Author: Colington Consulting

  • OCR Provides Ransomware Resources

    On September 21, the HHS Office for Civil Rights pushed out through their Listserv, a list of information to ensure that “HIPAA regulated entities are aware of the resources available to assist in preventing, detecting, and mitigating breaches of unsecured protected health information caused by hacking and ransomware.” Depending on the size of the organization and internal resources, some may handle theses critical issues in house. If this support is contracted to a managed service provider, your organization may want to make this information available to them.

    Healthcare data is a prime target for bad actor. Organizations must be pro-active in fighting cybersecurity threats, whether handled in house or contracted out as a service. The HIPAA regulations require a contingency plan be in place, regardless of the size of the organization in case ePHI data is compromised.

    Here is the list of those resources:

    HHS Health Sector Cybersecurity Coordination Center Threat Briefs:

    ยท https://www.hhs.gov/about/agencies/asa/ocio/hc3/products/index.html#sector-alerts

    HHS Resources on Section 405(d) of the Cybersecurity Act of 2015:

    OCR Guidance:

    CISA Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches:

    CISA Ransomware Guide:

    FBI Ransomware Resources:

    OCR Cybersecurity Newsletters:

    REMINDER: A ransomware attack may result in a breach of unsecured protected health information that triggers reporting requirements under the HIPAA Breach Notification Rule. HIPAA covered entities and business associates should review OCRโ€™s ransomware guidance at https://www.hhs.gov/sites/default/files/RansomwareFactSheet.pdffor information regarding potential breach notification obligations following a ransomware attack.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • OCR Settles Multiple Complaints Regarding Patient Right of Access

    by Jay Hodes โ€“ President, Colington Consulting

    In March and April of this year, the HHS Office for Civil Rights (OCR) announced its enforcement discretion when it came to some provisions within the HIPAA Security and Privacy Rules due to COVID-19. These notices were limited and narrow in scope. The March notice stated OCR would โ€œnot impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency.โ€ The April notice specified OCR โ€œwill not impose penalties for violations of certain provisions of the HIPAA Privacy Rule against health care providers or their business associates for the good faith uses and disclosures of protected health information (PHI) by business associates for public health and health oversight activities during the COVID-19 nationwide public health emergency.โ€

    It is my belief some in the healthcare sector, especially in the small to mid-size provider community, interpreted these notices to mean OCR was not going to enforce any of the HIPAA rules. That misunderstanding of enforcement discretion was enough for some organizations to put their HIPAA compliance programs on the back burner. The operational mindset, then and in some cases now, was there was not a need to perform required Security Risk Assessments, review or create HIPAA policies and procedures, or adhere to many of the obligations in the HIPAA Privacy Rule.

    Let me be clear; the rules are still the rules. Healthcare organizations and business associates must still comply with the HIPAA requirements. As the notices indicate, there still must be adherence to the good faith provision. That means regardless of any enforcement discretion, organizations must still be able to demonstrate compliance with the rules and show the effort to do so.

    As proof enforcement actions continue, this week OCR announced five settlements for violations under the HIPAA Privacy Rule that pertain to individualsโ€™ rights to access their medical records. Although not earth-shattering monetary settlement amounts that ranged from $3,500 to $70,000, these cases serve as another wake-up call to providers. There is just as much culpability under the Privacy Rule as the Security Rule.

    The two types of infractions in these recent cases involve (1) refusals by healthcare providers to give patients access and copies of their medical records and (2) when requests for medical records were made by personal representatives seeking access to those records for family members were denied.

    The OCR listserv email regarding these cases states โ€œOCR’s enforcement actions are designed to send a message to the health care industry about the importance and necessity of compliance with the HIPAA Rules.โ€ Message sending indeed as OCRโ€™s right of access initiative continues. OCR Director Roger Severino stated in the email “Today’s announcement is about empowering patients and holding health care providers accountable for failing to take their HIPAA obligations seriously enough.”

    Has your organization ever conducted a Privacy Assessment to see if requirements of the HIPAA Privacy Rule are being met and understood? This type of assessment is part of our overall assessment process for both Covered Entities and Business Associates.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Office for Civil Rights – Guidance on HIPAA IT Asset Inventories

    On August 25, 2020, OCR as part of its quarterly cybersecurity newsletter, provided outstanding guidance regarding HIPAA and IT Asset Inventories. As part of the risk assessment process at Colington Consulting, this is a critical area we address with all of our clients. We want to ensure there is a detailed asset inventory of all software, hardware, network or computing component that creates, receives, maintains, or transmits electronic protected health information (ePHI). Sometimes we find this information scattered into various documents or not centrally maintained. Our goal is to make sure there is a comprehensive list for software and hardware for these vital components throughout an organization.

    Here are some helpful sections from the newsletter:

    “The HIPAA Security Rule requires covered entities and business associates to ensure the confidentiality, integrity, and availability of all electronic protected health information (ePHI) that it creates, receives, maintains, or transmits. Conducting a risk analysis, which is an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI held by an organization, is not only a Security Rule requirement, but also is fundamental to identifying and implementing safeguards that comply with and carry out the Security Rule standards and implementation specifications. However, despite this long-standing HIPAA requirement, OCR investigations frequently find that organizations lack sufficient understanding of where all of the ePHI entrusted to their care is located. Although the Security Rule does not require it, creating and maintaining an up-to-date, information technology (IT) asset inventory could be a useful tool in assisting in the development of a comprehensive, enterprise-wide risk analysis, to help organizations understand all of the places that ePHI may be stored within their environment, and improve their HIPAA Security Rule compliance.”

    How to Create an IT Asset Inventory

    “An enterprise-wide IT asset inventory is a comprehensive listing of an organizationโ€™s IT assets with corresponding descriptive information, such as data regarding identification of the asset (e.g., vendor, asset type, asset name/number), version of the asset (e.g., application or OS version), and asset assignment (e.g., person accountable for the asset, location of the asset). When creating an IT asset inventory, organizations can include:

    • Hardware assets that comprise physical elements, including electronic devices and media, which make up an organizationโ€™s networks and systems. This can include mobile devices, servers, peripherals, workstations, removable media, firewalls, and routers.
    • Software assets that are programs and applications that run on an organizationโ€™s electronic devices. Well-known software assets include anti-malware tools, operating systems, databases, email, administrative and financial records systems, and electronic medical/health record systems. Though lesser known,there are other programs important to IT operations and security such as backup solutions, virtual machine managers/hypervisors, and other administrative tools that should be included in an organizationโ€™s inventory.
    • Data assets that include ePHI that an organization creates, receives, maintains, or transmits on its network, electronic devices, and media.”

    As part of this inventory process, we always recommend organizations have an accurate and up-to-date list of all vendors in which you have signed Business Associate Agreements in place with. You may also want to include a list of all types of physical, hard copy medical records, billing records, or any other paper documentation containing protected health information.

    All these asset inventory lists must be reviewed and confirmed during the risk assessment process.

    Not One and Done

    This should not be considered a “one and done” process. It is important to remember whoever is assigned this task, whether it is an individual or a department, that is an ongoing process. Lists must be updated as new equipment or software is added and legacy systems or devices are removed.

    Take Action Now

    If HIPAA compliance assistance is needed for your organization, we specialize in putting compliance programs in place or assessing your current program. We provide a full range of services that include conducting the required HIPAA Risk Assessment, ensuring critical asset inventory lists are in place, writing and customizing a HIPAA Risk Management Plan (HIPAA Policies and Procedures) for your organization, and providing your entire staff annual required HIPAA Security Awareness & Privacy Training through our web-based platform. Our fees are based on what specifically your organization will need to meet regulatory requirements and reasonably priced to accommodate any budget.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Best Practices for Teleworking & Telehealth Involving PHI/ePHI

    by Jay Hodes, President – Colington Consulting

    With the federal public health emergency in place as of January 31 to address COVID-19, many healthcare organizations have implemented teleworking options for their workforce. Providers are also using telehealth services to interact with their patients. For some organizations, this is a whole new world. If not already in place, organizations needed to implement policies and procedures to address these critical operational topics.

    The HHS Office for Civil Rights (OCR) has issued a number of guidance documents pertaining to this emergency. Here are some excerpts I feel are important:

    February 2020: โ€œIn an emergency situation, covered entities must continue to implement reasonable safeguards to protect patient information against intentional or unintentional impermissible uses and disclosures. Further, covered entities (and their business associates) must apply the administrative, physical, and technical safeguards of the HIPAA Security Rule to electronic protected health information.โ€

    As further stated in the guidance regarding PHI:

    โ€œThe HIPAA Privacy Rule protects the privacy of patientsโ€™ health information (protected health information) but is balanced to ensure that appropriate uses and disclosures of the information still may be made when necessary to treat a patient, to protect the nationโ€™s public health, and for other critical purposes.โ€

    March 2020: โ€œWhile the HIPAA Privacy Rule is not suspended during a public health or other emergency, the Secretary of HHS may waive certain provisions of the Privacy Rule under the Project Bioshield Act of 2004 (PL 108-276) and section 1135(b)(7) of the Social Security Act.โ€

    Although OCR has indicated some discretion with its enforcement authority and waiving some requirements, the HIPAA Privacy and Security Rules are still in place with very limited exceptions.

    With the OCR guidance clearly stated, there must be an operational balance and the need to apply a commonsense approach to minimize the risks for unauthorized disclosures in order for your workforce to be able to perform their jobs while teleworking and during telehealth sessions.

    Here are some best practices to consider implementing as part of your organizationโ€™s policies to address teleworking and telehealth sessions:

    • Staff should never leave any documents containing PHI in a vehicle overnight. Even if the vehicle is locked or the documents can be secured in a trunk, all PHI must be removed. No exceptions!
    • When working from home, the staff should follow the same protocols as if in an office, practice location, or providing services face-to-face. This means following the Minimum Necessary Requirement. If working from home and there are others in the house, such as family members or roommates, only have patient conversations where others cannot hear that conversation. Staff must try to make those conversations as private as possible. This includes VTC telehealth sessions and telephone calls.
    • Always keep documents containing PHI as secure as possible so others may not see them when performing work related duties.
    • Avoid having conversations with those in the house regarding any patient.
    • Never allow family members, roommates, or others in the house to access/use any organization issued devices including cell phones and laptops, unless personal use is approved by the organization.
    • If using a personal computer for organization business, make sure others in the home do not access while performing work related duties. If a computer needs to be utilized for non-organization business during the workday or shift, always log off from organization access or VPN.
    • If staff needs to leave an area in the home that is set up as a workstation to take a break, grab a coffee, or handle non-organization issues, always make sure to lock the computer and secure documents. Even for a few minutes.
    • At the end of the business day or shift, staff should log off from any computer they are using and properly secure any documents containing PHI.
    • If HIPAA compliant bags or containers are provided by the organization, then use those to secure the documents when not needed.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Additional Resources for Telehealth:

    OCR – FAQs on Telehealth and HIPAA during the COVID-19 nationwide public health emergency

    National Consortium of Telehealth Resource Centers

    The National Counsel – Best Practices for Telehealth During COVID-19 Public Health Emergency

    American Psychiatric Association – Best Practices in Videoconferencing-Based Telemental Health

    SAMHSA Telehealth Start-Up and Resource Guide

  • 6 More HIPAA Breaches Reported

    With healthcare attention clearly focused on combating the coronavirus, there were six more data breaches that occurred within a few days as the year began. The breaches reported by healthcare organizations, likely resulting in the unauthorized releases of patient data for at least 8,701 patients. As the sheer number of data breaches continues to rise, so too does your responsibility to protect the people who rely on your services. What happened in these latest occurrences, and what steps should you take to fulfil your obligation to prevent it from happening within your own organization?

    Kaiser Permanente is breached once again.

    Kaiser Permanente already had 4 data breaches by the time reports came out back in 2014. Then, in 2018, at least two more were reported. And then again in October of 2019. Now the latest breach occurred when Kaiser Permanente recently discovered letters have accidentally been mailed to patientsโ€™ former addresses. The HHSโ€™ Office for Civil Rights (OCR) breach portal indicates up to 500 patients may have been affected in this one. (This is not counting their prior breaches.)

    Riverview Health also experienced a mailing error.

    Much like Kaiser Permanenteโ€™s latest breach, this one also happened due to a mailing error. This time, however, the mix up exposed the names of 2,610 patients. Fortunately, no financial information – such as credit or debit card numbers – or medical data was exposed. However, the methods of patient notification used by Riverview are currently under review as a result of this incident.

    Harris Health System lost PHI during transport.

    On Friday, February 28th, Harris Health System announced that it was notifying 2,298 patients of a privacy breach that happened on December 30, 2019. Two envelopes that contained 143 pages of protected health information (PHI) were lost in transport to Ben Taub Hospital, which were being sent there for scanning and archiving in Harris Health’s electronic medical record system. The envelopes are thought to contain information on patients seen at Gulfgate Health Center from December 9, 2019 and December 27, 2019.

    Community Mental Health Council mental health records were found dumped in an alley.

    In 2012, the Community Mental Health Council was forced to permanently close its clinics due to lack of funding. Long after the fact, however, hundreds of medical records from CMHCl have been found abandoned in an alley in West Englewood, Chicago. The documents included full names, addresses, Social Security numbers, diagnosis information, medical records, and more. City officials are currently trying to determine who was responsible for dumping the records.

    Armada Physical Therapy had a server carried off.

    Data breaches through hacking, phishing scams, and mailing errors are nothing new. But what makes the breach of Armada Physical Therapy stand out is that this time around, someone actually broke into the building and stole an entire server. At the time of writing, the investigation is still ongoing, and the stolen server has not yet been recovered. The server holds intake forms that contain names, addresses, telephone numbers, email addresses, insurance numbers, and Social Security numbers for around 500 patients.

    Elk Ridge Dentistry had a hard drive stolen.

    Unlike the incident with Armada, one would imagine that stealing a portable hard drive is at least a bit easier than making off with an entire server. At least one such hard drive was stolen from Elk Ridge Dentistry. The hard drive in question was used to store backups, and was actually among several items taken from the practice. Much like Armadaโ€™s server, the hard drive has not yet been recovered. To make matters worse, it contained the records of 2,793 patients, which included names, addresses, dates of birth, healthcare information, X-ray images, Social Security numbers, treatment consent forms, referral letters, and emails.

    Take Action Now

    So many different occurrences all happening within such a short time should give anyone cause for serious alarm. The numbers are against you, and we here at Colington Consulting donโ€™t want you to become yet another statistic. Even as COVID-19 events have impacted healthcare organizations, we are still able to provide the majority of our services remotely. We are available and can set up an initial consultation to talk about our services and how we can assist your organization. Call us today at 844.740.7100 and find out how we can help you protect your patients from incidents like these.

  • OCR Provides Guidance on Telehealth During the COVID-19 Emergency

    Yesterday, the HHS Office for Civil Rights (OCR), announced it will exercise its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. This notification is effective immediately.

    Here is the complete transcript of the OCR notification:

    Notification of Enforcement Discretion for Telehealth Remote Communications during the COVID-19 Nationwide Public Health Emergency

    We are empowering medical providers to serve patients wherever they are during this national public health emergency. We are especially concerned about reaching those most at risk, including older persons and persons with disabilities. โ€“ Roger Severino, OCR Director.

    The Office for Civil Rights (OCR) at the Department of Health and Human Services (HHS) is responsible for enforcing certain regulations issued under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act, to protect the privacy and security of protected health information, namely the HIPAA Privacy, Security and Breach Notification Rules (the HIPAA Rules).

    During the COVID-19 national emergency, which also constitutes a nationwide public health emergency, covered health care providers subject to the HIPAA Rules may seek to communicate with patients, and provide telehealth services, through remote communications technologies. Some of these technologies, and the manner in which they are used by HIPAA covered health care providers, may not fully comply with the requirements of the HIPAA Rules.

    OCR will exercise its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. This notification is effective immediately.

    A covered health care provider that wants to use audio or video communication technology to provide telehealth to patients during the COVID-19 nationwide public health emergency can use any non-public facing remote communication product that is available to communicate with patients. OCR is exercising its enforcement discretion to not impose penalties for noncompliance with the HIPAA Rules in connection with the good faith provision of telehealth using such non-public facing audio or video communication products during the COVID-19 nationwide public health emergency. This exercise of discretion applies to telehealth provided for any reason, regardless of whether the telehealth service is related to the diagnosis and treatment of health conditions related to COVID-19.

    For example, a covered health care provider in the exercise of their professional judgement may request to examine a patient exhibiting COVID- 19 symptoms, using a video chat application connecting the providerโ€™s or patientโ€™s phone or desktop computer in order to assess a greater number of patients while limiting the risk of infection of other persons who would be exposed from an in-person consultation. Likewise, a covered health care provider may provide similar telehealth services in the exercise of their professional judgment to assess or treat any other medical condition, even if not related to COVID-19, such as a sprained ankle, dental consultation or psychological evaluation, or other conditions.

    Under this Notice, covered health care providers may use popular applications that allow for video chats, including Apple FaceTime, Facebook Messenger video chat, Google Hangouts video, or Skype, to provide telehealth without risk that OCR might seek to impose a penalty for noncompliance with the HIPAA Rules related to the good faith provision of telehealth during the COVID-19 nationwide public health emergency. Providers are encouraged to notify patients that these third-party applications potentially introduce privacy risks, and providers should enable all available encryption and privacy modes when using such applications.

    Under this Notice, however, Facebook Live, Twitch, TikTok, and similar video communication applications are public facing, and should not be used in the provision of telehealth by covered health care providers.

    Covered health care providers that seek additional privacy protections for telehealth while using video communication products should provide such services through technology vendors that are HIPAA compliant and will enter into HIPAA business associate agreements (BAAs) in connection with the provision of their video communication products. The list below includes some vendors that represent that they provide HIPAA-compliant video communication products and that they will enter into a HIPAA BAA.

    • Skype for Business
    • Updox
    • VSee
    • Zoom for Healthcare
    • Doxy.me
    • Google G Suite Hangouts Meet

    Note: OCR has not reviewed the BAAs offered by these vendors, and this list does not constitute an endorsement, certification, or recommendation of specific technology, software, applications, or products. There may be other technology vendors that offer HIPAA-compliant video communication products that will enter into a HIPAA BAA with a covered entity. Further, OCR does not endorse any of the applications that allow for video chats listed above.

    Under this Notice, however, OCR will not impose penalties against covered health care providers for the lack of a BAA with video communication vendors or any other noncompliance with the HIPAA Rules that relates to the good faith provision of telehealth services during the COVID-19 nationwide public health emergency.

    OCR has published a bulletin advising covered entities of further flexibilities available to them as well as obligations that remain in effect under HIPAA as they respond to crises or emergencies at https://www.hhs.gov/sites/default/files/february-2020-hipaa-and-novel-coronavirus.pdf – PDF.

    Guidance on BAAs, including sample BAA provisions, is available at https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html.

    Additional information about HIPAA Security Rule safeguards is available at https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html.

    HealthIT.gov has technical assistance on telehealth at https://www.healthit.gov/telehealth.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • How to Avoid a $100,000 HIPAA Settlement

    By Jay Hodes, President โ€“ Colington Consulting

    Question: How can an organization avoid a large HIPAA settlement with the HHS Office for Civil Rights (OCR)?

    Up to this point, the OCR has settled HIPAA violation cases with predominantly larger healthcare organizations. However, OCRโ€™s enforcement priority and direction has changed and all healthcare providers, regardless of size, must be on guard for the โ€œmessage sending casesโ€ on which OCR is currently focusing.

    As a case in point, on the first day of the recent National HIPAA Summit held in Arlington, Virginia, OCR announced a $100,000 settlement for a HIPAA violation case involving the practice of Steven A. Porter, M.D., a gastroenterological services provider and solo practitioner. This โ€œmessage sendingโ€ was twofold: 1) Serena Mosley-Day, Senior Advisor for HIPAA Compliance and Enforcement for OCR, provided a presentation emphasizing that small providers are not immune to OCR scrutiny and must meet the same requirements under HIPAA as do larger healthcare organizations; and 2) Announcing the settlement at a Summit where attendees included attorneys, Chief Compliance Officers, HIPAA Security and Privacy Officials, IT and cybersecurity experts was timed for maximum impact.

    According to the HIPAA Settlementโ€™s press release, Dr. Porter โ€œfiled a breach report with OCR related to a dispute with a business associate. OCRโ€™s investigation determined that Dr. Porter had never conducted a risk analysis at the time of the breach report, and despite significant technical assistance throughout the investigation, had failed to complete an accurate and thorough risk analysis after the breach and failed to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.โ€

    OCR Director Roger Severinoโ€™s comments in the press release are especially noteworthy. He states that โ€œAll health care providers, large and small, need to take their HIPAA obligations seriously,โ€ and โ€œthe failure to implement basic HIPAA requirements, such as an accurate and thorough risk analysis and risk management plan, continues to be an unacceptable and disturbing trend within the health care industry.โ€

    OCR has previously said that 95% of reported breaches are resolved with technical guidance. The key to avoiding a costlier outcome is to demonstrate to OCR that your organization has a HIPAA compliance plan in place and to cooperate with the OCR breach investigation.

    Answer: To reduce the risk of penalty or settlement or the cost of mitigating a breach, an organization MUST implement and maintain a HIPAA compliance program as follows:

    • Develop and implement policies and procedures to address all the HIPAA Security Standards and Implementation Specifications.
    • Prepare a HIPAA Risk Management Plan that includes policies and procedures, asset inventories, HIPAA-related forms and reports, a facility security plan, and a documented contingency plan.
    • Conduct he required HIPAA Security Risk Assessment.
    • Provide HIPAA Security Awareness Training to the entire workforce.
    • Assign HIPAA Security and Privacy Officer(s) to manage a HIPAA compliance program. Regardless of size, an organization must designate a workforce member(s) to handle these required responsibilities.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • The State of HIPAA Compliance in 2019 โ€“ Sound the Alarm Bells

    By Jay Hodes, President โ€“ Colington Consulting

    Recently, Buck, โ€œan integrated HR and benefits consulting, technology, and administration services providerโ€ based in New York, produced a 2019 HIPAA Readiness Survey. After reading the Survey, I was not surprised by the results, for its message is loud and clear: It is time to sound the alarm bells.

    In my mission to help organizations achieve HIPAA compliance, I know where organizations typically struggle in complying with HIPAA regulations. Several of the Surveyโ€™s findings drive home that point:

    • 42% of survey participants did not know when a risk/threat analysis was last conducted, or they last conducted one more than five years ago.
    • 33% of survey respondents either have not inventoried their business associates or did not know if they had done so; 16% did not have current business associate agreements or did not know if they had them.
    • 35% indicated they last offered HIPAA training between one and five years ago, 13% provide training only during onboarding, and 10% did not know when HIPAA training was last provided.

    The Survey states that โ€œstrong governance is essential to protecting informationโ€ and โ€œunderstanding the rules and complying with them in a way that protects your organization is the best way to prevent a breach and the only way to emerge successfully from a HIPAA audit.โ€

    Governance, Risk, and Compliance (GRC) and Beyond

    I recently had lunch with a GRC expert who pointed out that organizations are considered โ€œnegligentโ€ if they disregard or plead ignorance of HIPAA compliance requirements and other industry-wide regulatory controls and standards. The HHS Office for Civil Rights continues an aggressive campaign of seeking civil monetary penalties from organizations for HIPAA violations. In addition, these same negligent organizations expose themselves to class action lawsuits from individuals seeking damages from breaches of personally identifiable information. In summary, HIPAA compliance should be driven by costโ€”the costs incurred from both government penalties as well as the time and money spent on re-mediating the damage caused by data breaches.

    Sound the Alarm?

    Rather than sound the alarm after the fact, organizations should focus their urgency on prevention and corrective measures before a violation or data breach. GRC is not meant to be a one-and-done approach to punch a regulatory ticket, but rather a systematic process to deal with risk management, including conducting audits and assessments; reviewing the results; and implementing the changes necessary to mitigate risk. This process will take effort, buy-in, and cooperation from all organizational levels, especially from the leadership team.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Coronavirus and HIPAA – An Announcement from HHS

    In light of the recent Novel Coronavirus outbreak, the U.S. Department of Health and Human Services (HHS) has issued a reminder for HIPAA adherence pertaining to the ways that patient information can be shared during outbreaks of infectious disease and other emergency situations such as this one.

    According to the Office for Civil Rights, HIPAA covered entities may disclose, without patient authorization, protected health information (PHI) about the patient as necessary to perform treatment. How far does this leeway extend and how will privacy be protected during outbreaks? Letโ€™s take a closer look.

    HIPAA applies only to covered entities and business associates

    According to HHS, by law the HIPAA Privacy Rule applies only to covered entities โ€“ โ€œhealth plans, health care clearinghouses, and certain health care providers.โ€ At least this much has not changed. Normally, individuals, organizations and agencies that meet the definition of a covered entity under HIPAA would have to comply with the requirements to protect the privacy and security of health information and must provide individuals with certain rights with respect to their health information.

    However, โ€œtreatmentโ€ in these cases can include the coordination or management of healthcare and related services by one or more providers, which could also include consultations between providers as well as the referral of patients.

    Employees may not access or disclose patient records for an unauthorized purpose

    This much has not changed either. Under HIPAA, employees may only access or disclose patient records when specifically authorized to do so as part of their job, or when required to do so under law. Employees are not allowed to look up a patientโ€™s medical record to see if it mentions anything about coronavirus, no matter how strong that temptation may be.

    Information CAN be shared with friends and family of the coronavirus patient

    Family members, friends, and any individual involved in the care of the patient can be notified about the patientโ€™s condition so long as verbal permission has been obtained, or that it can be reasonably inferred that the patient does not object. If a patient is incapacitated, then professional judgement should be used as to whether the sharing of information is in the patientโ€™s best interest.

    Patient data may be shared to protect public health

    Providing specific information about an identifiable patient to the media or public at large is not permitted. However, if there is serious or imminent threat to the health and safety of another person or to the public, necessary information may be shared in order to protect those who would be affected. It should be noted that even this must be restricted. In general, the information thatโ€™s shared should be as minimal as possible.

    When outbreaks like these occur, itโ€™s easy for the public to begin to panic. From there itโ€™s a slippery slope, as rules and regulations can become blurred amidst the chaos. Thatโ€™s why when incidents like these do happen, itโ€™s more important than ever to have a clear set of guidelines to follow. And itโ€™s even more important to make sure youโ€™re following them correctly. Do not allow public panic to sway you from civic responsibility and the law.

    Take Action Now

    For more information on determining when and how information should be disclosed in the event of an emergency such as coronavirus and other similar outbreaks, HHS has published an Emergency Preparedness Decision Tool which can be found here.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Important Notice Regarding Individualsโ€™ Right of Access to Health

    On January 28, the HHS Office for Civil Rights issued an important notice regarding an individualsโ€™ right of access to health records and more specifically, when a request is made to transmit medical records to a third party.

    Here is the full transcript of the notice:

    On January 25, 2013, HHS published a final rule entitled โ€œModifications to the HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health Act, and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules.โ€ (2013 Omnibus Rule). A portion of that rule was challenged in federal court, specifically provisions within 45 C.F.R. ยง164.524, that cover an individualโ€™s access to protected health information. On January 23, 2020, a federal court vacated the โ€œthird-party directiveโ€ within the individual right of access โ€œinsofar as it expands the HITECH Actโ€™s third-party directive beyond requests for a copy of an electronic health record with respect to [protected health information] of an individual . . . in an electronic format.โ€ Additionally, the fee limitation set forth at 45 C.F.R. ยง 164.524(c)(4) will apply only to an individualโ€™s request for access to their own records, and does not apply to an individualโ€™s request to transmit records to a third party.

    The right of individuals to access their own records and the fee limitations that apply when exercising this right are undisturbed and remain in effect. OCR will continue to enforce the right of access provisions in 45 C.F.R. ยง 164.524 that are not restricted by the court order. A copy of the court order in Ciox Health, LLC v. Azar, et al., No. 18-cv-0040 (D.D.C. January 23, 2020), may be found at https://ecf.dcd.uscourts.gov/cgi-bin/show_public_doc?2018cv0040-51.

    What Healthcare Providers Should Know

    The HIPAA Privacy Rule permits a covered entity to impose a reasonable, cost-based fee to provide the individual (or the individualโ€™s personal representative) with a copy of the individualโ€™s PHI, or to direct the copy to a designated third party. The fee may include only the cost of certain labor, supplies, and postage:

    1. Labor for copying the PHI requested by the individual, whether in paper or electronic form.ย  Labor for copyingย includes onlyย labor for creating and delivering the electronic or paper copy in the form and format requested or agreed upon by the individual, once the PHI that is responsive to the request has been identified, retrieved or collected, compiled and/or collated, and is ready to be copied.ย  Labor for copyingย does not includeย costs associated with reviewing the request for access; or searching for and retrieving the PHI, which includes locating and reviewing the PHI in the medical or other record, and segregating or otherwise preparing the PHI that is responsive to the request for copying.
    2. Supplies for creating the paper copy (e.g.,ย  paper, toner) or electronic media (e.g., CD or USB drive)ย ifย theย  individual requests that the electronic copy be provided on portable media.ย  However, a covered entity mayย notย require anย  individual to purchase portable media; individuals have the right to have theirย  PHI e-mailed or mailed to them upon request.
    3. Labor to prepare an explanation or summary of the PHI, if the individualย in advanceย both chooses to receive an explanation or summaryย andย agrees to the fee that may be charged.
    4. Postage, when the individual requests that the copy, or the summary or explanation, be mailed.

    Thus, costs associated with updates to or maintenance of systems and data, capital for data storage and maintenance, labor associated with ensuring compliance with HIPAA (and other applicable law) in fulfilling the access request (e.g., verification, ensuring only information about the correct individual is included, etc.) and other costs not included above,ย even if authorized by State law, areย not permitted for purposes of calculating the fees that can be charged to individuals.ย  See 45 CFR 164.524(c)(4).

    Further, while the Privacy Rule permits the limited fee described above, covered entities should provide individuals who request access to their information with copies of their PHI free of charge.ย  While covered entities should forgo fees for all individuals, not charging fees for access is particularly vital in cases where the financial situation of an individual requesting access would make it difficult or impossible for the individual to afford the fee.ย  Providing individuals with access to their health information is a necessary component of delivering and paying for health care. We will continue to monitor whether the fees that are being charged to individuals are creating barriers to this access, will take enforcement action where necessary, and will reassess as necessary the provisions in the Privacy Rule that permit these fees to be charged.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.