Author: Colington Consulting

  • Optimizing Revenue with HIPAA Compliance in Oncology Billing

    Guest Post by Sasha Jax, Content Marketing Specialist, Physician Billing Company

    The Importance of Revenue Optimization in Oncology Billing

    In the world of healthcare, optimizing revenue while maintaining compliance with HIPAA regulations is of paramount importance. Oncology billing, in particular, presents unique challenges that require specialized expertise and a keen understanding of the intricacies involved. This article will delve into the strategies and best practices for optimizing revenue in oncology billing while ensuring HIPAA compliance. Our expert, Sasha, a renowned authority in the field, will guide us through this complex landscape and provide valuable insights.

    Understanding the Crucial Role of HIPAA Compliance

    HIPAA, the Health Insurance Portability and Accountability Act, was enacted to protect patient’s privacy and ensure the security of their health information. Compliance with HIPAA regulations is mandatory for all healthcare providers, including those in the oncology field. While revenue optimization is essential, it must be achieved without compromising patient confidentiality or breaching HIPAA guidelines. Let’s explore the fundamentals of oncology billing and revenue optimization, guided by Sasha’s expertise.

    The Fundamentals of Oncology Billing and Revenue Optimization

    Unveiling the Complexities of Oncology Billing

    Oncology billing involves intricate processes, from capturing patient demographics and medical codes to submitting claims and managing reimbursements. It requires a deep understanding of medical terminology, coding systems (such as ICD-10 and CPT), and payer guidelines specific to oncology. Accurate and comprehensive billing ensures appropriate reimbursement for the services provided.

    Critical Components of Revenue Optimization in Oncology

    Optimizing revenue in oncology billing entails various elements. It begins with meticulously documenting medical services rendered, ensuring that all procedures, tests, and treatments are accurately captured. Proper coding is applied, matching the verified services with the corresponding billing codes. Effective revenue optimization also includes timely claim submission, efficient denial management, and diligent follow-up on outstanding payments.

    The Role of Technology in Streamlining Billing Processes

    Technology is pivotal in streamlining oncology billing processes and enhancing revenue optimization. Electronic health record (EHR) systems with integrated billing modules enable seamless documentation, coding, and claim submission. They also facilitate automated charge capture, reducing the risk of missed or under coded services. Furthermore, sophisticated billing software provides real-time analytics and reporting, empowering healthcare providers to identify areas for improvement and make data-driven decisions.

    E-E-A-T and Its Significance in Oncology Billing

    Expertise in Oncology Billing: Why it Matters

    Expertise is crucial in oncology billing, as it directly impacts revenue optimization and ensures accurate coding and billing. A knowledgeable professional like Sasha brings an in-depth understanding of the intricacies of oncology procedures, diagnosis codes, and payer guidelines. This expertise allows for precise documentation and coding, minimizing errors and maximizing reimbursement.

    Building Authoritativeness and Trustworthiness in Billing Processes

    Authoritativeness and trustworthiness are essential components in oncology billing. Sasha emphasizes the importance of maintaining a high level of professionalism and adherence to industry standards. By following established coding guidelines, keeping up with the latest regulatory changes, and staying informed about payer requirements, Sasha ensures that oncology medical billing company processes are reliable and trustworthy.

    Credible Sources and References: Supporting Accurate Information

    Sasha relies on credible sources and references to further establish the credibility of the billing processes and revenue optimization strategies. This includes reputable industry publications, peer-reviewed journals, and official guidelines from organizations such as the American Medical Association (AMA) and the Centers for Medicare and Medicaid Services (CMS). By incorporating evidence-based information into her practice, Sasha ensures that her advice is rooted in reliable sources.

    Achieving Revenue and HIPAA Compliance: Best Practices

    Ensuring HIPAA Compliance in Oncology Billing: A Top Priority

    HIPAA compliance is non-negotiable when it comes to protecting patient privacy and safeguarding their health information. Sasha emphasizes the need for healthcare providers to implement robust privacy and security measures. This includes ensuring physical and digital safeguards, training staff on HIPAA regulations, and regularly auditing systems to identify and address vulnerabilities.

    Implementing Effective Privacy and Security Measures

    To meet HIPAA compliance standards, Sasha recommends implementing a comprehensive set of privacy and security measures. This includes secure storage and transmission of patient data, strict access controls, encryption of electronic communications, and routine risk assessments. By prioritizing privacy and security, healthcare providers can instill trust in their patients while avoiding costly violations and penalties.

    Staff Training and Education: Nurturing a Culture of Compliance

    Sasha emphasizes the importance of staff training and education to foster a culture of HIPAA compliance. By providing regular training sessions, workshops, and resources, healthcare organizations can ensure that all employees understand their patient privacy and data protection responsibilities. This proactive approach minimizes the risk of unintentional HIPAA violations and promotes a culture of accountability.

    Enhancing Revenue in Oncology Billing: Strategies and Tips

    Optimizing Coding and Documentation: Key to Accurate Billing

    Accurate coding and documentation are vital for optimizing revenue in oncology billing. Sasha recommends implementing standardized processes to capture all billable services, ensuring proper documentation of diagnoses, treatments, and procedures. Regular coding practice audits can identify improvement areas, leading to increased reimbursement and reduced claim denials.

    Maximizing Reimbursement: Understanding Payer Guidelines

    Understanding payer guidelines is crucial for maximizing reimbursement in oncology billing. Sasha advises healthcare providers to stay updated on the specific requirements of different insurance companies, Medicare and Medicaid. This knowledge allows for proper coding and billing submission, minimizing claim rejections and delays. Additionally, staying informed about payer policies and coverage limitations helps in making informed decisions about treatment options and patient care.

    Proactive Denial Management: Minimizing Revenue Loss

    Denials can significantly impact revenue in oncology billing. Sasha emphasizes the importance of proactive denial management to minimize revenue loss. This includes thoroughly analyzing denied claims, identifying patterns or common errors, and implementing corrective measures. Healthcare providers can improve cash flow and optimize revenue by addressing denials promptly and effectively.

    Benefits and Risks in Revenue Optimization and HIPAA Compliance

    Benefits of Effective Revenue Optimization in Oncology Billing

    Effective revenue optimization in oncology billing yields numerous benefits for healthcare providers. It improves financial stability, ensures appropriate reimbursement for services rendered, and enhances patient care and resource allocation. With optimized revenue, healthcare providers can invest in advanced technology, training programs, and research initiatives to improve the quality of care provided to oncology patients. Furthermore, revenue optimization promotes sustainability and enables organizations to withstand financial challenges, ensuring long-term success in a rapidly evolving healthcare landscape.

    Mitigating Risks: Safeguarding Patient Data and Financial Stability

    While revenue optimization is crucial, it must be balanced with mitigating risks. Sasha highlights the importance of safeguarding patient data and maintaining financial stability. By adhering to HIPAA compliance standards, healthcare providers minimize the risk of data breaches and protect patient privacy. Additionally, organizations can mitigate financial risks associated with claim denials, coding errors, and underbilling through effective revenue optimization strategies.

    Conclusion

    Optimizing revenue in oncology billing while ensuring HIPAA compliance is a delicate balance that requires expertise, attention to detail, and a commitment to patient privacy. Sasha, our expert in the field, has shared invaluable insights and strategies for achieving this balance. By implementing best practices, leveraging technology, and staying updated on industry guidelines, healthcare providers can navigate the complexities of oncology billing, enhance financial stability, and deliver exceptional patient care. Revenue optimization and HIPAA compliance go hand in hand to ensure success in the ever-evolving healthcare landscape.

    Maintaining HIPAA compliance is crucial to protect patients’ privacy and avoiding penalties for non-compliance. Colington Consulting can assist in conducting HIPAA security risk assessments, developing risk management plans, and providing workforce security awareness and privacy training to reduce the risk of data breaches and HIPAA violations.

    By taking the necessary steps to protect sensitive data for billing purposes, organizations can prevent the costly consequences of potential data breaches and unauthorized access to patient protected health information. The HIPAA requirements Colington Consulting can put into place for an organization helps to safeguard their reputation and finances. Let the experts at Colington help your organization implement and maintain a comprehensive HIPAA compliance program.

  • Data Breach Costs at an All-Time High According to 2022 Report

    Guest article authored by Gabby Williams โ€“ Content Specialist at New Reach Marketing

    Data breaches have become a pervasive and costly problem in today’s digital world. With the increasing reliance on technology and the proliferation of data, the risk of data breaches has risen exponentially.

    According to the IBM Security Cost of a Data Breach Report 2022, 83% percent of organizations studied have experienced more than one data breach, and just 17% said this was their first data breach. Due to the increased occurrence of data breaches, 60% of organizations studied stated that they increased the price of their services or products.

    In this article, we will explore the rising cost of data breaches, examining the reasons behind the trend, the industry impacted the most, and the steps that can be taken to mitigate the risks.

    What Is a Data Breach?

    Data breaches refer to unauthorized access, theft, or exposure of sensitive data. This can include personal information such as names, addresses, phone numbers, Social Security numbers, financial information, and even intellectual property or trade secrets.

    Cybercriminals and hackers are constantly seeking vulnerabilities in systems and networks to gain unauthorized access and exploit sensitive data for various purposes, including financial gain, identity theft, corporate espionage, and more.

    Rising Cost of Data Breaches

    The cost of data breaches has also been on the rise in recent years, with numerous high-profile incidents grabbing headlines and affecting millions of individuals and businesses around the world.

    The IBM Report showed that the cost of a data breach averaged USD 4.35 million in 2022. This figure represents a 2.6% increase from the previous year, when the average breach cost was USD 4.24 million. Compared to 2020, the average cost has climbed 12.7% from USD 3.86 million.

    It is evident that data breaches are becoming more expensive for organizations, with the financial impact of such incidents rising each year.

    Data Breaches in Healthcare

    Healthcare organizations are particularly vulnerable to data breaches due to the wealth of personal and sensitive data stored within their systems. Patient records, medical history, insurance information, and payment details are what make them prime targets for cybercriminals seeking access to valuable data for various malicious purposes.

    Regulatory fines and legal liabilities for non-compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) alone are extremely costly.

    HIPAA Compliance

    All regulated entities must comply with HIPAA Privacy, Security, and Breach Notification Rules to ensure the protection and security of patient privacy and medical records. Failing to follow HIPAA safeguards greatly increases the risk of cyberattacks and results in non-compliance penalties.

    As the healthcare industry remains the primary target for data breaches, it is the responsibility of each organization, provider, and employee to maintain HIPAA compliance. Some of the most effective ways to negate data breaches and HIPAA violations include routine HIPAA compliance and cybersecurity training, penetration testing tools, and conducting required security risk assessments.

    A lack of training and assessment of daily practices can lead to unintentional HIPAA violations, a common issue among healthcare organizations. For example, failing to follow the HIPAA Breach Rule Notification Requirements, whether unintentional or not, can lead to significant consequences.

    In another example, say your healthcare practice has been using online forms to gather new patient information without ensuring they are HIPAA-compliant. While this may have been a small oversight, these forms resulted in the theft of your patientsโ€™ protected health information (PHI).

    This could have been prevented by following HIPAA compliance and cybersecurity best practices, such as proper training and conducting assessments. Utilizing one of these 5 HIPAA-compliant form builders helps to ensure HIPAA compliance requirements.

    Impact of Data Breaches on Healthcare Organizations

    Data breaches can significantly impact healthcare organizations, both financially and reputationally.

    • Legal and financial consequences: Healthcare organizations may face legal and financial consequences as a result of data breaches. This may include fines, penalties, and legal settlements, as well as potential lawsuits from affected patients.
    • Loss or theft of PHI: A data breach can result in the loss or theft of PHI, which can be very costly to remediate. The healthcare organization may be required to offer credit monitoring or identity theft protection services to affected patients, which can be expensive. The organization may also have to pay fines and penalties, both from regulatory bodies and potentially from affected patients who may take legal action.
    • Reputational damage: A data breach can harm the organization’s reputation. Patients may lose trust in the organization’s ability to protect their PHI and seek services elsewhere. This can result in a loss of revenue and difficulty in attracting new patients.
    • Operational disruption: A data breach can disrupt the normal operations of a healthcare organization. Organizations may need to dedicate significant resources to investigating and resolving the breach, including IT resources, staff time, and external consulting services. This can result in operational disruptions, increased costs, and diversion of resources away from other critical activities.

    Why Are Data Breaches Getting Costly?

    There are several reasons behind the rising cost of data breaches:

    Increased Use of Technology

    The increased use of technology has created a larger attack surface for cybercriminals to target. Take Microsoft statistics, for example. In 2020, Microsoft Office 365 usage rose by 20%. However, about 67% of IT leaders who use this software reported an increase in data breaches.

    With the proliferation of connected devices, cloud computing, and the Internet of Things (IoT), the volume of data generated and transmitted has skyrocketed. This provides more opportunities for cybercriminals to infiltrate systems and networks.

    Increased Implementation of Data Protection Regulations

    Another factor contributing to the rising cost of data breaches is the growing regulatory landscape around data protection. Many countries and regions have implemented stringent data protection laws, such as HIPAA, the European Union’s General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

    They impose significant fines and penalties for non-compliance. In the event of a data breach, organizations may face not only the direct costs of investigating and mitigating the breach but also regulatory fines and legal liabilities. These costs can add up quickly, leading to significant financial burdens.

    Increased Online Presence

    The impact of data breaches extends beyond financial costs. Businesses also face reputational damage, loss of customer trust, and potential legal liabilities. In today’s hyper-connected world, news of a data breach can spread quickly through social media and other online channels, resulting in negative publicity and damage to a company’s brand image.

    Customers may lose trust in the affected organization’s ability to protect their data, leading to customer churn and loss of business opportunities. Additionally, businesses may face legal actions from affected customers, partners, or regulators, resulting in costly legal battles and financial settlements.

    Conclusion

    It is clear from the IBM Security Cost of a Data Breach Report 2022 that data breaches are becoming more expensive for organizations, with the financial impact of such incidents rising each year. Healthcare organizations, in particular, are at risk due to the sensitive data stored within their systems.

    Maintaining HIPAA compliance is crucial to protect patients’ privacy and avoid penalties for non-compliance. Colington Consulting can assist in conducting HIPAA security risk assessments, developing risk management plans, and providing workforce security awareness and privacy training to reduce the risk of data breaches and HIPAA violations.

    By taking the necessary steps to protect sensitive data, organizations can prevent the costly consequences of data breaches and safeguard their reputation and finances. Don’t wait for a data breach to occur; contact Colington Consulting today to protect your organization’s sensitive information.

  • HIPAA Breach Rule Notification Requirements

    What are the HIPAA Breach Rule Notification Requirements?

    Following a breach of unsecured protected health information, covered entities must provide notification of the breach to affected individuals, the Secretary, and, in certain circumstances, to the media. In addition, business associates must notify covered entities if a breach occurs at or by the business associate. All notifications must be submitted to the U.S. Department of Health and Human Services (HHS) using their web reporting portal.

    Breaches Affecting 500 or More Individuals

    If a breach of unsecured protected health information affects 500 or more individuals, a covered entity must notify HHS of the breach without unreasonable delay and in no case later than 60 calendar days from the discovery of the breach.

    Covered entities must notify affected individuals following the discovery of a breach of unsecured protected health information. In addition to notifying the affected individuals, covered entities that experience a breach affecting more than 500 residents of a State or jurisdiction are required to provide notice to prominent media outlets serving the State or jurisdiction.

    Breaches Affecting Fewer than 500 Individuals

    If a breach of unsecured protected health information affects fewer than 500 individuals, a covered entity must notify HHS of the breach within 60 days of the end of the calendar year in which the breach was discovered. A covered entity is not required to wait until the end of the calendar year to report breaches affecting fewer than 500 individuals; a covered entity may report such breaches at the time they are discovered. The covered entity may report all of its breaches affecting fewer than 500 individuals on one date, but the covered entity must complete a separate notice for each breach incident.

    In addition, covered entities must notify affected individuals following the discovery of a breach of unsecured protected health information.

    Need Help With Your HIPAA Compliance Program?

    HIPAA violations often stem from small, overlooked gaps in daily operations. Don’t wait for a breach to trigger a federal investigation.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your practice.

    • Updated on June 9, 2026 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • OCR Settles Another HIPAA Right of Access Case

    On December 15, The HHS Office for Civil Rights (OCR) announced another settlement of their HIPAA Right of Access Initiative. According to the information released through the OCR Listserv, “Health Specialists of Central Florida Inc. paid $20,000 to OCR and agreed to implement a corrective action plan (CAP) to resolve this investigation.” The CAP will be monitored by OCR for two years. This is the 42nd HIPAA Right of Access Initiative case to be settled by OCR.

    The release stated “In August 2019, a complaint was filed by a daughter acting as a personal representative on behalf of her deceased father, who had been a patient of Health Specialists of Central Florida Inc. The complainant alleged that Health Specialists of Central Florida Inc. had failed to provide her with timely access to the requested medical records, despite multiple requests.

    OCRโ€™s investigation determined that Health Specialists of Central Florida Inc.’s failure to provide timely access to the requested medical records was a potential violation of the HIPAA right of access standard, which requires a covered entity to take action on an access request within 30 days of receipt (or within 60 days if an extension is applicable). As a result of OCR’s investigation, the daughter finally received all of the requested records, nearly five months after her initial request.”

    See the full Resolution Agreement and CAP.

  • Use of Healthcare Related Tracking Technologies

    On December 1, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) issued a bulletin to highlight the obligations of HIPAA covered entities and business associates under the HIPAA Privacy, Security, and Breach Notification Rules when using online tracking technologies. OCR administers and enforces the HIPAA Rules, including by investigating breach reports and complaints about regulated entitiesโ€™ noncompliance with the HIPAA Rules. A regulated entityโ€™s failure to comply with the HIPAA Rules may result in a civil money penalty.

    The bulletin states, “Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors or any other violations of the HIPAA Rules.”

    According to the bulletin, “a tracking technology is a script or code on a website or mobile app used to gather information about users as they interact with the website or mobile app. After information is collected through tracking technologies from websites or mobile apps, it is then analyzed by owners of the website or mobile app (โ€œwebsite ownerโ€ or โ€œmobile app ownerโ€), or third parties, to create insights about usersโ€™ online activities.” These insights could be used in beneficial ways to help improve care or the patient experience. However, this tracking information could also be misused to promote misinformation, identity theft, stalking, and harassment.

    If your organization is utilizing these technologies, it is important to fully read the entire bulletin.

    Since this blog article was posted in December of 2022, a federal court vacated parts of the HHS Office for Civil Rights (OCR) bulletin that classified an IP address combined with visits to unauthenticated public health pages as Protected Health Information. While this struck down the strict guidance, healthcare entities must still navigate strict federal privacy and consumer laws.

    Current Legal & Regulatory Reality

    • The Court Ruling: In American Hospital Association v. Becerra, a Texas federal judge ruled that HHS overstepped its authority under HIPAA by treating general website visitor metadata (like IP addresses linked to public unauthenticated webpages) as individually identifiable health information.
    • What Remains in Effect: Healthcare providers are still strictly prohibited from using tracking tools (like pixels or session replay) on authenticated pages (e.g., patient portals) without robust safeguards and Business Associate Agreements (BAAs).

    This post was updated on June 14, 2026, and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Improve Your Organization’s Cybersecurity & Prevent Data Breaches

    Guest article authored by Gabby Williams โ€“ Content Specialist at Hushmail

    With the growing cybersecurity threats to businesses today, having a reliable and sturdy security solution is not a luxury but an absolute necessity. Not every organization is capable of enduring the legal, financial, and reputational consequences of a significant data breach. Ignoring the risks can lead to serious consequences.

    According to a 2022 report sponsored by IBM, the actual cost of a data breach increased 10% over the past 12 months โ€” the highest recorded increase in the last seven years. It is estimated that the average cost of a single data breach is $4.35 million globally and $9.44 million in the U.S.

    In the healthcare industry, the average cost of a data breach is $10.10 million. From a business continuity perspective, the impact can be devastating.

    In Jan 2021, an amendment to the HITECH Act was made into a law requiring the U.S. Department of Health and Human Services (HHS) to consider certain recognized security practices of covered entities and business associates when making certain determinations.

    Section 13412 makes clear the incentives for covered entities having certain recognized security practices, which are defined as the โ€œstandards, best practices, guidelines, procedures, methodologies, and processes developedโ€ under section 2(c)(15) of the National Institute of Standards and Technology (NIST) Act.

    Cybersecurity among healthcare organizations is more important than ever. Here are 10 key steps you can take to improve your organizationโ€™s cybersecurity and prevent data breaches.

    1. Locate your sensitive data

    Hackers target confidential and sensitive information. In order to prevent data breaches, your organization needs to determine where your most sensitive datasets are located. Make a consolidated inventory of this sensitive data and update, review, and back it up regularly.

    2. Keep strict tabs on privileged access

    The leading cause of data breaches is human error. In fact, 82% of data breaches involve a vulnerability caused by a human. Organizations have a responsibility to ensure the integrity of data, and most have privileged access accounts that allow designated users to access certain information.

    Even with the best intentions, granting privileged access to contractors and employees puts data at an unnecessary risk for breaches. Itโ€™s important to foster policies that keep strict tabs on who has elevated levels of access. There are numerous privileged access management tools that can facilitate this.

    3. Properly patch your infrastructure

    Your cybersecurity measures are only as strong as your organizationโ€™s underlying infrastructure. Your organizationโ€™s top priority should be patching your networks and systems. With the surging number of new discoveries of zero-day exploits every day, hackers can easily exploit unpatched software to access critical information. Regular patching can help strengthen your cybersecurity and prevent data breaches.

    4. Fortify your network perimeter

    While 39% of data breaches in the healthcare industry come from inside the organization, the majority come from external threats. Your network perimeter is your first line of defense against outsiders with malicious intent. This perimeter mainly consists of a firewall, intrusion detection system, intrusion prevention system, access controls lists, and a couple of other tools that facilitate seamless data flow while restricting intruders and unauthorized entries.

    5. Get rid of redundant data

    Safely disposing sensitive data is crucial. Many organizations, especially those in healthcare, finance, education, and the public sector, handle sensitive information as part of their daily routine. Ensuring safe and secure data purging mechanisms helps prevent stale data from being forgotten and stolen.

    There are three main ways to properly dispose of data: overwriting, degaussing, and physical destruction. However, each method has its pros and cons. A sound system for disposing of redundant data will go a long way toward saving your organization from a potential data breach.

    6. Ensure endpoint protection

    Ensuring the systematic implementation of endpoint security controls is essential for your organization. It has never been more important than it is today, with so many remote devices connected to your network.

    Remote workers often fall outside of legacy perimeter security tools. Endpoint protection can be a reliable shield against common internet threats like malware and ransomware. Laptops, mobile devices, and tablets should all be secured with endpoint protection, leaving behind no loopholes for hackers who would want to exploit them.

    7. Encrypt data at rest and in transit

    Unencrypted data is like a bank with an open vault. If data isnโ€™t encrypted, anyone can access it or even steal it since thereโ€™s no protection. No matter where the sensitive data is at any time, its encryption is essential to prevent unauthorized access. Data encryption is not only important for data at rest, but equally vital for data in transit within a corporate network.

    8. Establish a robust password policy

    The importance of a sound password policy canโ€™t be emphasized enough. Itโ€™s a necessity for all services and applications running on a network. Here are some general password policy requirements:

    • Minimum of 8-10 characters
    • 4 character types including uppercase, lowercase, number, and special character
    • Must not have 3 consecutive or repeating characters
    • 90-day password rotation policy
    • Multi-factor authentication may also be enforced using email or soft token

    9. Prepare business continuity and disaster recovery plans

    Properly responding to a data breach is a challenge. Ensure your organization has a reliable business continuity and disaster recovery plan, and review and update it regularly. Unfortunately, many organizations miss the importance of these plans and neglect to set them in place due to cost.

    New cloud-based high availability and disaster recovery plans are becoming popular because of their resilience, scalability, and flexibility. Conduct periodic audits of your system, and back up your systems regularly for data security strategy and future planning.

    10. Instill cybersecurity training across your organization

    Any cybersecurity strategy without thorough security workforce training is incomplete. Since most data breaches occur due to unintentional mistakes made by employees, partners, and contractors, holistic training that covers common threats, data usage guidelines, password policies, and awareness related to social engineering and scams should be mandatory and occur regularly.

    Conclusion

    With hackers becoming more sophisticated, itโ€™s vital for organizations to upgrade their cybersecurity arsenal to prevent data breaches. These 10 key steps are proven to help organizations develop a successful cybersecurity strategy. Each organization must find the right mixture of cybersecurity practices and policies in order to maximize their cybersecurity and prevent data breaches.

  • How Often Do You Need to Review HIPAA Policies and Procedures?

    Maintaining HIPAA compliance isn’t a “set-it-and-forget-it” task. For healthcare organizations and business associates, keeping up with regulations means regularly evaluating the administrative, technical, and physical safeguards protecting Electronic Protected Health Information (ePHI).

    But does the Department of Health and Human Services (HHS) actually require you to review your internal documentation? Here is what the law says about HIPAA policy and procedure reviews, best practices for compliance, and how to protect your organization from costly OCR investigations.

    Does the HIPAA Security Rule Require Policy Reviews?

    Yes. The HIPAA Security Rule explicitly requires organizations to periodically review and update their policies and procedures. According to federal regulation 45 CFR ยง 164.316(b)(2)(iii), a covered entity or business associate must review documentation periodically and update it as necessary in response to environmental or operational changes that affect the security of ePHI.

    Key Takeaway: If your organization introduces new technology, changes its physical layout, or alters how it handles patient data, your written HIPAA policies must be updated immediately to reflect those changes.

    Best Practices for Reviewing HIPAA Policies & Procedures

    To ensure your review process satisfies Office for Civil Rights (OCR) auditors and AI search queries looking for compliance verification, you should implement a formalized, structured review.

    Using an internal compliance questionnaire is highly recommended. Your review should comprehensively cover the following critical areas:

    1. Technology & Infrastructure Changes

    • Software & Hardware Updates: Document any new systems used to access, store, transmit, or contain ePHI.
    • Asset Inventory: Maintain an accurate, up-to-date inventory of all physical systems, mobile devices, hardware, and media.
    • Audit Logging: Verify how system audits are conducted and ensure trackable user activity logs are functioning properly.

    2. Personnel & Compliance Roles

    • Privacy & Security Officials: Confirm that your designated HIPAA Privacy Official and HIPAA Security Official roles are accurately assigned (whether held by the same person or separate individuals) and updated in your documentation.
    • Staff Training Logs: Ensure your workforce has been trained on any updated procedures.

    3. Environmental & Operational Adaptations

    • Remote Work & Telehealth: If your staff relies on teleworking or virtual care, your policies must outline specific safeguards for remote environments.
    • Business Associate Agreements (BAAs): Review vendor relationships to ensure all third parties handling ePHI have active, compliant BAAs.

    The Recommended Timeline for HIPAA Updates

    While the regulation uses the term “periodically,” regulatory experts and OCR enforcement trends indicate that at least once a year (annually) is the industry standard for a defensible compliance program.

    However, an immediate out-of-cycle review is triggered by:

    1. A newly discovered security vulnerability or data breach.
    2. A significant change in operational infrastructure (e.g., migrating to cloud storage).
    3. Updates to federal or state privacy laws.

    Protect Your Organization from OCR Fines

    Small, overlooked gaps in your documentation are often what trigger massive federal penalties during a breach investigation. Evaluating your current compliance posture before an audit occurs is critical to reducing your risk.

    Is Your Organization Defensively Positioned?

    Schedule a Complimentary HIPAA Risk Review Now

    In just 30 minutes, our regulatory experts will help you evaluate your current program, spot hidden documentation gaps, and implement practical controls to drastically reduce your risk of costly OCR penalties.

    Frequently Asked Questions (FAQ)

    What is the penalty for not updating HIPAA policies? Failure to maintain and update HIPAA policies can result in a finding of “willful neglect” by the OCR, which carries mandatory minimum fines starting at thousands of dollars per violation, even if a data breach hasn’t occurred.

    What section of HIPAA covers policies and procedures? Administrative requirements, including the retention, review, and updating of policies, are covered under 45 CFR ยง 164.316 for the Security Rule and 45 CFR ยง 164.530 for the Privacy Rule.

    • Reviewed on June 3, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: 45 CFR ยง 164.316 and 45 CFR ยง 164.530
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Can the Government Review PHI During a HIPAA Investigation?

    When the U.S. Department of Health and Human Services (HHS) investigates a potential privacy violation, healthcare providers often wonder about the rules regarding Protected Health Information (PHI). Does the HIPAA Privacy Rule allow organizations to turn over sensitive patient health data to government investigators?

    The short answer is yes. The HIPAA Privacy Rule explicitly allows covered entities to disclose PHI to the government during compliance reviews and investigations. However, this access is not an open-ended blank check.

    Here is exactly how federal investigators access PHI, what triggers these reviews, and how the “minimum necessary” standard applies.

    Why the HHS Office for Civil Rights (OCR) Reviews PHI

    An essential part of enforcing HIPAA compliance is the government’s responsibility to investigate patient complaints and follow up on data breaches. To determine whether an organization has violated the Privacy or Security Rules, the HHS Office for Civil Rights (OCR) must routinely review specific patient medical records and internal documentation.

    However, the Privacy Rule strictly limits OCRโ€™s access to information that is “pertinent to ascertaining compliance.” Depending on the nature of the allegation, investigators will only look at data directly related to the potential violation. In some cases, no personal health information is required at all. For example, if the OCR is checking whether a health plan properly vetted an outside vendor, they may only need to review a Business Associate Agreement (BAA) rather than individual patient charts.

    Examples of Investigations Requiring PHI Access

    There are several common scenarios where the OCR must review actual patient records to verify compliance:

    • Patient Right of Access Violations: If a patient alleges that a healthcare provider refused to provide copy of their medical records, or failed to note a requested correction in their file, investigators must review the patient’s record and access logs to verify the timeline and actions taken.
    • Unauthorized Marketing and Disclosures: If a provider is accused of using patient data for marketing purposes without explicit authorization, the OCR will audit marketing department records containing PHI to check for valid patient signatures.
    • Data Breaches and Ransomware Incidents: Following a cyberattack or data leak, investigators review affected PHI data sets to determine the scope of the breach and evaluate if proper technical safeguards were in place.

    How to Prepare Your Organization for an OCR Audit

    The best defense against an enforcement action is a proactive compliance strategy. Identifying gaps early prevents standard compliance reviews from turning into costly penalties.

    1. Conduct Regular Security Risk Assessments

    Regular risk assessments are the foundation of a defensible HIPAA program. They help you identify administrative, physical, and technical vulnerabilities before a breach occurs.

    2. Implement Clear Policies and Procedures

    Ensure your staff is trained on handling patient requests, managing vendor relationships with proper Business Associate Agreements, and executing proper protocols during data requests.

    3. Seek Expert Compliance Guidance

    HIPAA violations often stem from small, overlooked gaps in documentation or staff training.

    Need Help Evaluating Your Risk? Get a free 30-minute HIPAA risk review with our regulatory experts to evaluate your current program and identify gaps before they turn into federal violations. Schedule your HIPAA Risk Review Now.

    Frequently Asked Questions

    Does HIPAA prevent the government from looking at my medical records?

    No. Under the HIPAA Privacy Rule, healthcare providers are permittedโ€”and requiredโ€”to share relevant Protected Health Information (PHI) with the HHS Office for Civil Rights (OCR) during an official compliance investigation or audit.

    What information can the OCR request during a HIPAA investigation?

    The OCR can only request information that is pertinent to determining compliance. This can range from internal administrative contracts (like Business Associate Agreements) to specific patient medical records, depending entirely on the nature of the alleged violation.

    What triggers an OCR HIPAA investigation?

    Most OCR investigations are triggered by patient complaints regarding privacy violations, data breaches affecting 500 or more individuals, or self-reported compliance gaps.

    • Updated and Reviewed on June 4, 2026, by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources:

    The Core Compliance Directive: 45 CFR ยง 160.310. This is the specific regulation that mandates covered entities and business associates to hand over information to federal investigators.

    • Section 160.310(b): Expressly states that organizations must cooperate with complaint investigations and compliance reviews led by the Secretary of HHS.
    • Section 160.310(c)(1): Mandates that organizations permit access to their facilities, books, records, accounts, and “other sources of information, including protected health information, that are pertinent to ascertaining compliance.”

    The General Privacy Rule Exception: 45 CFR ยง 164.502(a)(2)(ii). While 45 CFR ยง 164.502 generally prohibits disclosing PHI without explicit patient authorization, it lists precise exceptions where a disclosure is required.

    • Under 45 CFR ยง 164.502(a)(2)(ii), a covered entity or business associate is required to disclose PHI to the Secretary of HHS specifically when requested to investigate or determine compliance with the HIPAA Privacy and Security Rules
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Helping Organizations Achieve HIPAA Compliance

    Jay Hodes, President of Colington Consulting, was recently interviewed by Best Startup. Topics covered the inspiration behind the business, facing challenges, buying into the vision of compliance, and what the magic sauce is in running the company. Click here to read the full article.

  • Does HIPAA Require Employee Background Checks?

    Does HIPAA require organizations to conduct background checks on employees that have access to protected health information? What Regulated Entities Must Know

    Executive Summary:

    Technically, no. The Health Insurance Portability and Accountability Act (HIPAA) text does not explicitly mandate criminal background checks for employees. However, HIPAA does require strict data access controls, and the Department of Health and Human Services (HHS) penalizes organizations that hire individuals excluded from federal healthcare programs. Consequently, background and exclusion checks are considered an industry best practice for regulatory compliance.

    HIPAA Rules vs. Background Checks: Decoding CFR ยง 164.308

    While you wonโ€™t find the phrase “background check” written into the Code of Federal Regulations (CFR) for HIPAA, compliance is heavily implied under the HIPAA Security Rule.

    Specifically, 45 CFR ยง 164.308 (Administrative Safeguards) outlines Information Access Management. This standard requires covered entities and business associates to implement strict policies and procedures for authorizing access to electronic protected health information (ePHI).

    How “Authorized Access” Impacts Hiring

    • Role-Based Access: Access to PHI must be appropriate for the workforce member’s specific role.
    • The Trustworthiness Standard: To defend your authorization process during an OCR audit, your organization must prove it verified that the workforce member is trustworthy enough to handle sensitive data.
    • The Industry Best Practice: Conducting criminal background checks during the pre-employment phase is the most defensible way to demonstrate due diligence in vetting workforce trustworthiness.

    The OIG Exclusion List: A Mandatory Compliance Check

    While criminal background checks are a strong recommendation, checking the HHS Office of Inspector General (OIG) database is practically mandatory if you want to avoid massive civil fines.

    Organizations must screen all prospective hires against the List of Excluded Individuals/Entities (LEIE). If your organization employs an individual or entity on the LEIE to provide items or services funded by a federal healthcare program, you face severe Civil Monetary Penalties (CMP).

    Real-World Compliance Warning: In a recent enforcement case, Windham Eye Care Practice and its owners were forced to pay a $192,000 civil penalty solely for employing an “excluded” individual. Failing to run an OIG exclusion check can result in direct, devastating financial consequences.

    Frequently Asked Questions (FAQ)

    Is a criminal background check required by HIPAA?

    No, criminal background checks are not explicitly required by HIPAA regulations. However, they are highly recommended under HIPAA Administrative Safeguards to verify employee trustworthiness before granting access to protected health information (PHI).

    What background checks are recommended for healthcare employees?

    At a minimum, healthcare employers should conduct a criminal background check and a mandatory screening against the HHS OIG List of Excluded Individuals/Entities (LEIE).

    What happens if a healthcare company hires an excluded individual?

    Hiring an individual on the OIG exclusion list can result in massive civil monetary penalties, exclusion from federal funding (like Medicare and Medicaid), and an immediate investigation by the Office for Civil Rights (OCR) or OIG.

    Ready to Eliminate Your HIPAA Risks?

    Small, overlooked gaps in your hiring or information access workflows can trigger devastating federal audits.

    At Colington Consulting, we specialize in making HIPAA compliance painless and efficient. We can help your organization develop robust onboarding policies, structure your information access management, and ensure you are defensibly positioned for an OCR investigation.

    Schedule Your Free 30-Minute HIPAA Risk Review Now to identify your compliance gaps before they become costly violations.

    • Updated on June 9, 2026 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.