HIPAA Privacy Policy and Security
Procedures
Overview
Yobi has established formal policies and procedures in accordance with the Health Insurance
Portability and Accountability Act (HIPAA). All staff members who have access to Protected
Health Information (PHI) must comply with this HIPAA Privacy and Security Plan. This Privacy
and Security Plan will be evaluated on an annual basis to ensure its adequacy and relevancy
regarding Yobi’s needs and goals.
Purpose
The policies and procedures are designed to provide Yobi with a documented and formalized
set of HIPAA Privacy and Security policies in accordance with the Health Insurance Portability
and Accountability Act (HIPAA). Compliance with the stated policies and procedures helps
ensure the safety and security of all Yobi system resources that store, process, and/or transmit
PHI, and other applicable sensitive and confidential information.
Scope
The subsequent referenced HIPAA Privacy and Security policies and procedures encompass all
system resources that store, process, and/or transmit PHI, and other applicable sensitive and
confidential healthcare information that are owned, operated, maintained, and controlled by Yobi
and all other system resources, both internally and externally, that interact with these systems,
and all other relevant systems.
Internal system resources are those owned, operated, maintained, and controlled by Yobi and
include all network devices (firewalls, routers, switches, load balancers, other network devices),
servers (both physical and virtual servers, along with the operating systems and applications
that reside on them) and any other system resources deemed in scope.
External system resources are those owned, operated, maintained, and controlled by any entity
other than Yobi, but for which these very resources may impact the confidentiality, integrity, and
availability (CIA) and overall security of the PHI environment and any other environments
deemed applicable.
Business Associate Responsibilities
I. Assignment of HIPAA Security and Privacy Officers
Zack Costa has been designated as the HIPAA Security Officer for Yobi and Aaron Bartos has
been designated as the HIPAA Privacy Officer for Yobi.
The Security Officer will be responsible for the development and implementation of the policies
and procedures relating to security, protecting the confidentiality (i.e. privacy), integrity and
availability of electronic PHI, or PHI that exists in a digital form.
The Privacy Officer will be responsible for the development and implementation of policies and
procedures relating to privacy, including but not limited to this Privacy Policy and the Company’s
use and disclosure procedures. The Privacy Officer will also serve as the contact person for
participants who have questions, concerns, or complaints about the privacy of their PHI.
II. Use and Disclosure of PHI
Yobi may use PHI for our management, administration, data aggregation and legal obligation to
the extent such use of PHI is permitted or required by the Business Associate (BA) Agreement
and not prohibited by law. Yobi may use or disclose PHI on behalf of, or to provide services to,
Covered Entities, if such use or disclosure of PHI is permitted or required by the BA Agreement
and would not violate the Privacy Rule.
III. Risk Assessment
The HIPAA Privacy Officer is responsible for conducting an annual HIPAA privacy and security
risk assessment. The assessment will be completed with the assistance of at least two other
personnel. Additional risk assessments may be necessary each time new software or hardware
is acquired and placed in service, when a new service or procedure is initiated, when there is a
significant change in an existing service or procedure, or when there is a change or addition to
the physical layout of our office. The HIPAA Privacy Officer will periodically but at least quarterly
review the Department of Health and Human Services HIPAA website to determine if there have
been any changes in the HIPAA rules and regulations and to determine if any changes or
modifications to this policy and procedure is necessary due to changes in HIPAA rules,
regulations or regulatory interpretations.
IV. Policy Regarding Confidentiality of All Forms of PHI
All PHI regardless of its form, mechanism of transmission, or storage is to be kept confidential.
Only individuals with a business need to know are allowed to view, read, or discuss any part of a
patient’s PHI. During initial new hire orientation and at annual HIPAA training, personnel are
reminded that any viewing, reading, or discussions of PHI that is not for business purposes is
prohibited. Any personnel who violates this confidentiality policy will be subject to sanctions up
to immediate termination. All personnel are required to verify in writing that they have read and
will comply with our policy regarding confidentiality of all forms of PHI.
V. Incident/Breach Investigation
Any incident in which the privacy/security of a patient’s PHI may have been compromised will be
immediately reported to Aaron Bartos. An incident investigation will be initiated without
unreasonable delay. The HIPAA Privacy Officer will establish an Incident Response Team (IRT)
to investigate incidents and determine if the incident rises to the level of a breach. An Incident
Report form must be completed by the person who identified the breach and provided to the
HIPAA Privacy Officer within 24 hours of occurrence.
Yobi will also notify the Covered Entity without unreasonable delay and no later than 60 days
from the discovery of the breach. To the extent possible, Yobi will provide the Covered Entity
with the identification of each individual affected by the breach, as well as any information the
Covered Entity may need to notify the affected individuals.
VI. Security Management Process
Passwords for all systems will be stored in appropriate cloud-based security and identity
management software for cloud applications. For local, on-premises deployments, they will be
protected physically with security measures, and secured using passwords and encrypted keys.
In the event of password compromise, immediate blocking measures will be implemented.
Access will be strictly limited, granted only on a need-to-know basis.
VII. Risk Analysis
Quarterly meetings will take place between the technical lead and the security officer to
evaluate and assess any potential risks related to ePHI.
VIII. Risk Management
Yobi will ensure all computing devices are secure, that ePHI is transmitted securely over the
network, and only on Yobi servers, which are secured.
IX. Sanction Policy
All personnel will receive training regarding Yobi’s policy for sanctioning personnel who violate
our HIPAA privacy/security policy. Personnel shall receive training prior to assuming work duties
and annually thereafter. Any personnel who does not comply with the organizational security
policies and procedures will receive a written warning, up to and including, termination.
X. Information System Activity Review
Quarterly access log reviews will be performed by a development operations team member.
The development operations team member will submit a formal report to the privacy officer.
XI. Assigned Security Responsibility
The security officer will be responsible for developing and implementing the policies and
procedures for Yobi. The security officer must understand the technical components that are
used by Yobi and understand the HIPAA guidelines, such that the proper guidance can be
provided to ensure HIPAA compliance of all ePHI.
XII. Information Access Management
Personnel requiring access to ePHI must have a full understanding of the HIPAA policies and
procedures regarding ePHI, as defined in Yobi’s Policies and Procedures guidelines.
XIII. Data Backup Plan
Yobi backs up differential backups, or changes made to the data since the last full backup, twice
a week on an encrypted and physically secured on-site server.
Continuous backups, or real-time backups or data changes, is done for critical systems and
databases. This data is stored on an encrypted and physically secured on-site server.
All backups are encrypted using industry standard encryption, and when reusing physical
backup media, Yobi employs secure overwriting methods including writing random data over the
entirety of the storage medium multiple times, ensuring the original data is irretrievable.
ePHI backups may differ on a client-by-client basis, but by default, all of a client’s ePHI data is
backed up to Amazon S3, an online file storage web service provided by Amazon, on a regular
basis.
XIV. Emergency Mode Operation Plan
In the event of an emergency, the appropriate personnel in an offsite location will be designated
to take over and manage the daily operations to ensure the security of ePHI. For Yobi data
hosted on the cloud and not maintained at a physical location, it will be stored across multiple
US based Data Centers.
XV. Evaluation
Quarterly reviews of our security controls will be conducted by the security officer. Any
operational changes that impact ePHI will be addressed to ensure compliance and the HIPAA
policies and procedures document will be updated accordingly.
XVI. Workstation Use
Any workstation having access to ePHI will be password protected. Personnel will be instructed
to not keep PHI downloaded on their workstation and any personnel that leaves the company
must remove any PHI data from their workstation.
XVII. Workstation Security
Any workstation having access to ePHI will be password protected. Workstations that store
ePHI will only be accessible through local network connections and worked on premise.
XVIII. Device and Media Controls
All hardware and electronic media containing ePHI will be password protected and encrypted.
XIX. Disposal
The hard drives on any hardware containing ePHI will be erased before being disposed. Hard
drives are physically destroyed through professional services utilizing specialized equipment
when a drive is deactivated, involving procedures such as shredding, degaussing, or other
methods that render the data unrecoverable.
For disposal of off-premises backups which cannot be physically destroyed, Yobi ensures the
secure destruction of all encryption keys rendering media unreadable.
XX. Access Control
The systems that maintain ePHI are password protected and managed with role-based access.
Usernames and passwords assigned to each person is maintained in an appropriate cloud
based security and identity management software.
Onsite systems are secured in a stored locked facility with logged entrance and camera
monitoring. Onsite systems require login/physical encryption key and time out during inactivity
after 15 minutes at idle.
XXI. Emergency Access Procedure
In case of an emergency, the technical lead will be given access to the cloud based security and
identity management software in order to obtain any necessary ePHI.
XXII. Audit Controls
All activity on systems that maintain ePHI will be logged and tracked and can be examined on
an as needed basis.
XXIII. Person or Entity Authentication
Personnel requiring access to ePHI will be authenticated using an appropriate cloud based
security and identity management software for access to data on Cloud. For onsite / on premise
deployments of software, physical access and authentication to the secure facility the servers
are located will be followed and logged.
XXIV. Document Retention Policy
All privacy policies and procedures will be documented and maintained for at least six years.
Policies and procedures must be changed as necessary or appropriate to comply with changes
in law, standards, requirements and implementation specifications (including changes and
modifications in regulations). Any changes to policies or procedures must be promptly
documented.
XXV. Access to ePHI
As provided by the BA Agreement, Yobi will make available internal practices, books, and
records, including policies and procedures, relating to the use or disclosure of ePHI, to the
Covered Entities. Yobi shall have a reasonable time within which to comply with requests for
such access and in no case shall access be required in less than five (5) business days after
receipt of request from the Covered Entity.