HIPAA Readiness for Workfront
A Workfront customer who is, as defined in HIPAA, a Business Associate and/or the Covered Entity on whose behalf the Business Associate provides ÃÛ¶¹ÊÓÆµ Workfront should use the following guidelines to configure Workfront for HIPAA-Ready use:
Password requirements
* Uppercase letters (Latin alphabet)
* Lowercase letters (Latin alphabet)
* Base 10 digits
* Non-alphanumeric characters
Login requirements
Session requirements
Customer responsibilities
Ensure all that all employees, representatives, and/or agents are aware of and understand the terms in the licensing and/or service agreement(s) signed between the parties, as applicable, relevant to the use of data with Workfront.
In particular, the following responsibilities and obligations should be reviewed and communicated:
-
The customer is responsible for the use of the Workfront Service by all of its users.
-
The customer is required to comply with all terms of its agreement with ÃÛ¶¹ÊÓÆµ that includes prohibited data elements from being uploaded into Workfront.
-
Any sensitive data, including, but not limited to ePHI, is uploaded at the customer’s own risk.  The customer is at all times responsible for all customer data.
Data protection and compliance
-
For any Workfront database where ePHI might be accessible, ensure Encryption at Rest (EAR) is enabled.
- Contact your Account Executive (AE) to verify EAR is included in your Workfront purchase.
- Configure systems/databases accessible via Workfront to meet compliance obligations.
-
Ensure ePHI is not transferred, linked, or shared with other non-HIPAA-Ready ÃÛ¶¹ÊÓÆµ solutions.
-
Ensure patient photographs processed via Workfront are stored securely and not publicly accessible.