logo
logo
Sign in

Why is a HIPAA Email Retention Policy Important?

avatar
Patrick Smith
Why is a HIPAA Email Retention Policy Important?

HIPAA requires covered entities and their business associates to retain all documents related to security, privacy policies, and procedures for a period of at least six years from the date the document is created or the date when it was last in effect – whichever is later.


Typically for most covered entities, the documentation that must be retained includes:


  • Information security policies and practices
  • Risk analyses
  • Notices of privacy practices
  • Patient authorizations
  • Business associate agreements
  • Access logs
  • IT security reviews and other IT security-related documents
  • Employee sanction policies
  • Breach notifications
  • Complaint and resolution documents
  • Training documents
  • Patient requests
  • Policies and procedural documentation.

Covered entities and business associates must also ensure documentation and PHI is backed up and that a retrievable, exact copy of electronic protected health information exists.


A HIPAA email retention policy should be developed that requires all the above documentation to be retained for 6 years or more to meet HIPAA requirements. An email archive can also help satisfy HIPAA backup requirements, meet state documentation and PHI retention laws, and an email archive is also incredibly valuable when dealing with complaints and e-discovery.


HIPAA Compliant Email Archiving


It is strongly recommended that you develop a HIPAA email retention policy and implement an email archiving solution with a HIPAA compliant email archiving company.


A HIPAA compliant email archiving solution, such as ArcTitan, is the ideal solution for healthcare organizations to help them meet state and federal data retention requirements. The solution can be used to store business-related emails which must be retained to comply with state laws, but it will also ensure that any PHI contained in emails is stored securely in compliance with the HIPAA Security Rule.


A HIPAA compliant email archive captures and retains all emails that are sent or received, the archive is searchable to allow quick retrieval of email data when required, email data is preserved in its original format and is tamper-proof, audit logs are maintained, and controls can be implemented to restrict access to authorized individuals only.


The email archive also serves as a data loss prevention tool and safeguards the confidentiality, integrity, and availability of PHI and HIPAA documents sent via email.


HIPAA Email Retention Policy FAQs

Do emails need to be encrypted to comply with HIPAA?

The encryption of ePHI is an addressable requirement of the HIPAA Security Rule. This means that emails containing ePHI should be encrypted unless a covered entity implement an equally effective security measure or can demonstrate that encryption is not necessary – for example, if the email server is only used for sending internal emails and is protected by a firewall.


Read more here

collect
0
avatar
Patrick Smith
guide
Zupyak is the world’s largest content marketing community, with over 400 000 members and 3 million articles. Explore and get your content discovered.
Read more