Showing posts with label HIPAA Inspection. Show all posts
Showing posts with label HIPAA Inspection. Show all posts

Thursday, October 15, 2015

More Effective HIPAA Enforcement Coming

OIG Says HIPAA Enforcement Needs Improvement

The HHS Office for Civil Rights should take 10 steps to strengthen its oversight of HIPAA Privacy Rule compliance as well as improve follow-up activities on reported data breaches, a government watchdog agency says in two new reports. Among the recommended steps are the launching of a long-overdue, permanent HIPAA compliance audit program, adding information about small breaches to OCR’s case-tracking system and expanding HIPAA education outreach efforts.

The Department of Health and Human Services’ Office of Inspector General issued the reports evaluating OCR, which is responsible for HIPAA enforcement. In each of the reports, OCR Should Strengthen Its Follow-up of Breaches of Patient Health Information Reported by Covered Entities and OCR Should Strengthen Its Oversight of Covered Entities’ Compliance With the HIPAA Privacy Standards, OIG made five recommendations. OCR agreed to carry out all of them.
In its report about OCR’s oversight of HIPAA Privacy Rule compliance by covered entities, OIG found that:
        OCR investigated possible noncompliance with the privacy standards primarily in response to complaints;
        OCR has not fully implemented the required audit program to proactively identify possible noncompliance from covered entities;
        In about half of the closed privacy cases that OIG reviewed, OCR determined that covered entities were noncompliant with at least one privacy standard;
        OCR documented corrective action for almost three-quarters of privacy cases in which it requested such actions from covered entities; however, 26 percent of cases had incomplete documentation;
        71% percent of OCR staff at least sometimes checked whether covered entities had been previously investigated; however, 29 percent rarely or never did so;
        OCR’s case-tracking system has limited search functionality; and
        27% of Medicare Part B providers did not address all five selected privacy standards reviewed by OIG.
OIG’s five recommendations, which OCR says it is implementing, include:
1.      Fully implementing a permanent audit program;
2.      Maintaining complete documentation of corrective action;
3.      Developing an efficient method in OCR’s case-tracking system to search for and track covered entities;
4.      Developing a policy requiring OCR staff to check whether covered entities have been previously investigated; and
5.      Continuing to expand HIPAA outreach and education efforts to covered entities.
In its report evaluating OCR’s following up on breaches reported by covered entities, OIG acknowledged that OCR routinely investigates breaches affecting 500 or more individuals, as required under the HITECH Act. In almost all of the completed investigations, OCR has determined that covered entities were noncompliant with at least one HIPAA Privacy Rule standard.
Although OCR documented corrective action for most of the closed large breach cases in which it made determinations of noncompliance, 23 percent of cases had incomplete documentation of corrective actions taken by covered entities, OIG says.
OIG says OCR also did not record information about smaller breaches in its case tracking system, which limits OCR’s ability to track and identify covered entities with multiple small breaches.
Although 61 percent of OCR staff checked at least sometimes as to whether covered entities had reported prior large breaches, 39 percent of OCR staff rarely or never did so, OIG says. “If OCR staff wanted to check, they may face challenges because its case tracking system has limited search functionality and OCR does not have a standard way to enter covered entities’ names in the system,” OIG notes.
Based on these findings, OIG said OCR should:
1.      Enter small-breach information into its case-tracking system or a searchable database linked to it;
2.      Maintain complete documentation of corrective action;
3.      Develop an efficient method in its case-tracking system to search for and track covered entities that reported prior breaches;
4.      Develop a policy requiring OCR staff to check whether covered entities reported prior breaches;
5.      Continue to expand outreach and education efforts to covered entities.
In response to OIG’s call for implementing a permanent HIPAA compliance audit program, as required under the HITECH Act, OCR Director Jocelyn Samuel outlined steps the office is taking toward that long-delayed goal.
“We will launch our audit program in early 2016. This phase will test the efficacy of a combination of desk reviews of policies as well as on-site reviews. It will target common areas of non-compliance and will include HIPAA business associates,” Samuels wrote in a letter dated Sept. 23.
Samuels noted that key audit-preparation activities over the next several months include “OCR updating its HIPAA audit protocols; refining the pool of potential audit subjects; and implementing a screening tool to assess size, entity type and other information about potential audit subjects.”
One HIPAA expert says OIG’s assessment of OCR’s enforcement activities spotlight several important issues.
“The reports in their formal federal language are an attempt to light a bigger fire under OCR to use the authority in the HITECH Act for the proactive audits to reach the second plateau of operation,” says independent HIPAA attorney Susan Miller.
“While all five recommendations in each report are important, the small-breach information and a fully implemented permanent audit program are very important for HIPAA enforcement to reach the next higher level of operations,” she says. “Both reports taken together put both investigations and audits on the same enforcement level, making each as important as the other. It is also a recognition that a complaint and its related investigation may lead to a breach finding, and that both investigations and breaches produce corrective action plans.”

(OIG website, ISMG website)


For more information on this and other topics related to HIPAA, HR, OSHA, and Medicare, please emailsupport@hcsiinc.com or visit our website at http://www.hcsiinc.com



Be sure to become a member of our Linkedin group by visiting; http://bit.ly/1FWmtq6

Wednesday, June 17, 2015

Are You Confident About Passing a HIPAA Audit?

Survey Reveals Over-confidence in HIPAA Compliance

With regulators gearing up to begin the next phase of HIPAA compliance audits, many covered entities appear to be over-confident about passing that scrutiny, according to the results of Information Security Media Group’s latest Healthcare Information Security Today survey.

Nearly 80 percent of healthcare organizations that participated in the 2015 survey said they were confident or somewhat confident that they’d “pass” a HIPAA compliance audit by the Department of Health and Human Service’s Office for Civil Rights with only minimal non-compliance issues.

But despite the strong confidence levels of most respondents when it comes to their organizations’ compliance efforts, a closer look at other survey results shows that many covered entities are still falling short in applying key technologies and practices to protect patient data against many current and emerging cyber threats, including measures called for by the HIPAA Security Rule.

For instance, the survey found:
     Only 75 percent of respondents say their organizations conducted a security risk assessment last year. The failure to conduct a thorough and timely risk assessment is the most common non-compliance issue that has been cited by OCR during HIPAA breach investigations and also in the agency’s pilot HIPAA compliance audit program.
     Despite lost or stolen unencrypted devices being the biggest cause of major health data breaches reported to OCR since 2009, only 60 percent of surveyed organizations are requiring encryption on portable devices and media.
     Although OCR looks for documented evidence of HIPAA compliance efforts, less than 60 percent of surveyed organizations have a documented security strategy.  Most of the other organizations say they are working on one.

Although confidence levels about HIPAA compliance appear to be high among the survey respondents, they, nevertheless, said their top information security priority for 2015 was improving regulatory compliance. That was followed by improving security awareness and training and preventing and detecting breaches. Those were also the top priorities in the two previous Healthcare Information Security Today surveys.
The online 2015 Healthcare Information Security Today survey was conducted in December 2014 and January 2015. Respondents included about 200 CISOs, CIOs, directors of IT and other senior leaders at hospitals, integrated delivery systems, physician group practices, insurers and other healthcare organizations.

(ISMG website)

Wednesday, May 13, 2015

How to Respond to an OCR Audit

Responding to an OCR Audit

The Office for Civil Rights (OCR) has not issued much information on the upcoming HIPAA audits, so it’s up to individual organizations to interpret what to expect and how to prepare. However the OCR has indicated that the audits will be conducted by OCR personnel rather than by a third party, unlike the 2012 pilot program. Also unlike last time, the audits will be more heavily weighted toward desk audits, with onsite audits occurring on a case-by-case basis.
According to information in presentations from Department of Health and Human Services personnel, here is what audited entities need to be aware of:
        A data request will specify content and file organization, file names and any other document submission requirements.
        Only requested data submitted on time will be assessed.
        All documentation must be current as of the date of the request.
        Auditors will not have the opportunity to contact the entity for clarification or to ask for additional information, so it is critical that the documents accurately reflect the program.
        Submitting extraneous information may increase the difficulty for the auditor to find and assess the required items.
        Failure to submit a response to requests may lead to a referral for regional compliance review.
        Document submission will be a time-consuming task, so gathering necessary evidence up front will minimize disruption to day-to-day operations.
Once an organization receives notification, it should start gathering information immediately. If subsequently chosen to submit to an audit, participants will only have a short time to respond. The following provides basic steps for a strategic OCR audit plan:
        Gather a team.
Privacy and security officials should be assigned to a task force responsible for handling audit requests. It’s also a good idea to notify internal or external legal counsel to keep them on stand-by should guidance be necessary.
        Follow guidelines on how to respond.
The OCR will provide specific instructions on how and when to respond. The OCR will not look favorably on a delayed response, and if unrequested documentation is submitted, it can be used in all observations and findings. Some of the areas the OCR audits will cover include:
1.      Risk analysis.
2.      Evidence of a risk management plan (e.g. list of known risks and how they are being dealt with).
3.      Policies and procedures and descriptions as to how they were implemented.
4.      Inventories of business associates and the relevant contracts and BAAs.
5.      An accounting of where electronic protected health information (ePHI) is stored (internally, printouts, mobile devices and media, third parties).
6.      How mobile devices and mobile media (thumb drives, CD’s, backup tapes) are secured and tracked.
7.      Documentation on breach reporting policies and incident response policies and procedures.
8.      A record of security training that has taken place.
9.      Evidence of encryption capabilities.
       Question findings if they appear to be inaccurate. Historically, the OCR has allowed organizations to respond to observations and findings. Organizations that have documented all compliance decisions will fare better when trying to defend their position. There are many areas where HIPAA lacks specific direction; the ability to demonstrate a thoughtful and reasonable approach (in writing) will tend to be viewed favorably.

By preparing up front and responding in a timely fashion, most OCR audits should progress fairly smoothly. For organizations that have instituted a reasonably compliant security program, there may be little or no follow-up. If there are a significant number of observations and findings, an organization may be subject to voluntary compliance activities, or a more in-depth compliance review. Should an in-depth review uncover significant issues, additional corrective action must be taken and/or fines may be imposed.


(HIMSS website)