quickest, cheapest and most convenient manner to provide this information is electronically through the internet. So those involved in designing web applications and hosting web sites can expect to see new HIPAA related opportunities. However, with these new opportunities come new responsibilities. The security provisions detailed in HIPAA are exacting. Working within the scope of HIPAA places an onus on web designers to ensure that potentially sensitive medical information is kept private.

What is HL7?

HL7 is an international community of healthcare subject matter experts and information scientists collaborating to create standards for the exchange, management and integration of electronic healthcare information.

The name "Health Level-7" is a reference to the seventh, or "application," layer of the ISO OSI Reference model. The name indicates that HL7 focuses on application layer protocols for the health care domain, independent of lower layers.

Hospitals and other healthcare provider organizations typically have many different computer systems used for everything from billing records to patient tracking. All of these systems should communicate with each other (or "interface") when they receive new information but not all do so. HL7 specifies a number of flexible standards, guidelines, and methodologies by which various healthcare systems can communicate with each other. Such guidelines or data standards are a set of rules that allow information to be shared and processed in a uniform and consistent manner. These data standards are meant to allow healthcare organizations to easily share clinical information. Theoretically, this ability to exchange information should help to minimize the tendency for medical care to be geographically isolated and highly variable.

Expert’s Offerings

To ensure compliance we provide

  • Database Level Security Services
  • Application Level Security Services
     

Database level security services include partitioned and encrypted database deployment, Oracle Vault implementations, to name a few.

Application level security services include development of encrypted data transfer methodologies, user authentication and roles implementation, amongst many others.

Best viewed in 1024 x 768 resolution and IE 7, mozilla 1.0 and above