Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Privacy And Security topic
No spam. Unsubscribe anytime.
HSS gives annual HIPAA refresher to commissioners; highlights minimum-necessary and breach risks
Summary
SFHSS privacy officer Wren Coleridge briefed commissioners on HIPAA privacy, security and breach-notification rules, the minimum-necessary standard, de-identification and cyber threats; emphasized using city systems and upcoming cybersecurity training.
Get email alerts on the Privacy And Security topic
No spam. Unsubscribe anytime.
Wren (Ryn) Coleridge, HSS director of enterprise systems and analytics and the agency's HIPAA privacy officer, delivered the annual HIPAA training to the board on Aug. 8, describing key privacy and security obligations for the Health Service System and its commissioners.
Coleridge reviewed the privacy and security rules, the definition of protected health information (PHI), and how the agency qualifies as a covered entity. He emphasized the "minimum necessary" standard — keep access to PHI limited to what is needed — and discussed de-identification techniques for sharing aggregate data. The presentation included a discussion of breach notifications, penalties, and reporting obligations to HHS and the California attorney general for incidents affecting more than 500 individuals.
On cybersecurity, Coleridge flagged threat actor activity and common phishing risks, noted that HSS and its vendors have experienced breaches historically, and encouraged commissioners to use city-provisioned systems, multifactor authentication and the forthcoming annual cybersecurity training. He also drew attention to recent federal guidance intended to protect reproductive health information and directed commissioners to SFHSS resources and the agency microsite for guidance.
