Privacy, Security & Compliance

HIPAA Security Policies

How Rhode Island Eye Institute safeguards electronic protected health information across our practice.

Rhode Island Eye Institute ("RIEI," "the Organization," "we," or "our") has adopted the security policies described below to define the reasonable and appropriate safeguards we use to protect electronic protected health information. These policies implement the standards and specifications of the Health Insurance Portability and Accountability Act ("HIPAA") Security Rule for the Protection of Electronic Protected Health Information, codified at 45 Code of Federal Regulations, Part 164, Subpart C.

Last Revision Date: April 1, 2026

Definitions and Abbreviations

Identifiable Health Information

As set forth at 45 CFR 160.103, this refers to information that (1) is created or received by a health care provider, health plan, employer, or health care clearinghouse, and (2) relates to an individual's past, present, or future physical or mental health or condition, the delivery of health care to that individual, or the past, present, or future payment for health care provided, and (i) that identifies the individual, or (ii) with respect to which there is a reasonable basis to believe the information can be used to identify the individual.

Information Systems

An integrated set of components used to collect, store, and process data, and to deliver information, knowledge, and digital outputs.

Patient Record

A written account documenting a patient's examination and care, including medical history and complaints, the clinician's physical findings, diagnostic and procedural results, and medications and therapies administered.

Protected Health Information (PHI)

Identifiable Health Information transmitted by electronic media, maintained in electronic media, or transmitted or maintained in any other form or medium, excluding the categories described in paragraphs (1) and (2) of the definition of protected health information at 45 CFR 160.103.

Electronic Protected Health Information (EPHI)

Protected health information transmitted by or maintained in electronic media.

Sensitive Information

Information that, when combined with other accessible information, could reasonably identify an individual's health information, or that could be used to compromise the administrative, physical, or technical safeguards in place to protect protected health information.

Workforce Members

Employees, volunteers, trainees, and other individuals whose work on behalf of a covered entity or business associate is performed under the direct control of that covered entity or business associate, whether or not compensation is provided.

Assigned Security Responsibility

The Organization designates an individual to serve as its HIPAA Security Officer. The HIPAA Security Officer is responsible for maintaining and enforcing these security policies, investigating suspected violations, responding to workforce questions and complaints, and communicating the policies to workforce members. The HIPAA Security Officer keeps the Organization reasonably informed about matters that arise under these policies. In cases where the Organization engages a business associate to manage or carry out procedures that support these policies, the HIPAA Security Officer is responsible for verifying that those procedures are performed in accordance with this policy.

Reference

  • Standard: Assigned Security Responsibility (45 C.F.R. § 164.308(a)(2))
  • HIPAA Security Procedures Section(s): Assigned Security Responsibility

Security Management Process

The Organization implements policies and procedures designed to prevent, detect, contain, and correct security violations. When any part of the security management process is carried out or overseen by a business associate, the HIPAA Security Officer reviews and approves the relevant procedures to confirm alignment with this section.

Reference

  • Standard: Security Management Process (45 C.F.R. § 164.308(a)(1)(i))
  • HIPAA Security Procedures Section(s): Risk Analysis and Management

Risk Analysis

The Organization conducts an accurate and thorough risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information. This assessment is performed at least annually, and additionally whenever major information systems are implemented, business processes change, or emerging threats indicate that a more frequent review is warranted. When a risk analysis is performed or overseen by a business associate, the HIPAA Security Officer reviews and approves the methodology, evaluates the likelihood, impact, and overall risk of the threats and vulnerabilities identified, and determines which security measures are reasonable and appropriate to reduce those risks.

Reference

  • Risk Analysis (Required) (45 C.F.R. § 164.308(a)(1)(ii)(A))
  • HIPAA Security Procedures Section(s): Risk Analysis and Management

Risk Management

The Organization puts security measures in place that are sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level, consistent with the HIPAA Security Rule. The HIPAA Security Officer reviews reports and related security data provided on a periodic basis by workforce members, contractors, or business associates in order to monitor ongoing risks and vulnerabilities. When security measures are implemented or overseen by a business associate, the HIPAA Security Officer reviews and approves the procedures that govern those risk management activities, including the reports and data to be submitted to the HIPAA Security Officer.

Reference

  • Risk Management (Required) (45 C.F.R. § 164.308(a)(1)(ii)(B))
  • HIPAA Security Procedures Section(s): Risk Analysis and Management

Sanctions Policy

The Organization applies appropriate sanctions to workforce members who fail to comply with its security policies and procedures. The HIPAA Security Officer oversees the investigation of policy violations in accordance with the Organization's Human Resources ("HR") policies, and sanctions are applied to workforce members as provided under those HR policies. Sanctions applicable to business associates are administered as provided in the Business Associates section of this policy and under the agreements in effect at the time of the compliance violation.


Anonymous Compliance Hotline

Our organization maintains an Anonymous Compliance Hotline as part of our commitment to integrity, accountability, and transparency. This hotline is available to patients, visitors, and staff members and provides a safe and confidential way to report concerns related to compliance, ethics, or workplace conduct. You are not required to identify yourself.

Phone: (917) 826-1702
Voicemail Box: 9531

You may leave a message at any time. Voicemails are monitored regularly and securely forwarded to the Compliance Department.

Concerns that may be reported include, but are not limited to:

  • Violations of company policies or procedures
  • Ethical concerns
  • Harassment, discrimination, or inappropriate workplace behavior
  • Fraud, waste, or abuse
  • Patient safety or regulatory issues

All reports will be reviewed promptly and appropriate follow-up will be conducted. Retaliation for making a report in good faith is strictly prohibited.