<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="cfr.xsl"?>
<CFRGRANULE xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="CFRMergedXML.xsd">
  <FDSYS>
    <CFRTITLE>45</CFRTITLE>
    <CFRTITLETEXT>Public Welfare</CFRTITLETEXT>
    <VOL>1</VOL>
    <DATE>2003-10-01</DATE>
    <ORIGINALDATE>2003-10-01</ORIGINALDATE>
    <COVERONLY>false</COVERONLY>
    <TITLE>Technical safeguards.</TITLE>
    <GRANULENUM>164.312</GRANULENUM>
    <HEADING>Section 164.312</HEADING>
    <ANCESTORS>
      <PARENT HEADING="Title 45" SEQ="4">Public Welfare</PARENT>
      <PARENT HEADING="SUBTITLE A" SEQ="3">DEPARTMENT OF HEALTHAND HUMAN SERVICES</PARENT>
      <PARENT HEADING="SUBCHAPTER C" SEQ="2">ADMINISTRATIVE DATA STANDARDS AND RELATED REQUIREMENTS</PARENT>
      <PARENT HEADING="PART 164" SEQ="1">SECURITY AND PRIVACY</PARENT>
      <PARENT HEADING="Subpart C" SEQ="0">Security Standards for the Protection of Electronic Protected Health Information</PARENT>
    </ANCESTORS>
  </FDSYS>
  <SECTION>
    <SECTNO>§ 164.312</SECTNO>
    <SUBJECT>Technical safeguards.</SUBJECT>
    <P>A covered entity must, in accordance with § 164.306:</P>
    <P>(a)(1) <E T="03">Standard: Access control.</E> Implement technical policies and procedures for electronic information systems <PRTPAGE P="715"/>that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights as specified in § 164.308(a)(4).</P>
    <P>(2) <E T="03">Implementation specifications:</E>
    </P>
    <P>(i) <E T="03">Unique user identification</E> (Required). Assign a unique name and/or number for identifying and tracking user identity.</P>
    <P>(ii) <E T="03">Emergency access procedure</E> (Required). Establish (and implement as needed) procedures for obtaining necessary electronic protected health information during an emergency.</P>
    <P>(iii) <E T="03">Automatic logoff</E> (Addressable). Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity.</P>
    <P>(iv) <E T="03">Encryption and decryption</E> (Addressable). Implement a mechanism to encrypt and decrypt electronic protected health information.</P>
    <P>(b) <E T="03">Standard: Audit controls.</E> Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.</P>
    <P>(c)(1) <E T="03">Standard: Integrity.</E> Implement policies and procedures to protect electronic protected health information from improper alteration ordestruction.</P>
    <P>(2) <E T="03">Implementation specification: Mechanism to authenticate electronic protected health information</E> (Addressable). Implement electronic mechanisms to corroborate that electronic protected health information has not been altered or destroyed in an unauthorized manner.</P>
    <P>(d) <E T="03">Standard: Person or entity authentication.</E> Implement procedures to verify that a person or entity seeking access to electronic protected health information is the one claimed.</P>
    <P>(e)(1) <E T="03">Standard: Transmission security.</E> Implement technical security measures to guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network.</P>
    <P>(2) <E T="03">Implementation specifications:</E>
    </P>
    <P>(i) <E T="03">Integrity controls</E> (Addressable). Implement security measures to ensure that electronically transmitted electronic protected health information is not improperly modified without detection until disposed of.</P>
    <P>(ii) <E T="03">Encryption</E> (Addressable). Implement a mechanism to encrypt electronic protected health information whenever deemed appropriate.</P>
  </SECTION>
</CFRGRANULE>
