Medi-Cal Minimum Computer Security Requirements

It is the responsibility of every California Medicaid (Medi-Cal) medical provider to comply with these minimum requirements. We, at The Tech Info Group, have a great deal of experience ensuring that you are in continuous compliance with these and other medical computer related data and network security requirements.

Are your records safe and protected from hacking, internal theft, accidental loss and/or disclosure? Is your MDS and data always in compliance and ready for an audit? We make sure that the answer to both of these questions is "YES."

The following requirements are being provided to all Medi-Cal users in an ongoing effort to assist all users in understanding the importance of the protection of Protected Health Information (PHI) and how it relates to computer security measures.

Any computer accessing the Medi-Cal Web site is required to abide by all applicable State and Federal laws enacted today or in the future.

All provider computers that access Medi-Cal data must meet the following requirements, in addition to any State and Federal required administrative, technical, physical and organizational safeguards:

  1. Anti-virus software. All workstations, laptops and other systems that access the Medi-Cal Web site or process and/or store Medi-Cal PHI must install and actively use a comprehensive anti-virus software solution with automatic updates scheduled at least daily.
  2. Patch Management. All workstations, laptops and other systems that access the Medi-Cal Web site or process and/or store Medi-Cal PHI must have critical security patches applied, with system reboot if necessary. There must be a documented patch management process, which determines installation timeframe based on risk assessment and vendor recommendations. At a maximum, all applicable patches must be installed within 30 days 
    of vendor release.
  3. System Timeout. The systems that access the Medi-Cal Web site or process and/or store Medi-Cal PHI must provide an automatic timeout, requiring re-authentication of the user session. It is recommended that the automatic timeout be after no more than 20 minutes of inactivity.
  4. User Name and Password Controls. The systems that access the Medi-Cal Web site or process and/or store Medi-Cal PHI should be accessed using a unique user name.  The user name must be promptly disabled, deleted, or the password changed upon the transfer or termination of an employee with knowledge of the password. Passwords are not to be shared. 

    Passwords must:
  • Be at least eight characters
  • Be a non-dictionary word
  • Not be stored in readable format on the computer
  • Be changed every 90 days, preferably 60 days
  • Be changed if revealed or compromised, and
  • Be composed of characters from at least three of the following four groups from the standard keyboard:
    • Uppercase letters (A-Z)
    • Lowercase letters (a-z)
    • Arabic numerals (0-9)
    • Non-alphanumeric characters (punctuation symbols)
  1. Workstation/Laptop Encryption. All workstations and laptops that access the Medi-Cal Web site or process and/or store Medi-Cal PHI are recommended to be encrypted using a FIPS 140-2 certified algorithm, which is 128-bit or higher, such as Advanced Encryption Standard (AES); full disk encryption is recommended.

Note: Fines for non-compliance may be imposed under Sections 130200 – 130205 of the California Health and Safety Code and Section 13410(d) of the Federal Health Information Technology for Economic and Clinical Health (HITECH) Act.

 
Get a Quote
   
 
Click below to get Live Support Now
 

Oct, 31 2011

  Benefits of Using IT Support Company on a Flat Rate  


Sep, 09 2011

  Finding Computer Support Company for Nursing Facility  


Sep, 07 2011

  vSphere 5 Is VMware's Jump into Data Storage Virtualization  


Aug, 17 2011

  Bomgar Analysis and Review at TTIG  


Jul, 22 2011

  What Do You Know About Your Backup?  


Jul, 22 2011

  Geopolitical Inputs Into Cloud Computing Decision  


Mar, 08 2011

  A Popular Hosting Company, Codero, is Attacked With a DDoS From China  


Feb, 13 2011

  Stuxnet. A War Among Nations – Why Should IT Managers Care?  


Aug, 11 2010

  AT&T and Verizon Design New Payment System to Compete with Credit Cards  


Jul, 11 2010

  Will The Perfect Citizen Protect?  


Jul, 04 2010

  Copper T1 Is One Way To Go, Microwave Wireless Is Another!  


Jun, 24 2010

  Don't Jump for the iPhone 4 Until You Look At Droid X  


Jun, 20 2010

  Google Apps Market Place  


Jun, 09 2010

  Microsoft and Adobe Release Critical Security Patches  


Feb, 08 2010

  Annoying explorer.exe taking up CPU fix  


Feb, 07 2010

  Biggest Mistakes Companies Make in Selecting an IT Provider or IT Company  


Jan, 26 2010

  Google Chrome Is Fast and Now Has Bookmark Sync and Extensions  


Jan, 26 2010

  Cyber Warfare Is Here - What Does That Mean For You?  


Jan, 25 2010

  Web Remote Workplace Doesn't Work with Internet Explorer - IE 8  


Dec, 09 2009

  Funny Windows 7 and Chrome Interaction  


Nov, 24 2009

  IE6 and IE7 vulnerable to latest flaw; IE8 immune  


Jul, 23 2009

  Denial of Service Attacks  


Oct, 23 2009

  New Microsoft Vulnerability Blacklisted by Firefox  


Oct, 19 2009

  New Vulnerabilities That Concern YOU!  


Aug, 01 2009

  Adobe Product Fixes Available Now  


Jul, 27 2009

  Critical Exploit Found in Adobe Products  


Jul, 08 2009

  Cyber Security And Your Family  


 

Backup Solutions

The TTIG managed backup solution is a safety net on steroids, providing daily motoring and confirmation of the integrity and safety of all data under management. Step into controlled environment of TTIG Disaster Recovery and Data Redundancy Planning.

+ Learn More
 

Security Solutions

In today's world of data vulnerability, we provide your organization with the best security practices, continuous risk assessments and even managed security monitoring when necessary. Our approach is comprehensive, our solutions increase security. Control Your Data!

+ Read More
 

Managed IT Services

We centralize our IT Management Process to ensure complete situational awareness through continuous client communication, network monitoring, alerting, and preventative network maintenance. Managed services allow for reduction of downtime through a highly proactive

+ Read More