

By Jay Hodes, President โ Colington Consulting
As a HIPAA consultant, I conduct many initial consultations with organizations, large and small, to cover requirements of the HIPAA Security and Privacy Rules. What I often find is not that organizations do want to comply with HIPAA compliance, but more of the case of not understanding what needs to be in place to meet regulatory requirements. I put a lot of emphasis on the educational aspects of understanding what the Code of Federal Regulations calls for in meeting HIPAA requirements.
Factoring in HHS Office for Civil Rights (OCR) enforcement initiatives and lessons learned from prior settlements, I want to make sure any organization we work with is well positioned should a breach occur. This means having a defendable, well documented HIPAA compliance program in place should an OCR breach investigation occur.
Let me cover a few topics as to why HIPAA compliance matters for healthcare organizations and patients. Remember, HIPAA defines what patient rights are when it comes to their protected health information, but more importantly, what an organizationโs responsibilities are for disclosing and safeguarding that information.
HIPAA Security Standards and Implementation Specifications:
- The HIPAA Security Rule identifies administrative, physical, and technical safeguards that must be in place. This sets the foundation for compliance.
- There are over 50 of these Standards and Implementation Specifications that are covered in the Code of Federal Regulations that include conducting required Security Risk Assessments.
Patient Privacy Rights/Organization Requirements:
- The Standards for Privacy of Individually Identifiable Health Information (โPrivacy Ruleโ) establishes a set of national standards for the protection of certain health information.
- The HIPAA Privacy Rule standards address the use and disclosure of individualsโ health informationโcalled โprotected health informationโ by organizations subject to the Privacy Rule โ called โcovered entities,โ as well as standards for individuals’ privacy rights to understand and control how their health information is used.
- A major goal of the Privacy Rule is to assure that individualsโ health information is properly protected while allowing the flow of health information needed to provide and promote high quality health care and to protect the public’s health and wellbeing.
Technical Safeguards for Electronic Protected Health Information (ePHI):
- The HIPAA Security Rule defines technical safeguards in CFR ยง 164.304 as โthe technology and the policy and procedures for its use that protect electronic protected health information and control access to it.โ
- These safeguards must address access control, unique user identification, emergency access procedures, encryption/decryption, audit controls, and transmission security.
- Organizations must conduct audits of any systems that contain ePHI, review audit reports, and maintain those reports for 6 years.
Breach Notification Rule Requirements:
- The HIPAA Breach Notification Rule, 45 CFR ยงยง 164.400-414, requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured protected health information.
- Following a breach of unsecured protected health information or ePHI, covered entities must provide notification of the breach to affected individuals, the Secretary, and, in certain circumstances, to the media. In addition, business associates must notify covered entities if a breach occurs at or by the business associate.
- Covered entities and business associates, as applicable, have the burden of demonstrating that all required notifications have been provided or that use, or disclosure of unsecured protected health information did not constitute a breach.
Business Associates:
- A โbusiness associateโ is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity.
- These functions or services include claims processing or administration; data analysis, processing, or administration; utilization review; quality assurance; billing; benefit management; practice management, legal; actuarial; accounting; consulting; data aggregation;
management; administrative; accreditation; and financial. - When these business relationships exist, a Business Associate Agreement (BAA) must be executed between both parties.
- There are specific elements that must be included in all BAAs.
Ensuring HIPAA Compliance:
- Organizations, regardless of size, must designate a HIPAA Security and Privacy Officer. It can be a combined role as the HIPAA Compliance Officer and be a collateral duty.
- HIPAA is not one and done, it takes program management. CFR 164.316(a) states โImplement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications, or other requirements.โ
- A security awareness and training program must be implemented and provided to all members of the workforce, including providers and management.
Failure to Comply:
- Can result in potential penalties and fines, the need to enter into Resolution Agreements, and be required to adopt a formal Corrective Action Plan.
- Loss of public and workforce trust. All reported breaches affecting 500 or more individuals are posted on the HHS breach portal and are open source for all to see.
Need Help With Your HIPAA Compliance Program?
At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review with me to evaluate your current policies and protect your organization.

