Showing posts with label Healthcare IT. Show all posts
Showing posts with label Healthcare IT. Show all posts

Thursday, July 28, 2016

Preparing for Phase 2 of HIPAA Audits

Phase 2 HIPAA audits are here. It’s no longer a matter of when.
The question is: Are you ready?
 HCSI
On March 21, 2016, the HHS Office for Civil Rights (OCR) launched the second phase of audits for compliance with HIPAA privacy, security and breach notification rules. And in his July 18, article, Second phase of HIPAA audits shifts into high gear, HDM’s Managing Editor Greg Slabodkin informed us that according to OCR, letters were delivered via email to “167 health plans, healthcare providers and clearinghouses” on July 11. Unlike the pilot audits that focused only on covered entities, Phase 2 targets both covered entities and their business associates.
While most of the Phase 2 audits will be desk audits, some onsite audits will be conducted. Phase 2 audits will focus on areas with high occurrences of noncompliance in Phase 1, particularly issues raised during data breach investigations. These include risk analysis and management, notice of privacy practices, timeliness of breach notification, reasonable safeguards, facility access control, and workforce training on policies and procedures.

To prepare for Phase 2 audits, covered entities and business associates should review their HIPAA privacy, security and breach notification policies and confirm that the following requirements are in place and current:

Comprehensive documented risk assessment. Promptly address any deficiencies and complete all action items. Build on the assessment outcomes to create a strong risk assessment management program. Conduct a follow-up security risk analysis periodically to identify, address and document deficiencies that may occur.

Written HIPAA policies and procedures. These should reflect privacy and security standards along with any risks or vulnerabilities identified during the assessment process.

Incident response plan for responding to breach of protected health information (PHI). Implement breach notification policies and procedures that are aligned with requirements under the HIPAA breach notification standards. Conduct practice rounds to prepare staff for a real event should it occur. 

Current Notice of Privacy Practices. Provide printed copies of the most recent notice to patients and also make the notice available on the organization’s website. 

Safeguards to protect all forms of PHI. This applies to paper, electronic and verbal PHI, including mobile devices and storage media. For employees who have personal devices, implement a BYOD policy aligned with HIPAA standards. Keep an up-to-date inventory of all systems and mobile devices.

Workforce training program. Conduct and document training for new employees. Conduct and document ongoing training for all workforce members.


Business associate agreements. Organizations must maintain a current inventory of all business associates. Agreements should be updated and implemented in compliance with current HIPAA requirements.

PHI transmission policy. Verify that all PHI is encrypted, or document a risk analysis to support the decision not to use encryption technology. 

Even if your organization is not selected for a Phase 2 audit, implementing judicious measures now will support future audits and improve HIPAA compliance. 

It doesn’t just end with an audit occurring within the four walls of a healthcare organization. With more healthcare professionals working from home, there is growing concern about the possibility of “at-home” audits - if not now, these may happen in the near future. We’re operating in a virtual world - building a remote workforce, and many HIM departments are sending people home - coders, transcriptionists, even management staff. 

Suppose OCR conducts an onsite audit at your facility and finds that some employees work from home. You must be prepared for the inevitable questions. How are you protecting information offsite? What measures are you taking to make sure PHI is secure? What policies and procedures are in place to address specific issues of at-home worksites? If you’re preparing for OCR audits - or any audits - these are increasingly important points to consider.

Business associates should also be taking a proactive approach in case auditors want to know how workers at home are being audited. Options might include Skype, Facetime or Hangouts. Here are some basic questions to ask employees when evaluating at-home privacy and security risks: 
  • Where are you located in your personal residence? 
  • Is your workspace private? 
  • Are passcodes properly concealed, not posted in the workspace? 
  • Do you use a virtual privacy network (VPN)? 
  • Do you have the capability to print information? 
  • Do you have appropriate shredding capability? 
  • Is your computer set to shut down (encryption mode) in your absence? 
These questions are just the beginning of the conversation. It is critical to communicate clear expectations to employees who work at home - along with consequences if they fail to maintain privacy and security according to your policies and procedures.

A company’s work-from-home policy defines the telecommuting work arrangement, including comprehensive privacy and security practices. The telecommuting employee must sign an agreement to ensure the protection of proprietary information and PHI, and to maintain the same level of confidentiality that exists on the company premises. If issues arise, there are several options depending on the severity of noncompliance - corrective action, education and training, increased audits, return to in-house, or termination of employment.

Although current OCR requirements do not specifically require at-home audits, the regulations clearly state that all reasonable precautions must be taken to ensure that all information is secure and privacy is maintained.

The best way to mitigate regulation issues is to have a solid HIPAA program in place and be well prepared to demonstrate best practices that proactively identify and address risks to PHI.

HIM must work closely with IT and other departments - risk management, C-suite, compliance, training and HR - to properly prepare for audits. HIM directors and their staff understand the content and use of PHI, where it is most likely to be at risk, and how to protect it. As experts in HIPAA and information governance practices, HIM professionals and Compliance Support Partners can lead organizations through a successful audit.

Also See: OCR's Top 7 Areas of Focus During Phase Two Audits



To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Tuesday, November 24, 2015

Why HIPAA Compliance is Lacking in Smaller Practices and Where to Begin

Why Compliance and Security Are Still Lacking


A number of healthcare data breaches have made the news of late, particularly involving large insurance companies and data clearinghouses. As the media portrays the situation, our private health information is leaking to the outside world at an alarming rate. Based on Bitsite's recently-released Third Annual Industry Benchmark Report, we should not be surprised. Based on the Bitsight report, the healthcare industry is near worst in overall security, with only education below them.

The data available prompts one big question – why is the security of our most personal data so poor? By comparison, security in the financial industry (best in the Bitsight report) is well addressed, with significant guidance and oversight being provided by PCI, GLBA and other bodies of regulations. The healthcare world has HIPAA, which admittedly, as security standards go, is fairly weak. That being said, it does not appear that it is being followed well. 

In her article Why are healthcare data breaches so common?, author Stephanie Tayengco suggests 5 reasons why 91 percent of healthcare organizations reported at least one breach over the last year: 
  1. Systems are old and complex
  2. Health IT is 95 percent manual work
  3. Disjointed monitoring
  4. "We’re already HIPAA compliant”
  5. Health data is valuable 
I tend to work with smaller healthcare organizations, the front lines of the healthcare cyberwar. They have less data than the big guys, but are usually much easier to hack. While Tayengco's list is quite appropriate for the industry as a whole, I see a somewhat different story in the niche I work with:

Transition to EMR without considering security 
Many smaller practices are adopting electronic medical record (EMR) systems. This is prompted partly by financial incentives available under the HITECH Act, and partly because an EMR system is seen as a pathway to HIPAA compliance. In most cases, practices are selecting “HIPAA compliant software,” thinking that the selection constitutes their compliance and as a result resolves their security issues. Sadly, this is a myth often spread by software companies as a sales tool. Compliance impacts the totality of a practice, not just the software used. 
Buy something that says “HIPAA,” and you are covered 
HIPAA is a complex standard, and not documented in a way that folks in medical practices can easily comprehend the requirements. As such, I have observed that a practice will buy something that claims HIPAA compliance, be it a secure email system, an encrypted storage system, etc, and assume that the purchase makes them compliant, and therefore secure. Again, HIPAA applies to the totality of a practice. It cannot be met by the purchase of a single product, no matter what the sales person said. 

No monitoring 
Tayengco is exactly correct in her point about disjointed monitoring, but again, that applies to the larger organizations. What I see in smaller practices is the complete lack of monitoring. These folks generally have no idea how to even open a log file, let alone review it. They often assume that their IT provider is handling it for them, which is usually not the case. Their network may be under attack, and they don’t even know it. 

Ignoring paper records 
While adoption of EMR by smaller practices has been strong, paper records almost always remain. This may result from the decision not to add archival paper records to the EMR system, or because they serve as a bit of a security blanket. Whatever the reason, they often sit in unlocked file cabinets with no controls in place, leaving them open to insider threats

Lack of basic network protection 
In my experience, smaller practices are not much different from small business in general with their adoption of basic security controls like firewalls, strong wireless systems and data encryption. I rarely see these practices properly adopted in any small business, medical or otherwise. 

No training or policies 
Have you ever tried to put together a bike for one of your kids at Christmas without the instructions? Unless you happen to be an engineer, attempting this will result in a string of expletives, and a disappointed kid. In the HIPAA world, we seem to expect staff members to fill their roles in the compliance effort without understanding what they are, or having the necessary basic training or skills to pull it off. We would not think of putting a medical office employee with a patient without the necessary technical training, so why is compliance different? 

I am just too small for anyone to mess with 
This may be the most common excuse I hear in small practices, and small businesses in general. Those in smaller groups consider themselves invisible as compared to Anthem, Blue Cross, or a large hospital. They miss the fact that they are usually easy to breach, and readily found on the Internet. If they use Comcast as their internet provider for example, their business information is likely on the Comcast website as a public hot spot
Unfortunately, while data breaches involving the big players usually become known reasonably quickly, patient data may be leaking from the smaller practices without anyone ever knowing. Once patient data hits the black market, we may never know its source. This makes the lack of security at smaller practices very dangerous. 

Addressing compliance and security
If you are reading this as a member of such a practice, here are the steps you should begin to take immediately to address compliance and security: 
  • Understand HIPAA requirements, and formulate a compliance plan
  • Implement essential security practices on your network
  • Training your employees, and give them policies and procedures to follow
  • Monitor your systems and logs for evidence of issues 
If the above seems a bit overwhelming, there are many organization's available to help. If you are reluctant to spend the money for such help, keep in mind that you would never consider fixing your X-Ray machine yourself. If you don't have the time or expertise for HIPAA/security, hire someone who does. 

Bottom line – as a small practice, you are not invisible. Rather, you are the front line of the battle. Recognize that you are at war with those who would steal patient data, and begin fighting back.


For more information on this and other healthcare compliance topics related to HIPAA, OSHA, Medicare and HR, simply email your questions to support@hcsiinc.com
visit our website at http://www.hcsiinc.com or post a question on our LinkedIn group at: http://bit.ly/1FWmtq6



To subscribe to this blog, enter your email address:


Delivered by FeedBurner