Showing posts with label Hipaa compliance training. Show all posts
Showing posts with label Hipaa compliance training. Show all posts

Thursday, August 10, 2017

Six Ways to Improve Data Security at Your Practice

A married couple — both doctors who shared a medical practice — almost divorced over a HIPAA breach that blindsided them when a patient called to say that her medical records appeared in a Google search and she was filing a lawsuit.

The orthopedist of a small practice didn’t want to fund the cost of an IT service provider to make sure his network was secure.  Instead the doctor hired his cousin who earned his IT stripes fixing performance problems on his own laptop.  Unfortunately, the family member never updated the practice’s malware software and patient data ended up on a rogue server.  Now it’s being held for ransom. 

The Smaller the Practice the Less the Compliance

For medical practices with 20 or less employees, doctors are often reluctant to spend money on HIPAA security than larger practices.  Importantly, the latter will have a compliance officer who makes sure HIPAA rules are followed, employees are trained, and policies and procedures are up to date. 

Doctors running small practices don’t believe they’re at risk for a data breach so they ignore the same steps taken by the compliance officer.  Meanwhile, it’s ordinary human errors that could take down the practice.  An employee leaves his tablet in a taxi or thieves break into the office and steal two laptops that contain patient records.  Or the doctor loses his laptop and keeps it under wraps since he thinks he hasn’t stored any patient records on it, so no one needs to know.  However, a disgruntled employee who was terminated gets revenge by reporting the practice to the Department of Health and Human Services’ Office of Civil Rights (OCR).  The OCR accuses the practice of having a breach and hiding it, and calls for an investigation. 

These are all real world events that have sent medical practices into a tailspin.  Doctors call a HIPAA compliance expert in a panic because they’re now caught in the web of the OCR and scrambling to prepare for an audit.  Worse yet, these compliance risks were right under their noses.

The Practice Needs As Much Care As the Patients

The risk of a data breach can be as life threatening to the practice that doesn’t protect its data, as the risk of lung cancer is for the patient who chain smokes.  Think of a data breach as a disease and the stolen laptop causing pain and suffering, and eventual death, which could all be prevented.  Doctors should think about data breach prevention and care for their businesses with the same commitment to disease prevention and care for their patients. 

When a practice fails to perform a security risk assessment or ensure that his employees used strong passwords, not long after he is convincing OCR auditors that the breach was an accident.  He has to hire attorneys to complete the audit and there is no budget left to invest in more network security, or cyber insurance. 

HIPAA Compliance Made Easy for Small Practices

There are some simple steps small practices can take that will take far less time than preparing for an OCR audit:

- Perform a security risk analysis — Analyze how patient information is currently protected. How often does the practice perform data backups? Is there a termination procedure when an employee leaves? Do employees have the minimum level of access to patient information? Are all portable devices encrypted?  Are medical records protected in case of fire or flood, or lost or stolen laptops that contain patient information?

- Train employees — Make sure they know how to spot phishing scams and suspicious links in emails, recognize fraudulent “IT experts” who call in to upgrade an operating system.  They should also know to avoid conducting business on public Wifi, and minimize sharing on social networks.

- Inventory patient information — Locate where all patient information is stored. It could be an EHR or a word document in the form of patient letters, or excel spreadsheets as billing reports or scanned images of your insurance carrier’s explanation of benefits (EOB).  This information resides on desktops, laptops and mobile devices, and should be encrypted.

- Employee data theft — Employee theft of information is one of the leading causes of HIPAA breaches in small organizations.  An employee steals patient information and opens a charge account at a local department store.  The patient finds out and sues the practice for not protecting her electronic protected health information (ePHI).  Employees should have minimal access to EHRs — only the information they need to perform their duties.   Also data logs should be checked.

- Breach Response Plan — Is there a response plan in place in case a breach does occur? The plan should include who will be on the response team, what actions the team will take to address the breach, and what steps they’ll take to prevent another similar breach from occurring. Make sure the plan is documented and all employees are trained on what they need to do.

These few actions can make the difference between being sued by patients for a data breach and gaining their confidence that their doctor cares as much about their health as he does for their security.

Source(s): https://www.hcsiinc.comhttp://www.physicianspractice.com

For more information on this and other healthcare compliance topics related to HIPAA, OSHA, Medicare and HR, simply email your questions to support@hcsiinc.com
visit our website at http://www.hcsiinc.com or post a question on our LinkedIn group at: http://bit.ly/1FWmtq6

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Thursday, October 13, 2016

Cutting the Fat from 2016 Compliance Officer Duties: HIPAA, OSHA, Medicare, HR



As you know, HIPAA, OSHA, Medicare, Human Resource Management have each established their own ongoing requirements for Compliance Officers, per location.

Would you agree that this list of duties can be confusing and overwhelming?

This is why we are going to have a training that will help cut the fat from these lists of responsibilities to help compliance officers who are also front desk, office managers, assistants, or even doctors 
to focus on the core procedures that must be documented and communicated to staff.

Also, Exciting news...we think!!! I'm going to be rolling out a HUGE Incentive Program for you!

I'm not going to roll out the red carpet with all the details of our Incentive Program until the webinar, but what I can say is that it involves HCSI mailing you $100 Holiday Gift Cards in October! 

Again, this webinar is going to do two things:
1) "Check up from the neck up": Ongoing Compliance Officer Duties
2) "Roll out the Red Carpet": Incentive Program

Who should watch this webinar:
•           Doctors
•           Practice Management (Office Manager, Assistants, etc.)
•           Compliance Officers (HIPAA, OSHA…)
•           Staff (Front Desk, Back Office, IT, etc.)

(Allow 1 hour for the training)

This video can also be viewed on YouTube, at: https://www.youtube.com/watch?v=LTHtwBydkhY

For more information on protecting your office regarding this issue or additional HIPAA, OSHA, HR, and Medicare resources, please visit our web site: http://www.hcsiinc.com or email support at: support@hcsiinc.com.


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Tuesday, March 17, 2015

Navigating the Healthcare Compliance Jungle with HCSI: HIPAA, OSHA, Medicare, and HR Employment Law Online Training

In the world of Healthcare compliance, you may agree that it has become increasingly difficult to identify the most practical, inexpensive, and automated resource option for training and maintaining compliance in case of an audit?

We provide HIPAA, OSHA, Medicare and Human Resources online training and personnel tracking. We provide each of our clients with a “Compliance Reference Guide”, a “Compliance Plan Audit Manual” (Policies and Procedures), and online access to regulatory forms and updates.

In addition, Administrative newsletters are sent out at weekly, monthly, and quarterly intervals. Sections of our Administrative alerts are posted on our LinkedIn Group (http://bit.ly/HCSIforum). Our support phones are answered by trained compliance experts, never an auto-attendant. Emailed support questions are answered promptly. Our goal is to provide the highest level of compliance support to the healthcare industry.



The HCSI Online Compliance Training Tutorial can be viewed along other tutorial videos at http://bit.ly/HCSITutorial

If you have not purchased our compliance training program, here is an incredible audio testimonial that may assist you in the decision making process:


Also, If you are just starting your career as a Healthcare Practice Administrator, you may be interested in learning about how others have navigated the Office Administrative Jungle. Listen now:


Want to know why others have considered our online program’s solutions? 
This compliance training is needed for those who fit anyone of the following:
             
1. For All Employees:  Required OSHA, HIPAA and Medicare Retraining
2. Complete training in OSHA, HIPAA, Employee Policies/ Employment Law and Medicare
3.Compliance Plan Manual, Reference Guide and  Ongoing Training and Certificate Binder
4. Phone and Email consulting services for all compliance questions
5. Monthly email administrative compliance updates
6. Quarterly employer/employee compliance newsletter to satisfy ongoing training requirements
7. Required federal forms continually updated (easily customized)  

For a Discount Code, we're offering 10% off the base price, from March 17-31st, 2015.
Call 801-947-0183 or e-mail support@hcsiinc.com (Ask for Lance King).

Learn more about Lance King: http://bit.ly/Hcarecomply
Join our Private Forum for Healthcare Administrators: http://bit.ly/HCSIforum

Tuesday, February 10, 2015

HCSI Healthcare Compliance Solutions Online Compliance Set-up Tutorial



Thanks for viewing the HCSI Online Compliance Training Tutorial. This video can be viewed along other tutorial videos at http://bit.ly/1zGWtJP.

If you have not purchased our compliance training program, here is an incredible audio testimonial that may assist you in the decision making process with your colleagues:


Want to know why others have considered our online program’s solutions? If not, you may consider just reading the Price below or going to http://hcsiinc.com if you haven’t already.
This compliance training is needed for those who fit anyone of the following:                 

1.            For All Employees:  Required OSHA, HIPAA and Medicare Retraining 
2.            For New Employees: Complete training in OSHA, HIPAA, Employee Policies/ Employment Law and Medicare
3.            Compliance Plan Manual, Reference Guide and  Ongoing Training and Certificate Binder
4.            Phone and Email consulting services for all compliance questions
5.            Monthly email administrative compliance updates
6.            Quarterly employer/employee compliance newsletter to satisfy ongoing training requirements
7.            Required federal forms continually updated (easily customized)              

Price: Base $550.00 (10% Discount on the Base Price, if purchased by February 30th, 2015)
Plus $3.00 per employee (please include Doctors) ….    Click here to view the price and compliance package details: http://bit.ly/1AR7S8I

EASIEST ORDER OPTIONS EVER!
•             Online at www.hcsiinc.com Click on the Red Health Care Provider Button and follow the prompts to complete the order.
•             Call Lance King @ (801) 947-0183 for assistance.