Security Rule conversations in Washington change timelines, but the direction is consistent: more specificity on encryption, multi-factor access, asset inventory, and the ability to restore operations after an incident. "We use TLS sometimes" will not read as a program.
Email, fax, and forms are in scope
Electronic PHI is electronic PHI whether it is a message, a TIFF from a fax server, or a form submission. If your risk analysis pretends those channels are "just communication," the analysis is incomplete.
A practice-sized response
- Name the systems that create or transmit ePHI.
- Require unique logins and MFA on those systems.
- Turn on audit logs you can actually export.
- Execute BAAs before go-live, not after a letter from OCR.
HIPAA Companion is already aligned with that list for physician offices: encrypted email and fax, logged form submissions, and a BAA on every plan. Use the product as part of the program, then write down the procedures so the technology is not the only control.
