HIPAA Compliance with Allscripts/Veradigm: Configuration Guide
Allscripts/Veradigm EHR & HIPAA Overview
Allscripts and Veradigm (formerly Allscripts) provide comprehensive cloud-based EHR and practice management solutions. These platforms include built-in HIPAA compliance features including role-based access control through Practice Fusion, audit logging, encryption capabilities, and secure patient portals. Proper configuration of these features combined with understanding cloud vendor responsibilities is essential for compliance.
10 HIPAA Compliance Configuration Steps for Allscripts/Veradigm
1. Execute Comprehensive Business Associate Agreement
- Verify current BAA is signed and covers all Allscripts/Veradigm products you use
- Confirm BAA includes Practice Fusion, billing, patient portal, and all integrations
- Review BAA data security, encryption, backup, and breach notification provisions
- Understand shared responsibilities: vendor obligations vs. your obligations
- Update BAA annually and when deploying new products or functionality
2. Configure Practice Fusion User Roles and Permissions
- Navigate to Administration → User Management → Roles in Practice Fusion
- Create job-specific roles (clinician, billing, administrative, IT, quality assurance)
- Apply principle of least privilege: assign minimum necessary permissions
- Restrict administrative access to essential personnel only
- Document all role definitions with business justification and management approval
3. Implement Strong Authentication Policies
- Enforce minimum 12-character passwords with complexity requirements (uppercase, lowercase, numbers, special characters)
- Enable Multi-Factor Authentication (MFA) for all users globally
- Configure automatic session timeout after 15 minutes of inactivity
- Disable password sharing and enforce unique user logins per employee
- Set password expiration to 90 days with change history enforcement
4. Enable Comprehensive Audit Logging
- Verify audit logging is enabled for all PHI access and modifications
- Configure Practice Fusion to track all user logins, document views, and data changes
- Set up automated alerts for suspicious activities (bulk downloads, unusual hours, multiple failed logins)
- Schedule monthly audit log reviews with documented analysis
- Retain all audit logs for minimum 6 years per HIPAA requirements
5. Establish Access Review and Termination Procedures
- Conduct quarterly user access reviews by department managers
- Deactivate terminated employee accounts within 24 hours of termination
- Use automated HR integration when available to trigger access removal
- Run monthly active user reports and compare against HR records
- Maintain documentation of all access changes with approval evidence
6. Secure the Patient Portal and Messaging
- Enforce strong patient account passwords (12+ characters with complexity)
- Configure account lockout after 5 failed login attempts
- Enable encryption for all patient-provider secure messaging
- Restrict patient portal access to their own records only
- Implement session timeout for inactive patient accounts (15 minutes maximum)
7. Implement Data Encryption Standards
- Confirm Allscripts/Veradigm encrypts data at rest using AES-256 or equivalent
- Verify TLS 1.2+ encryption for all data in transit
- Enable encryption for all exports, downloads, and external communications
- If managing local backups, ensure encryption is enabled and keys are secured
- Document all encryption configurations in your security policies
8. Manage Third-Party Integrations and API Access
- Review all integrated applications (labs, imaging, pharmacy, EMS) for HIPAA compliance
- Verify all third-party vendors have signed Business Associate Agreements
- Implement access controls limiting integrations to necessary data only
- Monitor and audit all data flows to integrated systems
- Disable or remove unnecessary integrations to minimize risk
9. Document Cloud Security and Vendor Responsibilities
- Create a responsibility matrix showing Allscripts/Veradigm vs. your organization's security obligations
- Document data location, backup procedures, disaster recovery, and retention policies
- Establish incident notification procedures with Allscripts/Veradigm for data breaches
- Understand and document backup restoration procedures and RTO/RPO targets
- Include cloud vendor security in your overall HIPAA Security Rule documentation
10. Establish Incident Response and Breach Procedures
- Document incident response procedures specific to Practice Fusion/Allscripts security events
- Create breach notification procedures aligned with HIPAA Breach Notification Rule timelines
- Implement automated alerting for potential security incidents
- Maintain incident logs with investigation findings and remediation actions
- Schedule annual incident response exercises and update procedures
Common Allscripts/Veradigm HIPAA Pitfalls
- Incomplete BAA Coverage: Many organizations have outdated or incomplete BAAs that don't cover all products. Verify BAA annually covers all Allscripts/Veradigm services you use.
- Overly Permissive Default Roles: Default Practice Fusion roles may grant excessive access. Create customized, job-specific roles and audit quarterly.
- Weak Patient Portal Security: Patient account sharing and weak authentication create unauthorized access risks. Monitor portal usage actively.
- Inadequate Audit Monitoring: Enabling audit logging without regular review provides false compliance. Schedule monthly audit reviews with analysis.
- Unclear Cloud Responsibility: Confusion about whether Allscripts/Veradigm or your organization handles encryption, backups, and security updates creates gaps.
- Unsecured Integrations: Connecting applications without verifying BAA creates data exposure. Review and audit all integrations regularly.
Frequently Asked Questions
A: Your BAA must cover all products and services you use, including Practice Fusion, billing, patient portal, and any integrations. It should specify data encryption, backup procedures, breach notification timelines, data retention, and your access rights to security documentation. Review it annually and update when services change.
A: Create job-specific roles matching actual functions rather than using broad defaults. For example: primary care clinician, specialist, billing staff, administrative, IT. Each role should have minimum necessary permissions. Document all roles and review quarterly for continued appropriateness.
A: Cloud providers typically encrypt data at rest and in transit. Your BAA should specify this clearly. You're responsible for configuring encryption settings, managing access controls, and verifying encryption is operational. Request Allscripts/Veradigm's SOC 2 Type II report for encryption verification.
A: HIPAA requires quarterly access reviews at minimum. Best practice is monthly automated reporting combined with quarterly manual reviews by department managers. Cloud systems present increased risk, warranting more frequent monitoring than on-premise systems.
Verify Your Allscripts/Veradigm HIPAA Compliance
Get a comprehensive security assessment of your Allscripts/Veradigm configuration to ensure full HIPAA compliance and identify improvement opportunities.
Schedule Your Assessment