Why is HIPAA compliance needed? Healthcare organizations and their service providers want to avoid federal fines and prevent their systems from being compromised. Healthcare data breaches have been consistently increasing over the last ten years, so it is even more critical to pay attention to defenses for protected health information (PHI) - particularly the electronic protected health information (ePHI) safeguarded within data environments, including with your web host.
If you are a healthcare company or otherwise interact with individuals' ePHI, your first consideration should always be verifying that the system is HIPAA-compliant. A HIPAA-compliant hosting company has the necessary protections in place to meet and exceed the parameters of the HIPAA Security Rule (managed firewall, encrypted VPN, encrypted backup, log management system, intrusion detection service, etc.) and is audited under SOC 2 / SOC 3. To understand HIPAA compliance further, read A Beginner's HIPAA Compliance Guide.
While having the right host is critical, you need more than HIPAA-compliant hosting services to protect yourself from violation. The preliminary step is a risk analysis. A risk analysis is key because it gives you two basic positive outcomes: assurance that the system serving your HIPAA-compliant WordPress installation can properly safeguard the data, and a documented foundation for the HIPAA Security Rule's expectations.
A risk analysis is necessary, not optional, if you want your WordPress site to be HIPAA-compliant. You cannot skip this step on the assumption that you have no risk, and it is not an aspect of your business that you can entirely entrust to a third party - your organization is ultimately liable. Reviewing the current risks present in your system lets you build the best strategy moving forward; once you have the risk analysis documentation in place, you can focus on making your HIPAA compliance program sustainable.
What is involved in a risk analysis to properly protect your WordPress hosting environment from violating the HIPAA regulation?
You'll need to answer important questions about your environment:
- What is the purpose of the WordPress site?
- What groups of people need access?
- What types of ePHI will it be processing, storing, or transferring?
- Will the WordPress instance be publicly accessible, or is the system only for internal purposes?
- What security controls are in place to safeguard it?
- What are your policies and procedures to handle the security needs of its data?
- What does the threat landscape look like, and what individual concerns apply?
- What are the chances that threats will be deployed, and what are the potential impacts?
Once you have answered the risk-analysis questions, it is time to think in terms of the controls you want to implement on your HIPAA WordPress site. You will be able to meet the requirements set by the Health and Human Services Department (HHS) through the standard system, plugins, or custom tools. Your HIPAA-compliant web hosting environment should meet five key control requirements - all of them described by the HIPAA Security Rule's language on technical safeguards.
First, your HIPAA-compliant environment will need access controls. A covered entity or business associate needs to put physical security controls, technologies, and systems in place. WordPress provides a combination of security configurations and plugins to achieve this; modifying user roles ensures permissions work for administrators, the public, and staff. Note that the standard authorization capabilities within WordPress are basic. You may need a plugin to disable a content type or module when users are not authorized - for instance, to allow users to edit content while not giving them access to ePHI within calendar registrations.
Second, you will need audit controls: deploying computing equipment, programs, and processes to monitor access and behavior within IT portals that contain ePHI.
Third, HIPAA-compliant WordPress hosting requires integrity controls. Data integrity must be maintained - data is not destroyed or unintentionally altered - and a mechanism should be installed that verifies no alteration or destruction is occurring.
Fourth, the Security Rule requires person or entity authentication. Verify identities of users through person or entity authentication methods. At minimum, confirm that privileges and the transmission device are valid.
Finally, a HIPAA-compliant organization has to build transmission security into its environment. These methods protect against compromise of the ePHI flowing through the infrastructure.
Considering all these controls, it becomes apparent that a big piece of any HIPAA-compliant WordPress site is the hosting company. It is a much simpler route than reinventing the wheel, since HIPAA regulations can be complex. Before you can build HIPAA-compliant WordPress, you need a web host with the healthcare IT knowledge to set up a system that will protect you from a HIPAA breach. At Atlantic.Net, our healthcare hosting is SOC 2 Type II and SOC 3 Type II certified and HIPAA audited - designed to secure critical data, records, and HIPAA WordPress installations. Reach out to us about our HIPAA-compliant WordPress hosting plans.
HIPAA-compliant WordPress hosting