Showing posts with label HIPAA Security. Show all posts
Showing posts with label HIPAA Security. Show all posts

Thursday, August 10, 2017

Six Ways to Improve Data Security at Your Practice

A married couple — both doctors who shared a medical practice — almost divorced over a HIPAA breach that blindsided them when a patient called to say that her medical records appeared in a Google search and she was filing a lawsuit.

The orthopedist of a small practice didn’t want to fund the cost of an IT service provider to make sure his network was secure.  Instead the doctor hired his cousin who earned his IT stripes fixing performance problems on his own laptop.  Unfortunately, the family member never updated the practice’s malware software and patient data ended up on a rogue server.  Now it’s being held for ransom. 

The Smaller the Practice the Less the Compliance

For medical practices with 20 or less employees, doctors are often reluctant to spend money on HIPAA security than larger practices.  Importantly, the latter will have a compliance officer who makes sure HIPAA rules are followed, employees are trained, and policies and procedures are up to date. 

Doctors running small practices don’t believe they’re at risk for a data breach so they ignore the same steps taken by the compliance officer.  Meanwhile, it’s ordinary human errors that could take down the practice.  An employee leaves his tablet in a taxi or thieves break into the office and steal two laptops that contain patient records.  Or the doctor loses his laptop and keeps it under wraps since he thinks he hasn’t stored any patient records on it, so no one needs to know.  However, a disgruntled employee who was terminated gets revenge by reporting the practice to the Department of Health and Human Services’ Office of Civil Rights (OCR).  The OCR accuses the practice of having a breach and hiding it, and calls for an investigation. 

These are all real world events that have sent medical practices into a tailspin.  Doctors call a HIPAA compliance expert in a panic because they’re now caught in the web of the OCR and scrambling to prepare for an audit.  Worse yet, these compliance risks were right under their noses.

The Practice Needs As Much Care As the Patients

The risk of a data breach can be as life threatening to the practice that doesn’t protect its data, as the risk of lung cancer is for the patient who chain smokes.  Think of a data breach as a disease and the stolen laptop causing pain and suffering, and eventual death, which could all be prevented.  Doctors should think about data breach prevention and care for their businesses with the same commitment to disease prevention and care for their patients. 

When a practice fails to perform a security risk assessment or ensure that his employees used strong passwords, not long after he is convincing OCR auditors that the breach was an accident.  He has to hire attorneys to complete the audit and there is no budget left to invest in more network security, or cyber insurance. 

HIPAA Compliance Made Easy for Small Practices

There are some simple steps small practices can take that will take far less time than preparing for an OCR audit:

- Perform a security risk analysis — Analyze how patient information is currently protected. How often does the practice perform data backups? Is there a termination procedure when an employee leaves? Do employees have the minimum level of access to patient information? Are all portable devices encrypted?  Are medical records protected in case of fire or flood, or lost or stolen laptops that contain patient information?

- Train employees — Make sure they know how to spot phishing scams and suspicious links in emails, recognize fraudulent “IT experts” who call in to upgrade an operating system.  They should also know to avoid conducting business on public Wifi, and minimize sharing on social networks.

- Inventory patient information — Locate where all patient information is stored. It could be an EHR or a word document in the form of patient letters, or excel spreadsheets as billing reports or scanned images of your insurance carrier’s explanation of benefits (EOB).  This information resides on desktops, laptops and mobile devices, and should be encrypted.

- Employee data theft — Employee theft of information is one of the leading causes of HIPAA breaches in small organizations.  An employee steals patient information and opens a charge account at a local department store.  The patient finds out and sues the practice for not protecting her electronic protected health information (ePHI).  Employees should have minimal access to EHRs — only the information they need to perform their duties.   Also data logs should be checked.

- Breach Response Plan — Is there a response plan in place in case a breach does occur? The plan should include who will be on the response team, what actions the team will take to address the breach, and what steps they’ll take to prevent another similar breach from occurring. Make sure the plan is documented and all employees are trained on what they need to do.

These few actions can make the difference between being sued by patients for a data breach and gaining their confidence that their doctor cares as much about their health as he does for their security.

Source(s): https://www.hcsiinc.comhttp://www.physicianspractice.com

For more information on this and other healthcare compliance topics related to HIPAA, OSHA, Medicare and HR, simply email your questions to support@hcsiinc.com
visit our website at http://www.hcsiinc.com or post a question on our LinkedIn group at: http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, March 16, 2017

Policies and Procedures, Compliance Training and HR

Maintaining Compliance and also Keeping HR in the Loop
 HCSI
In your ongoing efforts to provide an office culture of compliance, it is important to remember that HIPAA requires covered entities to establish and implement written policies and procedures that are consistent with its Privacy and Security Rules.  It can also be important for your Human Resource officer(s) to be involved with HIPAA compliance related issues in the business.

The U.S. Department of Health and Human Services, Office for Civil Rights (“OCR”) has begun its Phase 2 HIPAA Audit Program.  The Program will focus on the policies and procedures adopted and employed by covered entities and their business associates to meet the requirements of the Privacy, Security, and Breach Notification Rules.  Furthermore, if a group health plan is selected for an audit, it would have a very short time to produce its policies and procedures (i.e., 10 business days).  If the group health plan does not comply (for example, because it does not have policies and procedures), the OCR will likely impose corrective measures which could include costly civil monetary penalties.

HIPAA policies and procedures have important functions, including but not limited to:
  • Limiting uses and disclosures of Protected Health Information (“PHI”) to the minimum amount reasonably necessary to achieve the purpose of the use or disclosure;
  • Identifying the workforce members who need access to PHI and electronic PHI (“e-PHI”) to carry out their duties, the categories of PHI that they need, and any conditions under which they need the PHI to do their jobs;
  • Ensuring appropriate protection of e-PHI when it is transferred, removed, disposed and electronic media is re-used; and
  • Ensuring that e-PHI is not improperly altered or destroyed.
However, it is not sufficient for a covered entity to merely adopt its HIPAA policies and procedures.  The health practice office must also:
  • Designate a privacy and security official to develop and implement policies and procedures; 
  • Train applicable workforce members on its policies and procedures as necessary for them to carry out their functions, and apply appropriate sanctions against workforce members who violate its policies and procedures;
  • Periodically assess how well its policies and procedures meet the requirements of the Security Rule; and
  • Designate a contact person responsible for receiving complaints and providing individuals with information on the covered entity’s privacy practices.
There is no template for HIPAA policies and procedures.  Instead employers have the flexibility to design policies and procedures that are appropriate for their size, organizational structure, and risks to PHI and e-PHI.  Furthermore, as employers evolve, so should their policies and procedures.  For example, if an employer adopts a telework policy, it may wish to review whether its policies and procedures appropriately address issues involving remote access.


Summarizing, although not a new requirement, due to new technologies, evolving business and regulatory practices, along with impending HHS audits, employers may want to review their HIPAA policies and procedures to make sure that they are compliant and up-to-date. Many HIPAA policies inherently overlap with Human Resource's duties: training, disciplinary actions and employee health information for examples.
The increase in audits — combined with everything from changes in technology, the addition of a health and wellness program and concerns about hacking — serve as a good reminder why employers should revisit HIPAA training often and collaborate with HR to ensure compliance.

Many of the employers facing fines are healthcare providers, health plans or healthcare clearinghouses (organizations considered as covered entities under HIPAA). But most HR professionals also handle protected health information (PHI) to some extent, which puts them in danger of violating the HIPAA Privacy Rule.

Employers should have a written policy in place about how they handle PHI and designate PHI handlers and a HIPAA privacy officer. The policy should outline what types of information are considered PHI and how employers may and may not use it. It should also include a procedure for handling complaints and a process for employees to file them if they think their privacy rights are being violated.

Employees who may handle PHI should be trained on the dos and don’ts of handling protected health information, especially as it relates to electronic information. It’s vital for the HR team to understand the implications of handling PHI in emails, storing it on the cloud, or communicating about it over other electronic formats. And when discussing matters containing PHI with an employee, it’s important to have a signed HIPAA authorization form for the release of employee health information.

Lastly, the HIPAA privacy officer should review compliance documents and ensure that agreements with vendors who handle PHI, called “business associate agreements,” are up to date. The federal government considers vendors and subcontractors to be business associates if they handle PHI on behalf of the covered entity.

Source(s): http://www.hhs.com, http://www.jdsupra.comhttps://www.benefitnews.com, http://www.hcsiinc.com


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, October 19, 2016

Ten HIPAA Security Tips Saving Small Practice’s Time, Money and Reputation


This article was submitted by contributing author, Vic Berger.

My business practice focuses on helping organizations understand their risks related to security. Cyber Security is one risk every organization struggles with. Small businesses face the same types of risks as bigger companies but lack the staffing and resources to respond the same as a large organization. I am frequently asked by small business owners “What cost effective recommendations would you make for my business to make it more secure?” Here are my top ten recommendations for small businesses when dealing with information security.

1.                  Have A Written Security Policy
Every business needs a good written information security policy. This is the basis for your security plan, as well as your legal safety net when something happens. There is no single action a company can take that is more important. Yet this is often the first issue I find in audits of companies of every size, and in every sector.  The plan needs to be well written; read and understood by every employee in the company; and consistently maintained.  There are numerous templates and examples of security policies on the internet. Many consulting companies will tailor a stock plan to suit your organization.

2.                  Encrypt Everything
The first rule of I.T. security is “no solution is perfect 100% of the time”. You cannot always trust prevention methods to keep your data safe. The only way to consistently assure the protection of your data is to encrypt it so it cannot be read. This is especially important with cloud or internet based storage accounts. Dropbox, Google Drive, OneDrive, Box, and Egnyte are all great tools, but no cloud provider will guarantee the security of your data, and all have recently been breached. My basic rule of thumb is: if it is on the internet, consider it public access unless you have encrypted it. You can encrypt your cloud storage using a simple to use (and free for personal use) encryption program from nCryptedcloud that supports Dropbox, Box, Google Drive, OneDrive, and Egnyte available at https://www.encryptedcloud.com/  You can also use a portable USB format hardware encryption and key management device from BlackSquare called Enigma, at www.blacksquaretechnologies.com for personal and small business encryption on portable devices, computers, and cloud accounts.
  
3.                  Protect Your Website
Current information security statistics indicate that 85% of all websites have one or more significant security vulnerabilities. I apply patches to my websites almost daily to keep up with newly discovered vulnerabilities. There are three basic types of websites, with three different recommendations based on what you use:
A.      A static web page with basic company information that doesn’t change. Your biggest risk is disruption or defacing of this type of website. Your hosting provider or ISP will take care of the service disruption. For defacing, keep a good site backup and do a complete CLEAN restore as soon as possible (hackers leave behind gotchas).
B.      An interactive or dynamic web site with user content and/or e-commerce. Often these are created using a standard Content Management Software (CMS) package like WordPress, Joomla, or Drupal.  These are best left to a professional company to update and manage if possible. If you must do it yourself, get a good book on securing your type of CMS. Subscribe to the vulnerability notification feed for your CMS type (all of the common solutions have this). Check your website against new vulnerabilities often.
C.      A site dedicated to internet e-commerce or a highly interactive site where users log in to access content.  Hire this one out! Do not try to do this yourself unless information security is your core business, or you have an I.T. staff with specialized training and certifications in internet security.

4.                  Data Backups
I see irreplaceable data lost almost every day. I have seen it in government agencies, fortune 500 companies, and in every industry vertical. It can be from a data breach, a hardware failure, a natural disaster, or from human error. Whatever the reason, there is no excuse for not having good backups. You should have at least one full data backup per week. More if your data changes frequently. Store the backups offsite, and somewhere safe.  I suggest the granite vault at Perpetual Storage www.perpetualstorage.com, it is the safest storage site in the country. You should also buy a GoBox and store everything you would need to rebuild your business after a major disaster.

5.                  Avoid Consumer Grade
If you can buy an I.T. product at a local box store, electronics retailer, or office supply store it is probably consumer grade, and not designed for business. This includes firewalls, routers, wireless access points, servers, storage, networking devices, tape drives, or anything that protects, moves, or manages your data. Yes, commercial grade is more expensive, for a reason: It Is Commercial Grade! Consumer grade security equipment was designed to protect a few ports and protocols commonly used by consumers. Business applications use different ports and protocols. It either does not run behind consumer grade equipment or you have to poke holes in your security to make it work. Consumer grade security is also easy to breach. Commercial grade uses much better security methods, and is consistently tested. Call your local I.T. reseller and ask them what they recommend.

6.                  Know Your Risks
Knowing what you have, that would be of value to someone else, helps you determine what to focus on to protect. Do you have sensitive or privileged data? Is your data unique or valuable? Are there government regulations like HIPAA or Sarbanes-Oxley that affect your industry? Are customers or consumers ever given access to your data? How many employees do you have, and what risk areas do they create? Beyond what is already addressed elsewhere in this whitepaper, as a minimum you need: Antivirus (web search free antivirus), Anti spyware (web search free anti-spyware), and a good security shell for your organization (Try Arellia www.arellia.com). If you have customers that are EVER by your work computers you need an anti-keystroke logging solution (StrikeForce www.strikeforcetech.com). Your mail and web should have mandatory content filters (either through your ISP or your firewall).

7.                  Plan For BYOD
BYOD stands for bring your own device. This is a huge shift in the government and corporate sector, but probably business as usual in small businesses. Small businesses often use what they have, even if it is a personal device. This is increasingly creating security issues. What your employees, knowingly or unknowingly, have on their devices, and what they do with them in their own time is now brought into your environment. This can open up security holes as well as create liability issues. Make sure that BYOD is clearly defined and covered in your security policy. There is technology that can restrict the security vulnerabilities of personal devices, so ask your local I.T. reseller for assistance. Finally, make sure your employees clearly understand your expectations and limits where BYOD is concerned.
 
8.                  Who Is Guarding The Sheep
This applies whether you are a fortune 500 company or a small business. I.T. administrators have great power. They can view privileged information, and have an extremely high level of system access and control, more than even the owners and senior executives of the company. This is a great responsibility, but also a huge temptation. It is very common to discover that I.T. administrators have been inside payroll files, HR files, or other personal or sensitive material. A good security shell like Arellia (see #6) creates log files to review, but that means that someone has to faithfully do this. Again, start with policy and clearly define responsibilities and expectations. Two person integrity is always prudent where money and manpower permit. And as always, rule #2 applies: Encrypt everything!

9.                  Physical Security Is Information Security
Theft is about opportunities, and criminals use them very effectively. Data from a stolen laptop is easier to obtain than hacking. Why brute force passwords when you can easily install a keystroke logger. A screwdriver to the back door is as good as a key if there is no other security. You must have good physical security policies and practices to have good information security. Cameras are effective and have become reasonably cheap. Programs that wipe stolen devices are commonly available. Keeping sensitive information and records locked away after hours deters opportunistic thieves. Think like a criminal, and then protect yourself from what you would exploit.

10.              Know When To Call For Help
             I am a passable plumber, marginal carpenter, and just plain dislike auto mechanics. I can do all three if required but usually end up spending more time, effort, and money than what I had intended. I can tackle small jobs but I leave the major projects to the professionals. I.T. Security is a highly specialized field with significant training and experience necessary to operate at a professional level. Your whiz kid nephew, who is good with computers, does not have that level of training or the required experience. This is especially important when there is an incident. Less than 3% of all I.T. professionals have the security experience and certification necessary to handle a data breach. I leave significant plumbing, carpentry, and auto mechanics jobs to the professionals, leave your major I.T. security issues to the professionals as well.

This article was submitted by a contributing author:
Vic Berger
CEO, Opsis Technologies
855-99OPSIS


For more information on protecting your office regarding this issue or additional HIPAA, OSHA, HR, and Medicare resources, please visit our web site: http://www.hcsiinc.com or email support at: support@hcsiinc.com.



To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, October 4, 2016

Those Pesky Password Changes!

This article was written by a contributing author.

So the IT guy says you have to renew your password every 30 to 60 days but we have so many passwords to remember in healthcare already!   Where they all are stored?  Electronic medical record systems, in the office,  hospital systems, insurance sites, HR systems, accounting and payroll systems etc.

You get the picture by now.

We are already so burdened down with patients, billing and revenue, coding correctly, pay cuts!
I understand it is so challenging to work in the healthcare now and the virtual world we now live in.
So why must we take this serious!  It seems innocent to let your co-worker use your password just this once until he or she receives theirs.

Everyone in healthcare need to understand these words “Cyber Attack”!  In 2015 there were 10 breaches all made in the month of December of very serious nature reported to HHS Office of Civil Rights.

Let’s take a look 5 of these breaches! 
1. 12/01: Centegra Health System, Il, affected 2,929 people.
A mailing snafu may have exposed personal information of patients.
2. 12:01: Cottage Health, Calif. Affected 11,000 people
In a statement, Cottage Health officials said limited information from as many as 11,000 patients was exposed.
"Cottage Health recently hired a team of cyber security experts to test our data systems," the statement said. "This team discovered a single server that was exposed. We immediately shut down this server and began an investigation."
3. 12/02 Univesity of Colorado Heath, Co. 827 people affected.
A nurse at Poudre Valley Hospital was fired for viewing patients' medical records out of personal curiosity, the Coloradoan reported.
University of Colorado Health, which operates PVH and Medical Center of the Rockies in Loveland, is notified patients that an employee inappropriately accessed their electronic medical records.
4. 12/03 Blue Cross Blue Shield of Nebraska, 1,872 people affected Blue Cross and Blue Shield of Nebraska notified beneficiaries that a printing error caused some dental explanation of benefits forms to be sent to the wrong customers. The forms revealed treatment and services that the insurer paid for their insured.
5. 12/8 Maine General Health and subsidiaries, 500 people affected
On Nov. 13, 2015, the FBI notified MaineGeneral that agents had detected MaineGeneral data on an external website that is not accessible by the general public. The data affected includes the dates of birth and emergency contact names, addresses, and telephone numbers for certain patients referred by a treating physician to MaineGeneral Medical Center for radiology services since June 2009.

These incidents can cost from thousands of dollars to millions of dollars.  Ways to avoid these problems!  Perform risk analysis assessments; provide education and training, policies and procedures.  Role playing can be helpful to make these situations real to your employees and to ensure success in the event of a breach or cyber attack.  The best advice I can offer is to treat these systems and records as if it is your own bank account.  Be consistent with your HIPAA training and make it a constant work in process!

Don’t fret be consistent take advantage of the people in the know that can make your life easier! 

Marchelle Cagle, CPC,CPC-I, CEMC,CPB,CMOM
Cagle Medical Consulting, LLC
consult@caglecpc.com


This article was written by a contributing author, Marchelle Cagle. We are always open to receiving well written articles from people who have experience working with the following topics: HIPAA, OSHA, Medicare, and Human Resources. If you would like to contribute to this blog by writing an article that will help others who could be in your same situation, please email your article to jhuff@hcsiinc.com. All well written articles will be considered for publication.

Tuesday, July 26, 2016

OCR's Top 7 Areas of Focus During Phase Two Audits

Areas of improvement to focus on within your office.

During phase 2 of the Office for Civil Rights (OCR) HIPAA audits, they have decided to focus their attention on seven areas of compliance. These specific areas were chosen due to their history of non-compliance during multiple audits in the past. This is not to say that OCR will not investigate other areas, but their main focus will be on these specific requirements:

  • Under the HIPAA Privacy Rule
    • Notice of Privacy Practice and consent requirements
    • Provision of notice - electronic notice (NPP acknowledgement in electronic format)
    • Right to access (Patients right to access their PHI)
  • Under the HIPAA Security Rule
    • Security management process - risk analysis (Documented and completed internal risk analysis)
    • Security management process - risk management (Documented policies and procedures that prevent, detect, contain, and correct security violations)
  • Under the Breach Notification Rule
    • Timeliness of notification (Notification of breach given to individual and OCR within required specifications)
    • Content of notification (Notification of breach contains all of the required information as specified by OCR)
These are important areas of compliance that have been neglected or out right ignored by healthcare organizations. If you have not done so, get these areas of compliance in order within your organization.

For information on how to prepare for OCR's Phase 2 HIPAA audits go to:
http://hcsiinc.blogspot.com/2016/07/preparing-for-phase-2-of-hipaa-audits.html




To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, March 25, 2016

What to Expect in a 2016 HIPAA Audit (video)


Would you be surprised if OCR showed up for a HIPAA audit?

Who does this impact?
A Fine from OCR does not just impact the physician, but also the
office manager, the staff, and the reputation of the practice for years to come!

In this webinar, HCSI guides healthcare practices and business associates
on what to expect during a HIPAA audit, with our webinar.

3 main points of reference in the webinar:
1. Penalties for HIPAA Violations
2. Areas covered in an audit
3. Let's begin your Audit!

Additional resources at the end of the presentation:

1.       The change being made with OCR’s HIPAA Audit protocol
2.       Start to finish expectations for 2016 HIPAA audits
3.       HIPAA audit planning recommendations

Click here for the webinar or view below:


Contact support@hcsiinc.com or call 801-947-0187 for questions related to HIPAA, OSHA, etc.

If you are responsible for integrating a culture of compliance, then consider visiting and Liking our Facebook Page for supporting articles:
HCSI Facebook Page

http://hcsiinc.com

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, March 8, 2016

Share Your Opinion - Is This a HIPAA Breach or Merely an Accidental or Incidental Disclosure?

Emails Exposed BJC HealthCare Patients’ Data

What is the difference between an Incidental and an Accidental disclosure of protected health information (PHI) or a HIPAA Data Breach? Can you give examples of each? How do you handle each in your practice for an accounting of disclosures as required in the HIPAA privacy rule regulations?

The difference between an "incidental" and an "accidental" disclosure of PHI is the difference between complying with the privacy rule and violating it.
In a recent story, BJC HealthCare, a not-for-profit health system based in St. Louis, MO., has started notifying 2,393 of its patients that some of their protected health information has been exposed as a result of an email error that occurred on December 30, 2015.

An email containing sensitive data covered by HIPAA was emailed to another medical group. While HIPAA permits the sharing of healthcare data for certain healthcare operations, the Security Rule requires any shared data to be protected in transit.

If ePHI is to be shared electronically with another covered entity or business associate, it must be adequately protected to prevent unauthorized access and to protect the integrity of those data. Controls to protect the integrity of ePHI are addressable issued under 45 CFR § 164.312(e).

In this case, the data were not encrypted to the standards required by the Security Rule, and consequently the data could potentially have been intercepted in transit.

HIPAA requires covered entities to notify individuals when their PHI has been exposed or viewed by a third party to allow them to take precautions to protect their identities and reduce the risk of loss or harm.

Patients have been advised by mail that their name, date of birth, gender, and Medicare Beneficiary information were included in the email, although Social Security numbers were not exposed, and no financial or medical data were contained in the email. Patients affected by the email error were part of the healthcare provider’s accountable care organization.

An investigation into the incident showed that the email was received by the intended recipient and no other individual appeared to have gained access to any patient data, although the possibility cannot be ruled out. Out of an abundance of caution, all affected individuals have been offered complimentary credit monitoring services for a period of one year.

In order to prevent similar errors from occurring in the future, BJO HealthCare will be conducting further staff training to ensure that staff members are aware of the protocols that must be followed when transmitting data covered by HIPAA.

---

So with all information considered, would you say this incident is a Data Breach, an Accidental disclosure or an Incidental disclosure?  Please post a comment with your feedback.

Additional Information:

Certain "incidental" disclosures are a permitted use of PHI and, therefore, are not a violation of the regulations. (See Section 164.502(a)(1)(iii).) On the other hand, an "accidental" disclosure is not permitted under the regulations and would subject the organization to penalties for the violation. (See Section 164.502(a)(1) and (2) of the regulations.) The HIPAA statute would limit the penalties for an accidental disclosure to civil penalties alone. 


An "incidental" use and disclosure occurs as a by-product of another permissible or required use or disclosure under the privacy rule. It is a limited disclosure that cannot reasonably be prevented.   Examples of "incidental" disclosures include a hospital visitor overhearing a provider's confidential conversation with another provider or a patient, or a visitor catching a glimpse of a patient's information on a sign-in sheet or nursing station whiteboard.


An incidental use or disclosure may result from any use or disclosure permitted under the privacy rule. It is not limited to treatment communications or to communications among healthcare providers or other medical staff. An incidental use or disclosure may occur, for example, when a provider talks with an administrative staff member about billing a patient for a particular procedure and is overheard by 1 or more persons in the waiting room. 


An incidental use or disclosure is not a violation of the HIPAA medical privacy regulation provided the covered entity has applied reasonable safeguards (see Section 164.530(c) of the regulation) and implemented the minimum necessary standard (see Sections 164.502(b) and 164.514(d) of the regulation), where applicable, with respect to the underlying use or disclosure. (See Section 164.502(a)(1)(iii) of the regulation). If the underlying use or disclosure violates the privacy rule, however, the incidental use or disclosure would be a violation of the rule. 


Incidental disclosures do not have to be included in the accounting of disclosures provided at the patient's request. (See Section 164.528(a)(1)(iii) of the regulation.) 

Source(s): www.hipaajournal.comwww.medscape.com, www.law.cornell.edu, hhs.gov

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, November 11, 2015

Understanding Business Associates

To be compliant with HIPAA, you must understand the Business Associate aspect of the law.

Business Associates of covered entities must comply directly with the HIPAA Security and Privacy Rules, according to the Health Information Technology for Economic and Clinical Health (HITECH) Act. The Security Rule, which complements the HIPAA Privacy Rule, includes safeguards for protecting patients’ electronic protected health information (PHI), based on three components:

• Administrative: Organizations must have procedures that show how they will comply with the security rule
• Physical: Organizations must control how patients’ records are physically accessed and prevent inappropriate access
• Technical: Organizations must have a system to control computer access and monitor and protect communication that flows electronically over open networks.

Section 13401 of the HITECH Act includes the new BA requirements. The act also states that civil and criminal penalties for violations of the HIPAA and compliance audits apply directly to BAs. Covered entities must incorporate these additional requirements in their agreements with BAs, according to the new law.

A covered entity may disclose PHI to a business associate for purposes agreed to by contract.
HHS’ definition of a Business Associate:

• A business associate is a person or entity who provides certain functions, activities, or services on behalf of a covered entity involving the use and/or disclosure of PHI.
• A business associate is not a member of the health care provider’s workforce.
• A health care provider or other covered entity can also be a business associate to another covered entity.
• Covered entities who disclose PHI to providers for treatment are not business associates. An insurance company is not a business associate. They do not perform a function on behalf of a covered entity.

The provider’s office must document by means of a written contract or other written agreement the satisfactory assurances that the business associate will appropriately safeguard the information disclosed to them for their use.

Examples of a business associate are:

• A billing company
• A clearinghouse
• An answering service
• IT personnel who have access to computers containing PHI
• A document shredding company
• A collection agency
• An attorney
• Couriers

The contract with business associates covers a set of contractual obligations. Their function is to protect information generally and help the covered entity comply with the entity’s obligations under HIPAA.

HHS has stressed that PHI may be disclosed to a business associate only to help the providers and plans carry out their health care functions - not for independent use by the business associate.
To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Monday, November 9, 2015

HIPAA Security Risk Analysis

Risk analysis involves identifying risks and vulnerabilities in your information systems. 


It is a required implementation specification within the Security Management Process. It requires you to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) held by your office. It calls for you to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.

Perform a Risk Analysis

A risk analysis is a process that you should carry out in your practice in a step-by-step manner. Following is a suggested method of performing your risk analysis:

Inventory – You should begin by conducting a detailed inventory of your ePHI and your information systems that contain ePHI. Information systems can be complex. The inventory should seek to identify all inter-dependencies among these items.
• Information system hardware and software
• Identify the primary users of the information systems and ePHI
• Function and purpose of the ePHI and information system
• Technical controls (hardware or software access control mechanisms)
• Non-technical controls (security policies, employee training)
Threat identification – You should next identify all potential threats to your ePHI and your related information systems.
19
• Natural – floods, earthquakes, tornadoes, hurricanes, etc.
• Human – Unintentional (incorrect data entry or accidental deletion of data)- or - Intentional (installing malicious hardware, refusing service)
• Environmental – Power failures, hazardous material spill, etc.

Vulnerability Identification – Identify the vulnerabilities of your ePHI and related information systems. A vulnerability is a flaw or weakness in a system’s implementation, security, procedures, design, or internal controls that can be exploited by a threat and result in misuse or abuse of ePHI.
Examine your vulnerable sources by reviewing:
• Information systems
• Audit reports
• Information system test
• Evaluation reports
Security control analysis – You should next analyze the security controls that have you put into place to protect ePHI. There are two types of security controls that need to be assessed:
1. Preventative controls are designed to prevent or restrict the exploitation of vulnerabilities.
• Access control
• Authentication
2. Detective controls detect and report when violations occur.
• Audit trail
• Alarm
Determine risk likelihood – Three determining factors should be considered:
1.) Threat motivation and capability;
2.) Type of vulnerability; and
3.) Existence and availability of security controls.

Below are three risk likelihood levels and their definitions that may be used as examples:
• High likelihood - Threat is highly capable, motivated, or likely and current security controls are ineffective.
• Medium likelihood - Threat is capable, motivated or likely, but there are security controls in place that may prevent the exploitation of the vulnerabilities.
• Low likelihood – Threat is not capable, motivated or likely, or current security controls will likely prevent exploitation of the vulnerabilities.
20
Analyze the impact –Next, determine the impact that would result if a perceived threat were to actually take place in your practice. You should determine the impact in the following areas (define the impacts as high, medium, or low):
• Confidentiality - ePHI is disclosed or accessed in an unauthorized manner
• Integrity - ePHI is improperly modified
• Availability – ePHI is unavailable to authorized users

Determine the risk - For each vulnerability and its associated possible threat, you should make a risk determination based on:
• The likelihood that a threat will happen or attempt to happen.
• The level of impact to your practice in the event that the threat happens.
• The adequacy of the existing or planned security controls to protect your ePHI.
• High risk – Security controls should be implemented or improved as soon as possible.
• Medium risk – Security controls should be implemented or improved in a reasonable amount of time.
• Low risk – The security controls that are currently in place are probably adequate or the risk is acceptable.

Recommendations for Security Control – By using all of the above information, you should be able to conclude your Security Risk Analysis by implementing security controls that can mitigate or eliminate the unacceptable risks that you have identified. These controls should reduce the level of risk to your ePHI and your related electronic information systems to an acceptable level.
Documentation Requirements – Good documentation generally supports any situation in which an action is called into question. We often hear, “If is not documented, it was not done.” This is also true with security.

No documentation or poor documentation does not mean that you do not have a security risk. In fact, the better the documentation, the more likely it is for an external investigator to believe that an undocumented risk did not previously exist. Your diligence in documenting risks and your decisions relative to them can demonstrate that you made the effort to identify as many risks as reasonable and practical. If one is overlooked, you are much less likely than if your documentation is poor or nonexistent and you attempt to.

This type of Security Risk Analysis should be conducted on an annual basis. Be sure to document the specifics of your audit and its findings.
To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, November 5, 2015

HIPAA Workforce Security

HIPAA policies and procedures ensure all employees have appropriate ePHI access


Security Rule Language: Implement policies and procedures to ensure all members of its workforce have appropriate access to electronic protected health information (ePHI), as provided under paragraph (a) (4) of this section, and to prevent those workforce members who do not have access under paragraph (a) (4) of this section from obtaining access to electronic protected health information.”
45 CFR 164.308 (a)(3)(i)

The Workforce Security standard requires that you implement policies and procedures to ensure that all members of your workforce have appropriate access to ePHI and to prevent those workforce members who do not have access from obtaining access to ePHI. The type and extent of access to your information systems containing ePHI must be based on your Risk Analysis. Your Risk Analysis must consider the following factors:

• The importance of the applications running on the information system
• The value or sensitivity of the ePHI on the information system
• The extent to which the information system is connected to other information systems

Access to your information systems containing ePHI must be authorized only for your properly trained workforce members having a legitimate need for specific information in order to accomplish job responsibilities. All such access must be defined and documented. Such access must be regularly reviewed and revised as necessary.

Access to your information systems containing ePHI must be established through a formal, documented process. This process must include:

• Identification and definition of permitted access methods
• Identification and definition of how long access will be granted to user
• Procedure for granting a workforce member an access method (e.g. password or token) or changing an existing access method
• Procedure for managing access rights in networked environment
• Appropriate tracking and logging of actions of authorized workforce members on our information systems containing ePHI.

Your workforce members must not attempt to gain access to your information systems containing ePHI for which they have not been given proper authorization.

Following these policies and procedures will help prevent unauthorized access to ePHI while giving appropriate access to designated employees so that they can do their job.

To subscribe to this blog, enter your email address:

Delivered by FeedBurner