{"id":6694,"date":"2020-08-19T15:00:13","date_gmt":"2020-08-19T21:00:13","guid":{"rendered":"https:\/\/www.jumpcloud.com\/blog\/?p=6694"},"modified":"2024-11-14T17:18:14","modified_gmt":"2024-11-14T22:18:14","slug":"directory-supports-hipaa-security-rule","status":"publish","type":"post","link":"https:\/\/jumpcloud.com\/blog\/directory-supports-hipaa-security-rule","title":{"rendered":"How a Cloud Directory Supports the HIPAA Security Rule"},"content":{"rendered":"\n
The HIPAA Security Rule, as many know, is not a rigid specification like the Payment Card Industry\u2019s Data Security Standard (PCI DSS). The HIPAA Security Rule provides high-level guidance which then needs to be translated by IT organizations into specific actions. The HIPAA statute does not define solutions or specific approaches, but instead focuses on outcomes.<\/p>\n\n\n\n
Generally, the HIPAA Security Rule looks for a few things from the area of identity and access management. HIPAA compliance ensures unique user access, authentication controls, and audit logging. It also ensures that administrators follow proper procedures in controlling access. JumpCloud\u2019s\u00ae<\/sup> cloud directory<\/a> supports a number of the areas of the HIPAA Security Rule.<\/p>\n\n\n\n Like any other technical solution, the use of JumpCloud\u2019s Directory-as-a-Service\u00ae<\/sup><\/a> platform does not solely make you compliant with the HIPAA Security Rule and, specifically, areas such as Administrative and Technical Safeguards. It is how<\/em> JumpCloud is used and the processes that IT organizations follow<\/em> that ultimately constitute compliance. For more information about how to properly use JumpCloud for HIPAA compliance, leading audit firm Coalfire conducted a study of JumpCloud\u2019s support for HIPAA. You can read the report here<\/a>.<\/p>\n\n\n\n For example, JumpCloud cannot guarantee that an organization will not create user accounts that are then shared. Or that end users would not share their login credentials. However, a cloud directory can be a core part of the solution to achieving compliance along with excellent documentation and processes. In the example above, IT admins would set up multi-factor authentication (MFA) or JumpCloud\u2019s Directory Insights\u2122<\/a> (audit logging and governance technology) features to help enforce the idea of unique user accounts.<\/p>\n\n\n\n JumpCloud\u2019s cloud directory service makes it easy to create, manage, and terminate unique accounts<\/a>. Logging of access to various IT resources can be monitored by JumpCloud through it\u2019s Directory Insights feature. Administrative controls for password management are also a core part of the IDaaS platform including password complexity management, SSH key management, MFA, and anti-phishing technology.<\/p>\n\n\n\n There is a number of major areas in the HIPAA Security Rule, areas that cascade into a number of specific actions that IT organizations need to take. These areas include:<\/p>\n\n\n\n JumpCloud\u2019s cloud IAM<\/a> platform supports your efforts primarily in the areas of Administrative and Technical Safeguards. In both of those, controlling and monitoring access to IT resources is central to compliance<\/a>. Practices such as ensuring unique access per person, strong passwords and authentication mechanisms, multi-factor authentication<\/a>, and audit logging will generally cover most of the requirements of the statute.<\/p>\n\n\n\n Each auditor\u2019s confirmation of those controls may be different, but the thrust of their focus will be on ensuring that accounts are for unique people, that have access to only what they need, and that those people are using their access properly. There needs to be clear data and visibility for all of these areas. Additionally, if the access is not being used properly, the system must support detecting that. JumpCloud\u2019s IDaaS platform can support IT organizations in each of these areas<\/a> and more.<\/p>\n\n\n\n JumpCloud currently supports a number of health care customers subject to HIPAA. As a note, JumpCloud does not store or act on any electronic protected health information (ePHI) and thus is not subject to a Business Associate Agreement. If you still have questions about JumpCloud and BAAs, we can help.<\/p>\n\n\n\n To learn more about how JumpCloud can support HIPAA Security Rule compliance, drop us a note<\/a>. You can also read Coalfire\u2019s analysis<\/a> of JumpCloud\u2019s cloud directory platform and how it supports HIPAA. Alternatively, feel free to give our cloud directory a try<\/a>. Your first 10 users and 10 systems are free forever. And, simply access the in-app chat support 24×7 in the first 10 days to connect with our Customer Success Engineers.<\/p>\n","protected":false},"excerpt":{"rendered":" JumpCloud\u2019s cloud directory supports a number of the areas of the HIPAA Security Rule. Learn which areas, and start a free 30 Day Trial today.<\/p>\n","protected":false},"author":70,"featured_media":47249,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","inline_featured_image":false,"footnotes":""},"categories":[2781,2337],"tags":[],"collection":[2779,2775],"platform":[],"funnel_stage":[3016],"coauthors":[2515],"acf":[],"yoast_head":"\nComplying with the HIPAA Security Rule<\/h2>\n\n\n\n
Major HIPAA Security Areas<\/h2>\n\n\n\n
\n
How JumpCloud Helps<\/h2>\n\n\n\n
Learn More On JumpCloud & HIPAA Security Rule Compliance<\/h2>\n\n\n\n