Security requirements for patient information are also outlined in HIPAA. The security rule requires covered entities and business associates to safeguard the confidentiality, integrity, and availability of patient information by:
- Identifying and protecting against reasonable threats;
- Preventing unlawful disclosures of patient information; and
- Ensuring employee compliance with the law.
Business associates must abide by strict security protocols to share PHI without violating the law. Data breaches, like those described above, threaten an efficient and safe healthcare environment. Data breaches expose information, and may render entire IT systems unavailable for use, decreasing the availability and quality of care by causing delays in appointments and provider availability. Lack of access to PHI puts the safety of patients at risk when critical information for treatment is inaccessible.