Skip to page content


HIPAA TIPS OF THE WEEK



3.24.08 TIP OF THE WEEK
Auditing User's Access To Electronic PHI (ePHI)

Employees may only access electronic protected health information(ePHI) for purposes necessary to perform their own job duties.  The institution has put in place audit controls and is committed to using the appropriate controls on its information systems that contain or use ePHI (e.g. OACIS).  These systems are monitored to evaluate:

  • Access to certain data  (e.g. sensitive ePHI like HIV or mental health records).
  • Failed authentication attempts.
  • Possible security vulnerabilities and incidents.
  • User or system activity where appropriate.

Contact the HIPAA Program Office at 4-9716 or
HPO@bsd.uchicago.edu. for more information.




Back to Tips




Call 4-9716 for more details.