Introducing TypingDNA Human Likeness – A Novel Bot Detection Approach for the AI Age 

HIPAA Compliance Software

HIPAA compliance security software can help organizations implement safeguards designed to protect electronic protected health information (ePHI). The HIPAA Security Rule requires regulated organizations to protect the confidentiality, integrity, and availability of ePHI through administrative, physical, and technical safeguards. When employees work remotely or outside traditional healthcare facilities, protecting ePHI across endpoints can become an additional challenge.

HIPAA compliance software when working remotely

HIPAA compliance security software can support organizations in meeting requirements under the HIPAA Privacy and Security Rules. Among other safeguards, the Security Rule requires access controls that allow only authorized persons to access ePHI and procedures to verify that a person seeking access is who they claim to be. These requirements also apply when employees work remotely and have access to ePHI.

Authentication is therefore an important part of protecting access to healthcare information. TypingDNA Verify 2FA provides phone-free two-factor authentication using typing biometrics. When authentication is required, users type 4 short words displayed on-screen, allowing organizations to add an additional authentication step without requiring employees to use personal phones or additional authentication hardware.

Protecting access does not necessarily end at login. An authenticated workstation may be left unlocked and unattended, shared with another person, or otherwise accessed by an unauthorized user. TypingDNA ActiveLock adds continuous authentication to Windows and macOS endpoints by verifying the person behind the keyboard based on how they type. If an unauthorized user is detected, ActiveLock can lock the computer and alert administrators, helping reduce the risk of unauthorized access to ePHI after login.

The importance of endpoint safeguards has also appeared in HIPAA enforcement actions. For example, in 2016, Advocate Health Care Network agreed to a $5.55 million settlement following several incidents affecting approximately 4 million individuals. HHS identified issues including inadequate risk analysis, physical access controls, and failure to reasonably safeguard an unencrypted laptop containing ePHI. Continuous authentication can help address unauthorized use of an endpoint, but it should be used alongside other HIPAA safeguards such as encryption, access controls, device security, risk management, and appropriate policies and procedures.

HIPAA compliance depends on an organization's overall safeguards, policies, procedures, risk analysis, and implementation. Authentication technologies such as Verify 2FA and ActiveLock can support specific access control and identity verification objectives, but no single software product makes an organization HIPAA compliant on its own.

Learn more about protecting sensitive data and supporting HIPAA security controls for remote and hybrid work.