Author: Colington Consulting

  • 56% of Employees Still Receive No Security Awareness Training

    With all the recent and notable attention to data breaches, on-line security, and preventative measures, the fact that more than half the employees surveyed did not receive security awareness training is cause for concern.

    When it comes to HIPAA Security Rule requirements, security awareness training is mandated. The more robust your training is, the better positioned your practice or office can be when it comes to early detection of a possible breach.

    Below is a repost of a recent article regarding security awareness training from Help Net Security. A new research survey by EMA takes you inside todayโ€™s organizations to reveal how employee decisions related to information security can significantly increase organizational risk. The report examines the implementation of security awareness training in government, public and private companies and non-profit groups.

    According to employee responses in the survey report:

    • 30% leave mobile devices unattended in their vehicle
    • 33% use the same password for both work and personal devices
    • 35% have clicked on a link in an email from an unknown sender
    • 58% have sensitive information on their mobile devices
    • 59% store work information in the cloud.

    Some of the reported behaviors present inherent risks, while others depend on contributory factors like the failure to use device or data encryption.

    Fifty-six percent of corporate employees, excluding security and information technology staff, have not had security or policy awareness training from their organization, while 45% of employees received training in one annual session. Without the foundation of on-going security awareness training, employees donโ€™t receive the critical security information they need to make secure choices.

    EMA Research Director David Monahan said: โ€œPeople repeatedly have been shown as the weak link in the security program. Without training, people will click on links in email and release sensitive information in any number of ways. In most cases they don’t realize what they are doing is wrong until a third-party makes them aware of it.”

    “In reality, organizations that fail to train their people are doing their business, their personnel and, quite frankly, the Internet as a whole a disservice because their employeesโ€™ not only make poor security decisions at work but also at home on their personal computing devices as well,” Monahan added.

    Sixty-six percent of employees responding to the survey said it is important that training materials are easy to understand; and 59% say that interactive activities are important.

    โ€œWhile todayโ€™s organizations continue to harden their infrastructure to protect against the latest cyber threats, this report reveals that they too often fail to arm their employees with the critical information needed to avoid a data breach, prevent phishing, or report a possible security incident,โ€ said Craig Kunitani, COO with Security Mentor. โ€œEvery organization should make security awareness training part of its defense in depth strategy. Many of our customers report theyโ€™ve had great success in educating their staff using our security awareness training program because of our brief, interactive, and informative lessons.โ€

    Need Help with Your HIPAA Compliance Program?

    Colington Consulting provides comprehensive HIPAA training courses that instruct members of your organization on protecting patient health information of all forms, including electronic health records. We offer a variety of HIPAA training courses designed to easily and affordably meet annual security and privacy requirements.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your training program and protect your organization.

    • This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Survey Finds Lack of HIPAA Compliance Knowledge

    by Jay Hodes, President – Colington Consulting

    It came as no surprise to me when I reviewed a recent HIPAA survey conducted by NueMD, in conjunction with Porter Research and The Daniel Brown Law Group, which found that most healthcare providers and business associates that responded have a limited knowledge of compliance regulations. This was one of the most comprehensive surveys on HIPAA compliance that I have seen.

    Part of the survey asked over 1,000 providers, administrators and medical office staff a number of questions regarding their knowledge and awareness of HIPAA compliance requirements. Let me share some of those practice findings:

    • 68% of respondents were unaware that random HIPAA audits were going to be conducted.
    • Only 35% of respondents said they conducted a HIPAA-required risk analysis.
    • Only 24% of managers, owners and administrators reported that they evaluated all of their Business Associate Agreements.

    Why does it not come as a surprise to me? Well, for a number of reasons. Smaller medical practices do not have the in-house resources to handle the complexities of meeting all of their compliance requirements. Most donโ€™t realize what is involved. When I provide initial consultations with potential clients and explain all the areas that must be covered, I usually get the typical response that they did not think all the regulations applied to their practice or that their practice was too small and some of this compliance stuff was not necessary. Itโ€™s not that they donโ€™t want to be compliant; it is more that they do not know or understand what is entailed.

    Reinforcing this perception, when looking at โ€œpractices by size, (the survey) found that larger practices (particularly those with 10 or more providers) tended to do better when it came to compliance measures within the office – things like having a plan, training staff, appointing officers and conducting risk analyses. This wasn’t surprising, as larger organization usually have more resources to devote to regulatory compliance.โ€

    I feel part of the onus for so much confusion among smaller providers rests with my former agency, the U.S. Department of Health and Human Services. Although the Office for Civil Rights (OCR) has the primary responsibility to enforce HIPAA regulations, the Office of the National Coordinator for Health Information Technology (ONC) promotes the use of electronic exchanges of health information. ONC pushes out guidance on health information privacy, security and the implementation of electronic health records.

    Then there is the Centers for Medicare & Medicaid Services (CMS) that administers the EHR Incentive Program. CMS has started to conduct meaningful use attestation audits. One of the core objectives that must be attested to is that a HIPAA Risk Assessment was conducted, the same risk assessment that OCR requires and would review during their own audit or compliance review.

    A practice manager, already wearing so many hats, does not have the time to conduct the research, check the websites of three different agencies and find the necessary answers to what is reasonable and appropriate for that officeโ€™s environment. This leads to another survey finding from medical practices in that only 38% of respondents said โ€œthat someone at (the) business is actively ensuring (the) business’s compliance with HIPAA.โ€

    If you are unsure of where to start, have a HIPAA Risk Assessment conducted, especially if your practice or business has never done one. The assessment will identify vulnerabilities and threats to your current administrative, physical and technical safeguards for protected health information you maintain. A good assessment must provide an action plan or steps for remediation for all the vulnerabilities and threats that were detected. It provides a critical road map, based on the rated risk level, for what needs to be addressed immediately to meet compliance requirements.

    What is clear is the need to make HIPAA compliance an important part of the everyday operations for any healthcare practice or business, not just when there is a threat of an audit. Because compliance requirements can be such a time consuming process, consider outsourcing this responsibility. I know there are quite a few practice managers who need assistance and would relish having a consultant provide this service. In the end, it may be a cost saving measure to outsource HIPAA compliance assistance, saving workforce time and a lot of frustrating hours.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Indiana Dentist Fined by State for HIPAA Violations

    by Jay Hodes, President – Colington Consulting

    According to an article published in the Kokomo (Indiana) Tribune, a former Kokomo dentist, Joseph Beck, โ€œagreed to pay the state $12,000 for disposing of patient files in an Indianapolis dumpster, the Attorney Generalโ€™s Office (recently) reported. The Attorney Generalโ€™s Office sued Beck for failing to protect personal information and for improperly disposing of records containing personal information of Indiana residents, which violates state privacy laws as well as the federal Health Insurance Portability and Accountability Act (HIPAA).โ€

    What is significant is, โ€œThis is the first time Indiana has sued for a violation of HIPAA.โ€ The article went on to say, โ€œMore than 60 boxes of patient records from Beckโ€™s former Comfort Dental clinic in Kokomo were found discarded in an Indianapolis dumpster in March of 2013. The files contained records from 2002-2007.โ€ Not only are the Feds involved with compliance oversight, but now the states have an active interest, especially when civil monetary penalties can be imposed. States may view this as a way to step up their game when it comes to conducting audits, investigations and prosecutions for HIPAA compliance. With more and more data breaches occurring, it makes perfect sense for this course of action.

    The Office for Civil Rights (OCR), which enforces Federal regulations and compliance for HIPAA, has been conducting training for State Attorneys General (AGs). OCR developed HIPAA enforcement training to state AGs and their staff on how to use this authority to enforce the HIPAA Privacy and Security Rules. The training course provides assistance on how to investigate HIPAA violations. But more importantly, the training shows AGs how to seek civil damages for HIPAA violations that affect residents of their respective states.

    With this recent case in Indiana, the dentist โ€œhired a private company, Just the Connection, Inc. to retrieve and dispose of his patient records, which included names, medical records, phone numbers, birth dates, Social Security numbers, insurance cards, insurance information and state ID numbers.โ€ It is unclear if Beck had a Business Associate Agreement (BAA) in place with the private company to properly dispose of the records. The BAA would have been required in this case.

    As a covered entity, this story reinforces the need not only to have a BAA in place with any vendor who is accessing your protected health information, but also make sure your own HIPAA policies and procedures cover proper record disposal. Any BAA must require that a business implement the proper safeguards to prevent unauthorized use or disclosure of protected health information (PHI) not only for electronic records, but also for any paper records or charts. This is especially critical for the document destruction process for PHI.

    Although smaller state civil settlements are not on par with the millions OCR seeks during a resolution agreement, it does allow the states to become more engaged in investigating these types of breaches. Just more one reason to be HIPAA compliant.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Anthem HIPAA Breach

    Setting the Stage for More Government Oversight

    by Jay Hodes, President – Colington Consulting

    The dust has settled, and more facts have been coming to light regarding the recent HIPAA data breach at Anthem Blue Cross Blue Shield. It was only a matter of time before the U.S. Congress started making some noise about cybersecurity. Within days of news reports of the Anthem breach, the U.S. Senate Committee on Health, Education, Labor and Pensions announced a bipartisan initiative to focus on the security of health information technology. This initiative will also look at the health industryโ€™s overall preparedness for cyber threats.

    Although the timing was ironic and clearly not related to the Anthem breach, the White House announced its 2016 proposed budget that includes an increase in funding for HIPAA compliance programs. The proposed budget indicates around a 10% percent increase in funding for the Office for Civil Rights (OCR). OCR is the agency within the U.S. Department of Health and Human Services (HHS) with HIPAA compliance and oversight responsibilities.

    As far as the possible budget increase for OCR, we will wait to see what type of mood Congress is in to approve this. And, even with this congressional initiative, any proposed fixes will take time and money. In the meantime, hopefully the Anthem case sends a loud and clear message to all healthcare providers to up their game when it comes to protecting patient health information. Healthcare providers, plans and clearinghouses need to go on the offensive and be proactive when it comes to having the proper information technology safeguards in place. The threat of Congressional action or a beefed up OCR must not be the incentive to do so.

    Regrettably, the use of encryption is not a requirement of the HIPAA Security Rule. As shocking as that sounds, that does not mean covered entities do not need to encrypt their patient data. What the guidelines call for, as provided by HHS, is this:

    The encryption implementation specification is addressable, and must therefore be implemented if, after a risk assessment, the entity has determined that the specification is a reasonable and appropriate safeguard in its risk management of the confidentiality, integrity and availability of e-PHI [electronic protected health information]. If the entity decides that the addressable implementation specification is not reasonable and appropriate, it must document that determination and implement an equivalent alternative measure, presuming that the alternative is reasonable and appropriate. If the standard can otherwise be met, the covered entity may choose to not implement the implementation specification or any equivalent alternative measure and document the rationale for this decision.

    It is incumbent on covered entities to conduct a HIPAA Risk Assessment in order to make the determination on whether it is reasonable and appropriate to their particular circumstance to use encryption software. The assessment must be the basis for the decision. And if the decision is made not to encrypt, then the justification must be made abundantly clear in documentation.

    So if there is a breach and OCR asks during an investigation why your organization did not encrypt its protected health information, the justification must be based on a low threat to your data. Make sure you can back that up with documentation that is solid and well-defined. Possible civil and criminal prosecution will be based on the proof you provide.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 23, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • HIPAA Compliance โ€“ Waiting for the Other Shoe to Drop

    by Jay Hodes, President – Colington Consulting

    The expression โ€œwaiting for the other shoe to dropโ€ appears to have originated in the early 1900โ€™s and is often associated with the arrival of a seemingly inevitable event. I speculate we are at that point in terms of ramped up HIPAA compliance enforcement. The recent Anthem data breach shined a significant spotlight on how vulnerable health information technology can be without the proper safeguards in place.

    The Office for Civil Rights (OCR), the U.S. Department of Health and Human Services agency responsible for HIPAA oversight, has made a lot of noise about being more aggressive in enforcement of the regulations. You would think it is time for the proverbial other shoe to drop. But not so fast. With limited resources, there is only so much OCR can do. That needs to change. It will and probably soon.

    There is now, and has been for a while, a lot at stake in terms of making sure healthcare providers and business associates have safeguards in place to properly secure patientsโ€™ protected health information. If major healthcare plans like Anthem are not making sure they are meeting all the HIPAA required implementation specifications, what can be said for smaller healthcare providers?

    The Ponemon Institute recently released its โ€œFifth Annual Study on Medical Identity Theft.โ€ Among the findings, the study discovered that โ€œconsumers expect healthcare providers to be proactive in preventing and detecting medical identity theft.โ€ What was surprising is that โ€œmany respondents are not confident in the security practices of their healthcare provider.โ€ Another interesting outcome of study was that โ€œ79 percent of respondents say it is important for healthcare providers to ensure the privacy of their health records,โ€ and almost half of those respondents said โ€œthey would consider changing healthcare providers if their medical records were lost or stolen.โ€

    The results of the Ponemon study must be a wakeup call for healthcare providers. Can you afford to have half of your patients leave your practice if a breach occurs? As a healthcare provider, donโ€™t be surprised if patients start asking about how you are securing their protected health information (PHI). With all the recent data breaches in retail stores like Target, Sony PSN and Home Depot, consumers realize the vulnerabilities associated with the use of credit cards. As these same consumers seek healthcare services, it will be only a matter of time before questions are asked about safeguarding PHI.

    As a healthcare provider or business associate, make sure you are doing everything you can to protect health information. It goes way beyond a checklist. A robust HIPAA compliance program must be in place, regardless of the size of your practice or business. If you cannot meet all the HIPAA requirements by doing it in-house, consider outsourcing this responsibility. Take the burden off the plate of your office or practice manager or designated HIPAA officer.

    There is still time before that other shoe drops.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • HIPAA Requirements โ€“ Time for a Major Regulatory Change

    by Jay Hodes, President – Colington Consulting

    It is only fitting that legislation that was created in the mid 1990โ€™s be considered, as most HIPAA experts would agree, outdated. Even with changes brought about by HITECH and the Omnibus Act, the implementation specifications remain relatively unchanged. It is still one-size-fits-all when it comes to meeting the requirements.

    Sure, you could argue what is reasonable and appropriate for one healthcare provider is not for another. Therefore, it comes down to how each implementation specification is interpreted, how you decipher what the Code of Federal Regulation (CFR) is asking for. After spending 27 years working for the Federal government and being involved in policy and regulatory oversight, even I sometimes struggle with how to make sense of a particular CFR.

    For larger healthcare providers that have regulatory and compliance staff, HIPAA compliance might be a bit easier. But for the smaller providers who are required to follow all of the same requirements, albeit what is โ€œreasonable and appropriate,โ€ this is a colossal struggle. I can see why some small providers just throw their hands up and say, โ€œThis is way too complex for us to figure out.โ€

    When the HIPAA legislation was created, the healthcare system in this country was really starting to transform. Today, with more and more specialty practices and other types of healthcare service providers tapping into this growing market, updating regulation requirements must be a priority. It cannot be a one-size-fits-all requirement anymore. The U.S. Congress needs to take into consideration how the healthcare industry has changed, in particular with the emergence of new health related mobile apps hitting the techno-sphere. HIPAA regulatory requirements must be adaptable to meet this changing environment.

    When I conduct a HIPAA risk assessment for a smaller healthcare provider and I ask a question in an attempt to adhere to the implementation specification, often I get a non-applicable response. The hard work for me is how to get that provider covered in meeting a required implementation specification if it is non-applicable. If a provider is truly making the effort with due diligence to follow the HIPAA regulations, then that should be factored into the equation.ย  The process must allow for more discretion when it comes to some of the implementation specifications.

    All of this will require legislative fixes. The U.S. Congress can rattle a few cages and give the impression there is real concern with making sure healthcare providers are doing everything they can to safeguard patient records, but until there is movement towards making necessary legislative changes, HIPAA requirements will remain as confusing to some as the U.S. tax code.

    Back in the mid 1990โ€™s, Senators Kasebaum and Kennedy, the sponsors of the insurance reform legislation that became known as HIPAA, clearly had a vision about the changing landscape of healthcare security in this country. Which current day senators will have that vision and want to undertake this monumental task in reforming HIPAA for the next decade remains to be seen.ย  The time is now to start down this road.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • Reviewed on June 23, 2026 by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • HIPAA Privacy Rule โ€“ What is Confusing About the Requirements

    by Jay Hodes – President, Colington Consulting

    A great deal of attention is given to protecting electronic health records. The HIPAA Security Rule defines all the administrative, technical and physical safeguards that must be in place in order to be compliant. But, what about paper documents containing protected health information (PHI), required verbal conversations that need to take place in a healthcare practice and marketing?

    These topics are all covered in the HIPAA Privacy Rule. The rule clearly defines the โ€œwhatโ€ of protected health information in terms of health care providersโ€™ responsibilities, when it comes to patient privacy.ย  Although the Privacy Rule includes what is covered in terms of electronic transfers of PHI, the rule is also very extensive about the handling of PHI. Let me address a couple important sections of the Privacy Rule where many providers struggle in understanding what is and is not required. When it comes to uses and disclosures of protected health information (PHI), in general, a health care provider does not need patient authorization to:

    • Use or disclose PHI for treatment, payment or health care operations.
    • Use or disclose PHI for the treatment activities of another health care provider.
    • Disclose PHI to another covered entity or health care provider for the payment of the entity that receives the information.
    • Disclose PHI to another covered entity for health care operations activities of the entity that receives the information, if both entities have a relationship with the individual and the disclosure is for the purpose of conducting quality assessment and improvement activities, reviewing the competence or qualifications of health care professionals or for fraud and abuse detection or compliance.

    However, the heath care provider must still provide the patient with its Notice of Privacy Practices (NPP) and make a good faith effort to obtain written acknowledgement that the patient received the NPP.

    A health care practice must always be aware of the minimum necessary standard. The standard, a key protection of the HIPAA Privacy Rule, is derived from confidentiality codes and practices in common use today. It is based on sound, current practice that protected health information should not be used or disclosed when it is not necessary to satisfy a particular purpose or carry out a function. The minimum necessary standard requires health care providers to evaluate their practices and enhance safeguards, as needed, to limit unnecessary or inappropriate access to and disclosure of protected health information. The Privacy Ruleโ€™s requirements for the minimum necessary standard are designed to be sufficiently flexible to accommodate the various circumstances of any covered entity.

    Another confusing area of the HIPAA Privacy Rule concerns marketing. The Privacy Rule defines โ€œmarketingโ€ as making โ€œa communication about a product or service that encourages recipients of the communication to purchase or use the product or service.โ€ Generally, if the communication is โ€œmarketing,โ€ then the communication can occur only if the health care provider first obtains an individualโ€™s authorization.

    The Privacy Rule exceptions to the definition of marketing fall into three categories:

    • A communication is not โ€œmarketingโ€ if it is made to describe a health-related product or service (or payment for such product or service) that is provided by, or included in a plan of benefits of, the covered entity making the communication, including communications about:
    • The entities participating in a health care provider network or health plan network; replacement of, or enhancements to, a health plan; and
    • Health-related products or services available only to a health plan enrollee that add value to, but are not part of, a plan of benefits.

    This exception to the marketing definition permits communications by a health care providerโ€™s own products or services.

    1. A communication is not โ€œmarketingโ€ if it is made for treatment of the individual.
    2. A communication is not โ€œmarketingโ€ if it is made for case management or care coordination for the individual, or to direct or recommend alternative treatments, therapies, health care providers or settings of care to the individual.
    • Reviewed on June 23, 2026 by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Source: The HIPAA Privacy Rule (45 CFR ยง 164.524): This is the core federal regulation that establishes a patient’s legal right to inspect and obtain a copy of their protected health information (PHI).
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • PHI – Striking Fear When It Comes to Being Compromised

    by Jay Hodes, Presidentย – Colington Consultingย 

    I am not sure if those tasked with securing protected health information lose sleep every night worrying if they did enough to safeguard the data their organizations maintain. If they are losing sleep, though, that may be a good thing, because it could show how seriously they take this responsibility. But for the rest, that obnoxious wake up alarm that we all hate at times should be the recent ransomware case that occurred at the Hollywood (CA) Presbyterian Medical Center.

    A letter released by Allen Stefanek, President and CEO of the Center, acknowledged that $17,000 in a ransom was paid to the alleged perpetrators to get their electronic health records back. Stefanek stated the โ€œquickest and most efficient way to restore our systems and administrative functions was to pay the ransom and obtain the decryption key.โ€

    If a hospital system can be put into a virtual shutdown, how vulnerable are millions of small to mid-size providers?

    When conducting HIPAA risk assessments, I ask required questions about contingency, emergency and disaster recovery plans. Some organizations do not realize these are critical elements for HIPAA compliance. Policies and procedures must be in place and address these potential vulnerabilities that could result in a high risk rating. Unless these providers are outsourcing IT services and secure backup is part of the arrangement, many fall short in making sure all PHI maintained is available at all times, regardless of emergency or disaster โ€“ or data being taken hostage, as was the case with Hollywood Presbyterian.

    One of the lessons I learned from my time in Federal law enforcement is to โ€œwhat ifโ€ scenarios to death. Try to determine all the negatives an operation or mission could face, and then have a contingency plan to address each particular scenario. Being prepared is crucial because if something does go bad, a plan is already in place to address it. When it comes to protecting healthcare data, the same philosophy should hold true. There are required HIPAA implementation specifications for the standard of developing and maintaining contingency plans. Policy and procedure must be in place to address areas like data backup, disaster recovery, system criticality analysis and emergency mode operations.

    Although not technically a HIPAA requirement, I always bring up continuity of business operations when talking with clients. It goes beyond needing access to protected health information in emergency conditions. I recommend timelines in cases where a facility cannot be occupied after a natural or man-made disaster and there is the need to assign roles and responsibilities to do certain things, such as locating temporary office space, procuring IT, telecom, and medical equipment and establishing a process to notify patients about the closure or relocation.

    Many larger organizations have procedures in place and routinely test and drill their contingency plans. Small to mid-size organizations must have the same protocols in place; albeit to a lesser extent because of the nature of their business operations.

    Fearing if your organization is going to be compromised is a reality that needs to be faced. Most experts agree it is not if, but when. Having addressed these issues before a breach occurs and having a game plan in place can go a long way in making sure any impact can be minimized as much as possible.

    • Reviewed on June 23, 2026 by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • MACRA โ€“ Are There Additional HIPAA Concerns for Providers?

    By Jay Hodes, President โ€“ Colington Consultingย 

    I am not claiming to be an expert on the Medicare Access and CHIP Reauthorization Act of 2015 (MACRA), other than the inherent emphasis this Act places on HIPAA requirements. The U.S. Department of Health and Human Services, which has a number of internal agencies that deal with patient privacy concerns, is starting to see the need to further enforce required health record safeguards. ย For better or worse, this is what HIPAA is all about. It appears parts of MACRA continue this trend.

    Here is a little background on MACRA. On April 14, 2015, a large bipartisan majority in Congress passed the MACRA. President Obama signed the MACRA into law on April 16, 2015. It repeals the Sustainable Growth Rate (SGR) formula, which linked Medicare annual payment updates for physicians and other professionals to prior year spending and gross domestic product (GDP) growth. MACRA contains scheduled Physician Fee Schedule (PFS) updates, a new Merit-Based Incentive Payment System (MIPS), a new Technical Advisory Committee for assessing Physician Focused Payment Model (PFPM) proposals, and incentive payments for participation in Alternative Payment Models (APMs).

    The Act also includes strict privacy and security requirements for all entities receiving Medicare analyses or data, as well as new annual reporting requirements.

    Obviously there is much more to this Act, but I wanted to address it from the HIPAA compliance perspective. Simply stated, MACRA requirements to maximize payments will require practitioners to meet certain requirements to protect the health information of patients by implementing certified electronic medical records technology. ย 

    If your healthcare organization already carries the designated title of being a Covered Entity, you should be doing this already. This is the foundation of the safeguards under the HIPAA Security Rule, and MACRA makes a number of strongly worded references to privacy and security requirements.ย 

    This means Covered Entities must be conducting HIPAA Risk Assessments and have an overall risk management plan in place. A HIPAA Risk Management Plan is the foundation of any compliance program. Regardless of the size of your practice, a plan is the most essential component for implementing compliance. Contained within the plan must be a policy and procedure on how your organization is going to conduct the risk assessment process. MACRA will put more emphasis on the assessment process in determining vulnerabilities and threats to electronic health information maintained, transmitted and created by Covered Entities. ย 

    If organizations have a comprehensive compliance program in place then there should be no additional HIPAA concerns that MACRA will pose. But for many small to mid-size healthcare providers, it is still a struggle meeting all the HIPAA compliance requirements. And now with some MACRA formulas designed to maximize payments tied to safeguards, the burden will be even greater for these providers.ย 

    With the MACRA roll out in place, there is still time for Covered Entities to have risk assessments conducted. Do not delay โ€” start the process soon to maximize those future payments.ย 

    This blog was previously posted August 10, 2016

  • OCR Announces Initiative to More Widely Investigate Breaches

    OCR Announces Initiative to More Widely Investigate Breaches Affecting Fewer than 500 Individuals

    by Jay Hodes, President – Colington Consulting

    Since the passage of the Health Information Technology for Economic and Clinical Health Act of 2009 and the subsequent implementation of the Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule, OCR has prioritized investigation of reported breaches of protected health information (PHI). The root causes of breaches may indicate entity-wide and industry-wide noncompliance with HIPAAโ€™s regulations, and investigation of breaches provides OCR with an opportunity to evaluate an entityโ€™s compliance programs, obtain correction of any deficiencies, and better understand compliance issues in HIPAA-regulated entities more broadly. ย OCRโ€™s Regional Offices investigate all reported breaches involving the PHI of 500 or more individuals. ย Regional Offices also investigate reports of smaller breaches (involving the PHI of fewer 500 individuals), as resources permit. ย 

    Beginning this month, OCR, through the continuing hard work of its Regional Offices, has begun an initiative to more widely investigate the root causes of breaches affecting fewer than 500 individuals. ย Regional Offices will still retain discretion to prioritize which smaller breaches to investigate, but each office will increase its efforts to identify and obtain corrective action to address entity and systemic noncompliance related to these breaches. ย Among the factors Regional Offices will consider include: ย 

    โ€ข The size of the breach;
    โ€ข Theft ย of or improper disposal of unencrypted PHI;
    โ€ข ย Breaches that involve unwanted intrusions to IT systems (for example, by hacking); The amount, nature and sensitivity of the PHI involved; ย orย 
    โ€ข ย Instances where numerous breach reports from a particular covered entity or business associate raise similar issues. ย ย 

    Regions may also consider the lack of breach reports affecting fewer than 500 individuals when comparing a specific covered entity or business associate to like-situated covered entities and business associates. ย 

    Take Action Now

    If HIPAA compliance assistance is needed for your organization, we specialize in putting compliance programs in place or assessing your current program. We provide a full range of services that include conducting the required HIPAA Risk Assessment, writing and customizing a HIPAA Risk Management Plan (HIPAA Policies and Procedures) for your organization, and providing your entire staff annual required HIPAA Security Awareness & Privacy Training through our web-based platform. Our fees are based on what specifically your organization will need to meet regulatory requirements and reasonably priced to accommodate any budget.

    Letโ€™s start the process with a free, initial consultation. In as little as 15 minutes, we can evaluate your current compliance program to determine if all mandatory privacy and security safeguards are in place to meet government regulations.

    This blog was previously posted August 19, 2016