Quick Overview
- This standard sets the specific requirements SFA must meet to protect Protected Health Information (PHI) and its electronic form (ePHI) under the federal HIPAA law.
- Scope is narrow: HIPAA applies only to SFA's Academic Clinics that are designated as Healthcare Components under the University's hybrid-entity designation.
- Student Health Services and Counseling Services are NOT in scope. Student treatment records are governed by FERPA, not HIPAA, and are expressly excluded from HIPAA's definition of PHI.
- It covers HIPAA's administrative, physical, and technical safeguards plus privacy and breach-notification rules, and aligns them with NIST and TAC 202.
- HIPAA is federal law, so meeting this standard is mandatory; no exception may authorize breaking a HIPAA-required control.
HIPAA is the federal law that protects people's health information. This standard spells out what SFA's health care operations
must do to keep that information confidential, accurate, and available: analyze and manage risk, train the workforce, control who
can see records, secure devices and facilities, sign agreements with outside vendors, honor patient privacy rights, and notify people
if a breach happens. Because SFA is only partly a health care organization, these rules apply to a limited set of clinics
rather than to the whole University.
|
i
|
Policy vs. Standard
The matching policy (06-107.1) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps will live in procedures.
|
Who This Applies To
This standard applies to SFA's Academic Clinics that are designated as Healthcare Components under the University's
hybrid-entity designation (45 CFR 164.105), and to any unit, system, or function that creates, receives, maintains, or transmits
PHI/ePHI on behalf of one of those clinics. It covers the workforce members of those components
(employees, faculty, staff, students acting in a workforce role, volunteers, and trainees) and the outside business associates
who handle PHI for them. It applies wherever PHI is handled: on-premises, in the cloud, on mobile devices, on removable media, and on paper.
Important scope note: Student Health Services and Counseling Services are NOT in scope of HIPAA.
Records created when SFA treats its own students are student treatment records governed by FERPA, and federal law
expressly excludes those records from HIPAA's definition of PHI. Do not apply this HIPAA standard to student health or
counseling records; those are handled under FERPA and SFA's privacy standards instead.
|
i
|
Baseline, not a ceiling
Everything here is the minimum SFA must do. Where this standard and another SFA standard cover the same control, the more stringent requirement governs for Healthcare Components. Departments may add stricter requirements, but never anything weaker.
|
Who Is Responsible
Key roles & responsibilities
⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
- SFA Chief Information Security Officer (CISO): Serves as, or formally designates, the HIPAA Security Officer and owns the Security Rule compliance program for all Healthcare Components. Directs risk analysis and risk management for ePHI, approves the control baseline, and coordinates incident response and breach decisions with the Privacy Officer.
- Privacy Officer (PO): Serves as the HIPAA Privacy Official. Owns the privacy policies, the Notice of Privacy Practices, patient rights, authorizations, and privacy training, and co-leads breach risk assessments with the CISO.
- HIPAA Security Officer: The person formally assigned to develop and implement the Security Rule controls for ePHI. This may be the CISO or a delegate who reports to the CISO.
- Healthcare Component Management: The directors and supervisors of the designated clinics who make sure local workflows, access, facilities, and vendor relationships follow this standard, and who approve and review workforce access.
- Office of Information Security: Builds and runs the technical and physical safeguards, such as access control, audit logging, encryption, and backups, under the CISO's direction.
- Workforce Members: Everyone working under a Healthcare Component must complete HIPAA training, use PHI only as permitted and only to the minimum necessary, protect their credentials and workstations, and report suspected incidents promptly.
- Business Associates: Outside vendors that handle PHI for a clinic must sign a Business Associate Agreement, safeguard the information, and report incidents and breaches to SFA on time.
Full role definitions
Complete responsibilities for each role are in the attached standard PDF.
What This Standard Requires
The requirements are grouped into six areas that follow the structure of the HIPAA Rules. Expand any area for a plain-language summary
of what it requires. The official requirement numbers (like 06-107.1.7.1.1) are shown so you can match them to the attached PDF.
1 Administrative Safeguards
HIPAA
People, policies & oversight
⌄
These are the management practices that keep ePHI safe: analyzing risk, assigning responsibility, training people, and planning for emergencies.
- Maintain a documented Security Management Process and conduct a thorough Risk Analysis of ePHI, reviewed at least annually and after major changes (06-107.1.7.1.1).
- Take Risk Management measures to reduce risks to a reasonable and appropriate level, and track remediation and residual-risk decisions to closure (06-107.1.7.1.2).
- Apply a documented Sanction Policy, consistently and proportionately, against workforce members who violate the rules (06-107.1.7.1.3).
- Regularly review records of system activity such as audit logs, access reports, and incident reports for systems holding ePHI (06-107.1.7.1.4).
- Formally assign, in writing, a HIPAA Security Officer (the CISO or a delegate reporting to the CISO) (06-107.1.7.1.5).
- Implement Workforce Security procedures for authorizing, supervising, clearing, and promptly terminating access to ePHI (06-107.1.7.1.6).
- Implement Information Access Management so access to ePHI follows least privilege and role-based need (06-107.1.7.1.7).
- Run a Security Awareness and Training program, including malware, log-in monitoring, and password practices, at least annually (06-107.1.7.1.8).
- Follow Security Incident Procedures to identify, respond to, document, and mitigate incidents, coordinating with the Privacy Officer (06-107.1.7.1.9).
- Maintain a Contingency Plan with data backup, disaster recovery, and emergency-mode operation, and test it periodically (06-107.1.7.1.10).
- Perform periodic technical and nontechnical Evaluations of Security Rule compliance and feed gaps into risk management (06-107.1.7.1.11).
2 Physical Safeguards
HIPAA
Facilities, workstations & devices
⌄
These protect the physical places, computers, and media where ePHI lives, from the building down to a USB drive.
- Implement Facility Access Controls, including a facility security plan, access validation, visitor control, and maintenance records (06-107.1.7.2.1).
- Set Workstation Use rules covering proper functions, screen positioning, and privacy in shared or public areas (06-107.1.7.2.2).
- Apply Workstation Security safeguards such as theft protection, privacy filters, automatic locking, and controls for mobile devices (06-107.1.7.2.3).
- Enforce Device and Media Controls for disposal, re-use, accountability, and backup, sanitizing media consistent with NIST SP 800-88 (06-107.1.7.2.4).
3 Technical Safeguards
HIPAA
Access, logging & encryption
⌄
These are the technology controls built into the systems themselves, so only the right people and programs can reach ePHI and any tampering can be detected.
- Implement technical Access Control with unique user IDs, emergency access, automatic logoff, and encryption of ePHI at rest as standard practice (06-107.1.7.3.1).
- Implement Audit Controls that record and examine activity in systems containing ePHI, protected against tampering (06-107.1.7.3.2).
- Implement Integrity controls to confirm ePHI has not been improperly altered or destroyed (06-107.1.7.3.3).
- Require Person or Entity Authentication, including multi-factor authentication for remote and privileged access to ePHI systems (06-107.1.7.3.4).
- Apply Transmission Security, encrypting ePHI in transit across open or untrusted networks as standard practice (06-107.1.7.3.5).
4 Organizational Requirements
HIPAA
Agreements, hybrid entity & records
⌄
These define SFA's formal structure as a HIPAA hybrid entity and its written commitments with vendors and plans.
- Obtain a signed Business Associate Agreement (BAA) from every vendor handling PHI, before any PHI is shared, and ensure subcontractors do the same (06-107.1.7.4.1).
- Maintain a documented Hybrid Entity designation naming the Healthcare Components, and retain it for at least six years (06-107.1.7.4.2).
- If SFA sponsors a group health plan that is a covered entity, ensure plan documents require proper safeguards and separation; if not, document why this does not apply (06-107.1.7.4.3).
- Keep required policies, procedures, and records in writing for six years, available to those who implement them, and updated as conditions change (06-107.1.7.4.4).
5 Privacy Rule Requirements
HIPAA
Patient rights & proper use
⌄
These govern how PHI may be used and shared, and the rights patients have over their own information.
- Use and disclose PHI only as the Privacy Rule permits or as the individual authorizes in writing (06-107.1.7.5.1).
- Apply the Minimum Necessary standard, limiting PHI to the least needed for the purpose, with role-based access (06-107.1.7.5.2).
- Maintain and provide a Notice of Privacy Practices (NPP) explaining uses, rights, duties, and how to complain (06-107.1.7.5.3).
- Fulfill individual rights, including access, amendment, accounting of disclosures, restrictions, and confidential communications (06-107.1.7.5.4).
- Obtain a valid written Authorization for any use or disclosure not otherwise permitted, including most psychotherapy notes and marketing (06-107.1.7.5.5).
- Train the workforce on privacy, designate a Privacy Officer, provide a complaint process, apply sanctions, and prohibit retaliation (06-107.1.7.5.6).
6 Breach Notification
HIPAA
Telling people when PHI is exposed
⌄
If unsecured PHI is exposed, HIPAA sets strict rules and deadlines for deciding whether it is a breach and who must be told.
- Treat any impermissible exposure of unsecured PHI as a presumed breach unless a documented four-factor Breach Risk Assessment shows low probability of compromise (06-107.1.7.6.1).
- Notify each affected individual in plain language without unreasonable delay and no later than 60 calendar days after discovery (06-107.1.7.6.2).
- For a breach affecting more than 500 residents of a State or jurisdiction, notify prominent media within the same 60-day window (06-107.1.7.6.3).
- Notify the Secretary of HHS via the breach portal, immediately for 500 or more, and via annual log for smaller breaches (06-107.1.7.6.4).
- Require business associates, through their BAAs, to report breaches to SFA within 60 days and identify affected individuals (06-107.1.7.6.5).
- Keep documentation proving notifications were made, or that the burden of proof was met, and retain it for at least six years (06-107.1.7.6.6).
Conformance & Exceptions
Conformance is mandatory for all SFA Healthcare Components and their workforce members, business associates, and systems.
Requests for an exception must be submitted, risk-assessed, and approved or denied through the exception process in the SFA 06-107.1 policy,
with the SFA Chief Information Security Officer (CISO) and the Privacy Officer as required approvers. Approved exceptions must be documented,
time-limited, compensated by alternative controls where feasible, and retained for at least six years.
|
!
|
Important
HIPAA is federal law. Where any University practice conflicts with these requirements, HIPAA and this standard control, and no exception may authorize noncompliance with a control that HIPAA itself requires. Exceptions may only address how a required outcome is achieved, never whether it is met.
|
Compliance Mapping (Reference)
For auditors and security staff. Everyday users can skip this section.
Frameworks & control references
⌄
Each requirement in this standard maps to one or more of these authoritative sources:
- HIPAA, 45 CFR Parts 160 and 164, including the Security Rule (Subpart C), Privacy Rule (Subpart E), Breach Notification Rule (Subpart D), and organizational provisions (164.105, 164.314, 164.316).
- NIST SP 800-66 Rev. 2, Implementing the HIPAA Security Rule.
- NIST SP 800-53, for example the AC, AT, AU, CP, IR, MP, PE, PS, and PT control families.
- TAC 202, for example 202.71, 202.72, 202.73, 202.74, 202.75, and 202.76.
The full requirement-by-requirement control mapping is in the attached standard PDF and the SFA 06-107 Controls Crosswalk.
Related Policies & Standards
Supporting policy: SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy
Related standards:
Definitions: SFA 06-107 Definitions
Other references:
- 45 CFR Part 160 — General Administrative Requirements
- 45 CFR Part 164 — Subparts A, C, D, and E (including 164.105 Hybrid Entity Designation)
- NIST SP 800-66 Rev. 2 — Implementing the HIPAA Security Rule (February 2024)
- NIST SP 800-53 Rev. 5 — Security and Privacy Controls for Information Systems and Organizations
- NIST SP 800-88 Rev. 1 — Guidelines for Media Sanitization
- Texas Administrative Code, Title 1, Part 10, Chapter 202 — Information Security Standards (TAC 202)
- HHS HIPAA Security Rule NPRM, 90 FR 898 (proposed January 6, 2025) — referenced as forthcoming; not in force as of this standard's effective date
Responsible office: Office of Information Security; Privacy Officer ·
Contact: itsecurity@sfasu.edu
|
📎
|
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.
|
Need Help?
Contact the IT Help Desk at
(936) 468-4357 (HELP) or submit a ticket at
help.sfasu.edu.
For questions about this standard, contact the Office of Information Security at
itsecurity@sfasu.edu.