[CESPPA] Privacy Rule Compliance Is Not Enough:
Three Things You Should Know about the HIPAA Security Rule

[CESPPA] Privacy Rule Compliance Is Not Enough:
Three Things You Should Know about the HIPAA Security Rule

Dear EDs:

It has come to our attention that a number of practitioners are under the impression that the actions they took to comply with the Privacy Rule are enough to also make them compliant with the HIPAA Security Rule. This is inaccurate. While there is some overlap, the Security Rule is separate and distinct, and requires a different set of compliance activities than the Privacy Rule. A recent APA Practice Organization "PracticeUpdate" newsletter article listed three important things every psychologist should know about Security Rule compliance in effort to address this issue. The article is attached below should you want to run it in its entirety on your website or use it in your newsletters.

The article can also be found on APApractice.org at:
http://www.apapractice.org/apo/insider/hipaa_reg/hipaa/hipaa_security_rule/notenough.html#.

-- APA Practice

Posted 5/13/05