Showing posts with label OCR Audit. Show all posts
Showing posts with label OCR Audit. Show all posts

Tuesday, March 29, 2016

New HIPAA Audits May Prove Troublesome...If Not Prepared

The long-awaited next round of HIPAA audits has started, and providers may face a host of compliance and enforcement challenges, say health-care attorneys.

For example, the Health and Human Services Office for Civil Rights said it may conduct additional compliance reviews if an audit uncovers “serious issues,” which could lead to civil monetary penalties, Daniel Gottlieb, an attorney with McDermott Will & Emery in Chicago, told Bloomberg BNA on March 23, 2016.

Gottlieb said it's unclear how the OCR will define what constitutes a “serious issue,” and that uncertainty will be a burden to providers.

Certain policies that haven't been updated recently could become the grounds for additional compliance reviews outside the audit process, depending on the OCR's definition of a serious issue, Gottlieb said.

OCR Director Jocelyn Samuels announced the start of the phase two audits at a March 21 conference.

The compliance audits are intended to determine if health-care organizations and their contractors are complying with the Health Insurance Portability and Accountability Act's Privacy, Security and Breach Notification rules.

While the first round of audits focused solely on covered entities, phase two will address covered entities and business associates.

The audits are being conducted by FCi Federal, a government services provider in Ashburn, Va., that was awarded the contract in October 2015 .

Gottlieb said some covered entities, such as small physician practices, might have some HIPAA compliance issues involving their comprehensive risk assessments, which can be very data intensive and complicated for organizations with limited resources.

However, Gottlieb said he expected larger covered entities and business associates would be up-to-speed on HIPAA compliance.

“Organizations that prioritize HIPAA compliance should do pretty well, but no one is perfect,” Gottlieb said.

Data security is an ongoing process, Gottlieb said, and organizations should continuously make changes to their policies to meet a changing threat environment, including hacking attempts and patient data shared via social media channels.
Justified Enforcement
The next round of audits has been characterized by the OCR as a compliance improvement exercise, but covered entities and business associates may be in store for more enforcement actions as the OCR uncovers serious issues, Eric Fader, an attorney with Day Pitney LLP in New York, told Bloomberg BNA March 24, 2016.

“At this point, the OCR could be excused for calling almost any HIPAA violation a serious issue,” Fader said.

HIPAA has been around a long time and the OCR has provided plenty of warnings over the last few years, Fader said.

James Bowers, an attorney with Day Pitney in Hartford, Conn., said the OCR is likely to ramp up HIPAA enforcement after the criticism it received from the HHS Office of Inspector General in a September 2015 report (pdf).

The OIG said in the report that the OCR wasn't investigating enough small data breaches or keeping track of all health-care organizations it finds in violation of federal privacy laws.

“OCR's knuckles were rapped pretty hard, so going forward there's going to be a no-nonsense enforcement policy,” Bowers told Bloomberg BNA March 24.

Bowers said he expected to see steeper fines and more corrective action plans.
Audit Priority Items
Gottlieb said the OCR's phase one audits, which were conducted in 2011 and 2012, identified several areas of concerns regarding HIPAA compliance, and he said the upcoming phase two audits are likely to focus on them.

For example, a significant portion of audit subjects from phase one hadn't performed a comprehensive security risk assessment, Gottlieb said.

“Organizations should review their risk assessments and see if they comply with the HIPAA Security rule as well as OCR guidance,” Gottlieb said.

Gottlieb said he expected the second round of audits will also focus on the HIPAA Security rule's provisions concerning the secure disposal of electronic devices and encryption of data in transit and at rest.

“A lot of recent OCR enforcement has focused on stolen unencrypted laptops,” Gottlieb said.

The OCR reached two multimillion-dollar settlements in March 2016 with providers over stolen unencrypted laptops .
Audit Preparation
Also See: What to Expect in a HIPAA Audit for 2016 (Webinar Video)

In preparation for a potential HIPAA audit, organizations should identify and gather all of their documentation related to the OCR's phase one-identified priority areas and should ensure their security policies are reasonable and updated, Gottlieb said.

Kevin Page, an attorney with Waller Lansden Dortch & Davis, LLP in Nashville, told Bloomberg BNA March 23, 2016 that covered entities should maintain a list of all their business associates as well as have written HIPAA compliance policies and procedures in place.

Page said the audits will likely look to see if organizations have conducted a comprehensive, enterprisewide security risk analysis and if they've implemented a risk management plan based on the results of the analysis.

“I suspect we'll be seeing more audits, and what they learn from these current audits will inform future audits,” Page said.

Page said it would be smart for business associates to be make sure they're up to speed on the HIPAA Privacy and Security rules, as this will be the first time they're having to open their books to the OCR and demonstrate compliance.

Day Pitney's Bowers said business associates are increasingly holding large amounts of patient data either in electronic health records or in cloud storage.

“These vendors have to make certain the data is secured six ways to Sunday,” Bowers said.
Little Cause for Alarm
While the upcoming phase two audits may be inconvenient for organizations as they gather their HIPAA policies and procedures, there's little cause for alarm, Colin Zick, an attorney with Foley Hoag LLP in Boston, told Bloomberg BNA March 24, 2016.

Zick said the audits are trying to encourage good compliance and aren't designed to be punitive.

If you haven't pulled the HIPAA compliance binder off the shelf in a while, this would be a good time to start!

When it comes to HIPAA compliance, no one's perfect and breaches will happen, Zick said.

Organizations with strong underlying HIPAA compliance policies and procedures are less likely to face enforcement action if compliance problems are found, Zick said.

Zick also said covered entities are likely to fare better in HIPAA audits than business associates, which are organizations that contract with health-care organizations.

“There's such a variety of business associates, it's a much greater challenge for them to stay in compliance,” Zick said.

Looking to the future, a big question is what the next phase of audits will look like, Zick said.

“Will they decide not to do any more because the results show everyone's OK with compliance, or will they will ratchet up enforcement?” Zick said.
Planning Ahead
Before any potential HIPAA audit, covered entities and business associates should:




  • locate all HIPAA Privacy and Security compliance policies and procedures, and find out when you last updated them;
  • review your risk analysis/assessments and risk management plan;
  • update any policies and proceedures/documentation as necessary; 
  • update and organize all Business Associate Agreements/contracts; and
  • schedule annual and ongoing training.


  • Organizations need to cooperate completely with an audit request.

    Reece Hirsch, an attorney with Morgan, Lewis & Bockius LLP in San Francisco, echoed Zick's comments and said it's crucial for audit subjects to respond within the mandated 10-day period.

    “Make sure the audit-related address verification letter doesn't end up in your spam folder,” Hirsch told Bloomberg BNA March 24, 2016.

    Organizations should create audit response teams to ensure they meet the response deadline, and should perform document-gathering dry runs to determine how fast the process is, Hirsch said.

    Hirsch said it's important that an organization's HIPAA compliance policies and procedures are updated.

    “If you've done your updating prior to the audit start, you're OK, but if you do your updating after you receive an audit request, that's a different story,” Hirsch said.


    Also See: What to Expect in a HIPAA Audit for 2016 (Webinar Video)





    To subscribe to this blog, enter your email address:


    Delivered by FeedBurner

    Friday, March 25, 2016

    What to Expect in a 2016 HIPAA Audit (video)


    Would you be surprised if OCR showed up for a HIPAA audit?

    Who does this impact?
    A Fine from OCR does not just impact the physician, but also the
    office manager, the staff, and the reputation of the practice for years to come!

    In this webinar, HCSI guides healthcare practices and business associates
    on what to expect during a HIPAA audit, with our webinar.

    3 main points of reference in the webinar:
    1. Penalties for HIPAA Violations
    2. Areas covered in an audit
    3. Let's begin your Audit!

    Additional resources at the end of the presentation:

    1.       The change being made with OCR’s HIPAA Audit protocol
    2.       Start to finish expectations for 2016 HIPAA audits
    3.       HIPAA audit planning recommendations

    Click here for the webinar or view below:


    Contact support@hcsiinc.com or call 801-947-0187 for questions related to HIPAA, OSHA, etc.

    If you are responsible for integrating a culture of compliance, then consider visiting and Liking our Facebook Page for supporting articles:
    HCSI Facebook Page

    http://hcsiinc.com

    To subscribe to this blog, enter your email address:


    Delivered by FeedBurner

    Thursday, October 15, 2015

    Meaningful Use program for 2015-2017 and implementing Stage 3

    CMS Unveils Final Meaningful Use Rule
    The Centers for Medicare and Medicaid Services and the Office of the National Coordinator for Health Information Technology have issued the long-awaited final rules changing the requirements of the Meaningful Use program for 2015-2017 and implementing Stage 3 of the program.

    The rules “shift the paradigm so health IT becomes a tool for care improvement, not an end in itself,” according to the October 6 announcement. The rule eases the reporting burdens, simplifies requirements, adds flexibility, supports interoperability and improves outcomes. It also transitions to a new and more responsive regulatory framework based on the Medicare Access and CHIP Reauthorization Act (MACRA), which essentially moves physicians out of the Meaningful Use program into a new Merit-based Incentive Payment System (MIPS).  
    Some of the changes include:
            Providers and state Medicaid agencies will now have until Jan. 1, 2018, to prepare for and comply with the next set of system improvements;
            Stage 3 will now be optional in 2017;
            Stage 3 will have eight objectives, with more than 60 percent requiring interoperability;
            Public health reporting will have flexibility options;
            APIs will be required;
            Cybersecurity requirements have been strengthened; and
            The reporting period for 2015 will be only 90 days for all providers, for new providers in 2016 and 2017 and for any provider moving to Stage 3 of the program in 2017
    HHS had received more than 2,500 comments on the proposed rules.
    Addressing concerns that the rule is coming out too late for providers to report in 2015, Patrick Conway M.D., acting principal deputy administrator and chief medical officer at CMS, pointed out that the deadlines could be extended and that providers can apply for hardship exemptions.
    The rules also do not delay Stage 3, although many stakeholders have been asking that Stage 3 be “paused” and reevaluated. Conway indicated in a media call that a 60-day comment period will “get us to a similar place.” He also pointed out that HHS had to combine the alteration and Stage 3 rules; using a comment period is just a different mechanism to do so.
    CMS will accept comments on the EHR Incentive Programs final rule for 60 days after it appears in the Federal Register, which is expected on October 16. The feedback will help shape future EHR rulemaking and will also be considered as CMS works to develop rulemaking around MACRA, which was passed by Congress earlier this year to replace the sustainable growth rate. Additional information about MACRA is expected in spring 2016.
    A fact sheet on the new rule can be found here on the CMS website.

    For more information on this and other topics related to HIPAA, OSHA, Medicare and HR, please emailsupport@hcsiinc.com or visit our website at http://www.hcsiinc.com
    Become a member of our LinkedIn group at: http://bit.ly/1FWmtq6

    Thursday, June 11, 2015

    Phase 2 HIPAA Audits Launched by OCR

    OCR Launches Phase 2 HIPAA Audit Program


    The U.S. Department of Health and Human Services Office for Civil Rights has sent pre-audit screening surveys to covered entities (CE) and their business associates (BA) that could be selected to participate in Phase 2 of the HIPAA audit program, OCR has confirmed.

    In an emailed statement, OCR said it has started verifying contact information for covered entities. “Additional information about the audit program is forthcoming,” the statement said. “Check our website for updates.”

    The HITECH Act of 2009 first called on OCR to conduct periodic HIPAA audits to ensure CEs and BAs were following Privacy, Security, and Breach Notification Rules, amid a regulatory push for greater use of health IT and national standards for security and privacy. It was a recognition that new technologies can also pose increased risk to consumer privacy.

    OCR conducted and evaluated the HIPAA pilot audits between 2011 and 2013, measuring the efforts of 115 CEs at complying with HIPAA standards. The process to finalize procedures for Phase 2 of the audits dragged on due to various delays until a pre-audit survey was approved by the Office of Management and Budget on March 13, 2015 for distribution to 500 CEs and 200 BAs.

    The survey was then mailed out in mid-May. The intent of the pre-audit survey is to collect information to help OCR identify a broad range of organizations that are suitable for HIPAA audits. It looks at such things as size, complexity, operations, use of EHR, revenue, and how BAs handle PHI. A smaller sample of the survey group will then be selected for the audits that were originally slated to begin in the fall of 2014.

    This past March, OCR Director Jocelyn Samuels confirmed the audit procedures were still being finalized, but would begin soon, presumably sometime in 2015. Audits for BAs should begin after CE audits are underway.

    Questions still remain on the actual protocol or criteria OCR will use for the Phase 2 audit. The agency hasn’t shed any light yet on whether this protocol will be different than in the pilot audit. However, one difference in the process is that OCR expects to use desk-based assessments, meaning the agency will not conduct on-site audits unless resources are available.

    Even though there are no firm dates yet, CEs and BAs should begin preparing for a possible audit. Visit the OCR audit program website for official updates.


    (HCPro website, FierceMarkets website)

    Wednesday, May 13, 2015

    How to Respond to an OCR Audit

    Responding to an OCR Audit

    The Office for Civil Rights (OCR) has not issued much information on the upcoming HIPAA audits, so it’s up to individual organizations to interpret what to expect and how to prepare. However the OCR has indicated that the audits will be conducted by OCR personnel rather than by a third party, unlike the 2012 pilot program. Also unlike last time, the audits will be more heavily weighted toward desk audits, with onsite audits occurring on a case-by-case basis.
    According to information in presentations from Department of Health and Human Services personnel, here is what audited entities need to be aware of:
            A data request will specify content and file organization, file names and any other document submission requirements.
            Only requested data submitted on time will be assessed.
            All documentation must be current as of the date of the request.
            Auditors will not have the opportunity to contact the entity for clarification or to ask for additional information, so it is critical that the documents accurately reflect the program.
            Submitting extraneous information may increase the difficulty for the auditor to find and assess the required items.
            Failure to submit a response to requests may lead to a referral for regional compliance review.
            Document submission will be a time-consuming task, so gathering necessary evidence up front will minimize disruption to day-to-day operations.
    Once an organization receives notification, it should start gathering information immediately. If subsequently chosen to submit to an audit, participants will only have a short time to respond. The following provides basic steps for a strategic OCR audit plan:
            Gather a team.
    Privacy and security officials should be assigned to a task force responsible for handling audit requests. It’s also a good idea to notify internal or external legal counsel to keep them on stand-by should guidance be necessary.
            Follow guidelines on how to respond.
    The OCR will provide specific instructions on how and when to respond. The OCR will not look favorably on a delayed response, and if unrequested documentation is submitted, it can be used in all observations and findings. Some of the areas the OCR audits will cover include:
    1.      Risk analysis.
    2.      Evidence of a risk management plan (e.g. list of known risks and how they are being dealt with).
    3.      Policies and procedures and descriptions as to how they were implemented.
    4.      Inventories of business associates and the relevant contracts and BAAs.
    5.      An accounting of where electronic protected health information (ePHI) is stored (internally, printouts, mobile devices and media, third parties).
    6.      How mobile devices and mobile media (thumb drives, CD’s, backup tapes) are secured and tracked.
    7.      Documentation on breach reporting policies and incident response policies and procedures.
    8.      A record of security training that has taken place.
    9.      Evidence of encryption capabilities.
           Question findings if they appear to be inaccurate. Historically, the OCR has allowed organizations to respond to observations and findings. Organizations that have documented all compliance decisions will fare better when trying to defend their position. There are many areas where HIPAA lacks specific direction; the ability to demonstrate a thoughtful and reasonable approach (in writing) will tend to be viewed favorably.

    By preparing up front and responding in a timely fashion, most OCR audits should progress fairly smoothly. For organizations that have instituted a reasonably compliant security program, there may be little or no follow-up. If there are a significant number of observations and findings, an organization may be subject to voluntary compliance activities, or a more in-depth compliance review. Should an in-depth review uncover significant issues, additional corrective action must be taken and/or fines may be imposed.


    (HIMSS website)