Author: Colington Consulting

  • Improve Your Organization’s Cybersecurity & Prevent Data Breaches

    Guest article authored by Gabby Williams โ€“ Content Specialist at Hushmail

    With the growing cybersecurity threats to businesses today, having a reliable and sturdy security solution is not a luxury but an absolute necessity. Not every organization is capable of enduring the legal, financial, and reputational consequences of a significant data breach. Ignoring the risks can lead to serious consequences.

    According to a 2022 report sponsored by IBM, the actual cost of a data breach increased 10% over the past 12 months โ€” the highest recorded increase in the last seven years. It is estimated that the average cost of a single data breach is $4.35 million globally and $9.44 million in the U.S.

    In the healthcare industry, the average cost of a data breach is $10.10 million. From a business continuity perspective, the impact can be devastating.

    In Jan 2021, an amendment to the HITECH Act was made into a law requiring the U.S. Department of Health and Human Services (HHS) to consider certain recognized security practices of covered entities and business associates when making certain determinations.

    Section 13412 makes clear the incentives for covered entities having certain recognized security practices, which are defined as the โ€œstandards, best practices, guidelines, procedures, methodologies, and processes developedโ€ under section 2(c)(15) of the National Institute of Standards and Technology (NIST) Act.

    Cybersecurity among healthcare organizations is more important than ever. Here are 10 key steps you can take to improve your organizationโ€™s cybersecurity and prevent data breaches.

    1. Locate your sensitive data

    Hackers target confidential and sensitive information. In order to prevent data breaches, your organization needs to determine where your most sensitive datasets are located. Make a consolidated inventory of this sensitive data and update, review, and back it up regularly.

    2. Keep strict tabs on privileged access

    The leading cause of data breaches is human error. In fact, 82% of data breaches involve a vulnerability caused by a human. Organizations have a responsibility to ensure the integrity of data, and most have privileged access accounts that allow designated users to access certain information.

    Even with the best intentions, granting privileged access to contractors and employees puts data at an unnecessary risk for breaches. Itโ€™s important to foster policies that keep strict tabs on who has elevated levels of access. There are numerous privileged access management tools that can facilitate this.

    3. Properly patch your infrastructure

    Your cybersecurity measures are only as strong as your organizationโ€™s underlying infrastructure. Your organizationโ€™s top priority should be patching your networks and systems. With the surging number of new discoveries of zero-day exploits every day, hackers can easily exploit unpatched software to access critical information. Regular patching can help strengthen your cybersecurity and prevent data breaches.

    4. Fortify your network perimeter

    While 39% of data breaches in the healthcare industry come from inside the organization, the majority come from external threats. Your network perimeter is your first line of defense against outsiders with malicious intent. This perimeter mainly consists of a firewall, intrusion detection system, intrusion prevention system, access controls lists, and a couple of other tools that facilitate seamless data flow while restricting intruders and unauthorized entries.

    5. Get rid of redundant data

    Safely disposing sensitive data is crucial. Many organizations, especially those in healthcare, finance, education, and the public sector, handle sensitive information as part of their daily routine. Ensuring safe and secure data purging mechanisms helps prevent stale data from being forgotten and stolen.

    There are three main ways to properly dispose of data: overwriting, degaussing, and physical destruction. However, each method has its pros and cons. A sound system for disposing of redundant data will go a long way toward saving your organization from a potential data breach.

    6. Ensure endpoint protection

    Ensuring the systematic implementation of endpoint security controls is essential for your organization. It has never been more important than it is today, with so many remote devices connected to your network.

    Remote workers often fall outside of legacy perimeter security tools. Endpoint protection can be a reliable shield against common internet threats like malware and ransomware. Laptops, mobile devices, and tablets should all be secured with endpoint protection, leaving behind no loopholes for hackers who would want to exploit them.

    7. Encrypt data at rest and in transit

    Unencrypted data is like a bank with an open vault. If data isnโ€™t encrypted, anyone can access it or even steal it since thereโ€™s no protection. No matter where the sensitive data is at any time, its encryption is essential to prevent unauthorized access. Data encryption is not only important for data at rest, but equally vital for data in transit within a corporate network.

    8. Establish a robust password policy

    The importance of a sound password policy canโ€™t be emphasized enough. Itโ€™s a necessity for all services and applications running on a network. Here are some general password policy requirements:

    • Minimum of 8-10 characters
    • 4 character types including uppercase, lowercase, number, and special character
    • Must not have 3 consecutive or repeating characters
    • 90-day password rotation policy
    • Multi-factor authentication may also be enforced using email or soft token

    9. Prepare business continuity and disaster recovery plans

    Properly responding to a data breach is a challenge. Ensure your organization has a reliable business continuity and disaster recovery plan, and review and update it regularly. Unfortunately, many organizations miss the importance of these plans and neglect to set them in place due to cost.

    New cloud-based high availability and disaster recovery plans are becoming popular because of their resilience, scalability, and flexibility. Conduct periodic audits of your system, and back up your systems regularly for data security strategy and future planning.

    10. Instill cybersecurity training across your organization

    Any cybersecurity strategy without thorough security workforce training is incomplete. Since most data breaches occur due to unintentional mistakes made by employees, partners, and contractors, holistic training that covers common threats, data usage guidelines, password policies, and awareness related to social engineering and scams should be mandatory and occur regularly.

    Conclusion

    With hackers becoming more sophisticated, itโ€™s vital for organizations to upgrade their cybersecurity arsenal to prevent data breaches. These 10 key steps are proven to help organizations develop a successful cybersecurity strategy. Each organization must find the right mixture of cybersecurity practices and policies in order to maximize their cybersecurity and prevent data breaches.

  • How Often Do You Need to Review HIPAA Policies and Procedures?

    Maintaining HIPAA compliance isn’t a “set-it-and-forget-it” task. For healthcare organizations and business associates, keeping up with regulations means regularly evaluating the administrative, technical, and physical safeguards protecting Electronic Protected Health Information (ePHI).

    But does the Department of Health and Human Services (HHS) actually require you to review your internal documentation? Here is what the law says about HIPAA policy and procedure reviews, best practices for compliance, and how to protect your organization from costly OCR investigations.

    Does the HIPAA Security Rule Require Policy Reviews?

    Yes. The HIPAA Security Rule explicitly requires organizations to periodically review and update their policies and procedures. According to federal regulation 45 CFR ยง 164.316(b)(2)(iii), a covered entity or business associate must review documentation periodically and update it as necessary in response to environmental or operational changes that affect the security of ePHI.

    Key Takeaway: If your organization introduces new technology, changes its physical layout, or alters how it handles patient data, your written HIPAA policies must be updated immediately to reflect those changes.

    Best Practices for Reviewing HIPAA Policies & Procedures

    To ensure your review process satisfies Office for Civil Rights (OCR) auditors and AI search queries looking for compliance verification, you should implement a formalized, structured review.

    Using an internal compliance questionnaire is highly recommended. Your review should comprehensively cover the following critical areas:

    1. Technology & Infrastructure Changes

    • Software & Hardware Updates: Document any new systems used to access, store, transmit, or contain ePHI.
    • Asset Inventory: Maintain an accurate, up-to-date inventory of all physical systems, mobile devices, hardware, and media.
    • Audit Logging: Verify how system audits are conducted and ensure trackable user activity logs are functioning properly.

    2. Personnel & Compliance Roles

    • Privacy & Security Officials: Confirm that your designated HIPAA Privacy Official and HIPAA Security Official roles are accurately assigned (whether held by the same person or separate individuals) and updated in your documentation.
    • Staff Training Logs: Ensure your workforce has been trained on any updated procedures.

    3. Environmental & Operational Adaptations

    • Remote Work & Telehealth: If your staff relies on teleworking or virtual care, your policies must outline specific safeguards for remote environments.
    • Business Associate Agreements (BAAs): Review vendor relationships to ensure all third parties handling ePHI have active, compliant BAAs.

    The Recommended Timeline for HIPAA Updates

    While the regulation uses the term “periodically,” regulatory experts and OCR enforcement trends indicate that at least once a year (annually) is the industry standard for a defensible compliance program.

    However, an immediate out-of-cycle review is triggered by:

    1. A newly discovered security vulnerability or data breach.
    2. A significant change in operational infrastructure (e.g., migrating to cloud storage).
    3. Updates to federal or state privacy laws.

    Protect Your Organization from OCR Fines

    Small, overlooked gaps in your documentation are often what trigger massive federal penalties during a breach investigation. Evaluating your current compliance posture before an audit occurs is critical to reducing your risk.

    Is Your Organization Defensively Positioned?

    Schedule a Complimentary HIPAA Risk Review Now

    In just 30 minutes, our regulatory experts will help you evaluate your current program, spot hidden documentation gaps, and implement practical controls to drastically reduce your risk of costly OCR penalties.

    Frequently Asked Questions (FAQ)

    What is the penalty for not updating HIPAA policies? Failure to maintain and update HIPAA policies can result in a finding of “willful neglect” by the OCR, which carries mandatory minimum fines starting at thousands of dollars per violation, even if a data breach hasn’t occurred.

    What section of HIPAA covers policies and procedures? Administrative requirements, including the retention, review, and updating of policies, are covered under 45 CFR ยง 164.316 for the Security Rule and 45 CFR ยง 164.530 for the Privacy Rule.

    • Reviewed on June 3, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: 45 CFR ยง 164.316 and 45 CFR ยง 164.530
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Can the Government Review PHI During a HIPAA Investigation?

    When the U.S. Department of Health and Human Services (HHS) investigates a potential privacy violation, healthcare providers often wonder about the rules regarding Protected Health Information (PHI). Does the HIPAA Privacy Rule allow organizations to turn over sensitive patient health data to government investigators?

    The short answer is yes. The HIPAA Privacy Rule explicitly allows covered entities to disclose PHI to the government during compliance reviews and investigations. However, this access is not an open-ended blank check.

    Here is exactly how federal investigators access PHI, what triggers these reviews, and how the “minimum necessary” standard applies.

    Why the HHS Office for Civil Rights (OCR) Reviews PHI

    An essential part of enforcing HIPAA compliance is the government’s responsibility to investigate patient complaints and follow up on data breaches. To determine whether an organization has violated the Privacy or Security Rules, the HHS Office for Civil Rights (OCR) must routinely review specific patient medical records and internal documentation.

    However, the Privacy Rule strictly limits OCRโ€™s access to information that is “pertinent to ascertaining compliance.” Depending on the nature of the allegation, investigators will only look at data directly related to the potential violation. In some cases, no personal health information is required at all. For example, if the OCR is checking whether a health plan properly vetted an outside vendor, they may only need to review a Business Associate Agreement (BAA) rather than individual patient charts.

    Examples of Investigations Requiring PHI Access

    There are several common scenarios where the OCR must review actual patient records to verify compliance:

    • Patient Right of Access Violations: If a patient alleges that a healthcare provider refused to provide copy of their medical records, or failed to note a requested correction in their file, investigators must review the patient’s record and access logs to verify the timeline and actions taken.
    • Unauthorized Marketing and Disclosures: If a provider is accused of using patient data for marketing purposes without explicit authorization, the OCR will audit marketing department records containing PHI to check for valid patient signatures.
    • Data Breaches and Ransomware Incidents: Following a cyberattack or data leak, investigators review affected PHI data sets to determine the scope of the breach and evaluate if proper technical safeguards were in place.

    How to Prepare Your Organization for an OCR Audit

    The best defense against an enforcement action is a proactive compliance strategy. Identifying gaps early prevents standard compliance reviews from turning into costly penalties.

    1. Conduct Regular Security Risk Assessments

    Regular risk assessments are the foundation of a defensible HIPAA program. They help you identify administrative, physical, and technical vulnerabilities before a breach occurs.

    2. Implement Clear Policies and Procedures

    Ensure your staff is trained on handling patient requests, managing vendor relationships with proper Business Associate Agreements, and executing proper protocols during data requests.

    3. Seek Expert Compliance Guidance

    HIPAA violations often stem from small, overlooked gaps in documentation or staff training.

    Need Help Evaluating Your Risk? Get a free 30-minute HIPAA risk review with our regulatory experts to evaluate your current program and identify gaps before they turn into federal violations. Schedule your HIPAA Risk Review Now.

    Frequently Asked Questions

    Does HIPAA prevent the government from looking at my medical records?

    No. Under the HIPAA Privacy Rule, healthcare providers are permittedโ€”and requiredโ€”to share relevant Protected Health Information (PHI) with the HHS Office for Civil Rights (OCR) during an official compliance investigation or audit.

    What information can the OCR request during a HIPAA investigation?

    The OCR can only request information that is pertinent to determining compliance. This can range from internal administrative contracts (like Business Associate Agreements) to specific patient medical records, depending entirely on the nature of the alleged violation.

    What triggers an OCR HIPAA investigation?

    Most OCR investigations are triggered by patient complaints regarding privacy violations, data breaches affecting 500 or more individuals, or self-reported compliance gaps.

    • Updated and Reviewed on June 4, 2026, by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources:

    The Core Compliance Directive: 45 CFR ยง 160.310. This is the specific regulation that mandates covered entities and business associates to hand over information to federal investigators.

    • Section 160.310(b): Expressly states that organizations must cooperate with complaint investigations and compliance reviews led by the Secretary of HHS.
    • Section 160.310(c)(1): Mandates that organizations permit access to their facilities, books, records, accounts, and “other sources of information, including protected health information, that are pertinent to ascertaining compliance.”

    The General Privacy Rule Exception: 45 CFR ยง 164.502(a)(2)(ii). While 45 CFR ยง 164.502 generally prohibits disclosing PHI without explicit patient authorization, it lists precise exceptions where a disclosure is required.

    • Under 45 CFR ยง 164.502(a)(2)(ii), a covered entity or business associate is required to disclose PHI to the Secretary of HHS specifically when requested to investigate or determine compliance with the HIPAA Privacy and Security Rules
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Helping Organizations Achieve HIPAA Compliance

    Jay Hodes, President of Colington Consulting, was recently interviewed by Best Startup. Topics covered the inspiration behind the business, facing challenges, buying into the vision of compliance, and what the magic sauce is in running the company. Click here to read the full article.

  • Does HIPAA Require Employee Background Checks?

    Does HIPAA require organizations to conduct background checks on employees that have access to protected health information? What Regulated Entities Must Know

    Executive Summary:

    Technically, no. The Health Insurance Portability and Accountability Act (HIPAA) text does not explicitly mandate criminal background checks for employees. However, HIPAA does require strict data access controls, and the Department of Health and Human Services (HHS) penalizes organizations that hire individuals excluded from federal healthcare programs. Consequently, background and exclusion checks are considered an industry best practice for regulatory compliance.

    HIPAA Rules vs. Background Checks: Decoding CFR ยง 164.308

    While you wonโ€™t find the phrase “background check” written into the Code of Federal Regulations (CFR) for HIPAA, compliance is heavily implied under the HIPAA Security Rule.

    Specifically, 45 CFR ยง 164.308 (Administrative Safeguards) outlines Information Access Management. This standard requires covered entities and business associates to implement strict policies and procedures for authorizing access to electronic protected health information (ePHI).

    How “Authorized Access” Impacts Hiring

    • Role-Based Access: Access to PHI must be appropriate for the workforce member’s specific role.
    • The Trustworthiness Standard: To defend your authorization process during an OCR audit, your organization must prove it verified that the workforce member is trustworthy enough to handle sensitive data.
    • The Industry Best Practice: Conducting criminal background checks during the pre-employment phase is the most defensible way to demonstrate due diligence in vetting workforce trustworthiness.

    The OIG Exclusion List: A Mandatory Compliance Check

    While criminal background checks are a strong recommendation, checking the HHS Office of Inspector General (OIG) database is practically mandatory if you want to avoid massive civil fines.

    Organizations must screen all prospective hires against the List of Excluded Individuals/Entities (LEIE). If your organization employs an individual or entity on the LEIE to provide items or services funded by a federal healthcare program, you face severe Civil Monetary Penalties (CMP).

    Real-World Compliance Warning: In a recent enforcement case, Windham Eye Care Practice and its owners were forced to pay a $192,000 civil penalty solely for employing an “excluded” individual. Failing to run an OIG exclusion check can result in direct, devastating financial consequences.

    Frequently Asked Questions (FAQ)

    Is a criminal background check required by HIPAA?

    No, criminal background checks are not explicitly required by HIPAA regulations. However, they are highly recommended under HIPAA Administrative Safeguards to verify employee trustworthiness before granting access to protected health information (PHI).

    What background checks are recommended for healthcare employees?

    At a minimum, healthcare employers should conduct a criminal background check and a mandatory screening against the HHS OIG List of Excluded Individuals/Entities (LEIE).

    What happens if a healthcare company hires an excluded individual?

    Hiring an individual on the OIG exclusion list can result in massive civil monetary penalties, exclusion from federal funding (like Medicare and Medicaid), and an immediate investigation by the Office for Civil Rights (OCR) or OIG.

    Ready to Eliminate Your HIPAA Risks?

    Small, overlooked gaps in your hiring or information access workflows can trigger devastating federal audits.

    At Colington Consulting, we specialize in making HIPAA compliance painless and efficient. We can help your organization develop robust onboarding policies, structure your information access management, and ensure you are defensibly positioned for an OCR investigation.

    Schedule Your Free 30-Minute HIPAA Risk Review Now to identify your compliance gaps before they become costly violations.

    • Updated on June 9, 2026 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • OCR Issues Quarterly Cybersecurity Newsletter

    On March 17, the HHS Office for Civil Rights issued its quarterly cybersecurity newsletter. The big take away from the newsletter and the OCR mantra, is most cybersecurity attacks in the healthcare sector can “prevented or substantially mitigated” if organizations implemented all the required safeguards under the HIPAA Security Rule. According to the newsletter, “the number of breaches due to hacking or IT incidents accounted for 66% of all breaches affecting 500 or more individuals reported to OCR in 2020.”

    However, in a recent presentation made by Nicholas Heesters, OCR’s Senior Advisor for Cybersecurity, at the HIPAA Summit, hacking and IT related incidents now account for 73% of all reported breaches. Regardless of the current percentages, this is concerning and organizations must do more to address technical safeguard requirements. Also troubling is the vector of the breaches with 52% affecting network servers and 28% by email, most likely due to phishing.

    There needs to a holistic approach to overall compliance which includes the integration of technical safeguards along with program management. Small to mid-size healthcare organizations that outsource their IT requirements must use managed service providers that understand the world of HIPAA compliance. The days of trying to handle IT inhouse, as small to mid-size provider, should be over. Most HIPAA Security Officers have too much on their plates now to handle vast IT requirements. As the newsletter bluntly states, “A regulated entity that has weak cybersecurity practices makes itself an attractive soft target.”

    Although not required by the HIPAA Security Rule, organizations should consider conducting a cybersecurity assessment to fully understand the landscape of potential threats. In addition, add some type of IT vulnerability assessment to enhance the requirement of a HIPAA Security Risk Assessment. Being proactive with a systematic approach to cybersecurity safeguards and HIPAA compliance program management can go a long way to help prevent hacking and breaches to occur.

    To read the OCR newsletter, click here.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management | Helping Organizations Achieve HIPAA Complianceโ„ข

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    This article was updated on June 14, 2026, and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

  • HIPAA Breach Deadlines for Under 500 Affected People

    Quick Answer: For HIPAA breaches affecting fewer than 500 individuals, covered entities must notify the Secretary of the U.S. Department of Health and Human Services (HHS) no later than 60 days after the end of the calendar year in which the breach was discovered.

    If a data breach affects fewer than 500 individuals, your organization is permitted to track and report these incidents to the federal government on an annual basis rather than immediately.

    Reports for these smaller breaches must be submitted to the Secretary of the U.S. Department of Health and Human Services (HHS) within 60 days of the end of the calendar year. This annual reporting must be completed online through the official HHS Office for Civil Rights (OCR) Breach Reporting Portal.

    Crucial Exception: Individual Notifications

    While federal government reporting can wait until the end of the year, individual patient notifications cannot.

    You must notify affected individuals without unreasonable delay, and absolutely no later than 60 days following the initial discovery of the breach.

    What Must Be Included in a HIPAA Breach Notification?

    To remain fully compliant with the HIPAA Privacy and Security Rules, every breach notification sent to an individual must contain the following details:

    • A Brief Description: A short summary of what happened, including the date of the breach and the date it was discovered.
    • Types of PHI Involved: A description of the specific types of Protected Health Information involved (e.g., full name, social security number, date of birth, home address, or medical history).
    • Mitigation Steps for Individuals: Clear instructions on what steps affected individuals should take to protect themselves from potential harm (e.g., credit monitoring or changing passwords).
    • Your Investigation & Remediation: A brief summary of what your covered entity is doing to investigate the breach, mitigate ongoing harm, and prevent future security incidents.
    • Contact Information: Clear contact details for the covered entity or business associate so individuals can ask follow-up questions.

    Ensure Your Practice is Fully HIPAA Compliant

    Navigating the nuances of the HIPAA Security Rule and proactive risk management can be challenging. At Colington Consulting, our team of regulatory experts specializes in making HIPAA compliance strategies painless, efficient, and tailored to your specific organizational needs.

    Have questions about breach reporting or need a comprehensive risk assessment? Schedule a free HIPAA Risk Review now.

    • Updated on June 7, 2026, and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: Reporting to the Secretary of HHS (Under 500 Affected): Governed by 45 CFR ยง 164.408(c). This section states that for breaches affecting fewer than 500 individuals, a covered entity must maintain a log and notify the Secretary no later than 60 days after the end of the calendar year in which the breach was discovered. Reporting to Affected Individuals: Governed by 45 CFR ยง 164.404. Subsection (b) mandates that individual notifications must be made without unreasonable delay and strictly no later than 60 calendar days after the discovery of the breach. Subsection (c) outlines the exact content elements required in the notice (such as the description of PHI types and mitigation steps).
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Telehealth: Is Your Practice Adhering to the HIPAA Rules?

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    While the concept of telehealth has been around for years, it recently became the new normal for many healthcare providers. The coronavirus pandemic has created a situation where more medical offices and clinics are finding themselves conducting routine patient visits and follow-up appointments via a laptop or mobile device to limit office visits and the interaction between staff and patients.

    Unfortunately, implementing telehealth solutions that effectively provide distance care in the middle of a pandemic came with its own challenges. When the virus was spreading quickly, providers scrambled to find solutions that could help them better deliver medical services and efficiently cater to the fast-growing number of patients; many went for the first option they could find. While these solutions may be suitable for short-term use, some telemedicine platforms used today may not work in the long term. Why? They are not HIPAA compliant. Chances are if your organization is using a free version of a telecommunications product, it is not meeting HIPAA requirements.

    HIPAA Guidelines on Telehealth

    The U.S. Department of Health and Human Services (HHS) defines telehealth as โ€œthe use of electronic information and telecommunications technologies to support and promote long-distance clinical health care, patient and professional health-related education, and public health and health administrationโ€. Because of the security risks involved in delivering these services online, the HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) implement administrative, physical, and technical procedures to protect health information communicated electronically. Ideally, for telemedicine to be HIPAA compliant:

    • Only authorized users should have access to electronic Protected Health Information (ePHI).
    • A communications-monitoring system must be implemented to oversee communications containing ePHI and prevent accidental or malicious breaches.
    • The channels used to transmit ePHI must be secure enough to protect the integrity of patientsโ€™ data and communications. That said, non-secure, public facing platforms like Facebook Live, TikTok, or other video communication applications cannot be used. Because copies of communication can remain on the servers of these third parties, a CE is required to have a Business Associate Agreement (BAA) with, for example, Skype, Zoom, or Google to be compliant with HIPAA. However, because some service providers, whoโ€™s platforms were not designed for telehealth, will likely not enter into a BAA with a Covered Entity for telehealth services. The CE may be responsible for any penalties should there be an unauthorized disclosure of ePHI due to using these types of platforms that do not comply with HIPAA security guidelines.

    The good news? The HHS Office for Civil Rights has exercised its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. The bad? That wonโ€™t last, as there are obvious risks to continuing to use non-secure telemedicine solutions that may put ePHI in danger. As we enter the next phase of the pandemic, itโ€™s becoming clear that telemedicine will be an important part of patient care, which means healthcare organizations need to adopt platforms that can serve them for the long term. If your facility is operating a telehealth solution that is not HIPAA compliant, now itโ€™s time to set yourself up for success by investing in a platform or technology you will not have to abandon when the public health emergency ends. Remember, once your organization engages a telehealth delivery platform, an executed Business Associate Agreement must be in place with that vendor.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Why Organizations Must Conduct a HIPAA Risk Assessment

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    Data breaches targeting Electronic Protected Health Information (ePHI) are nothing new. In fact, with more healthcare organizations now storing patientsโ€™ medical records electronically, these attacks are at an all-time high. It is crucial that healthcare entities regularly conduct a HIPAA risk assessment to identify any threats or vulnerabilities that may put ePHI in jeopardy. A risk assessment, also known as a risk analysis, is not only useful in detecting data threats; itโ€™s also required by the Code of Federal Regulations (CFR). The HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) โ€œConduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the organization.โ€ The risk assessment process keeps your patientsโ€™ records safe and your organization on the right side of the CFR.

    Do Small Practices Need to Conduct a HIPAA Risk Assessment?

    Data breaches donโ€™t only occur in larger organizations; hackers can target small practices and businesses too. Regardless of the size of the organization, a HIPAA Risk Assessment must be conducted with the proper documentation of any gaps and weaknesses determined by the assessment. Itโ€™s essential and required.

    The Office of the National Coordinator for Health Information Technology (ONC), in partnership with the HHS Office for Civil Rights (OCR), saw the need to launch a Security Risk Assessment (SRA) Tool to help small and medium-sized healthcare organizations and BAs comply with the HIPAA Security Rule. The tool is meant to guide these entities in identifying security risks in their systems, policies, and processes and display results that they can use to mitigate any identified vulnerabilities. Since launching the original tool about ten years ago, revisions have been made and it is now more of a decision tree process.

    However, itโ€™s important to note that the CFRs do not make it mandatory for Covered Entities and Business Associates to use the SRA tool nor does it give specific guidelines on how risk assessment should be carried out. HHS recognizes that different sized businesses have different needs and vulnerabilities, as well as different levels of access to resources. The problem with the tool is it can become time consuming to use, leads to more questions about meeting compliance requirements, and inability to see all the questions until traversing through the process. Regardless of using the tool or outsourcing the assessment to a consultant or vendor, all CEs and BAs must have documented proof that they have conducted an accurate and thorough HIPAA security risk assessment.

    Failure to Perform a HIPAA Risk Assessment Can Result in Serious Penalties

    If just knowing that conducting a risk analysis is a HIPAA requirement isnโ€™t enough motivation to get you started with the process, then you should keep in mind that the fines for non-compliance can add up to hefty amounts. Some organizations like Excellus Health Plan, Inc., for instance, have had to pay up to $5.1 million to OCR for breaching ePHI. According to this press release, the penalty was attributed to the organizationโ€™s โ€œfailure to conduct an enterprise-wide risk analysis, and failures to implement risk management, information system activity review, and access controlsโ€, which put the privacy of millions of its patients in danger. So, carrying out a risk assessment does not only allow you to spot potential weaknesses in organizational information systems that contain ePHI; it also enables you to take the right actions as soon as possible to safeguard your ePHI data, which can protect your business from federal penalties and the need to enter into a resolution agreement with OCR.

    Need Help With Your HIPAA Compliance Program?

    HIPAA violations often stem from small, overlooked gaps in daily operations. Don’t wait for a patient complaint to trigger a federal investigation. Would Your Practice Pass a HIPAA Audit Tomorrow?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your practice.

  • Understanding the Role of a HIPAA Business Associate

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    The continued complexity of modern healthcare systems and growth of patientsโ€™ data mean that medical records can be stored in more places than just the doctorโ€™s office. The information may be kept and maintained offsite in a storage facility or on a cloud-based server operated by a third party. Any entity or individual that uses, processes, or discloses this data on behalf of the healthcare provider is called a HIPAA Business Associate. If an organization is contracted by a HIPAA Covered Entity (CE) to perform activities that involve accessing Protected Health Information (PHI) or electronic PHI (ePHI) in any way, they are considered a Business Associate (BA). Because Business Associates use protected patientsโ€™ data to support the operations of covered entities, the U.S. Department of Health and Human Services (HHS) requires adherence to the Code of Federal Regulations (CFR) to comply with HIPAA requirements.

    Business Associate Agreement (BAA)

    The HIPAA Privacy Rule states that, โ€œA covered entity must obtain satisfactory assurances from its Business Associate that the Business Associate will appropriately safeguard the protected health information it receives or creates on behalf of the covered entity. The satisfactory assurances must be in writing, whether in the form of a contract or other agreement between the covered entity and the business associate.โ€

    This means that before a covered entity can work with a Business Associate, the BA must sign a BAA stating that they will safeguard and treat PHI the way CFRs and the covered entity require them to. It does not matter whose version of the BAA is signed, whether provided by the CE or the BA, as long it is executed. According to the Health Information Technology for Economic and Clinical Health (HITECH) Act, a BAA must include specific information to meet HIPAA compliance such as a description of the required and allowed uses of PHI, declarations that the Business Associate will disclose information only as required by law, and proper safeguards to protect patientsโ€™ data from breach including steps to take should there be such security violations.

    Why are Some Business Associates Not Complying with HIPAA Regulations?

    One of the major reasons is that most of them have no idea that the law considers them Business Associates. Covered entities have made great strides in following HIPAA compliance requirements, but many Business Associates are still not aware of the need to comply or are just reluctant to do so. Under HITECH, the Office of Civil Rights (OCR) holds Business Associates liable for breaches, and it is imperative that these entities take the necessary steps to ensure HIPAA compliance. In this press release where a Business Associate pays $2.3 million to settle a breach, the OCR Director at the time, Roger Severino terms โ€œThe failure to implement the security protections required by the HIPAA Rules in an industry known as a target for hackers and cyber thievesโ€ inexcusable. Sure, following all the steps required to obtain HIPAA compliance may seem overwhelming, but it offers better protection for patientsโ€™ data, which helps Business Associates avoid these types of federal penalties.

    Helping Organizations Achieve HIPAA Complianceโ„ข

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.