Service Manual – 60 / 63
XE_ABS_MT_AN_200224
16. HIPAA COMPLIANCE
The Health Insurance Portability and Accountability Act (HIPAA) regulations include
elements that focus on securing medical records in order to ensure patient privacy.
QUANTEL MEDICAL has implemented the following technical measures to be compliant with
the HIPAA regulations:
16.1. Security awareness and training
Implementation
specification
The covered entity must
“implement periodic
security updates”.
Security updates are controlled by
Windows Operating System (Windows
Operating System control panel/
Windows update menu).
When a new software is released; the
unit can be updated by authorized
people only (who have previously
been trained by Quantel Medical).
Protection from
malicious
software
The covered entity must
“implement procedures
for guarding against,
detecting, and reporting
malicious software.”
- Windows Firewall parameters may
be adjusted from the Control Panel
of the Windows session;
- UAC may be adjusted to the
correct level (Medium Level).
- A third party antivirus may be
installed, but the IT person who
installs this kind of software has to
adjust the appropriate parameters
and validate that the software does
not disrupt the normal functioning
of the Quantel Medical software.
- Via Windows OS settings, it is
possible to lock the access of the
memory stick on the USB
connectors (the files of the memory
stick cannot be read and cannot be
accessible).
The covered entity must
“implement procedures
for monitoring log-in
attempts and reporting
discrepancies.”
The Log-in monitoring is controlled
by Windows Operating System (audit
account login).
The covered entity must
“implement procedures
for creating, changing,
and safeguarding
passwords.”
This function is controlled by
Windows Operating System (User
Accounts window / password
management).