Frequently Asked Questions
About NHSN
- Do I need to purchase new software?
- Do I need special computer systems?
- Where do we find information on security of the NHSN site and HIPAA information to share with my Information Services department?
Do I need to purchase new software?
NHSN is an internet application and requires no special software. There is no charge for participation in the NHSN.
Do I need special computer systems?
System requirements can be found on the NHSN System Requirements page.
Where do we find information on security of the NHSN site and HIPAA information to share with my Information Services department?
Security for the NHSN is provided through the Secure Data Network (SDN). The SDN provides various controls and user authentication as follows:
- Physical and environmental controls – The computer room that houses NHSN is physically secure and environmental controls are used to protect NHSN computing resources from system damage or failure.
- Network controls - The SDN is located behind a firewall and is protected by a centralized security gateway (proxy server).
- User Authentication – All users must authenticate their identities with digital certificates
- A digital certificate provides an electronic means of proving a person's identity in order to securely conduct business with the NHSN. Digital certificates provide the following benefits:
- Data being sent to the NHSN is encrypted so that only NHSN can read it
- Provides assurance to the NHSN that the data has not been changed in transit
- Verifies that the certificate owner is the individual who actually sent the data.
The HIPAA Privacy Rule applies to the NHSN under the following:
- CDC is a public health authority authorized by law to receive patient health data.
- NHSN is a public health activity for which identifiable health data may be shared without an individual patient's authorization.
- Hospitals disclosing individually identifiable NHSN data must comply with the Privacy Rule’s requirements applicable to all covered entities, including the accounting requirements.
- For more information about the HIPAA Privacy Rule and how it relates to NHSN, the following resources are available:
- For more information about HIPAA Privacy Rule requirements, you may review the Guidance from the CDC at the following website: www.cdc.gov/mmwr/preview/mmwrhtml/m2e411a1.htm
Get email updates
To receive email updates about NHSN, enter your email address:
Contact NHSN:
-
Centers for Disease Control and Prevention
National Healthcare Safety Network
MS-A24
1600 Clifton Rd
Atlanta, GA 30333 - nhsn@cdc.gov

