Showing posts with label Audit. Show all posts
Showing posts with label Audit. Show all posts

Friday, August 5, 2016

Compliance Essentials: Documentation

Documentation is one of the essential cornerstones of any effective compliance program.

Henry was understandably nervous on the day his office was being audited by the Office for Civil Rights (OCR). While still feeling some butterflies, he was confident that his compliance efforts will pass the HIPAA audit. Henry was then asked a series of questions:

Auditor - Does your office have establish policies and procedures?
Henry - Yes we do!
Auditor - Show them to me.
Henry - Here is a copy of our employee handbook.
Auditor - This does not contain the necessary written information.
Henry - I thought it was enough . . .

Auditor - Does your office train your employees continuously?
Henry - Yes we do!
Auditor - Show me the training documentation.
Henry - Our employees are trained on compliance every year at our annual "compliance and pizza" meeting.
Auditor - That is not what I asked for.
Henry - I thought it was enough . . .

Auditor - Show me your breach disclosure log.
Henry - Our breach disclosure log . . .
Auditor - Do you not have one?
Henry - I'm not even sure what that log is.

At this point in the audit, Henry's confidence has vanished and he is now thinking about the possibility of having to look for another job.

OCR has stated that it views compliance as an "ongoing journey". When you are on a journey, your attention is focused on what lies ahead. However, if you stop for a moment and look behind you, you will see past evidence of your journey in the form of footprints. If you turn around, you will be able to retrace your journey by following those footprints. If it was not for your footprints, you would not be able to retrace your journey back to where you started.

This same idea of retracing your footprints and being able to follow the history of your journey, applies to your "ongoing journey of compliance". However, rather then leaving footprints behind you, you leave a paper trail called, documentation. By keeping your documentation up-to-date, you have a history of your compliance activity and evidence of where you currently stand (policies and procedures).

There are numerous benefits to good documentation:
  1. Paper Trail - This will be useful in demonstrating your compliance activity for an audit or possible protection against liability.
  2. Compliance Story - It is not only about what you did and the final outcome, but rather what factors were a part of your decision making process and what lead you to make the final decision.
  3. Hand-Me-Down - When an office changes Administrators or Compliance Officers, the newly appointed employee will be able to review previous documentation and have a better understanding of the organizations compliance history.
  4. Employee "Misunderstandings" - Documentation of policies and procedures go a long way to eliminating the employee "misunderstandings" that tend to crop-up. If an employee says that they did not know the policy, you can refer to the written policy and their acknowledgement of it that they signed during their training.
During an audit by OCR, they are wanting to look at your "ongoing journey of compliance". If your documentation is done well and is up-to-date, then you won't have to shy away from their questions. Simply take their hand and guide them through the history of your "ongoing journey of compliance" by following your own footprints.



To subscribe to this blog, enter your email address:


Delivered by FeedBurner


Tuesday, July 26, 2016

OCR's Top 7 Areas of Focus During Phase Two Audits

Areas of improvement to focus on within your office.

During phase 2 of the Office for Civil Rights (OCR) HIPAA audits, they have decided to focus their attention on seven areas of compliance. These specific areas were chosen due to their history of non-compliance during multiple audits in the past. This is not to say that OCR will not investigate other areas, but their main focus will be on these specific requirements:

  • Under the HIPAA Privacy Rule
    • Notice of Privacy Practice and consent requirements
    • Provision of notice - electronic notice (NPP acknowledgement in electronic format)
    • Right to access (Patients right to access their PHI)
  • Under the HIPAA Security Rule
    • Security management process - risk analysis (Documented and completed internal risk analysis)
    • Security management process - risk management (Documented policies and procedures that prevent, detect, contain, and correct security violations)
  • Under the Breach Notification Rule
    • Timeliness of notification (Notification of breach given to individual and OCR within required specifications)
    • Content of notification (Notification of breach contains all of the required information as specified by OCR)
These are important areas of compliance that have been neglected or out right ignored by healthcare organizations. If you have not done so, get these areas of compliance in order within your organization.

For information on how to prepare for OCR's Phase 2 HIPAA audits go to:
http://hcsiinc.blogspot.com/2016/07/preparing-for-phase-2-of-hipaa-audits.html




To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, February 5, 2016

Avoid Being On The Wall Of Shame In 2016

Lessons Learned from 2015 Health Data Breaches
Nine of the top 10 incidents in 2015 on the Department of Health and Human Services’ “wall of shame” tally of major breaches involved hacker attacks, a huge shift from previous years, when hacker attacks were relatively rare.
The biggest health data breach of 2015 - the cyber attack on health insurer Anthem Inc. - affected nearly 79 million individuals, making it, by far, the biggest healthcare breach on the list since its inception in late 2009. And the top six hacker attacks affected a combined total of 90 million individuals.
While hacker attacks account for less than 11 percent of the incidents listed on the HHS tally so far, they account for 75 percent of breach victims. Some 56 hacker breaches added to the tally in 2015, affecting a total of nearly 112 million individuals.
And a Dec. 31 snapshot of the wall of shame shows 1,425 breaches impacting a total of more than 154 million individuals. That’s more than three times the number of victims affected by health data breaches as of one year ago - a result of the massive hacker attacks.
So what are the top lessons to be learned from the epidemic of mega-hacks in 2015?
“Healthcare organizations need to become more mature in their security posture and be a lot more proactive about protecting data,” says Jay Trinckes, senior practice lead for healthcare and life sciences at the consulting firm Coalfire. “We see many small organizations basically doing the bare minimum when it comes to security, such as ‘checking the box’ type activities for HIPAA compliance. But it’s interesting to note that the top breaches are happening to the large covered entities believed to have a higher security maturity level.”
The hacker attacks point to the need for continual risk analysis, says privacy attorney Kirk Nahra. “These ‘cyber’ risks really aren’t new, but the form they take keeps evolving, and other risks change as well,” he says. “Security protection - whether as a regulatory requirement or just as smart business - cannot be stagnant; it must be reviewed, assessed and improved almost constantly.”
The cyberattacks in 2015 also point to the need to conduct more rigorous and thorough penetration testing on a regular basis, Trinckes says.
Healthcare entities, as well as their business associates, also need to comply with industry standards that go far beyond the HIPAA Security Rule, he stresses. The wall of shame indicates that business associates have been involved in about 20 percent of all breaches.
“A trend we’ve noticed is that business associates are realizing the benefits of assessing risk against many compliance standards/frameworks - including HITRUST, SOC, ISO, PCI - as a competitive differentiator to increase revenue,” Trinckes says. “They’re using this level of thoroughness as a marketing tool to demonstrate their high bar of data protection and to meet customer demands. This is also particularly evident with cloud service providers that serve the healthcare industry.”
Another important step that healthcare entities and BAs can take to bolster breach prevention and detection in 2016 is to improve their communication, Nahra says.
When it comes to BA’s alerting the organizations they serve about breaches, Nahra says, “make sure that reporting channels are clear - that people know where to go as soon as possible. Also make sure that reporting suspicions [about breaches] is incredibly important. People need to know that they should report, even if it turns out to be nothing, and that they shouldn’t try to ‘figure things out’ before reporting. The faster that these problems can be stopped, the better for everyone.”
Organizations in the healthcare sector also should consider performing social engineering tests in an attempt to prevent falling victim to phishing attacks, which are frequently at the center of major hacking incidents, Trinckes says. “Results of this testing often lead to identifying the need for more effective internal training,” he says.
Healthcare organizations are also under pressure to bolster their breach detection and incident response plans, he adds. They should consider implementing sophisticated intrusion detection and prevention solutions along with log monitoring systems, he suggests. But they must ensure they have “the resources to maintain and monitor these solutions on a continuous basis.”
Looking ahead to 2016, Nahra predicts the cyberattack epidemic will endure. “These breaches will continue on a large scale, and will continue to be in the news because they have a long tail - both in cleaning up problems and in subsequent enforcement, if any, which can occur several years later,” he says.
The increased value of protected health information and personally identifiable information in the black market underground for use in such crimes as identity theft and fraud is fueling the surge in breaches, he adds.
“We will see more healthcare organizations pursuing the purchase of cyber insurance coverage, and these insurers will require these organizations to demonstrate a high level of data security practices, along with having a comprehensive, proactive information security program,” he predicts.

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, November 11, 2015

Understanding Business Associates

To be compliant with HIPAA, you must understand the Business Associate aspect of the law.

Business Associates of covered entities must comply directly with the HIPAA Security and Privacy Rules, according to the Health Information Technology for Economic and Clinical Health (HITECH) Act. The Security Rule, which complements the HIPAA Privacy Rule, includes safeguards for protecting patients’ electronic protected health information (PHI), based on three components:

• Administrative: Organizations must have procedures that show how they will comply with the security rule
• Physical: Organizations must control how patients’ records are physically accessed and prevent inappropriate access
• Technical: Organizations must have a system to control computer access and monitor and protect communication that flows electronically over open networks.

Section 13401 of the HITECH Act includes the new BA requirements. The act also states that civil and criminal penalties for violations of the HIPAA and compliance audits apply directly to BAs. Covered entities must incorporate these additional requirements in their agreements with BAs, according to the new law.

A covered entity may disclose PHI to a business associate for purposes agreed to by contract.
HHS’ definition of a Business Associate:

• A business associate is a person or entity who provides certain functions, activities, or services on behalf of a covered entity involving the use and/or disclosure of PHI.
• A business associate is not a member of the health care provider’s workforce.
• A health care provider or other covered entity can also be a business associate to another covered entity.
• Covered entities who disclose PHI to providers for treatment are not business associates. An insurance company is not a business associate. They do not perform a function on behalf of a covered entity.

The provider’s office must document by means of a written contract or other written agreement the satisfactory assurances that the business associate will appropriately safeguard the information disclosed to them for their use.

Examples of a business associate are:

• A billing company
• A clearinghouse
• An answering service
• IT personnel who have access to computers containing PHI
• A document shredding company
• A collection agency
• An attorney
• Couriers

The contract with business associates covers a set of contractual obligations. Their function is to protect information generally and help the covered entity comply with the entity’s obligations under HIPAA.

HHS has stressed that PHI may be disclosed to a business associate only to help the providers and plans carry out their health care functions - not for independent use by the business associate.
To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Monday, November 9, 2015

HIPAA Security Risk Analysis

Risk analysis involves identifying risks and vulnerabilities in your information systems. 


It is a required implementation specification within the Security Management Process. It requires you to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) held by your office. It calls for you to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.

Perform a Risk Analysis

A risk analysis is a process that you should carry out in your practice in a step-by-step manner. Following is a suggested method of performing your risk analysis:

Inventory – You should begin by conducting a detailed inventory of your ePHI and your information systems that contain ePHI. Information systems can be complex. The inventory should seek to identify all inter-dependencies among these items.
• Information system hardware and software
• Identify the primary users of the information systems and ePHI
• Function and purpose of the ePHI and information system
• Technical controls (hardware or software access control mechanisms)
• Non-technical controls (security policies, employee training)
Threat identification – You should next identify all potential threats to your ePHI and your related information systems.
19
• Natural – floods, earthquakes, tornadoes, hurricanes, etc.
• Human – Unintentional (incorrect data entry or accidental deletion of data)- or - Intentional (installing malicious hardware, refusing service)
• Environmental – Power failures, hazardous material spill, etc.

Vulnerability Identification – Identify the vulnerabilities of your ePHI and related information systems. A vulnerability is a flaw or weakness in a system’s implementation, security, procedures, design, or internal controls that can be exploited by a threat and result in misuse or abuse of ePHI.
Examine your vulnerable sources by reviewing:
• Information systems
• Audit reports
• Information system test
• Evaluation reports
Security control analysis – You should next analyze the security controls that have you put into place to protect ePHI. There are two types of security controls that need to be assessed:
1. Preventative controls are designed to prevent or restrict the exploitation of vulnerabilities.
• Access control
• Authentication
2. Detective controls detect and report when violations occur.
• Audit trail
• Alarm
Determine risk likelihood – Three determining factors should be considered:
1.) Threat motivation and capability;
2.) Type of vulnerability; and
3.) Existence and availability of security controls.

Below are three risk likelihood levels and their definitions that may be used as examples:
• High likelihood - Threat is highly capable, motivated, or likely and current security controls are ineffective.
• Medium likelihood - Threat is capable, motivated or likely, but there are security controls in place that may prevent the exploitation of the vulnerabilities.
• Low likelihood – Threat is not capable, motivated or likely, or current security controls will likely prevent exploitation of the vulnerabilities.
20
Analyze the impact –Next, determine the impact that would result if a perceived threat were to actually take place in your practice. You should determine the impact in the following areas (define the impacts as high, medium, or low):
• Confidentiality - ePHI is disclosed or accessed in an unauthorized manner
• Integrity - ePHI is improperly modified
• Availability – ePHI is unavailable to authorized users

Determine the risk - For each vulnerability and its associated possible threat, you should make a risk determination based on:
• The likelihood that a threat will happen or attempt to happen.
• The level of impact to your practice in the event that the threat happens.
• The adequacy of the existing or planned security controls to protect your ePHI.
• High risk – Security controls should be implemented or improved as soon as possible.
• Medium risk – Security controls should be implemented or improved in a reasonable amount of time.
• Low risk – The security controls that are currently in place are probably adequate or the risk is acceptable.

Recommendations for Security Control – By using all of the above information, you should be able to conclude your Security Risk Analysis by implementing security controls that can mitigate or eliminate the unacceptable risks that you have identified. These controls should reduce the level of risk to your ePHI and your related electronic information systems to an acceptable level.
Documentation Requirements – Good documentation generally supports any situation in which an action is called into question. We often hear, “If is not documented, it was not done.” This is also true with security.

No documentation or poor documentation does not mean that you do not have a security risk. In fact, the better the documentation, the more likely it is for an external investigator to believe that an undocumented risk did not previously exist. Your diligence in documenting risks and your decisions relative to them can demonstrate that you made the effort to identify as many risks as reasonable and practical. If one is overlooked, you are much less likely than if your documentation is poor or nonexistent and you attempt to.

This type of Security Risk Analysis should be conducted on an annual basis. Be sure to document the specifics of your audit and its findings.
To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, September 3, 2015

14 Questions for RAC Self-Audits

RAC Self-Auditing

Here are 14 simple questions that will give you peace of mind regarding your RAC self-audits.

Randomly select 10 Medicare patient records then apply these simple questions to each record: 
  1. Are the services and supplies proper and needed for diagnosis and treatment of the diagnosis?
  2. Do any charges appear to be “unbundled”?
  3. Does the procedure code correctly describe the service provided?
  4. Are the HCPCS and/or CPT codes updated and correct?
  5. Are the E and M codes used appropriate and does the documentation support their use?
  6. Are the modifiers used properly?
  7. Were the correct and updated ICD-9 or ICD-10 CM codes linked to the diagnoses and procedure code(s)?
  8. Is the place of service appropriate?
  9. Are there duplicate services rendered on the same date?
  10. Does the documentation support the services billed?
  11. Is the medical record clearly written, accurate and complete?
  12. Is there any evidence of “intentional deception”?
  13. Did the billing provider actually render the service?
  14. Were all billed services actually rendered?

Wednesday, June 17, 2015

Are You Confident About Passing a HIPAA Audit?

Survey Reveals Over-confidence in HIPAA Compliance

With regulators gearing up to begin the next phase of HIPAA compliance audits, many covered entities appear to be over-confident about passing that scrutiny, according to the results of Information Security Media Group’s latest Healthcare Information Security Today survey.

Nearly 80 percent of healthcare organizations that participated in the 2015 survey said they were confident or somewhat confident that they’d “pass” a HIPAA compliance audit by the Department of Health and Human Service’s Office for Civil Rights with only minimal non-compliance issues.

But despite the strong confidence levels of most respondents when it comes to their organizations’ compliance efforts, a closer look at other survey results shows that many covered entities are still falling short in applying key technologies and practices to protect patient data against many current and emerging cyber threats, including measures called for by the HIPAA Security Rule.

For instance, the survey found:
     Only 75 percent of respondents say their organizations conducted a security risk assessment last year. The failure to conduct a thorough and timely risk assessment is the most common non-compliance issue that has been cited by OCR during HIPAA breach investigations and also in the agency’s pilot HIPAA compliance audit program.
     Despite lost or stolen unencrypted devices being the biggest cause of major health data breaches reported to OCR since 2009, only 60 percent of surveyed organizations are requiring encryption on portable devices and media.
     Although OCR looks for documented evidence of HIPAA compliance efforts, less than 60 percent of surveyed organizations have a documented security strategy.  Most of the other organizations say they are working on one.

Although confidence levels about HIPAA compliance appear to be high among the survey respondents, they, nevertheless, said their top information security priority for 2015 was improving regulatory compliance. That was followed by improving security awareness and training and preventing and detecting breaches. Those were also the top priorities in the two previous Healthcare Information Security Today surveys.
The online 2015 Healthcare Information Security Today survey was conducted in December 2014 and January 2015. Respondents included about 200 CISOs, CIOs, directors of IT and other senior leaders at hospitals, integrated delivery systems, physician group practices, insurers and other healthcare organizations.

(ISMG website)

Wednesday, May 13, 2015

How to Respond to an OCR Audit

Responding to an OCR Audit

The Office for Civil Rights (OCR) has not issued much information on the upcoming HIPAA audits, so it’s up to individual organizations to interpret what to expect and how to prepare. However the OCR has indicated that the audits will be conducted by OCR personnel rather than by a third party, unlike the 2012 pilot program. Also unlike last time, the audits will be more heavily weighted toward desk audits, with onsite audits occurring on a case-by-case basis.
According to information in presentations from Department of Health and Human Services personnel, here is what audited entities need to be aware of:
        A data request will specify content and file organization, file names and any other document submission requirements.
        Only requested data submitted on time will be assessed.
        All documentation must be current as of the date of the request.
        Auditors will not have the opportunity to contact the entity for clarification or to ask for additional information, so it is critical that the documents accurately reflect the program.
        Submitting extraneous information may increase the difficulty for the auditor to find and assess the required items.
        Failure to submit a response to requests may lead to a referral for regional compliance review.
        Document submission will be a time-consuming task, so gathering necessary evidence up front will minimize disruption to day-to-day operations.
Once an organization receives notification, it should start gathering information immediately. If subsequently chosen to submit to an audit, participants will only have a short time to respond. The following provides basic steps for a strategic OCR audit plan:
        Gather a team.
Privacy and security officials should be assigned to a task force responsible for handling audit requests. It’s also a good idea to notify internal or external legal counsel to keep them on stand-by should guidance be necessary.
        Follow guidelines on how to respond.
The OCR will provide specific instructions on how and when to respond. The OCR will not look favorably on a delayed response, and if unrequested documentation is submitted, it can be used in all observations and findings. Some of the areas the OCR audits will cover include:
1.      Risk analysis.
2.      Evidence of a risk management plan (e.g. list of known risks and how they are being dealt with).
3.      Policies and procedures and descriptions as to how they were implemented.
4.      Inventories of business associates and the relevant contracts and BAAs.
5.      An accounting of where electronic protected health information (ePHI) is stored (internally, printouts, mobile devices and media, third parties).
6.      How mobile devices and mobile media (thumb drives, CD’s, backup tapes) are secured and tracked.
7.      Documentation on breach reporting policies and incident response policies and procedures.
8.      A record of security training that has taken place.
9.      Evidence of encryption capabilities.
       Question findings if they appear to be inaccurate. Historically, the OCR has allowed organizations to respond to observations and findings. Organizations that have documented all compliance decisions will fare better when trying to defend their position. There are many areas where HIPAA lacks specific direction; the ability to demonstrate a thoughtful and reasonable approach (in writing) will tend to be viewed favorably.

By preparing up front and responding in a timely fashion, most OCR audits should progress fairly smoothly. For organizations that have instituted a reasonably compliant security program, there may be little or no follow-up. If there are a significant number of observations and findings, an organization may be subject to voluntary compliance activities, or a more in-depth compliance review. Should an in-depth review uncover significant issues, additional corrective action must be taken and/or fines may be imposed.


(HIMSS website)