HIPAA Compliance in ServiceDesk Plus Cloud

The Health Insurance Portability and Accountability Act (including the Privacy Rule, Security Rule, Breach notification Rule, and Health Information Technology for Economic and Clinical Health Act) ("HIPAA"), requires Covered Entities and Business Associates to take certain measures to protect health information that can identify an individual. It also provides certain rights to individuals. Zoho does not collect, use, store or maintain health information protected by HIPAA for its own purposes. However, ManageEngine ServiceDesk Plus provides certain features (as described below) to help its customers use ServiceDesk Plus Cloud in a HIPAA compliant manner.

HIPAA requires Covered Entities to sign a Business Associate Agreement (BAA) with its Business Associates. You can request our BAA template by sending an email to legal@zohocorp.com.

ServiceDesk Plus Cloud enables organizations secure their user's health-related information using the following features:

 

Mark and encrypt fields containing ePHI 

When configuring an additional field, you can mark a field containing any confidential information as electronic Protected Health Information(ePHI) and encrypt the field. You can mark single-line, multi-line, phone, email, and numeric fields as ePHI.

To add an ePHI field,

 

 

You can also add ePHI fields for incident and service request templates when configuring the template. Click here to know more.

 

Mark Resource Information containing ePHI 

Resource information added to service request templates might contain sensitive data.

To mark a resource question as ePHI,

 

 

Click here to learn how to add a resource to service templates.

 

Anonymize and erase ePHI 

In ServiceDesk Plus Cloud, you can secure personal information of users leaving the organization by configuring privacy settings. With privacy settings, you can anonymize and erase all sensitive data of deleted users.

 

To anonymize and erase ePHI fields,

 

 

 

 

Secure Data Export 

In ServiceDesk Plus Cloud, you can export sensitive data in a secure manner by embedding the data in a password protected zip file. The password protection applies to module-wise data export and reports exported or scheduled via email.

To enable password protection for your organization files,

  1. Go to Setup >> Users & Permissions >> Privacy Settings.

  2. Under the File Protection Password tab, select the Enable File Protection Password checkbox.

  3. Enter a strong password under File Password. We recommend sharing this password with the intended users using a password sharing tool to ensure security.

  4. Click Save.

 

Technicians can configure their own file protection password, which takes a higher priority over the common password.

Requesters or technicians without valid login credentials and non-users must access files shared with them using the password configured in the application.

You can reset this password anytime. Make sure you communicate the new password with the intended users using a password sharing tool.

 

 

Maintain ePHI log 

ServiceDesk Plus Cloud automatically logs all actions related to ePHI fields across the application under Setup >> Data Administration >> PII/ePHI log. Clicking a log displays detailed information on the action as given in the below screenshot:

 

 

 

To export the logs, select the required duration using the available filters. Click Export as and choose whether to export the logs in CSV/XLS format.