Author: Colington Consulting

  • 2025 HIPAA Enforcement Trends So Far: What To Know

    2025 HIPAA Enforcement Trends So Far: What Healthcare Providers Need to Know

    As we enter the month of October, healthcare compliance has faced a new level of scrutiny so far this year. The HHS Office for Civil Rights (OCR), the agency responsible for enforcing HIPAA, is no longer focusing only on isolated breaches. Instead, enforcement is targeting systemic gaps in security and compliance programs, particularly in areas where healthcare providers continue to fall short.

    Risk Analysis Remain the Cornerstone

    OCR has made it clear that a comprehensive, documented security risk analysis (SRA) remains the foundation of HIPAA compliance. Organizations that fail to conduct and regularly update an SRA put themselves at serious enforcement risk. Regulators expect healthcare practices to not only identify vulnerabilities but also take measurable steps to address them. Outdated or incomplete assessments are one of the most common triggers for enforcement actions.

    Ransomware is Now a Compliance Issue

    The dramatic rise in ransomware has changed the enforcement landscape. A cyberattack is no longer viewed as an isolated IT issue โ€” it is now a compliance problem. If inadequate patching, lack of encryption, or a weak incident response plan contribute to a ransomware event, OCR is likely to pursue penalties or corrective action. Healthcare organizations must view ransomware preparedness as both a cybersecurity and a regulatory obligation.

    Modernization of the Security Rule

    HIPAA itself is evolving. Proposed updates to the Security Rule reflect the realities of todayโ€™s threat environment. Multi-factor authentication, encryption, vendor oversight, and formal incident response planning are poised to become explicit requirements rather than best practices. Providers who move early to implement these safeguards will be better positioned to demonstrate compliance when enforcement follows.

    Ongoing Right of Access Enforcement

    OCRโ€™s Right of Access Initiative continues to be one of the agencyโ€™s most active enforcement areas. Patients must be able to access their records quickly and affordably. Practices that delay, overcharge, or fail to provide access face growing regulatory risk. In addition, business associates and third-party vendors are under greater scrutiny as regulators focus on the entire chain of responsibility for protected health information (PHI).

    Overlapping Compliance Pressures

    HIPAA is no longer the only regulatory concern. Telehealth, digital marketing, and state-level privacy laws are creating overlapping obligations. OCR and state attorneys general are increasingly aligned, making it essential for providers to understand and address compliance at both federal and state levels.

    Looking into the Crystal Ball for 2026

    The message from regulators is clear: compliance must be proactive, measurable, and ongoing. Organizations should:

    • Perform and document accurate and thorough security risk analysis.
    • Implement multi-factor authentication and encryption across systems.
    • Ensure Business Associate Agreements are in place, as appropriate for vendors.
    • Maintain and test an incident response plan.
    • Ensure all patientsโ€™ right-of-access requests are handled promptly.

    At the end of the day, OCR is rewarding organizations that can prove their compliance efforts are more than policies on paper. Demonstrable action is the key to avoiding costly enforcement.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    Is your organization ready for HIPAA enforcement? Contact our office today to schedule a free HIPAA compliance review and take the first step toward protecting your organization from regulatory risk.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Why Small Healthcare Providers Struggle with HIPAA Compliance

    The Health Insurance Portability and Accountability Act (HIPAA) was designed to protect patient privacy and safeguard sensitive health information. Yet, while compliance is mandatory for every covered entity, small healthcare providersโ€”independent practices, rural clinics, and specialty officesโ€”face significant challenges in meeting these requirements. As someone who has worked extensively with providers on HIPAA compliance, Iโ€™ve seen firsthand the barriers that smaller organizations must overcome.

    1. Limited Resources

    Larger healthcare systems can dedicate entire teams to compliance oversight. In smaller practices, however, responsibility for HIPAA often falls to an office manager or even the physician, in addition to their core responsibilities. Without a dedicated compliance professional, it becomes extremely difficult to stay current with risk assessments, policies, and monitoring obligations.

    2. The Financial Strain of Compliance

    HIPAA compliance comes with real costs. Secure messaging platforms, encrypted email, advanced EHR systems, and documented staff training programs all require investment. Small providers frequently operate on narrow margins and struggle to balance compliance with other financial priorities. Unfortunately, relying on free or low-cost tools that lack proper safeguards only increases risk.

    3. A Moving Target: Regulatory Complexity

    HIPAA regulations are not static. The Office for Civil Rights (OCR) continues to refine its guidance, with recent emphasis on the patient right-of-access, telehealth, and mobile security. Larger organizations employ compliance officers to track these changes and update protocols accordingly. For small providers, keeping pace often feels overwhelmingโ€”yet ignorance of updates does not exempt them from enforcement.

    4. Cybersecurity Vulnerabilities

    Healthcare data is one of the most sought-after assets for cybercriminals. Smaller providers, with limited IT infrastructure, are often easy targets. Weak firewalls, outdated systems, or something as simple as a stolen laptop can result in a breach. And when a breach occurs, OCR makes no distinction between a single-physician office and a major health system. Liability is the same.

    5. Training and Human Error

    Most HIPAA violations are the result of human error. Employees who lack ongoing training may inadvertently discuss PHI in public areas, leave files exposed, or send unencrypted emails. Small practices often deliver training only onceโ€”at hireโ€”and fail to reinforce it. OCR requires regular, documented training, and failing to provide it can be considered a non-compliance.

    6. Lack of Formal Documentation

    Verbal policies and โ€œthe way weโ€™ve always done thingsโ€ do not stand up under scrutiny. HIPAA requires written policies, risk assessments, and documentation of compliance efforts. In an investigation, the absence of documented evidence is treated as noncomplianceโ€”even if the practice believes it is following proper procedures.

    The Bottom Line

    Small healthcare providers are held to the same HIPAA standards as large organizations but face far greater challenges in meeting them. Noncompliance is not simply a regulatory issue; it jeopardizes patient trust and creates financial and reputational risks that many small practices cannot afford.

    For smaller providers, the key is not to ignore or delay compliance but to seek practical, scalable solutions. That means investing in secure systems, building a culture of privacy through training, andโ€”most importantlyโ€”partnering with experienced compliance professionals who understand both the law and the realities of running a small practice.

    HIPAA compliance does not have to overwhelm your practice. With the right guidance, even the smallest provider can protect patient data, reduce risk, and demonstrate compliance with confidence.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    Contact our office today to schedule a free compliance review for your practice.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Key Facts About HIPAA Compliance โ€“ Breach Reporting Requirements

    Our series is designed to explain best practices about HIPAA compliance, HIPAA settlements, and the various requirements an organization must have in place under the HIPAA Security & Privacy Rules.

    When does a HIPAA Breach Affecting Fewer than 500 Individuals Need to be Reported by?

    If a breach of unsecured protected health information affects fewer than 500 individuals, a covered entity must notify the Secretary of the breach within 60 days of the end of the calendar year in which the breach was discovered. That makes the reporting date March 1, 2025.

    A covered entity is not required to wait until the end of the calendar year to report breaches affecting fewer than 500 individuals; a covered entity may report such breaches at the time they are discovered. The covered entity may report all its breaches affecting fewer than 500 individuals on one date, but the covered entity must complete a separate notice for each breach incident. The covered entity must submit the notice electronically and complete all the fields of the breach notification form.

    If your organization needs to report this type of breach notification, here is the link to submit the notification.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    Allow our team of regulatory experts to assess your organizationโ€™s compliance with the HIPAA Security and Privacy Rules, the risk assessment process, and breach notification requirements. We offer customized services to meet specific requirements for your organization, making HIPAA compliance strategies effective and efficient. For a free, initial consultation to see how we can assist your organization, give our office a call at 844.740.7100.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Enhancing HIPAA Security Awareness: Training Strategies

    Guest Post by Andrew Tate

    Introduction

    Healthcare data breaches have been on the rise, with malicious actors increasingly targeting healthcare organizations for their sensitive patient data. The impact of these breaches goes beyond financial penalties; they erode patient trust and put healthcare organizations at risk of severe HIPAA violations. One of the most effective ways to mitigate these risks is through comprehensive security awareness training. This blog will explore how healthcare organizations can implement training strategies to enhance HIPAA security awareness and foster a culture of compliance.

    The Role of Security Awareness Training in HIPAA Compliance

    The HIPAA Security Rule mandates that healthcare organizations safeguard electronic protected health information (ePHI) through administrative, physical, and technical safeguards. A critical component of these safeguards is employee training. Employees are often the first line of defense against cybersecurity threats, making it essential for them to be well-versed in identifying and preventing potential risks.

    Security awareness training helps employees understand their role in protecting sensitive data and preventing breaches. By educating staff on recognizing common threats such as phishing emails or improper data handling, organizations can significantly reduce the likelihood of breaches. Moreover, regular training instills a culture of compliance, ensuring that security practices become second nature to all employees.

    Key Topics to Cover in HIPAA Security Awareness Training

    A well-rounded training program should address the following critical topics to ensure comprehensive HIPAA compliance:

    • Phishing Attempts and Social Engineering: Employees should be trained to identify suspicious emails, links, and attachments that may contain malware or attempt to steal login credentials. Real-world examples can be used to illustrate common phishing tactics.
    • Password Management Best Practices: Educating employees on the importance of strong passwords and the dangers of password reuse is vital. Implementing multi-factor authentication (MFA) should also be emphasized as a crucial security measure.
    • Proper Handling and Transmission of ePHI: Employees must understand the appropriate methods for accessing, sharing, and storing ePHI to minimize unauthorized disclosures. This includes using secure communication channels and encryption.
    • Identifying and Reporting Security Incidents: Employees should know how to recognize and promptly report potential security incidents. Quick reporting can prevent small issues from escalating into significant breaches.
    • Mobile Device and Remote Work Security: With the rise of remote work, it is essential to train employees on securing mobile devices and home networks. This includes using VPNs, avoiding public Wi-Fi, and ensuring devices are updated with the latest security patches.
    • Consequences of HIPAA Violations: Employees should be aware of the legal and financial repercussions of HIPAA violations, both for the organization and themselves. Understanding the gravity of non-compliance can enhance vigilance.

    Effective Training Methods and Strategies

    To maximize the effectiveness of HIPAA security awareness training, organizations should adopt a variety of engaging and educational methods:

    • Interactive Training: Incorporate real-world scenarios and role-playing exercises to help employees apply their knowledge in practical situations. Interactive sessions are more memorable and encourage active participation.
    • Frequent Refreshers: Regularly revisiting key training topics helps reinforce concepts and keeps security top-of-mind. Quarterly or bi-annual training sessions can prevent knowledge gaps.
    • Personalized Content: Tailor training materials to address the specific roles and responsibilities of different departments. For example, administrative staff may require different training than clinical staff.
    • Use of Technology: Leverage e-learning platforms and gamified training modules to enhance engagement. Gamification can motivate employees to complete training and retain information better.
    • Regular Assessments: Conduct periodic quizzes or tests to gauge employees’ understanding of the training material. These assessments can identify areas for improvement and help refine the training program.

    Overcoming Common Training Challenges

    Implementing a successful training program may come with challenges, but proactive measures can address these issues:

    • Training Fatigue: Employees may become disinterested if training is repetitive or unengaging. To combat this, diversify training methods and incorporate real-world examples to make sessions more relatable.
    • Remote and Hybrid Workforces: Ensuring consistent training for remote employees can be challenging. Utilize virtual training sessions, recorded webinars, and online modules to provide flexible learning options.
    • Leadership Buy-In: Senior leadership support is essential for a successful training program. Leadership should actively participate in training sessions and emphasize the importance of security awareness.

    Measuring the Effectiveness of Your Training Program

    To ensure the success of a security awareness program, organizations must regularly evaluate its effectiveness:

    • Training Completion Rates: Track the percentage of employees who complete each training session. High completion rates indicate that employees are engaged and committed to compliance.
    • Knowledge Assessments: Use quizzes and assessments to test employees’ understanding of key concepts. Analyze results to identify common knowledge gaps and adjust training materials accordingly.
    • Employee Feedback: Conduct surveys to gather feedback on the training program. Employees’ insights can help improve the content, delivery methods, and overall effectiveness of the training.
    • Incident Monitoring: Track security incidents and breaches to determine whether there has been a reduction in human error-related events. A decrease in incidents may indicate improved awareness and compliance.

    Benefits of a Strong Security Awareness Program

    A well-implemented security awareness program offers numerous benefits to healthcare organizations:

    • Reduced Risk of Breaches: Educated employees are less likely to fall victim to phishing attempts and other cyber threats, minimizing the risk of breaches.
    • Improved Employee Confidence: Training empowers employees to handle ePHI securely and confidently, fostering a sense of responsibility and accountability.
    • Enhanced Patient Trust: Patients are more likely to trust organizations that demonstrate a commitment to data security and compliance.
    • Regulatory Compliance: A robust training program helps organizations meet HIPAA training requirements, reducing the risk of fines and penalties.

    Conclusion and Call to Action

    Continuous security awareness training is a cornerstone of HIPAA compliance and an essential safeguard against data breaches. By implementing comprehensive training strategies, healthcare organizations can empower employees to recognize and mitigate security risks effectively.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    HIPAA compliance is vital to maintain a thriving compliant organization. Colington Consulting offers scalable solutions and compliance consultations to keep healthcare practices and business associate vendors compliant with HIPAA regulations. To meet HIPAA training requirements, we offer web-based self-enroll courses; live, instructor led training; and customized organization specific training. If your organization needs assistance with HIPAA training, give our office a call at 844.740.7100.

    Helping Organizations Achieve HIPAA Complianceโ„ข

    Guest Blog Post Author: Andrew Tate, I’m a highly accomplished healthcare professional with over 8 years of experience in healthcare administration, medical billing and coding, and compliance. I hold several AAPC specialty certifications and have a Bachelorโ€™s Degree in Health Administration. I enjoy sharing my knowledge and experience as a certified PMCC instructor. I have authored many articles for healthcare publications and has been a featured speaker at workshops and coding conferences across the country. By leveraging my expertise, I work with organizations like Nexus io to provide valuable insights that enhance financial efficiency and streamline operations, ultimately driving success in todayโ€™s complex healthcare environment.

  • OCRโ€™s 2024 HIPAA Audits & Clarification on Breach Reporting

    By Jay Hodes, President โ€“ Colington Consulting

    In February of this year, the U.S. Department of Health and Human Services (HHS) published an Agency Information Collection Request in the Federal Register. The request indicates the HHS Office for Civil Rights (OCR), the agency that enforces HIPAA compliance, is looking to initiate a HIPAA Audit Review Survey. OCR, according to the request, โ€œis conducting a review of the 2016-2017 HIPAA Audits to determine its efficacy in assessing the HIPAA compliance efforts of covered entities.โ€ The abstract states โ€œinformation collection consists of 39 online survey questions that will be sent to 207 covered entities and business associates that participated in the 2016-2017 OCR HIPAA Audits. The survey will gather information relating to the effect of the audits on the audited entities and the entities’ opinions about the audit process.โ€

    The good news, at least from the early indication in the request, is that these new audits will only affect organizations that participated in the prior audits. With a limited budget and lack of staffing, OCR will be hard pressed to go beyond what is indicated in the request. In the past, OCR contracted out parts of the audit program and it remains to be seen if that will also occur with this new round of audits. Publicly, OCR has not provided any information as to when the audits would begin.

    When the audits do begin, OCR will use an online survey to:

    • Measure the effect of the 2016-2017 HIPAA Audits on covered entities’ and business associates’ subsequent actions to comply with the HIPAA Rules.
    • Provide entities with an opportunity to give feedback on the Audit and its features, such as the helpfulness of HHS’ guidance materials and communications, the utility of the online submission portal, whether the Audit helped improve entity compliance, and the entities’ responses to the Audit-report findings and recommendations.
    • Provide OCR with information on the burden imposed on entities to collect audit-related documents and to respond to audit-related requests; and
    • Seek feedback on the effect of the HIPAA Audit program on the entities’ day-to-day business operations.
    • The information, opinions, and comments collected using the online survey will be used to improve future OCR HIPAA Audits.

    The limited scope of these planned audits does not mean organizations that must comply with HIPAA regulations are off the hook because they were not included in the initial group. Organizations are still required to comply with all HIPAA regulatory compliance requirements, including a self-reporting breach notification to HHS OCR if any PHI or ePHI is compromised, regardless of how many individuals were affected. If the breach affects 500 individuals or more, the likelihood of an OCR investigation is probable.

    Last week, OCR sent out through their listserv, a FAQ regarding updated clarification on Change Healthcare Cybersecurity Incident. As part of one of the FAQs, OCR provided a summary of breach notification requirements and reporting procedures for covered entities.

    As an important reminder, if a breach of unsecured PHI or ePHI affects 500 or more individuals, a covered entity must notify the HHS OCR of the breach without unreasonable delay and in no case later than 60 calendar days from the discovery of the breach. The notification clock starts the day the breach is discovered.

    OCR also indicated if the number of individuals affected by a breach is uncertain at the time of notification submission, the covered entity should provide an estimate, and, if it discovers additional information, submit updates in the manner specified below. If only one option is available in a particular submission category, the covered entity should pick the best option, and may provide additional details in the free text portion of the submission.

    Organizations should use the planned HIPAA Audit Review Survey as a proactive exercise to determine compliance with all aspects of HIPAA, including breach notification requirements.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    Allow our team of regulatory experts to assess your organizationโ€™s compliance with the HIPAA Security and Privacy Rules, the risk assessment process, and breach notification requirements. We offer customized services to meet specific requirements for your organization, making HIPAA compliance strategies effective and efficient. For a free, initial consultation to see how we can assist your organization, give our office a call at 844.740.7100.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Fundamental Requirements for HIPAA Compliance

    By Jay Hodes, President โ€“ Colington Consulting

    As a HIPAA consultant, I conduct many initial consultations with organizations, large and small, to cover requirements of the HIPAA Security and Privacy Rules. What I often find is not that organizations do want to comply with HIPAA compliance, but more of the case of not understanding what needs to be in place to meet regulatory requirements. I put a lot of emphasis on the educational aspects of understanding what the Code of Federal Regulations calls for in meeting HIPAA requirements.

    Factoring in HHS Office for Civil Rights (OCR) enforcement initiatives and lessons learned from prior settlements, I want to make sure any organization we work with is well positioned should a breach occur. This means having a defendable, well documented HIPAA compliance program in place should an OCR breach investigation occur.

    Let me cover a few topics as to why HIPAA compliance matters for healthcare organizations and patients. Remember, HIPAA defines what patient rights are when it comes to their protected health information, but more importantly, what an organizationโ€™s responsibilities are for disclosing and safeguarding that information.

    HIPAA Security Standards and Implementation Specifications:

    • The HIPAA Security Rule identifies administrative, physical, and technical safeguards that must be in place. This sets the foundation for compliance.
    • There are over 50 of these Standards and Implementation Specifications that are covered in the Code of Federal Regulations that include conducting required Security Risk Assessments.

    Patient Privacy Rights/Organization Requirements:

    • The Standards for Privacy of Individually Identifiable Health Information (โ€œPrivacy Ruleโ€) establishes a set of national standards for the protection of certain health information.
    • The HIPAA Privacy Rule standards address the use and disclosure of individualsโ€™ health informationโ€”called โ€œprotected health informationโ€ by organizations subject to the Privacy Rule โ€” called โ€œcovered entities,โ€ as well as standards for individuals’ privacy rights to understand and control how their health information is used.
    • A major goal of the Privacy Rule is to assure that individualsโ€™ health information is properly protected while allowing the flow of health information needed to provide and promote high quality health care and to protect the public’s health and wellbeing.

    Technical Safeguards for Electronic Protected Health Information (ePHI):

    • The HIPAA Security Rule defines technical safeguards in CFR ยง 164.304 as โ€œthe technology and the policy and procedures for its use that protect electronic protected health information and control access to it.โ€
    • These safeguards must address access control, unique user identification, emergency access procedures, encryption/decryption, audit controls, and transmission security.
    • Organizations must conduct audits of any systems that contain ePHI, review audit reports, and maintain those reports for 6 years.

    Breach Notification Rule Requirements:

    • The HIPAA Breach Notification Rule, 45 CFR ยงยง 164.400-414, requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information.
    • Following a breach of unsecured protected health information or ePHI, covered entities must provide notification of the breach to affected individuals, the Secretary, and, in certain circumstances, to the media. In addition, business associates must notify covered entities if a breach occurs at or by the business associate.
    • Covered entities and business associates, as applicable, have the burden of demonstrating that all required notifications have been provided or that use, or disclosure of unsecured protected health information did not constitute a breach.

    Business Associates:

    • A โ€œbusiness associateโ€ is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity.
    • These functions or services include claims processing or administration; data analysis, processing, or administration; utilization review; quality assurance; billing; benefit management; practice management, legal; actuarial; accounting; consulting; data aggregation;
      management; administrative; accreditation; and financial.
    • When these business relationships exist, a Business Associate Agreement (BAA) must be executed between both parties.
    • There are specific elements that must be included in all BAAs.

    Ensuring HIPAA Compliance:

    • Organizations, regardless of size, must designate a HIPAA Security and Privacy Officer. It can be a combined role as the HIPAA Compliance Officer and be a collateral duty.
    • HIPAA is not one and done, it takes program management. CFR 164.316(a) states โ€œImplement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements.โ€
    • A security awareness and training program must be implemented and provided to all members of the workforce, including providers and management.

    Failure to Comply:

    • Can result in potential penalties and fines, the need to enter into Resolution Agreements, and be required to adopt a formal Corrective Action Plan.
    • Loss of public and workforce trust. All reported breaches affecting 500 or more individuals are posted on the HHS breach portal and are open source for all to see.

    Need Help With Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review with me to evaluate your current policies and protect your organization.

  • Self-Insured Group Health Plans and HIPAA Requirements

    Some organizations are bringing their employee health plan options in house as a self-insured group health plan. Although, this conversion may not be right for certain companies based on several reasons and issues. Our short and to the point blog article will provide a quick overview.

    According to information provided by the Employee Benefit Research Institute in 2023:

    • The percentage of private-sector establishments offering a self-insured health plan increased through 2016 but has since ebbed and flowed with no discernible long-term trend.
    • Recent trends have been more clearly defined when examined by firm size.
    • Since 2018, the percentages of small and medium-sized establishments offering at least one self-insured plan both increased. In contrast, the percentage of large establishments offering a self-insured plan has declined. The decline among large establishments occurred in most years since 2013.
    • Overall, the percentage of workers in self-insured plans has been bouncing around between 58 percent and 60 percent since 2010 but fell to 55 percent in 2022. This occurred despite the increase in self-insurance among small and medium-sized companies because of the drop in self-insurance among large firms.

    When going the route of becoming a self-insured group health plan, it now opens the door to meeting HIPAA requirements as a Covered Entity. Here is some information you will find helpful on this topic.

    A self-insured group health plan is one in which an employer takes on the financial risk of providing healthcare benefits to its employees, rather than purchasing a traditional โ€œfully-insuredโ€ plan from an insurance carrier. Hereโ€™s how it works:

    1. Financial Risk: The employer sets up a special trust fund or uses general funds to cover incurred claims. They assume the financial risk associated with healthcare expenses.
    2. Administration: The employer may administer the plan themselves or hire a third-party administrator (common for larger employers).
    3. Coverage: Self-insured plans can include not only traditional health coverage but also medical expense reimbursement flexible spending account plans (medical FSAs) and health reimbursement account plans (HRAs).

    HIPAA Compliance for Self-Insured Group Health Plans

    HIPAA imposes requirements on Covered Entities, which include health plans, healthcare providers, and health care clearinghouses. Self-insured group health plans fall under this umbrella. Here are key points regarding HIPAA compliance for self-insured plans:

    1. Privacy and Security Rules: The HIPAA Privacy Rule and the HIPAA Security Rule set national standards for the privacy of individually identifiable health information and the security of electronic Protected Health Information (ePHI) at transit and at rest.
    2. Breach Notification Rule: Added in 2009, this rule mandates reporting of breaches involving PHI.
    3. Exemptions:Exemptions from HIPAA compliance for self-insured companies are rare. Only if a self-insured group health plan is self-administered, has fewer than fifty employees, and administers medical FSAs and HRAs internally, is it exempt from HIPAA compliance.
    4. Partial Compliance: Some self-insured plans fall into a gray area known as โ€œpartial compliance.โ€ These plans occur when neither the sponsor nor its insurance agent has access to or transmits PHI electronically.

    HIPAA Compliance for Self-Insured Plans

    There are many requirements an organization will need to meet in standing up a HIPAA compliance program. This includes:

    1. Appoint Officers: Designate a Privacy Officer and a Security Officer.
    2. Develop Policies: Create HIPAA privacy policies and procedures to be included in a Risk Management Plan.
    3. Business Associate Agreements: Ensuring these BAAs are in place with any vendor who can access your organizationโ€™s protected health information.
    4. Risk Assessment: Conduct regular security, privacy, and breach risk assessments to identify vulnerabilities. A security risk assessment is required by the HIPAA Security Rule.
    5. Training: Provide HIPAA Security Awareness and Privacy Training to appropriate members of your workforce.
    6. Breach Response: Establish protocols for breach notification and response.

    Compliance requirements will be based on the organizationโ€™s business operations, structure, and size. If your organization is planning to become a self-insured health plan and needs to understand the regulatory requirements of HIPAA to safeguard sensitive health information, please contact our office for a free, initial consultation. We have helped many small organizations implement, maintain, and manage a comprehensive HIPAA compliance program as a Covered Entity.

  • OCR Releases Guidance for Implementing the HIPAA Security Rule

    On February 16, the U.S. Department of Health and Human Services (HHS) released of the final version of Special Publication 800-66 Rev. 2, titled โ€œImplementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guideโ€.

    Overview

    The HIPAA Security Rule is a critical framework for safeguarding electronic protected health information (ePHI) held or maintained by regulated entities. To address the evolving cybersecurity landscape, the National Institute of Standards and Technology (NIST) has revised and updated Special Publication 800-66 to provide practical guidance and resources for regulated entities.

    Key Details

    • Publication Title: Special Publication (SP) 800-66 Rev. 2
    • Date Published: February 2024
    • Supersedes: SP 800-66 Rev. 1 (10/23/2008)

    Purpose and Scope

    The revised publication, developed in collaboration with the HHS Office for Civil Rights, serves several purposes:

    1. Risk Assessment and Management: It assists regulated entities (including HIPAA-covered entities and business associates) in assessing and managing risks related to ePHI.
    2. Information Security Program: It identifies typical activities that regulated entities should consider implementing as part of their information security program.
    3. Cybersecurity Guidance: It offers practical guidance to improve cybersecurity posture and achieve compliance with the HIPAA Security Rule.

    Key Content Areas

    The resource guide covers the following topics:

    1. Administrative Safeguards: Strategies for managing ePHI security at the organizational level.
    2. Physical Safeguards: Measures to protect physical access to ePHI.
    3. Technical Safeguards: Recommendations for securing ePHI through technology controls.
    4. Risk Assessment and Risk Management: Practical approaches to identifying and mitigating risks.
    5. Mappings to NIST Cybersecurity Framework: Aligning HIPAA Security Rule standards with NIST Cybersecurity Framework subcategories.
    6. Relevant NIST Publications: Listings of NIST publications relevant to each HIPAA Security Rule standard.

    Conclusion

    For the most part, the totality of the release is a collection of links to access supplemental documentation. Organizations that have never conducted an accurate and thorough Security Risk Assessment will probably find the documentation to be overwhelming. Even for experienced assessors, most of what is provided is not new but more of a one-stop location to find these resources.

    As the healthcare industry continues to rely on electronic health records and digital systems, adherence to the HIPAA Security Rule is paramount. Regulated entities, especially small to mid-size organizations, can use this resource guide to enhance knowledge of cybersecurity practices and how to better protect sensitive health information.

    Remember, safeguarding ePHI is not just a legal requirementโ€”itโ€™s essential for maintaining trust and ensuring patient privacy in this very connected digital world.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    Helping Organizations Achieve HIPAA Complianceโ„ข

    HIPAA compliance is vital to maintain a thriving compliant organization. Colington Consulting offers scalable solutions and compliance consultations to help healthcare practices and vendors meet HIPAA regulatory compliance requirements. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review.

  • HIPAA: Then & Now

    A story about HIPAA that starts with once upon a time, in the late 1990s, the U.S. healthcare system was in dire need of a change. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) was created to address this need. The act aimed to improve the portability and accountability of health insurance coverage, guarantee coverage for employees with pre-existing conditions, and prevent โ€œjob lockโ€ โ€“ a scenario in which plan members stayed in a job to avoid losing health benefits.

    HIPAA introduced several measures to ensure the continuity of coverage between jobs, including the creation of national standards to protect sensitive patient health information from being disclosed without the patientโ€™s consent or knowledge. The U.S. Department of Health and Human Services (HHS) issued the HIPAA Privacy Rule to implement the requirements of HIPAA. The Privacy Rule standards address the use and disclosure of individualsโ€™ health information (known as protected health information or PHI) by entities subject to the Privacy Rule. These individuals and organizations are called โ€œcovered entitiesโ€. The Privacy Rule also contains standards for individualsโ€™ rights to understand and control how their health information is used.

    The story of HIPAA is not just about the creation of a law, but also about the implementation and enforcement of that law. The HIPAA Security Rule protects a subset of information covered by the Privacy Rule. The Security Rule requires appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and security of electronic protected health information.

    The implementation of HIPAA has not been without its challenges. There have been concerns about the cost of implementing the Privacy and Security Rules, as well as understanding what is reasonable and appropriate for an organization, based on size. However, the benefits of HIPAA are clear. The act has helped to ensure that patientsโ€™ health information is protected, and that they have greater control over how their information is used. The act also required that Covered Entities and Business Associates must do to protect that information and comply with the HIPAA Security Standards and Implementation Specifications.

    In 2009, the enforcement authority was delegated to the HHS Office for Civil Rights (OCR) by then U.S. Secretary of Health and Human Services, Kathleen Sebelius. Since then, OCR has settled or imposed a civil money penalty in 137 cases resulting in a total dollar amount of almost $137 million. OCR continues to investigate privacy and security complaints against numerous organizations and businesses, regardless of size.

    But legislative changes are needed, especially with the advancements in health technology applications and data analytics. The regulations have not kept pace with technical safeguard requirements. From a compliance standpoint, there are times when it feels like you are trying to stick a round peg into a square hole. It takes experienced compliance officers, HIPAA consultants, and lawyers to understand what the regulations call for, now almost 30 years since HIPAA was enacted. At some point, Congress will need to tackle the issue of updating the HIPAA regulations. For now, keep those round pegs available.

  • OCR Announces a Significant HIPAA Settlement of $1.3 Million

    OCR just announced a significant HIPAA settlement of $1.3 million with LA Care, one of the largest health plan providers in the country. There where substantial “potential” violations found by OCR which included failure an organization-wide risk assessment and failure to implement sufficient procedures to regularly review records of information system activity.

    LA Care agreed to a comprehensive corrective action plan for three years to ensure compliance with HIPAA requirements.

    Read the full press release: https://www.hhs.gov/about/news/2023/09/11/hhs-office-civil-rights-settles-with-la-care-health-plan-potential-hipaa-security-rule-violations.html