HIPAA Compliance with Greenway Health: Intergy & Prime Suite
Greenway Health EHR & HIPAA Overview
Greenway Health provides Intergy (on-premise) and Prime Suite (cloud-based) EHR solutions serving small to mid-size practices. These platforms include role-based access control, audit trail capabilities, encryption features, and patient portal functionality. HIPAA compliance requirements differ based on whether you deploy on-premise (requiring your IT infrastructure security) or cloud-based (requiring vendor BAA), making proper understanding of your deployment critical.
10 HIPAA Compliance Configuration Steps for Greenway Health
1. Verify Your Deployment Model and Security Responsibilities
- Identify whether you're using Intergy (on-premise) or Prime Suite (cloud)
- For Prime Suite: Execute and maintain current Business Associate Agreement with Greenway
- For Intergy: Understand your organization is responsible for infrastructure security (servers, backups, encryption)
- Document security responsibilities specific to your deployment model
- Review deployment security documentation from Greenway
2. Configure User Roles and Access Controls
- Navigate to Administration → User Management → Roles in Greenway
- Create specific roles matching clinical and administrative functions
- Apply principle of least privilege: each role has minimum necessary permissions
- Restrict system administration and configuration to essential personnel
- Document all roles and review quarterly for continued appropriateness
3. Implement Strong Authentication Policies
- Enforce minimum 12-character passwords with complexity requirements
- Enable Multi-Factor Authentication (MFA) for all user access
- Configure automatic session timeout after 15 minutes of inactivity
- Disable password sharing and enforce unique user credentials
- Set password expiration to 90 days with change history enforcement
4. Enable Comprehensive Audit Trail Logging
- Navigate to Administration → Audit Trail Settings
- Enable detailed logging of all user access, modifications, and deletions
- Configure alerts for suspicious activities (bulk downloads, unusual hours, multiple failed logins)
- Schedule monthly audit trail reviews with documented findings
- Retain all audit logs for minimum 6 years per HIPAA requirements
5. Establish Access Review and Termination Procedures
- Implement quarterly user access reviews by department managers
- Deactivate terminated employee accounts within 24 hours
- Maintain documentation of all access changes with approval evidence
- Generate monthly active user reports for comparison with HR records
- For Intergy on-premise: Verify deactivated accounts are removed from all systems
6. Configure Data Encryption (Deployment-Specific)
- For Prime Suite Cloud: Verify Greenway encrypts data at rest and in transit
- For Intergy On-Premise: Implement encryption for data at rest using AES-256
- Enforce TLS 1.2+ encryption for all data in transit regardless of deployment
- Enable encryption for all backups (on-premise responsibility) or verify cloud encryption
- Document encryption configuration in your security policies
7. Implement On-Premise-Specific Security (If Using Intergy)
- Secure server access with firewalls and network security controls
- Implement regular system patching and security updates
- Configure server-level access controls and logging
- Establish secure backup procedures with encryption and offsite storage
- Document disaster recovery procedures and test quarterly
8. Manage Third-Party Integrations
- Review all external system integrations (labs, imaging, pharmacy, billing) for HIPAA compliance
- Verify all third-party vendors have signed Business Associate Agreements
- Implement secure integration protocols (encryption, secure authentication)
- Monitor and audit all external data access and transfers
- Disable unnecessary integrations to minimize risk exposure
9. Implement Patient Portal Security
- Configure patient portal with strong authentication requirements
- Enforce patient account lockout after 5 failed login attempts
- Enable encryption for all patient-provider secure messaging
- Restrict patient access to their own records only
- Set session timeout for inactive patient accounts (15 minutes maximum)
10. Establish Incident Response and Breach Procedures
- Document incident response procedures specific to Greenway Health security events
- Create breach notification procedures aligned with HIPAA Breach Notification Rule
- For Prime Suite: Establish incident reporting process with Greenway
- For Intergy: Document your incident response and notification procedures
- Schedule annual incident response exercises and update procedures
Common Greenway Health HIPAA Pitfalls
- Confusion About Security Responsibility: On-premise vs cloud deployment changes who's responsible for encryption, backups, and security updates. Clarify responsibilities before implementation.
- Missing Prime Suite BAA: Cloud deployments require current BAA. Verify BAA is signed and covers all Greenway services you use.
- Overly Permissive Default Roles: Default roles may be too broad. Create customized roles and audit quarterly.
- Inadequate Audit Trail Monitoring: Having audit trails is insufficient. Schedule regular review and analysis for suspicious activity.
- Poor Intergy Server Security: On-premise deployments require proper server security, patching, and backup. Don't neglect infrastructure security.
- Unsecured Integrations: Third-party integrations require BAAs and secure protocols. Audit regularly for unauthorized data access.
Frequently Asked Questions
A: Intergy (on-premise) makes your organization responsible for server security, encryption, backups, and patching. Prime Suite (cloud) makes Greenway responsible for infrastructure, but you remain responsible for user access control, audit review, and BAA compliance. Prime Suite requires a current BAA; Intergy does not.
A: Navigate to Administration → Audit Trail Settings and enable comprehensive logging. Configure alerts for suspicious patterns. Export logs monthly for 6-year retention. Schedule monthly review and investigation of unusual activity. Verify all PHI access is logged.
A: Yes, on-premise deployment makes your organization responsible for encryption configuration. Implement AES-256 encryption for data at rest and TLS 1.2+ for data in transit. Encrypt all backups and document encryption procedures in your security policies.
A: HIPAA requires quarterly access reviews at minimum. Best practice is monthly automated reports combined with quarterly manual reviews by managers. For larger practices or Prime Suite cloud deployments, more frequent review (weekly reports) provides better security oversight.
Verify Your Greenway Health HIPAA Compliance
Get a comprehensive security assessment of your Greenway (Intergy or Prime Suite) deployment to ensure HIPAA compliance and identify improvement opportunities.
Schedule Your Assessment