Showing posts with label HIPAA Privacy. Show all posts
Showing posts with label HIPAA Privacy. Show all posts

Thursday, August 10, 2017

Six Ways to Improve Data Security at Your Practice

A married couple — both doctors who shared a medical practice — almost divorced over a HIPAA breach that blindsided them when a patient called to say that her medical records appeared in a Google search and she was filing a lawsuit.

The orthopedist of a small practice didn’t want to fund the cost of an IT service provider to make sure his network was secure.  Instead the doctor hired his cousin who earned his IT stripes fixing performance problems on his own laptop.  Unfortunately, the family member never updated the practice’s malware software and patient data ended up on a rogue server.  Now it’s being held for ransom. 

The Smaller the Practice the Less the Compliance

For medical practices with 20 or less employees, doctors are often reluctant to spend money on HIPAA security than larger practices.  Importantly, the latter will have a compliance officer who makes sure HIPAA rules are followed, employees are trained, and policies and procedures are up to date. 

Doctors running small practices don’t believe they’re at risk for a data breach so they ignore the same steps taken by the compliance officer.  Meanwhile, it’s ordinary human errors that could take down the practice.  An employee leaves his tablet in a taxi or thieves break into the office and steal two laptops that contain patient records.  Or the doctor loses his laptop and keeps it under wraps since he thinks he hasn’t stored any patient records on it, so no one needs to know.  However, a disgruntled employee who was terminated gets revenge by reporting the practice to the Department of Health and Human Services’ Office of Civil Rights (OCR).  The OCR accuses the practice of having a breach and hiding it, and calls for an investigation. 

These are all real world events that have sent medical practices into a tailspin.  Doctors call a HIPAA compliance expert in a panic because they’re now caught in the web of the OCR and scrambling to prepare for an audit.  Worse yet, these compliance risks were right under their noses.

The Practice Needs As Much Care As the Patients

The risk of a data breach can be as life threatening to the practice that doesn’t protect its data, as the risk of lung cancer is for the patient who chain smokes.  Think of a data breach as a disease and the stolen laptop causing pain and suffering, and eventual death, which could all be prevented.  Doctors should think about data breach prevention and care for their businesses with the same commitment to disease prevention and care for their patients. 

When a practice fails to perform a security risk assessment or ensure that his employees used strong passwords, not long after he is convincing OCR auditors that the breach was an accident.  He has to hire attorneys to complete the audit and there is no budget left to invest in more network security, or cyber insurance. 

HIPAA Compliance Made Easy for Small Practices

There are some simple steps small practices can take that will take far less time than preparing for an OCR audit:

- Perform a security risk analysis — Analyze how patient information is currently protected. How often does the practice perform data backups? Is there a termination procedure when an employee leaves? Do employees have the minimum level of access to patient information? Are all portable devices encrypted?  Are medical records protected in case of fire or flood, or lost or stolen laptops that contain patient information?

- Train employees — Make sure they know how to spot phishing scams and suspicious links in emails, recognize fraudulent “IT experts” who call in to upgrade an operating system.  They should also know to avoid conducting business on public Wifi, and minimize sharing on social networks.

- Inventory patient information — Locate where all patient information is stored. It could be an EHR or a word document in the form of patient letters, or excel spreadsheets as billing reports or scanned images of your insurance carrier’s explanation of benefits (EOB).  This information resides on desktops, laptops and mobile devices, and should be encrypted.

- Employee data theft — Employee theft of information is one of the leading causes of HIPAA breaches in small organizations.  An employee steals patient information and opens a charge account at a local department store.  The patient finds out and sues the practice for not protecting her electronic protected health information (ePHI).  Employees should have minimal access to EHRs — only the information they need to perform their duties.   Also data logs should be checked.

- Breach Response Plan — Is there a response plan in place in case a breach does occur? The plan should include who will be on the response team, what actions the team will take to address the breach, and what steps they’ll take to prevent another similar breach from occurring. Make sure the plan is documented and all employees are trained on what they need to do.

These few actions can make the difference between being sued by patients for a data breach and gaining their confidence that their doctor cares as much about their health as he does for their security.

Source(s): https://www.hcsiinc.comhttp://www.physicianspractice.com

For more information on this and other healthcare compliance topics related to HIPAA, OSHA, Medicare and HR, simply email your questions to support@hcsiinc.com
visit our website at http://www.hcsiinc.com or post a question on our LinkedIn group at: http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, July 27, 2017

HHS Launches New Video Training Module for HIPAA Patient Right to Access


The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced that it has a new video training module for health care providers.

According to HHS, the new training module provides an “in-depth review of the components of the HIPAA right of access and ways in which it enables individuals to be more involved in their own care.” The training module provides helpful suggestions about how health care providers can integrate aspects of the HIPAA access right into medical practice. This activity is intended for primary care physicians, obstetricians and gynecologists, pediatricians, and nurses.

The goal of this activity is to review components of the Health Insurance Portability and Accountability Act (HIPAA) right of access and ways in which it enables individuals to be more involved in their own care.

Upon completion of this activity, participants will have increased knowledge regarding:

  • The components of the HIPAA access right, including an individual's ability to direct a copy of their health information to a third party, including a researcher 
  • How the HIPAA right of access enables individuals to become more involved in their care
Information about training materials can be found on the HHS website here: https://www.hhs.gov/hipaa/for-professionals/training/index.html.

The video module can be found here: http://www.medscape.org/viewarticle/876110
.


The module contains a video (approximately 37 minutes) titled “An Individuals’ Right to Access and Obtain Their Health Information Under HIPAA” and features Devan McGraw, the Deputy Director for Health Information Privacy at the US Department of Health and Humans Services. The video talks about why privacy protections are important, but mainly focuses on the patient’s right of access, including:

  • what fees that can be charged
  • whether records may be sent unsecured at the patient’s request
  • how quickly the records need to be provided to the patient upon request
  • which records can be excluded from a patient’s right to access
  • an individual’s ability to have a copy of his/her health information sent directly to a third party.

Upon completion of this activity, participants will receive free Continuing Medical Education (CME) credit for physicians and Continuing Education (CE) credit for health care professionals. In order to receive credit, it is required to have a Medscape user ID and password, which is free to sign up. There are no fees for participating in or receiving credit for this CME.



Additional Training Materials and Resources



Helping Entities Implement Privacy and Security Protections

The HIPAA Rules are flexible and scalable to accommodate the enormous range in types and sizes of entities that must comply with them. This means that there is no single standardized program that could appropriately train employees of all entities. 

HealthIT.gov’s Guide to Privacy and Security of Electronic Health Information provides a beginners overview of what the HIPAA Rules require, and the page has links to security training games, risk assessment tools, and other aids.

Patient Privacy: A Guide for Providers (login required), is an educational program for health care providers on compliance with various aspects of the HIPAA Privacy and Security Rules. Physicians can earn free Continuing Medical Education (CME) credits and health care professionals will receive Continuing Education (CE) credits.

State Attorneys General Training materials provide a more comprehensive overview of HIPAA compliance:




Want to learn more about the HIPAA Privacy & Security Rules? Sign Up for the OCR Privacy & Security Listserv

OCR has established two listservs to inform the public about health information privacy and security FAQs, guidance, and technical assistance materials. We encourage you to sign up and stay informed!

For additional information about HIPAA Privacy and HIPAA Security training for your self and your staff, please contact Healthcare Compliance Solutions Inc. (HCSI). (801)-947-0183

 HCSI

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, April 25, 2017

Walking the Social Media Tightrope

Much like walking on a tightrope, participating on social media is a science as well as an art.


People post on social media all the time. They like to post pictures, tag their location when they are somewhere cool and they even like to write about what they are eating. Unfortunately, many people do not see any harm in what they post. For example, below is an example of somebody posting something that they perceived as innocent and, in their eyes, thoughtful:

In an assisted living center, a housekeeper posted a picture of a vision and hearing impaired resident on her social networking webpage, with the caption "This is my friend," along with the resident's first name.

By posting the picture of the resident without their consent, the employee violated HIPAA Privacy regulations. After the violation was brought to the employees’ attention, the employee apologized and immediately removed the photo. She said she was not aware that a person could not do such a thing without the resident's consent. While the employee did not have malicious intent, the action was still a violation of the resident’s privacy.

Social media is a double edged sword. If used properly, social media can be an amazing tool that can be used in many beneficial ways. However, if used improperly, social media can do extensive damage to the user and the organization they work for.

Dangers of Social Media

Use of social media by healthcare professionals can present some challenges and possibly open the door to HIPAA Privacy violation and future liability. Here are some examples of social media privacy violations that have lead to a HIPAA Privacy audit:

  • Posting pictures of patients/residents without their consent
  • Posting a video of a patient
  • Posting a video describing a patient or a patients situation
  • Posting a “selfie” in a restricted area where Protected Health Information (PHI) is visible
  • Writing a post or comment about a patients situation

These social media posts can severely damaging to an organization and to the individual who’s privacy had been compromised. In addition to these actions leading to a HIPAA Privacy audit, these type of social media posts also have a negative effect on the reputation of the healthcare organization. Privacy violations do not go unnoticed by other patients and these privacy violations do cause patients to rethink their trust in their healthcare provider.

As with walking a tightrope, it is very easy to slip and fall into unwanted territory with social media posts.

Beauty of Social Media

While social media can have many negative effects on an organization and patients, it can also be used for some great things. These are some examples where social media can have a positive impact in the healthcare world:

  • Educate followers with various health tips
  • Maximize exposure of an organizations community contribution
  • Give patients a platform for them to write positive reviews
  • Celebrate the accomplishments of your employees (post with their permission)
  • Announce specials, discounts, or new product

There is so much an organization can do with social media that will have a positive effect. However, social media posting in the healthcare industry is like walking a very fine line. When posting on social media, it is important to have established guidelines and policies in writing. This will enable a healthcare provider to safely post on social media without fear of slipping and falling into unwanted territory.

Be sure to take to have documented training on social media for your employees. They need to know the impact their social media posting can have on patients and on the organization itself. In addition, having documented training will help protect the organization against liability if the need arises to discipline an employee for not following social media policies and procedures.

If done right, having a positive social media presence will be very beneficial to an organization. However, it is important to stay on that narrow rope when posting. It can be very easy to move slightly to one side or the other and fall into unwanted post territory.


For more information about safely posting on social media, please watch the following webinar:




To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, March 16, 2017

Policies and Procedures, Compliance Training and HR

Maintaining Compliance and also Keeping HR in the Loop
 HCSI
In your ongoing efforts to provide an office culture of compliance, it is important to remember that HIPAA requires covered entities to establish and implement written policies and procedures that are consistent with its Privacy and Security Rules.  It can also be important for your Human Resource officer(s) to be involved with HIPAA compliance related issues in the business.

The U.S. Department of Health and Human Services, Office for Civil Rights (“OCR”) has begun its Phase 2 HIPAA Audit Program.  The Program will focus on the policies and procedures adopted and employed by covered entities and their business associates to meet the requirements of the Privacy, Security, and Breach Notification Rules.  Furthermore, if a group health plan is selected for an audit, it would have a very short time to produce its policies and procedures (i.e., 10 business days).  If the group health plan does not comply (for example, because it does not have policies and procedures), the OCR will likely impose corrective measures which could include costly civil monetary penalties.

HIPAA policies and procedures have important functions, including but not limited to:
  • Limiting uses and disclosures of Protected Health Information (“PHI”) to the minimum amount reasonably necessary to achieve the purpose of the use or disclosure;
  • Identifying the workforce members who need access to PHI and electronic PHI (“e-PHI”) to carry out their duties, the categories of PHI that they need, and any conditions under which they need the PHI to do their jobs;
  • Ensuring appropriate protection of e-PHI when it is transferred, removed, disposed and electronic media is re-used; and
  • Ensuring that e-PHI is not improperly altered or destroyed.
However, it is not sufficient for a covered entity to merely adopt its HIPAA policies and procedures.  The health practice office must also:
  • Designate a privacy and security official to develop and implement policies and procedures; 
  • Train applicable workforce members on its policies and procedures as necessary for them to carry out their functions, and apply appropriate sanctions against workforce members who violate its policies and procedures;
  • Periodically assess how well its policies and procedures meet the requirements of the Security Rule; and
  • Designate a contact person responsible for receiving complaints and providing individuals with information on the covered entity’s privacy practices.
There is no template for HIPAA policies and procedures.  Instead employers have the flexibility to design policies and procedures that are appropriate for their size, organizational structure, and risks to PHI and e-PHI.  Furthermore, as employers evolve, so should their policies and procedures.  For example, if an employer adopts a telework policy, it may wish to review whether its policies and procedures appropriately address issues involving remote access.


Summarizing, although not a new requirement, due to new technologies, evolving business and regulatory practices, along with impending HHS audits, employers may want to review their HIPAA policies and procedures to make sure that they are compliant and up-to-date. Many HIPAA policies inherently overlap with Human Resource's duties: training, disciplinary actions and employee health information for examples.
The increase in audits — combined with everything from changes in technology, the addition of a health and wellness program and concerns about hacking — serve as a good reminder why employers should revisit HIPAA training often and collaborate with HR to ensure compliance.

Many of the employers facing fines are healthcare providers, health plans or healthcare clearinghouses (organizations considered as covered entities under HIPAA). But most HR professionals also handle protected health information (PHI) to some extent, which puts them in danger of violating the HIPAA Privacy Rule.

Employers should have a written policy in place about how they handle PHI and designate PHI handlers and a HIPAA privacy officer. The policy should outline what types of information are considered PHI and how employers may and may not use it. It should also include a procedure for handling complaints and a process for employees to file them if they think their privacy rights are being violated.

Employees who may handle PHI should be trained on the dos and don’ts of handling protected health information, especially as it relates to electronic information. It’s vital for the HR team to understand the implications of handling PHI in emails, storing it on the cloud, or communicating about it over other electronic formats. And when discussing matters containing PHI with an employee, it’s important to have a signed HIPAA authorization form for the release of employee health information.

Lastly, the HIPAA privacy officer should review compliance documents and ensure that agreements with vendors who handle PHI, called “business associate agreements,” are up to date. The federal government considers vendors and subcontractors to be business associates if they handle PHI on behalf of the covered entity.

Source(s): http://www.hhs.com, http://www.jdsupra.comhttps://www.benefitnews.com, http://www.hcsiinc.com


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, January 27, 2017

Disclosure VS Breach

What is the difference between an incidental/accidental disclosure and a breach?

With the approaching breach notification deadline (Before March 1st, all breaches must be reported 60 days after the end of the previous calendar year that the breach occurred), I have receive many calls and emails asking, "is this a breach and do I need to report it?". This is an important topic that needs some clarification.

Incidental Disclosure

These disclosures are non-intentional and occur as a by-product of allowed uses and disclosures. They are allowed as long as the minimum necessary standard and reasonable safeguards are applied in the course of your everyday operations. An example would be if a passerby overhears PHI being discussed at a nursing station. These disclosures do not have to be accounted for.

Accidental Disclosure

These types of disclosures are distinctly different from incidental disclosures. Accidental disclosures
happen when a mistake is made in disclosing a patient’s PHI. Examples include faxing or mailing PHI to the wrong destination or disclosing PHI to an unauthorized person. If you are aware of an accidental disclosure, you need to log the disclosure on the disclosure log. If the disclosure is potentially harmful or damaging to the patient, you need to notify the patient of the accidental disclosure.

Identifying a Breach of Unsecured PHI

A breach is defined in the HIPAA HITECH Act as:

The unauthorized acquisition, access, use, or disclosure of unsecured protected
health information which compromises the security or privacy of such
information, except where an unauthorized person to whom such information is
disclosed would not reasonably have been able to retain such information. (Note
that de-identified health information, as defined in HIPAA’s Privacy Rule, is not
PHI; therefore no breach notification is required.)

Exceptions include:

• Any unintentional acquisition, access, or use of protected health information by an
employee or individual acting under the authority of a covered entity if:
• Such acquisition, access, or use was made in good faith and within the course and
scope of the employment or other professional relationship of such employee or
individual, respectively, with the covered entity; and
• Such information is not further acquired, accessed, used, or disclosed by any
person; or
• Any inadvertent disclosure from an individual who is otherwise authorized to
access protected health information at a facility operated by a covered entity to
another similarly situated individual at the same facility; and
• Any such information received as a result of such disclosure is not further
acquired, accessed, used, or disclosed without authorization by any person.

I hope the information listed above helps you have a better understanding of the difference between an incidental/accidental disclosure and a breach. Here is another article that could offer some additional information.

If you would like additional information, please feel free to email support@hcsiinc.com




To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, January 17, 2017

OCR Updates HIPAA Guidance on Sharing Information with Patients’ Loved Ones, Family and Friends

Clarification For Sharing Patient Information
A January 10, 2017 Issuance from Heath and Human Services' (HHS) Office if Civil Rights (OCR) updating new privacy guidance is aimed at clarifying that the HIPAA Privacy Rule does permit disclosures of health information to a patient's loved ones regardless of whether they are recognized as relatives under applicable law. This guidance for healthcare professionals is to help clear up confusion about allowable disclosures of protected health information to spouses, relatives, and patients’ loved ones.

The majority of healthcare professionals are aware that the HIPAA Privacy Rule permits them, within the exercise of their own professional judgement, to share the protected health information of a patient with a relative or loved one or if it is in the patient's best interest. However, the 2016 Orlando nightclub shooting incident revealed that many healthcare professionals are unsure about how the HIPAA Privacy Rule – 45 CFR164.510(b) – applies to same sex couples.

OCR has confirmed that the Privacy Rule permits a covered entity to “share PHI with an individual’s family member, other relative, close personal friend, or any other person identified by the individual, the information directly relevant to the involvement of that person in the patient’s care or payment for health care.” OCR has also confirmed that covered entities are allowed to disclose relevant information “to notify, or assist in the notification of (including by helping to identify or locate), such a person of the patient’s location, general condition, or death.”
The recipient can be a “patient’s family member, relative, guardian, caregiver, friend, spouse, or partner,” but also any other individual that is a nominated personal representative of the patient. A personal representative of a patient must, as far as the Privacy Rule is concerned, be treated as the individual for purposes such as exercising the patient’s Privacy Rule rights, including providing access to their health information. There are limited exceptions, which are detailed in 45 CFR164.502(g).

OCR has confirmed that covered entities are permitted to share a patient’s PHI with same-sex partners, and explains that the list of potential recipients of PHI is in no way affected by an individual patient’s sex or gender identity, and neither by the sex or gender of the potential recipient.

OCR also sought to confirm who can be classed as a personal representative of the patient, saying “the Privacy Rule generally looks to state laws governing which persons have authority to act on behalf of an individual in making decisions related to health care.”

For example, if a state grants legally married spouses health care decision making authority for each other, a covered entity would be in violation of the Privacy Rule if access to the patient’s information was not granted if requested by a spouse, regardless of the sex of that individual.

While the covered entity should seek permission from the patient concerned prior to sharing information, in cases when the patient is incapacitated or not available, covered entities should use their professional judgement if the sharing of information is in the patient’s best interest. Should a patient be deceased, information can be shared with a person who has been involved in the patient’s care or who has made payment for medical services prior to the patient’s death.

The new OCR privacy rule guidance, issued in a frequently asked questions format, was developed in large part to address confusion following the 2016 Orlando nightclub shooting about whether and when hospitals may share protected health information with patients' loved ones, OCR says in a statement. "In particular, the FAQ makes clear that the potential recipients of information under the relevant permissive disclosure provisions ... are not limited by the sex or gender identity of the person," OCR says.

On that same topic, OCR also issued updated guidance "that makes clear that the terms 'marriage, spouse and family member' include, respectively, all lawful marriages - whether same-sex or opposite-sex) - lawfully married spouses and the dependents of all lawful marriages, and clarifies certain rights of individuals under the Privacy Rule."

Heathcare Compliance Solutions Inc. recommends consulting with your practice or organization's attorney and/or your state medical association/board to verify your state's legislation regarding the definitions and legal ramifications of terms relating to this regulation such as: "Personal Representative", "Lawful Marriage", "Family Member", etc..

 HCSI



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, August 24, 2016

Discussion Point: Patients Making Recordings In Healthcare Settings

Policies Restricting Patient Recordings In Medical Settings

What are your opinions on a medical office or practice creating a policy to prevent/limit patients from making audio/video recordings in exam rooms or other common areas where HIPAA or patient privacy could be violated by improper use of these recordings?


Does the office or practice have free reign to create such a policy?  What if any limitations might apply?

What about the patient?  Do they have any "rights" providing them the freedom to be able to record a procedure or practitioner giving treatment instructions for example? 

What about recordings in a maternity ward/nursery or during child birth?  What about the potential for cell phones to disrupt sensitive medical equipment?  What about patient's using apps like Pokemon Go and inadvertently or covertly overhearing and recording sensitive patient information?
What HIPAA regulations or legal ramifications might be evoked by such a situation?  How does an office notify patients of and enforce such a policy?  Should the office require patients to sign an acknowledgement of said policy or is a posted sign or notice adequate?

I would love to hear all your thoughts on this topic and any addition related issues that might come up that I have not already listed in the situations above. 

 HCSI
To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, July 26, 2016

OCR's Top 7 Areas of Focus During Phase Two Audits

Areas of improvement to focus on within your office.

During phase 2 of the Office for Civil Rights (OCR) HIPAA audits, they have decided to focus their attention on seven areas of compliance. These specific areas were chosen due to their history of non-compliance during multiple audits in the past. This is not to say that OCR will not investigate other areas, but their main focus will be on these specific requirements:

  • Under the HIPAA Privacy Rule
    • Notice of Privacy Practice and consent requirements
    • Provision of notice - electronic notice (NPP acknowledgement in electronic format)
    • Right to access (Patients right to access their PHI)
  • Under the HIPAA Security Rule
    • Security management process - risk analysis (Documented and completed internal risk analysis)
    • Security management process - risk management (Documented policies and procedures that prevent, detect, contain, and correct security violations)
  • Under the Breach Notification Rule
    • Timeliness of notification (Notification of breach given to individual and OCR within required specifications)
    • Content of notification (Notification of breach contains all of the required information as specified by OCR)
These are important areas of compliance that have been neglected or out right ignored by healthcare organizations. If you have not done so, get these areas of compliance in order within your organization.

For information on how to prepare for OCR's Phase 2 HIPAA audits go to:
http://hcsiinc.blogspot.com/2016/07/preparing-for-phase-2-of-hipaa-audits.html




To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, May 20, 2016

Discussion Point: Releasing Patient Information to a Pharmacy, Relating to Drug Use


I have a question for all of you.

A Doctor's office received a fax from a pharmacy (for the sake of clarification, let’s just say it was CVS) asking questions about one of their patients. The Doctor's office had treated the patient for one specific procedure and had prescribed medication (non-refillable) relating only to that procedure. The Pharmacy’s fax listed numerous prescriptions from various other sources that seemed excessive they and were apparently concerned the patient may be abusing these prescriptions in one way or another. The pharmacy wanted the Doctor's office to answer a questioner about the patient, their treatment, diagnosis, etc. A pharmacy is considered a Covered Entity but do they have the right, under HIPAA, to ask the Dr. these types of questions about the patient that are not necessarily related to a specific Treatment per se?
What are your thoughts based on your understanding of HIPAA and what limits, if any, are there on what the pharmacy may ask of the practice?  Should the pharmacy be able to ask any questions they want or is there a limit or minimum necessary, before the Privacy boundary is crossed?


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, April 8, 2016

Being Clear on Healthcare Social Media Policies

 Healthcare Compliance Solutions INC.
Define Your Social Media Policies Now To Reduce Future Issues

Love it or hate it, social media is a fact of life. It can be a great means for medical practices to raise awareness, educate, and engage patients.
However, it's also easy to find stories about social media gone wrong in healthcare. Many of these involve HIPAA violations by staff who don't understand the inherent lack of privacy in social media posts. ProPublica, an investigative news organization, recently reported on more than 30 incidents where staff inappropriately shared images and other patient information over social media networks.

In light of the horror stories, there is a temptation for practices to construct a "defensive" policy focused solely on restricting staff use of social media; essentially "What you don't say can't hurt us." Instead, you should seek a balance that not only protects patient privacy and discourages public relations gaffes, but also allows those who know your practice best — its staff — to show pride in their work and promote it. Designing a good social media policy for your practice can tip that balance to the positive.

Here are some ways to help you get there:

1. Keep it simple. Staff will view a policy that is too long and tries to cover everything negatively — if it's read at all. Further, because social media is constantly evolving, too much specificity will virtually guarantee your policy will quickly become obsolete.

2. Be clear about your goals. To provide context for your social media policy, put the focus on what you are trying to accomplish. These goals may be things such as maintaining patient confidentiality, compliance with applicable laws and regulations, protecting the practice from negative outcomes, enhancing the practice's professional image, and ensuring a productive and focused workplace.

3. Don't reinvent the wheel. There are many easily adaptable, great policies available online. You can find many examples here and can even view policies by professional sector, including healthcare of course.

4. Get beyond the "thou shalt not." See the positive as well as the negative. Don't be so afraid of the worst-case disaster that you stop staff from telling your practice's story. The average adult Facebook user has about 300 friends, meaning that even in a small practice you could easily reach thousands of people with a positive message. Imagine someone saying, "I'd love to tell my Facebook friends about the money we raised at the local charity event, but our social media policy won't allow us to post on work-related topics."

5. Don't just dictate, educate. Beyond the policy itself, staff may need help in thinking through how this all works "in real life." Again, there already are some great resources to give you a running start on this. One example is "A Nurse's Guide to the Use of Social Media." You can offer real examples and scenarios that help your staff understand the repercussions on using social media to represent your practice.
6. Listen and respond to feedback. This allows you to not only hear concerns staff may have, but also get a sense whether they understand your social media policy. Initial staff reaction to a social media policy may not be warm and fuzzy. Most staff will easily understand rules on using practice equipment and network connections for personal use during the workday. However, you may get pushback on "restrictions" outside of work time. Point out that HIPAA violations hurt patients — and they can have negative legal consequences for not only the practice, but also the individual staff member. Be upfront and explain that your policy covers both staff social media activity at work and off the clock. Respond to any concerns by communicating the practice's expectations of staff professionalism, both on and off the clock.

7. Back it up. Enforcement and sanctions may be unpleasant, but they are an absolute necessity. Having a policy but not enforcing it may be worse than no policy at all, since this sends staff the message that you're not serious. It also can create liability for the practice if you have a policy in place and make no effort to ensure that it is followed. Your medical practice's sanctions for policy violations — especially those involving HIPAA — should be documented and consistently applied to all staff.

If you are successful, your social media policy and staff education efforts will offer bright-line guidance prohibiting illegal or unethical activity, while also encouraging staff to share their successes at your practice. That is a win-win for patients, the practice, and staff.

Source(s): Stephen McCallisterhttp://www.physicianspractice.com, www.hcsiinc.com

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, March 25, 2016

What to Expect in a 2016 HIPAA Audit (video)


Would you be surprised if OCR showed up for a HIPAA audit?

Who does this impact?
A Fine from OCR does not just impact the physician, but also the
office manager, the staff, and the reputation of the practice for years to come!

In this webinar, HCSI guides healthcare practices and business associates
on what to expect during a HIPAA audit, with our webinar.

3 main points of reference in the webinar:
1. Penalties for HIPAA Violations
2. Areas covered in an audit
3. Let's begin your Audit!

Additional resources at the end of the presentation:

1.       The change being made with OCR’s HIPAA Audit protocol
2.       Start to finish expectations for 2016 HIPAA audits
3.       HIPAA audit planning recommendations

Click here for the webinar or view below:


Contact support@hcsiinc.com or call 801-947-0187 for questions related to HIPAA, OSHA, etc.

If you are responsible for integrating a culture of compliance, then consider visiting and Liking our Facebook Page for supporting articles:
HCSI Facebook Page

http://hcsiinc.com

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, March 8, 2016

Share Your Opinion - Is This a HIPAA Breach or Merely an Accidental or Incidental Disclosure?

Emails Exposed BJC HealthCare Patients’ Data

What is the difference between an Incidental and an Accidental disclosure of protected health information (PHI) or a HIPAA Data Breach? Can you give examples of each? How do you handle each in your practice for an accounting of disclosures as required in the HIPAA privacy rule regulations?

The difference between an "incidental" and an "accidental" disclosure of PHI is the difference between complying with the privacy rule and violating it.
In a recent story, BJC HealthCare, a not-for-profit health system based in St. Louis, MO., has started notifying 2,393 of its patients that some of their protected health information has been exposed as a result of an email error that occurred on December 30, 2015.

An email containing sensitive data covered by HIPAA was emailed to another medical group. While HIPAA permits the sharing of healthcare data for certain healthcare operations, the Security Rule requires any shared data to be protected in transit.

If ePHI is to be shared electronically with another covered entity or business associate, it must be adequately protected to prevent unauthorized access and to protect the integrity of those data. Controls to protect the integrity of ePHI are addressable issued under 45 CFR § 164.312(e).

In this case, the data were not encrypted to the standards required by the Security Rule, and consequently the data could potentially have been intercepted in transit.

HIPAA requires covered entities to notify individuals when their PHI has been exposed or viewed by a third party to allow them to take precautions to protect their identities and reduce the risk of loss or harm.

Patients have been advised by mail that their name, date of birth, gender, and Medicare Beneficiary information were included in the email, although Social Security numbers were not exposed, and no financial or medical data were contained in the email. Patients affected by the email error were part of the healthcare provider’s accountable care organization.

An investigation into the incident showed that the email was received by the intended recipient and no other individual appeared to have gained access to any patient data, although the possibility cannot be ruled out. Out of an abundance of caution, all affected individuals have been offered complimentary credit monitoring services for a period of one year.

In order to prevent similar errors from occurring in the future, BJO HealthCare will be conducting further staff training to ensure that staff members are aware of the protocols that must be followed when transmitting data covered by HIPAA.

---

So with all information considered, would you say this incident is a Data Breach, an Accidental disclosure or an Incidental disclosure?  Please post a comment with your feedback.

Additional Information:

Certain "incidental" disclosures are a permitted use of PHI and, therefore, are not a violation of the regulations. (See Section 164.502(a)(1)(iii).) On the other hand, an "accidental" disclosure is not permitted under the regulations and would subject the organization to penalties for the violation. (See Section 164.502(a)(1) and (2) of the regulations.) The HIPAA statute would limit the penalties for an accidental disclosure to civil penalties alone. 


An "incidental" use and disclosure occurs as a by-product of another permissible or required use or disclosure under the privacy rule. It is a limited disclosure that cannot reasonably be prevented.   Examples of "incidental" disclosures include a hospital visitor overhearing a provider's confidential conversation with another provider or a patient, or a visitor catching a glimpse of a patient's information on a sign-in sheet or nursing station whiteboard.


An incidental use or disclosure may result from any use or disclosure permitted under the privacy rule. It is not limited to treatment communications or to communications among healthcare providers or other medical staff. An incidental use or disclosure may occur, for example, when a provider talks with an administrative staff member about billing a patient for a particular procedure and is overheard by 1 or more persons in the waiting room. 


An incidental use or disclosure is not a violation of the HIPAA medical privacy regulation provided the covered entity has applied reasonable safeguards (see Section 164.530(c) of the regulation) and implemented the minimum necessary standard (see Sections 164.502(b) and 164.514(d) of the regulation), where applicable, with respect to the underlying use or disclosure. (See Section 164.502(a)(1)(iii) of the regulation). If the underlying use or disclosure violates the privacy rule, however, the incidental use or disclosure would be a violation of the rule. 


Incidental disclosures do not have to be included in the accounting of disclosures provided at the patient's request. (See Section 164.528(a)(1)(iii) of the regulation.) 

Source(s): www.hipaajournal.comwww.medscape.com, www.law.cornell.edu, hhs.gov

To subscribe to this blog, enter your email address:


Delivered by FeedBurner