DESIGNATING AN INFORMATION SECURITY OFFICER AND ESTABLISHING AN INFORMATION SECURITY TEAM

Committee Status: 
Approved
Budget Status: 
No Fiscal Impact
Decision Impact: 
Routine
FTE Impact: 
No
Funding Source: 
Other (see budget status)

Purpose

To establish a security contact for HIPAA compliance per the HIPAA Rules.  In addition this resolution establishes an Information Security Team to assist in the development and maintenance of system security policy for the County

Background

HIPAA privacy rules were adopted by the Federal Government in 1996.  In 2004 Sauk County adopted a HIPAA privacy manual which established Sauk County's privacy stance under these regulations.

In 2009, the Health Information Technology for Economic and Clinical Health Act (HITECH) Act established standards for compliance with the HIPAA security rules.

Following  this HHS published interim final regulations to implement the breach notification provisions at section 13402 of the HITECH Act (74 FR 42740), which were effective September 23, 2009.

Similarly, the Federal Trade Commission (FTC) published final regulations implementing the breach notification provisions at section 13407 for personal health record vendors and their third party service providers on August 25, 2009 (74 FR 42962), effective September 24, 2009.

For purposes of determining what information the HHS FTC breach notification regulations apply, the Department also issued, first on April 17, 2009 (published on April 27, 2009, 74 FR 19006), and then later with its interim final rule, the guidance required by the HITECH Act under 13402(h) specifying the technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals.

Additionally, to conform the provisions of the Enforcement Rule to the HITECH Act’s tiered and increased civil money penalty structure, which became effective on February 18, 2009, the Department published an interim final rule on October 30, 2009 (74 FR 56123), effective November 30, 2009.

The final set of rules published (to date) is referred to as the HIPAA Omnibus rule, published in 2013,  which attempts to "clarify" the practical application of many of the standards established prior.

As a result of the changes and "clarifications" provided in these final rules, many organzitions have under took the process of reviewing and updating their compliance programs, as is  the case with Sauk County.

Budget Status (Other/External Sources): 

No Fiscal Impact

Resolution Body

WHEREAS, Sauk County is considered a covered entity under the Federal Government’s Health Insurance Portability and Accountability Act of 1996, codified at 42 U.S.C.§ 300gg, 1181 et. seq., and 1320d et. seq.; and,

 

              WHEREAS, resolution xx-04 adopted the Sauk County HIPAA Privacy Manual which established basic provisions for implementation of the HIPAA rules within Sauk County Government; and,

 

              WHEREAS, pursuant to 45 CFR §164.308(a)(2) Sauk County is required to “identify a security official who  responsible for the development and implementation of the policies and procedures required by this subpart for the covered entity or business associates” and those responsibilities relate directly to electronic information security and are the responsibility of the MIS Coordinator; and,

 

              WHEREAS, your undersigned committees believe that it is necessary to designate the MIS Coordinator as Sauk County’s Information Security Officer and vest in that position the authority to appoint an Information Security Team and that Team be delegated the authority to make administrative policies related to the security of information systems as required by law.        

 

              NOW THEREFORE BE IT RESOLVED, by the Sauk County Board of Supervisors met in regular session, that the MIS Coordinator be designated as Sauk County’s Information Security Officer in accordance with  45 CFR § 164.308(a)(2); and,       

 

 BE IT FURTHER RESOLVED that, the Sauk County Information Security Officer is delegated the authority to appoint the Sauk County Information Security Team to be comprised of not less than one staff from each of the following departments: Corporation Counsel, Human Services, Health, ADRC, Health Care Center; and Veteran’s, with other staff as deemed necessary; and,

 

BE IT FURTHER RESOLVED that the Sauk County Information Security Team, under the guidance of the Information Security Officer, is delegated the authority to create, maintain and implement policies, procedures and standards applicable to Sauk County’s information systems, for the purpose of safeguarding Sauk County’s electronic information, and other forms of protected information, in a manner consistent with all applicable laws and regulations.

 

For consideration by the Sauk County Board of Supervisors on February 17, 2015. 

Requested Board Review Date: 
Monday, February 2, 2015
Committee Review 1: 
Pending
Committee Review 1 Date: 
Committee Review 2: 
Approved
Committee Review 2 Date: 
Committee Review 3: 
Pending