Updated 2025: Looking for a Business Associate Agreement? Download our FREE template

TotalHIPAA Logo

Windows XP™ is Gasping for Breath – HIPAA Compliance Becomes an Issue

Summary:

Microsoft: Bring out your dead…. Bring out your dead! Windows 8: Here’s one! Windows XP: I’m not dead yet! Windows 8: Well, can you hang around for a couple of minutes? He won’t be long. Windows XP: I feel fine, I feel happy, I feel happy! (Inspired by Monty Python and the Holy Grail) Selecting […]

Microsoft: Bring out your dead…. Bring out your dead!

Windows 8: Here’s one!

Windows XP: I’m not dead yet!

Windows 8: Well, can you hang around for a couple of minutes? He won’t be long.

Windows XP: I feel fine, I feel happy, I feel happy!

(Inspired by Monty Python and the Holy Grail)

Selecting the right Windows operating system for your PCs is more confusing than ever, and HIPAA makes this decision even more important.

Windows XP has had a remarkable shelf life, but Microsoft has set April 8, 2014, as the last day they will support XP. Here is Microsoft’s Countdown Clock. This means no more security updates, and you should consider yourself vulnerable to hackers. XP still accounts for 20% of all computers online, which means millions of companies are in a difficult position.

Windows XP is a really old operating system. I mean, it’s ancient in computer terms. It was first released in 2001… that’s 13 years old, folks. You are 2 operating systems behind what is current, and this XP jalopy is ready to go to the scrap heap before your new computer dies.

What does this mean for you and HIPAA compliance? Well, this means that you are not going to be HIPAA compliant if you are using XP after April 8th. That’s right, the HIPAA Security Rule requires that you protect your client’s PHI, and make sure that sensitive data doesn’t fall into the wrong hands. If you’re using an outdated operating system like XP, that doesn’t have any security updates, you are vulnerable, and not HIPAA compliant.

When you upgrade your computers make sure the operating system has a support and commitment for security upgrades. There are all kinds of malware out there looking for PCs to attack; so regular security updates are a must. Do you need to be HIPAA compliant?  If so, you will need to choose between Windows 7 and 8.1 or wait for 9. One of the most important updates to the recent HIPAA 2013 Omnibus ruling now requires that you encrypt all files containing Protected Health Information stored on computers. Windows 7 Professional and Enterprise, as well as 8.1, have this ability built into the operating system for no extra cost.

Making the choice on which operating system has become more confusing. HP just announced that ‘Back by Popular Demand,’ they are offering consumers a choice and will install either Windows 7 or 8 on new desktops. Their assessment is that customers have been equivocal about Windows 8’s tiled interface since its launch in October 2012.  Windows 7 has a 55% share of the OS worldwide and Window 8 only claims a 7.8% share. Windows 9 is projected to bring significant changes. Once 9 is released, Microsoft will move away from Windows 8 branding.

In short, XP’s time has come. Talk to your IT professional today, and come into the second decade of the 21st century… it’s much safer here!

By Jason Karn
Google+

Sharing is caring!

Looking for a Business Associate Agreement?

Download our free template to get started on your path toward HIPAA compliance.

Download Now

Want to stay informed?

Join our community, stay ahead of the curve on HIPAA compliance and receive free expert guidance.

Related Posts

HHS’ Office for Civil Rights Settles Ransomware Investigation with Health Plan

HHS’ Office for Civil Rights Settles Ransomware Investigation with Health Plan

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a $450,000 settlement with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans. Triggered by a 2021 ransomware attack that compromised the electronic Protected Health Information (ePHI) of over 10,000 individuals, the investigation revealed systemic failures to conduct accurate risk analyses and implement proper policies and procedures. This case serves as a massive wake-up call. HIPAA compliance extends far beyond traditional healthcare settings; it applies to any organization managing employer-sponsored group health plans, including self-funded and self-insured arrangements.

Why do we need to test our Disaster Recovery Plan every year?

Why do we need to test our Disaster Recovery Plan every year?

Even if your internal software and servers remain perfectly static, the infrastructure, vendor updates, and cyber threats around them are constantly shifting. Waiting 2 or 3 years to test your backup systems leaves you vulnerable. This post breaks down the four external factors that degrade an untested playbook, explores HIPAA compliance mandates under NIST SP 800-66, and provides a granular, step-by-step example of what a compliant disaster recovery blueprint actually looks like.

How to Maintain HIPAA Compliance in Public Cloud Environments

How to Maintain HIPAA Compliance in Public Cloud Environments

Storing ePHI in the public cloud offers scalability but requires a strict “Shared Responsibility” approach. To remain HIPAA compliant, organizations must go beyond basic Business Associate Agreements (BAAs). The implementation of AES-256 encryption, multi-factor authentication (MFA), and microsegmentation are now required. This guide outlines the essential steps to securing your cloud infrastructure while meeting the latest HHS and OCR standards.

Save & Share Cart
Your Shopping Cart will be saved and you'll be given a link. You, or anyone with the link, can use it to retrieve your Cart at any time.
Back Save & Share Cart
Your Shopping Cart will be saved with Product pictures and information, and Cart Totals. Then send it to yourself, or a friend, with a link to retrieve it at any time.
Your cart email sent successfully :)