The Electronic Healthcare Network Accreditation Commission (EHNAC), a non-profit standards development organization and accrediting body for organizations that electronically exchange healthcare data, announced today the release of new criteria versions for all 18 of its accreditation programs for use starting January 1, 2019.
Significant updates to the 2019 criteria include the upgrade of all 18 stakeholder-specific accreditation programs to HITRUST CSF® Version 9.1. This update, incorporated by EHNAC in September of this year, includes the addition of EU General Data Protection Regulation (GDPR) and New York State Cybersecurity Requirements for Financial Services Companies (23 NYCRR 500). In addition to enhancing EHNAC's accreditation programs with criteria that will support GDPR and NYCRR requirements, all 18 accreditation programs will include new criteria regarding the use of international vendors and locations as well as added third-party Cloud Service Provider (CSP) criteria.
Healthcare industry stakeholders are encouraged to regularly visit the EHNAC website to download and review the latest EHNAC criteria versions in full detail. Applicant candidates commencing the accreditation or re-accreditation process in 2019 will be required to adhere to these updated criteria versions.
Following the standard, 60-day public comment period, EHNAC's criteria committee and commission has incorporated public feedback to finalize and adopt the enhanced and final criteria versions for the following accreditation programs:
The EHNAC criteria for each of its accreditation programs sets the foundational requirements for measuring an organization's ability to meet federal and state healthcare reform mandates such as HIPAA, Omnibus, ARRA/HITECH, ACA and other mandates for covered entities and business associates focusing on the areas of privacy, security, confidentiality, best practices, procedures and assets. Visit www.ehnac.org for more details or to review the latest EHNAC criteria.
1 The Cloud Enabled Accreditation Program has been modified for 2019. Many criteria covered by the prerequisite to use only FedRAMP-certified CSPs has been eliminated.
2 OSAP includes 10 different accreditation programs tailored for Accountable Care Organization Technology Service Providers; Call Centers; Data Centers; DRP Facilities; Health Information Exchange Technology Service Providers; Media Storage; Network Administrators; Printing; Product Development; and Scanning. Support has been added for accrediting Cloud Service Providers to OSAP.