data transmission standards | calculating roi | planning for ebusiness | whitepapers | T5 tech specs | T5 training
         
Templar 5 and HIPAA

Below are some basic questions about HIPAA and how Templar 5 address the issues.

How is Templar's AS2 functionality related to HIPAA?
Templar’s ability to send information via HTTP(S) or AS2 follows HIPAA’s security rules that address electronically protected health information. HIPAA standards require that all information remain fully encrypted in transit between two organizations

Who is using AS2 for HIPAA, and in what scenarios?

Every healthcare provider or any service provider who submits and receives transactions electronically having to do with healthcare, including government agencies, must transmit data via HIPAA security standards. Templar's AS2 functionality abides by all HIPPA standards for secure data transfer and will simplify and guarantee patient privacy.

What are the benefits of using Templar's AS2 functionality for HIPAA?

Utilizing Templar's AS2 functionality for HIPAA automatically allows the user to connect to any other certified AS2 solution on the market (see ebusinessready.org for more details on AS2 certified products). This means that your customer or Trading Partner need only another certified AS2 solution to connect with you, it does not need to be Templar. Templar's AS2 functionality directly addresses HIPPA security requirements for electronic signature, privacy and transaction necessities, asynchronous message disposition notification (receipt), ability to package audio or video and the software is robust to allow for scalability.

What specific HIPAA requirements does Templar's AS2 functionality address?

Templar's AS2 functionality addresses the HIPAA security rules for:

  • Electronic Signature
    • User authentication
    • Non-Repudiation of receipt and origin
    • Message Integrity
  • Transmission Security
    • Transfer of encrypted data over a HTTP(S) connection
    • SMIME encryption
    • Digital signing of data to validate sender and receiver
    • Message Disposition Notification to prove data transfer and receipt of data
  • Encryption and Decryption
    • Templar will encrypt and decrypt all AS2 messages
    • HTTP(S) allowing for encrypted data transmission
  • Access Control
    • Templar has the ability to grant certain access rights to each user
    • Templar has the ability to limited access rights to users

Templar safeguards all sensitive patient records (social security numbers, medical history, address, telephone numbers) during transmission over the Internet assuring complete privacy and security.

Can I leverage Templar's AS2 functionality with other health standards (HL7, NCPDP, etc.)?

Yes, Templar's AS2 functionality has the ability to transfer any type of data. The data can be EDI, XML, Video, Jpeg, etc. Templar can transfer any flat file in any format.

Does Templar's AS2 functionality support "mailboxing" of messages or pull-style messaging?

AS2 does not have specific features for pull-style messaging. Software vendors and end users may implement this type of "mailbox" style delivery using AS2 as the underlying message transport.

   
What is HIPAA?

HIPAA is the Health Insurance Portability and Accountability Act. Article II of the law regulates the use of individual's protected health information. There are four basic HIPAA principles:

  • Consumer Control - The regulation provides consumers with critical new rights to control the release of their medical information.
  • Boundaries - With few exceptions, an individual's health care information can be used only for health care purposes.
  • Accountability - Under HIPAA, for the first time, there will be specific federal penalties if a patient's right is violated.
  • Security - It is the responsibility of organizations that are entrusted with health information to protect it against deliberate or inadvertent misuse or disclosure.

In addition, HIPAA is a wide-ranging set of U.S. government legislation intended to:

  • Enhance portability of individual health plans from one provider to another
  • Provide privacy for patient information
  • Lower industry costs by prescribing standards for health claim-related transactions

There are many discussion groups and web sites dedicated to HIPAA. The U.S. government organizations responsible for HIPAA include

WEDI/SNIP is an influential HIPPA DSMO (Designated Standards Maintenance Organization).