10.08.2013 Views

ehr onc final certification - Department of Health Care Services

ehr onc final certification - Department of Health Care Services

ehr onc final certification - Department of Health Care Services

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Response. We disagree. As stated above, we believe that audit log capabilities<br />

are an essential component <strong>of</strong> Certified EHR Technology. As we mentioned above, we<br />

believe that the actions we have specified in the standard, in response to public comment,<br />

are already common industry practice. Moreover, audit logs will provide valuable<br />

information to eligible pr<strong>of</strong>essionals and eligible hospitals in the event <strong>of</strong> a security<br />

incident.<br />

Comments. Several commenters acknowledged the importance <strong>of</strong> the audit log,<br />

but emphasized that the audit log requirements should address the availability <strong>of</strong> the audit<br />

log and its security. Several commenters recommended that additional requirements be<br />

added, including that the audit log always be on during normal production for the<br />

minimum elements specified in 170.210(b), be maintained in a secure manner, be<br />

produced in a human readable format, and be retained in conjunction with the retention<br />

period <strong>of</strong> the record.<br />

Response. We agree with these commenters on the merits <strong>of</strong> their suggestions. In<br />

particular, we note that audit logs provide an important resource for eligible pr<strong>of</strong>essionals<br />

and eligible hospitals. Audit logs can assist in the identification <strong>of</strong> security incidents,<br />

such as unauthorized access, as well as serve to deter users from conducting fraudulent or<br />

abusive activities and detect such activities. The purpose <strong>of</strong> adopted <strong>certification</strong> criteria<br />

is to specify the capabilities Complete EHRs and EHR Modules must include in order to<br />

be certified, not when such capabilities must be used. Accordingly, we do not believe<br />

that it would be appropriate to specify in this <strong>certification</strong> criterion the time period for<br />

which an audit log should be “on.” We agree with commenters that audit logs should be<br />

maintained in a secure manner. For this reason, we have preserved the capability we<br />

Page 109 <strong>of</strong> 228

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!