Home > Security & HIPAA
Security & HIPAA
All transactions are made across a secure socket layer connection to the
QPAweb site. This QPA web site secures your private information using
a VeriSign SSL Certificate. Information exchanged with any address
beginning with https is encrypted using SSL before transmission.
QPAweb HIPAA COMPLIANCE INFORMATION
The QPAweb.com server, accessibility, transmissions, and database are
HIPAA compliant. The server hosting QPAweb.com is located in a HIPAA compliant Data
Center.
The QPA web site authenticates users, encrypts data and provides secure communication
between the users and the QPA application to which they are connected. The QPA
site is HIPAA Compliant, having satisfied the conditions set forth in the following
sections of the HIPAA Internet Security Standards:
164.312(a) Access control
Logical Access: Unique identification is required to access the QPA site.
Access to the QPA site is restricted and only users who have been created by the QPA
system administrator site are allowed in. The server is protected against
unauthorized exposure to the internet.
Physical Access: Access to the datacenter where the QPA site server is
located is controlled by twenty-four hours a day, seven days a week
secured access.
164.312(b) Audit controls
All sessions and transactions are logged. Monitoring applications are in place
which record and allow examination of system activity.
164.312(c) Integrity
QPA uses secure socket layer (SSL) encryption to protect the transmission
of the information submitted to QPA throughout a user’s session.
System processing is complete, accurate, timely, and authorized. No
processes in the QPA application will alter the integrity or authenticity of
data that has been entered by a user.
164.312(d) Person or entity authentication
User authentication is provided through usernames and passwords that are
required for entry to the web site.
164.312(e) Transmission security
QPA guards against unauthorized access to the site by providing
integrity control and encryption for all Internet transmissions.
|