Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cybersecurity topic

No spam. Unsubscribe anytime.

County staff reports HIPAA and cybersecurity upgrades; staff to draft resolution implementing recent IT changes

5602465 · April 7, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

A county staff member reported progress on HIPAA documentation, ADA website compliance, email archiving and encryption, backups and multifactor authentication for health department and EMS; staff said a formal resolution to implement the changes will be considered once details are finalized with legal counsel.

A county staff member updated commissioners on work to tighten HIPAA documentation and other IT-related security measures affecting the health department and emergency medical services.

The staff member said the county is using an ADA-monitoring tool (Monsido) to reduce website accessibility issues, has implemented email archiving and plans to roll out email encryption and multifactor authentication for the health department and EMS. The county has added a new server for backups and is configuring onsite and offsite redundancy, including backup to the public-safety building. The staff member also reported that penetration testing has begun and that antivirus with isolation capability will be deployed to allow an infected machine or segment to be isolated through centralized administration.

"So I've come given a an update again on the HIPAA documentation policy stuff that I've been working on," the staff member said, describing the implemented changes and upcoming training and documentation steps.

Staff said they will share technical recommendations with county legal counsel (Kutak Rock) and then present a formal resolution implementing the policies that have been developed over the past two years. Commissioners acknowledged the work and asked for a follow-up presentation when the implementation plan and resolution are ready.

Why it matters: The changes target systems that handle protected health information and emergency services communications; staff said the measures are being implemented to meet HIPAA requirements and to reduce cybersecurity risk to county operations.