6.6. ERMUSR 05-16-2006.^~/
Elk River -~
Municipal Utilities
13069 Orono Parkway
Elk River, MN 55330
May 8, 2005
To: Elk River Municipal Utilities commission
Jerry Takle
Jim Tralle
John Dietz
From: Theresa Slominski
Subject: HIPAA security policy
phone: 763.441.2020
1'ax: 763.441.8099
Small businesses were required to be in compliance with security of electronic protected
health information (ePHI) as of April 20, 2006. There were 18 standards that needed to
be addressed and implemented. Elk River Municipal Utilities has completed an internal
review and has the necessary procedures in place. I think that the final step in this
process would be to have the commission approve the policies that ERMU is following.
The policies are attached and also the related forms that would be signed to document our
compliance.
Elk River Municipal Utilities Health Plan HIPAA Security Policy
Elk River Munic~al Utilities ("Plan Sponsor") sponsors one or more health plans
("The Plan(s)" or "Plan(s)") for eligible employees. The Plan(s) is(are) a "Covered Entity" as
defined by the Health Insurance Portability and Accountability Act of 1996, Pub. L. 104-191
(HIPAA).
Pursuant to the Security Standards contained in HIPAA (45 CFR 160 and 164), the Plan
Sponsor adopts this Security Policy ("Policy") for the protection of Electronic Protected
Health information (ePHI).
The Plan(s) is not (are not) administered by a third party acting as a "Business Associate" of
The Plan(s) as defined by 45 CFR § 160.103.
1. Effective Date
The Plan's Security Policy is effective Apri120, 2006. The Policy will remain in force until
changed or rescinded by The Plan Sponsor's designated Security Official or Board Action.
2. Security Management Process
Risk Analysis and Risk Management [§164.308(a)(1)(ii)(A) and §164.308(a)(1)(ii)(B)]
The covered entity has conducted a thorough assessment of potential security risks related to
any Plan ePHI and made the following risk and vulnerability determinations:
1. The Plan(s) occasionally maintains or transmits limited ePHI, the Plan(s) maintains or
transmits no ePHI that is critical to the health or life of Plan members.
2. ePHI maintained by The Plan(s) may be important to Plan operations, but is rarely
mission critical.
3. Appropriate security measures implemented by The Plan(s) to protect the
confidentiality and integrity of this information are described in this policy.
Employee Sanctions [§164.308(a)(1)(ii)(C)]
The Plan(s) and Plan Sponsor will apply appropriate employee sanctions, consistent with
existing plan sponsor employee discipline and sanction policies, to any employee of The Plan
Sponsor who violates The Plan's Security Policy. Sanctions can include termination of
employment when appropriate.
3. Security Official
The Plan(s) will officially designate a Security Official and maintain written record of the
designation. The current Security Official designation is the Finance Director.
Responsibilities of The Plan(s) Security Official include:
a. Periodically evaluate this Policy and the procedures implemented to protect ePHI.
The Security Official will maintain reasonable and appropriate policies and
procedures to comply with the HIPAA Security Standards and make appropriate
changes when necessary. § 164.308(a)(8), § 164.316(a)
b. Regularly review the activity of any information systems involved in the
maintenance or transmission of PHI to determine if ePHI has been used or
disclosed in an inappropriate manner as required by § 164.308(a)(1)(ii)(D).
c. Report to appropriate Plan Administrator and/or corporate office of Plan Sponsor
any suspected or known security incidents as defined by § 164.308(a)(6)(ii).
4. Workforce Security
[§164.308(a)(3) and §164.308(a)(4), §164.312(d)]
Employee authorization to access systems that maintain or transmit ePHI, including
determination of appropriate employee clearance level, person authentication, and effective
and timely termination of system access for employees who no longer qualify for system
access will be the responsibility of The Plan(s) Security Official. The Security Official may
delegate these duties to appropriate parties based on exiting plan sponsor information system
access policies and procedures.
The Plan(s) and Plan Sponsor do not perform clearinghouse functions as defined by HIPAA
so no procedures are necessary to meet security standards defined in § 164.308(a)(3)(ii)(B).
5. Security Awareness and Training
The Plan(s) will require any employee of The Plan(s) or Plan Sponsor who is involved in the
administration or management of The Plan(s) to certify in writing that they have received
training and have read and understood The Plan's Security Policy.
Employees will also be provided additional existing Plan Sponsor security training when
available and appropriate. This training may include (but not be limited to) security
reminders, protection from malicious software, and log-in monitoring if The Plan Sponsor has
existing procedure to identify inappropriate system access attempts.
Employees will be trained on procedures for creating and maintaining appropriate and
effective passwords consistent with existing Plan Sponsor information system password
policies and procedures.
At least once per year, The Plan's Security Officer will review the Security Policy with
individuals involved in the administration and management of The Plan(s).
6. Contingency Plan
Data Backup Plan and Application and Data Analysis [§164.308(a)(7)(ii)(A),
§164.308(a)(1)(ii)(E), §164.310(d)(2)(iv)]
The Plan(s) will backup ePHI, and critical applications according to existing Plan Sponsor
information system backup procedures and policies.
Disaster Recovery, Emergency Mode Operation Plan, Testing and Revision Procedures
[§164.308(a)(1)(ii)(B), §164.308(a)(1)(ii)(C), §164.308(a)(1)(ii)(D), §164.312(a)(2)(ii)]
It has been determined that a formal disaster recovery operation plan applicable only to ePHI
is not reasonable or necessary. The Plan(s) will operate in the event of an emergency based on
existing emergency operation procedures of the plan sponsor, including granting access to
facilities during an emergency.
The Plan's Security Official will periodically review The Plan's contingency procedures to
determine if changes or testing of the procedures is appropriate.
7. Business Associate Contracts
The Plan(s) will allow a Business Associate of The Plan(s) to create, receive, maintain, or
transmit ePHI on behalf of The Plan(s), only once The Plan(s) obtains written assurance
through the use of business associate agreements that the Business Associate will
appropriately safeguard The Plan's ePHI as required by § 164.314(a).
8. Facility Access Controls
The Plan's ePHI is not located in facilities or locations that make it reasonable to implement
facility security, access control or maintenance of security records procedures applicable ePHI
locations only. Physical access to facilities where ePHI is maintained will be subject to
existing Plan Sponsor physical security procedures and policies when applicable.
9. Workstation Use and Security and Access and Audit Controls
[§164.310(b), §164.310(c), §164.312(a)(2)(i), §164.312(a)(2)(iii), ~164.312(a)(2)(iv)]
The Plan(s) implements the following procedures to control access to ePHI and manage
access to workstations that can be used to access ePHI.
Employees will be assigned unique user names and passwords for systems used to access ePHI.
These unique user IDs maybe assigned according to existing Plan Sponsor system access policies
and procedures.
The following workstation procedures will be implemented to mirturuze the potential risk of
inappropriate use of ePHI to the extent possible and reasonable.
a. When accessing ePHI on a workstation, employees will reduce visible windows or close
programs whenever they are not physically present at the workstation or when individuals
not authorized to access the ePHI can view the workstation.
b. Workstation screensavers will be set to engage at a reasonably short timeframe.
c. VC~orkstations located in areas where viewing by unauthorized individuak is likely will be
equipped with monitor screens that limit the visibility of data to anyone other than the
workstation user.
d. Users with portable workstations such as laptops or PDAs are not allowed to store ePHI on
workstation drives. All ePHI should be stored on Plan Sponsor servers subject to security
procedures described in this policy unless The Plan(s) Security Officer determines it is
necessary for plan administration purposes to store ePHI on portable workstations.
It has been determined that it is not reasonable to develop automatic logoff procedures or data
encryption mechanisms specifically for systems used to access ePHI. Automatic logoff and data
encryption will be used for systems used to access ePHI if exiting existing Plan Sponsor system
access policies and procedures include these capabilities and requirements.
When ePHI is accessed by using systems that contain audit control capabilities, The Plan(s) will
periodically review audit reports to assist in determining if a security violation has occurred.
Employees who have been granted access to ePHI according to The Plan(s) policies and
procedures will be subject to The Plan's sanction policy if they allow unauthorized access to
ePHI by circumventing access control (e.g. sharing their unique login LD. and password).
10. Device and Media Controls and Integrity of Data
[§164.310(d)(1), §164.310(d)(2)(i), §164.310(d)(2)(ii), §164.310(d)(2)(iii), §164.312(c)(1)
Any ePHI stored by The Plan(s) in electronic storage media will be subject to the following
procedures to ensure that the ePHI is not inappropriately used.
• All hardware, storage devices, and electronic media which contains or contained ePHI will be
erased, re-formatted or rendered unusable in a technically sufficient manner prior to disposal, or
re-use for other purposes, to assure no unauthorized access to ePHI is possible in the future.
• The Plan's SecuriryOfficial will be responsible to ensure that electronic media is controlled in
accordance with this policy and maintain any reasonable documentation necessary.
1t has been determined that it is not reasonable or necessary to implement technical procedures
for automatic data integrity checks for systems used to access ePHI alone. The Plan(s) will
use existing Plan Sponsor data integrity procedures and policies, if available and reasonable, to
determine if ePHI has been altered or destroyed in an unauthorized manner.
11. Transmission Security
[§164.312(e)(1), §164.312(e)(2)(i)]
The Plan(s) will implement the following measures to protect ePHI that is being transmitted
over electronic communications networks including the Internet.
It has been determined that it is not reasonable or necessary to implement transmission integrity
controk or email and electronic communication encryption procedures only for systems used to
access or transmit ePHI. The Plan(s) will use existing Plan Sponsor transmission integrity and
email and communication encryption procedures, if available and reasonable, to protect ePHI
transmitted over electronic networks.
If the Plan Sponsor does not have existing transmission integrity or encryption procedures
available, The Plan will implement the following procedures to protect ePHI transmitted over
electronic networks:
a. ePHI sent via email will be contained in a separate file sent as an attachment whenever
reasonable. Files containing ePHI will be protected bya password when possible. Passwords
necessary to access the file will be sent to the recipient via separate communication.
12. Group Health Plan Document Requirements
The Plan's Plan Documents are amended to require that the Plan Sponsor reasonably and
appropriately safeguards ePHI that it receives, maintains or transmits on behalf of the group
healt}i plan.
13. Documentation
[§164.316(b)(1), §164.316(b)(2)(i)]
The Plan(s) will maintain written (which may be in electronic form) policies and procedures
necessary to comply with the HIPAA Security Standards.
• Documentation will be retained for 6 years from the date of its creation or the date when it was
last in effect, whichever is later.
• The documentation will be made available to persons responsible for implementing the
procedures to which the documentation pertains.
• The Plan(s) mill review all documentation periodically, and update as needed, in response to
environmental or operational changes affecting the security of the ePHI.
HIPAA Designation of Security Official
Elk River Municipal Utilities, the "Plan Sponsor", hereby designates the Finance
Director as the HIPAA Security Official for the Plan Sponsor's health care benefit
plans as required by 164.308(a)(2).
This designation shall remain in force until changed in writing by an Officer of the Plan
Sponsor or Plan Sponsor's Board of Directors.
Signed
Title
Date
Plan Sponsor's HIPAA Privacy
Rule Certification Form
I, , on behalf of Elk River Municipal Utilities, am
(OH'ner, or Ofl7cer Name)
authorized to make the following certification for each of the employee benefits plans.
1. The Plan Sponsor will not further use or disclose protected health information (PHI)
except as required by the plan documents or by law.
2. The Plan Sponsor will ensure that the Plan Sponsors' agents and subcontractors
comply with the Employer's HIPAA Privacy Policy.
3. The Plan Sponsor will not use or disclose the PHI for employment-related actions or
decisions.
4. The Plan Sponsor will not use or disclose the PHI in connection with any other
benefit or employee benefit plan of the sponsor except as permitted under HIPAA.
5. The Plan Sponsor will self-report any disclosure violations to the plan.
6. The Plan Sponsor will meet certain administrative requirements applicable to
health plans.
7. The Plan Sponsor will make its internal practices, books and records related to use
and disclosure of PHI received from the plan available to the Secretary of Health
and Human Services for compliance review.
8. Where feasible, the Plan Sponsor will return or destroy all PHI received from the
plan when done with it.
9. The Plan Sponsor will maintain adequate separation between the group health plan
and the sponsor.
Signature of Owner or Officer
Date
Name of Employee Benefit Plan sponsored by Employer: Elk River Municipal Utilities
Medical Health Plan, Long Term Disability Plan, Life Insurance Plan.
HIPAA Privacy Rule Employee
Confidentiality Form
I, ,have read and understand Elk River Municipal
(Employee Name)
Utilities policies regarding the privacy of individually identifiable health information
(or protected health information (PHI), as mandated by the Health Insurance
Portability and Accountability Act of 1996 (HIPAA) and the State of Minnesota. In
addition, I acknowledge that I have received training in Elk River Municipal Utilities
policies concerning PHI use, disclosure, storage and destruction as required by HIPAA.
In consideration of my employment or compensation from Elk River Municipal
Utilities, I hereby agree that I will not at any time -either during my employment or
association with Elk River Municipal Utilities or after my employment or association
ends -use, access or disclose PHI to any person or entity, internally or externally,
except as is required and permitted in the course of my duties and responsibilities with
Elk River Municipal Utilities, as set forth in Elk River Municipal Utilities privacy
policy and procedures or as permitted under HIPAA. I understand that this obligation
extends to any PHI that I may acquire during the course of my employment or
association with Elk River Municipal Utilities, whether in oral, written or electronic
form and regardless of the manner in which access was obtained.
I understand and acknowledge my responsibility to apply Elk River Municipal Utilities
policies and procedures during the course of my employment or association. I also
understand that unauthorized use or disclosure of PHI will result in disciplinary action,
up to and including termination of employment or association with Elk River
Municipal Utilities and the imposition of civil penalties and criminal penalties under
applicable federal and state law, as well as professional disciplinary action as
appropriate.
I understand that this obligation will survive the termination of my employment or end
of my association with Elk River Municipal Utilities, regardless of the reason for such
termination.
Signature Date
Name
HIPAA Privacy and Security
Policy Acknowledgment Form
This notice tells all employees how and why personal information about employees will be collected, how it
will be handled and secured, and with whom the information is shared. ~y'e respect the privacy of personal
information and maintain it securely according to the privacy and security rules under HIPAA. This notice
applies to information regarding all current and former employees.
Why we collect personal information:
• To determine eligibility for health care coverage
• To transmit premium payments to the health insurance carrier
• To provide test results to an officer of the company, government regulatory agencies, or companies
that require certain tests under contract
• For pre-employment physicals and to determine fitness-for-duty of the employee's job
• To evaluate work-related injuries and comply with workers' compensation laws
• For requests for accommodation under the ADA
• To administer leave under FMLA (where applicable)
• To comply with OSHA, MSHA, and similar state laws
• For judicial or administrative proceedings
Personal information we collect from employees:
We ask people seeking employment and benefits to provide certain information when they begin employment
and enroll in a benefit plan. This information includes but is not limited to:
• Name, address, and phone number
• Social Security Number
• Birth date
• Marital status
• Information regarding current illnesses, injuries, or disabilities that may affect the ability to perform
the job.
• Consent to release all applicable information, including physical exam, drug screening and fitness-for-
duty results to the company and its agents and service providers
How ~~'e protect personal information under federal la~v:
Employee personal medical information is maintained in accordance with HIPAA and/or any other state or
federal law to protect the privacy of such information. The confidentiality, integrity, and availability of any
electronic protected health information (ePHI) will be ensured via appropriate safeguards as specified under
HIPAA's security rule beginning on or before the rule's effective date (4/21/06 for small health plans; 4/21/05
for all other covered entities).
How we protect personal information under state law:
Employee personal medical information is maintained in accordance with state law where such rules are more
stringent than, but not contrary to, the federal law to protect the privacy of such information. In general, state
laws that are contrary to HIPAA's privacy rule are preempted by the federal requirements, which mean that the
federal requirements will apply. The HIPAA privacy rule provides exceptions to the general rule of federal
preemption for contrary state laws that require certain health plan reporting, provide greater privacy protections,
or provide for the reporting of disease or injury, child abuse, birth, or death.
If you want more information on HIPAA as it applies to your personal health information, please contact the
owner or an officer of the company or customer service for:
Elk River Municipal Utilities Health Care Plan
Acknowledgment of receipt:
Employee
Date
HIPAA Privacy Rule Authorization
for Release of Health Information
I,
(Employee Name)
protected health information as follows:
authorize the specified person(s) to disclose
1. Person authorized to make disclosure: Elk River Municipal Utilities Health Care
Plan.
2. Person authorized to receive the disclosed information: Elk River Municipal
Utilities.
3. Specific description of the protected health information that may be used or
disclosed:
4. I understand that the information received pursuant to this authorization may be
disclosed by° the recipient and might lose its protected status.
5. I understand that I may revoke this authorization at any time by giving written
notice to
(Financial Director)
6. I understand that I am entitled to receive a copy of this authorization.
7. I understand that after this information is disclosed, federal law might not protect it
and the recipient might re-disclose it.
S. I understand that my initial and continued employment and position are subject to
my agreement to this authorization, and any additional authorization Elk River
Municipal Utilities requests.
9. I understand that this authorization will expire when my employment with Elk River
Municipal Utilities terminates or when I am no longer covered by the company's
employee benefits plan or COBRA plan, whichever is later.
Signature of Employee:
Name:
Date:
If a Personal Representative executes this form, that Representative warrants that he or
she has authority to sign this form on the basis of:
(Description of personal representative's authority)