10.08.2013 Views

ehr onc final certification - Department of Health Care Services

ehr onc final certification - Department of Health Care Services

ehr onc final certification - Department of Health Care Services

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Comment. One commenter suggested that we require automated notification <strong>of</strong><br />

user activity to system administrators when emergency access is invoked.<br />

Response. We appreciate this suggestion. However, at the present time, we do<br />

not believe that this requirement should be a condition <strong>of</strong> <strong>certification</strong> because a person<br />

or entity’s organizational policies and procedures may ensure timely notification <strong>of</strong><br />

appropriate personnel.<br />

§170.302(q) - Automatic log-<strong>of</strong>f<br />

Meaningful Use Stage 1<br />

Objective<br />

Protect electronic health<br />

information created or<br />

maintained by the certified<br />

EHR technology through the<br />

implementation <strong>of</strong><br />

appropriate technical<br />

capabilities<br />

Meaningful Use Stage 1<br />

Measure<br />

Conduct or review a security<br />

risk analysis per 45 CFR<br />

164.308 (a)(1) and implement<br />

security updates as necessary<br />

and correct identified security<br />

deficiencies as part <strong>of</strong> its risk<br />

management process<br />

Page 103 <strong>of</strong> 228<br />

Certification Criterion<br />

Interim Final Rule Text:<br />

Automatic log-<strong>of</strong>f. Terminate an<br />

electronic session after a predetermined<br />

time <strong>of</strong> inactivity.<br />

Final Rule Text:<br />

§170.302(q)<br />

Unchanged<br />

Comments. One commenter supported this requirement. Another commenter<br />

c<strong>onc</strong>urred with the purpose <strong>of</strong> the <strong>certification</strong> criterion, but noted that it may be difficult<br />

in some circumstances for eligible pr<strong>of</strong>essionals or eligible hospitals to implement this<br />

capability if the Certified EHR Technology is <strong>of</strong>fered as a service and multiple<br />

individuals are using the Certified EHR Technology at the same time.<br />

Response. We appreciate the commenters’ support for the adoption <strong>of</strong> this<br />

<strong>certification</strong> criterion. We believe that automatic log<strong>of</strong>f capabilities are commonplace<br />

and that this <strong>certification</strong> criterion can be met by any Complete EHR or EHR Module<br />

developer. We are aware that many web services today log<strong>of</strong>f customers after a period <strong>of</strong><br />

inactivity and do not believe this requirement is unduly burdensome for any Complete<br />

EHR or EHR Module developer.<br />

§170.302(r) - Audit log

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!