Before You Begin
Ensure you have a valid UofL user account and login credentials.
Review UofL Information Security Policies and Procedures for HIPAA compliance. HIPAA is the Health Insurance Portability and Accountability Act of 1996.
Identify if your work involves PHI or regulated health data. PHI is Protected Health Information, which falls under the HIPAA act.
Objective or Task
Learn how to identify, protect and manage HIPAA-regulated health data in compliance with university and federal requirements.
Instructions
Identify HIPAA Data
- Determine if your data includes PHI, such as patient records, medical billing or health research data.
- Review university policies for definitions and examples of HIPAA-regulated data.
Protect HIPAA Data
- Store PHI only on approved, secure systems and encrypted devices.
- Limit access to PHI to authorized personnel only.
- Do not share PHI via email, cloud storage or unapproved platforms.
- Use secure methods for transmitting PHI, such as encrypted email or secure portals.
Manage and Retain HIPAA Data
- Follow university retention schedules and HIPAA requirements for health data.
- Purge PHI securely when no longer needed, unless retention is required by law.
- Report any accidental or intentional exposure of PHI immediately.
Report Incidents and Get Help
- If you suspect unauthorized access, disclosure, or loss of PHI, report the incident to secureit@louisville.edu or the ITS HelpDesk.
- For questions about HIPAA compliance or data management, contact the Information Security Office.
Outcome
After completing these steps, you will be able to identify, protect, and manage HIPAA-regulated health data in compliance with university policies and federal law.
Further Readings
- UofL Security Information
Need Additional Help
• Contact the ITS HelpDesk: Call 502-852-7997 during business hours:
o Monday through Thursday: 6:00am – 10:00pm
o Friday: 6:00am – 5:00pm
o Saturday: 7:00am – 5:00pm
o Sunday: 10:00am – 10:00pm
o University Holidays: 7:00am – 5:00pm
o Closed on Thanksgiving, the day after Thanksgiving, and Christmas.
o If you have an emergency during off hours, call the HelpDesk to be transferred to an on-call technician, or leave your request on voicemail. Your call will be returned the next day starting at 7am unless you specify a time.
• Live Chat: Chat with the ITS HelpDesk at https://apps.louisville.edu/it/livechat/phplive.php during business hours.
• Submit a Ticket: Use the self-service portal at http://service.louisville.edu to log requests or check the status of existing tickets.
• In-Person Support: Visit the iTechConnect 1:1 help located on the lower level of the Miller Information Technology Center, Belknap Campus, during business hours.