Author: Colington Consulting

  • How Prepared is Your Organization for a HIPAA Audit?

    by Jay Hodes, President – Colington Consulting

    Could your organization be prepared for an onsite HIPAA audit in ten days? Before you answer, let me explain what documentation you will need for the auditors, lawyers and investigators the U.S. Health and Human Services (HHS) Office for Civil Rights (OCR) will be sending to your office or business. ย 

    One of the first documents OCR will be asking for is a copy of your most recent HIPAA Risk Assessment. ย Conducting a risk assessment is a regulatory requirement to determine the vulnerabilities and threats to any electronic protected health information your organization accesses, stores, creates or transmits. A checklist is not sufficient, and a comprehensive risk assessment needs to be made available to OCR. ย  ย 

    OCR will be interested in seeing how your organization has attempted to mitigate those vulnerabilities and threats. Just conducting the assessment is not good enough. A remediation plan must be implemented. I always recommend a systematic approach to remediation by addressing high threats first, then on to moderates, and concluding with the lows if actionable items are needed. ย 

    Once the risk assessment is provided, be prepared to hand over any number of HIPAA policies and procedures that an organization must have in place. How do you know what OCR will ask for? That is a tough question to answer. Based on my knowledge from others who have been onsite during an audit or investigation, all bets are off as far as which of those policies and procedures will be requested.ย 

    When you look at the HIPAA Implementation Specifications, all of these must be covered with policies and procedures. As former Assistant Inspector General for Investigations in the HHS IGโ€™s office involved with the oversight of complex criminal investigations, my experience tells me OCR will ask for a lot, if not all, of policies and procedures generated by the organization. ย ย 

    If I were to pick a handful of policies that OCR would be interested in seeing, I would include the Mobile Device Management Policy; Breach Notification Policy; Facility Security Plan and Policy; Audit Control Policy; and the Sanction Policy. All of these are critical areas that must be addressed with not only policy, but procedures on how to implement the policy. ย ย 

    Expect OCR to request documentation regarding the annual HIPAA Security Awareness Training requirement. Your organization will need to show you provided this training to each member of your workforce. This includes all physicians, part-timers, interns and volunteers, along with the rest of the staff. ย 

    I can tell you from my expertise in compliance, if you do not have all the HIPAA requirements currently in place, there is no way an organization can be prepared for audit in ten days. OCR will look for specific dates for items, such as when an access audit was conducted or when a HIPAA Risk Assessment was conducted, as well as entry dates on a maintenance record log. Your organization must be prepared as if any day now a letter is going to arrive from HHS indicating you have been identified for an audit. This will make it easier having required compliance requirements in place and minimize any concerns if that letter does come.

    This blog was previously posted October 24, 2016

  • Training Staff in HIPAA Regulations

    In July 2017, Jay Hodes – President of Colington Consulting, provided comments to the Renal & Urology News regarding the effectiveness of HIPAA Security Awareness Training. ย The HIPAA Security Rule requires that all staff of Covered Entities receive annual HIPAA training. ย This training is also required for members of a Business Associate workforce that must access any protected health information in conducting services. ย 

    With 80% of HIPAA data breaches caused by human error, training your workforce can help to cut down in costly HIPAA fines and penalties and promote a culture of compliance within in your organization. โ€œAt the end of training, the person should walk away feeling like they understand HIPAA better,โ€ Hodes said. โ€œThere is nothing worse for an organization than to have someone say after aย breach, โ€˜No one ever told me I couldn’t take that laptop home’.” ย If your organization is investigated for a HIPAA violation or a data breach, documentation you trained your workforce will be asked for by the HHS Office for Civil Rights. ย 

    There are a number of ways training requirements can be accomplished. ย Whether using a video presentation, an instructor led class , or a web based program, the goal is being able to meet this annual requirement. ย 

    To read the complete article, click here.ย 

  • HIPAA Requirements for Web App Development for Medical Websites

    If you are part of the medical community, you are probably well aware of HIPAA, and the importance of maintaining compliance when it comes to Protected Health Information (PHI). But, do you really understand what you need to do to make sure your web application development for your website is HIPAA compliant?

    Web applications associated to your practice and your website are a great way for patients to interact with their healthcare providers. From accessing test results and paying bills to scheduling appointments, things like patient portals help free up medical staff and enhance productivity. Here are some things you need to be aware of regarding your web app development when it comes to HIPAA compliance.

    Is My Web App HIPAA Compliant?

    In order for your app to be HIPAA compliant, you need to make certain the following is in place:

    ยทย ย ย ย ย ย  Data Transport Encryption: Chances are that the data on your generic website is not encrypted before or during transmission. HIPAA requires that any ePHI (electronic Protected Health Information) be encrypted prior to being transmitted.

    ยทย ย ย ย ย ย  Backup: Your current website server might have a backup, as most web hosts provide backup and restoration features. HIPAA requires that ePHI is backed up for recovery and restoration, if needed. But, do you know if the location of those backup files is HIPAA compliant, too? If not, you may have just unlawfully shared PHI. Anybody hosting, maintaining, or monitoring server space containing PHI should adhere to the Business Associate Agreement, addressed below.

    ยทย ย ย ย ย ย  Authorization: You may already have authorization in place on your medical app, or you may not. This needs to be confirmed. The only people who should have access to ePHI are authorized staff members trained and versed in HIPAA compliance rules, or a serious breach could easily occur.

    ยทย ย ย ย ย ย  Data Integrity: On a generic website or app, there is no guarantee that data has not been modified. You must make certain that ePHI is not subject to unsanctioned changes.

    ยทย ย ย ย ย ย  Storage Encryption: Generic websites do not encrypt stored data. Stored data must be encrypted to ensure patient privacy.

    ยทย ย ย ย ย ย  Disposal: This might already exist on a generic website.ย  Just be aware that some web hosting providers store backups indefinitely. You must make sure that once ePHI is no longer needed, it can be safely and permanently disposed of.

    ยทย ย ย ย ย ย  Business Associate Agreement: Many web hosting providers do not know what HIPAA is, and will be reluctant to run any risks signing the HIPAA Business Associate Agreement, which might contradict their own business processes. It is imperative that your ePHI is hosted on servers of a company with whom a Business Associate Agreement is in place, and signed. The alternative is to host your ePHI on secure in-house servers.

    It is important to note that every vendor that deals with your patient health data must sign a Business Associate Agreement in order for you to be HIPAA compliant. It is imperative that your web hosting provider follows security requirements and provides infrastructure that is HIPAA compliant. The same is true for website design and functionality.

    Privacy Policy

    It is strongly encouraged that health app developers and any party associated with a website or app โ€“ that must be HIPAA compliant due to hosting patient health information โ€“ acknowledge and accept a well-defined privacy policy. This is not the same as a notice of privacy practices, as it signifies individual responsibility towards protecting patient rights.

    Need Help?

    HIPAA compliance can be complex, and breaches are messy and costly. It is important that your business understands what is necessary and appropriate to protect ePHI during the creation and maintenance of healthcare applications and websites.

    If you are concerned about your businessโ€™s privacy and security needs and HIPAA compliance, contact us at 800-733-6379. We are experts in the field of HIPAA rules and procedures. Colington Consulting can help you avoid reputation problems and steep fines, by bringing your business into complete HIPAA compliance. It is what we do best, allowing you to do what you do bestโ€ฆprovide health care to your patients.

    This blog was previously posted February 14, 2018

  • The Elements of a HIPAA Risk Analysis

    by Jay Hodes, President – Colington Consulting

    The Department of Health and Human Services (HHS) requires all Covered Entities and Business Associates handling protected health information to conduct a risk analysis as the first step toward implemented safeguards specified in The HIPAA (Health Insurance Portability and Accountability Act) Security Rule, and actively maintaining HIPAA compliance.

    At first glance, it may seem like a daunting task. But itโ€™s a necessary one that can help protect your practice from costly violations while โ€“ more importantly โ€“ protecting your patientsโ€™ privacy and personal security.

    Nine Key Components

    There are numerous methods of performing risk analysis and there is no single method or โ€œbest practiceโ€ that guarantees compliance with the Security Rule.

    However, the HHS Security Standards Guide outlines nine mandatory components of a risk analysis that healthcare organizations and healthcare-related organizations that store or transmit electronic protected health information (ePHI) must include in their document:

    • Scope of the Analysis โ€“ This addresses any potential risks and vulnerabilities to the privacy, availability, and integrity of ePHI. It includes all electronic media your organization uses to create, receive, maintain or transmit ePHI such as portable media, desktops, and networks. Network security between multiple locations is also important to include, and may include aspects of your HIPAA hosting terms with a third party or business associate.
    • Data Collection โ€“ This focuses on where the ePHI goes. You need to locate where data is being stored, received, maintained, or transmitted. If youโ€™re hosting at a HIPAA compliant data center, youโ€™ll need to contact your hosting provider to document where and how your data is stored.
    • Potential Threats and Vulnerabilities โ€“ Identify and document sensitive data and any vulnerabilities that may lead to the leaking of ePHI. By anticipating any potential HIPAA violations, you can help your organization reach a resolution swiftly and effectively.
    • Current Security Measures โ€“ Assess the kind of security measures youโ€™re taking to protect your data. This might include any encryption, two-factor authentication, or other security methods out in place by your HIPAA hosting provider.
    • Likelihood of Threat Occurrence โ€“ Determine the probability of potential risks to ePHI. This assessment allows for estimates on the likelihood of ePHI breaches.
    • Potential Impact of Threat Occurrence โ€“ Use qualitative or quantitative methods to assess the maximum impact of a data threat to your organization. Question how many people could be affected and to what extent private data โ€“ medical records or both health information and billing information –could be exposed.
    • Determine the Level of Risk โ€“ HHS suggest taking the average of the assigned likelihood and impact levels to determine the level of risk. Documented risk levels should be accompanied by a list of corrective actions that can be performed to mitigate risk.
    • Documentation Finalization โ€“ Compile everything in an organized document. Any format will suffice as long as the analysis is in writing.
    • Periodic Review and Updates to the Risk Assessment โ€“ One requirement is that the risk analysis process be conducted on a regular, ongoing basis. The Security Rule doesnโ€™t set a required timeline, but HHS recommends that organizations conduct another risk analysis whenever your company implements or plans to adopt new technology or business operations. This could include switching your data storage methods from managed servers to cloud computing, and updating after any ownership or key staff turnover.

    Take Action Now

    Performing a risk analysis is a complex process. The HIPAA compliance experts at Colington Consulting have conducted numerous compliance assessments. You can benefit from their expertise in knowing what is reasonable and appropriate for your organization. They understand the field of HIPAA rules and procedures and can help you avoid problems and steep fines by helping your organization maintain complete HIPAA compliance. It is what they do best, allowing you to do what you do best โ€ฆ provide health care to your patients. Contact Colington Consulting today at 800-773-6379.

    This blog was previously posted March 2, 2018

  • What is the HIPAA Privacy Rule?

    Part of the Heath Insurance Portability and Accountability Act (HIPAA) that became law in 1996, the HIPAA Privacy Rule defined the part of the law that protects patientsโ€™ protected health information (PHI). Among organizations this rule applies to are health plans and providers who use electronic medical records (EMR) either internally or to invoice insurance companies. The Privacy Rule defines safeguards to protect patient privacy, whether it is disclosed intentionally or not. What does that mean for you?

    The Standards for Privacy of Individually Identifiable Health Information (โ€œPrivacy Ruleโ€) established, for the first time, a set of national standards for the protection of certain health information. Before 1996, states had their own laws in place for patient information. Laws could vary in stringency and penalties for non-compliance were not equally severe. There were also some federal privacy laws in place, but it was a gray area, especially since the use of computers for holding the data of patient files or sending it to insurance companies for claims was not at all widespread until the late 90s.

    With new uses for electronic media, storage, and transmission, there was a need for new rules that every healthcare practitioner or institution would adhere to. Some doctors or health insurance companies were selling and distributing patientsโ€™ private health histories or medical records. HIPAA changed the rules to protect patient privacy; there must be a valid medical reason to transmit patient information and the patient must be informed of the intent and give permission in each case. It also mandates that a patient may access his or her own medical files at any time.

    What is protected health information?

    The Privacy Rule protects all individually identifiable health information (IIHI) held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information protected health information (PHI). This includes:

    ยทย ย ย ย ย ย  the individualโ€™s past, present or future physical or mental health orย condition

    ยทย ย ย ย ย ย  the provision of health care to the individual, or

    ยทย ย ย ย ย ย  the past, present, or future payment for the provision of health care to theย individual

    and that identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual. IIHI includes many common identifiers such as name, address, birth date, Social Security Number, and not so common identifiers like IP or URL addresses.

    Who needs to comply?

    The Privacy Rule, as well as all the Administrative Simplification rules, apply to health plans, health care clearinghouses, and to any health care provider who transmits health information in electronic form.ย  This includes Business Associates of those entities, which is any company or organization that may have access to PHI in the course of its business with the healthcare provider.ย  Business Associates must also comply with HIPAA rules. The laws regarding compliance are complex and the procedures and policies that are required should be reviewed every year. Even the smallest HIPAA violation may result in initiating a compliance investigation which can lead to civil and criminal penalties or the need for government imposes corrective action plans.ย  The government will not except any excuses for failing to comply with HIPAA.

    How to protect yourself

    Navigating and complying with HIPAA Privacy Rules takes serious resources. Rules can and do change as the landscape of electronic security evolves. Protecting patient data requires a forward-thinking and broad perspective. To mitigate risk of a data breach or accidental non-compliance, it makes sense to trust experienced experts who will guide you in all aspects of HIPAA compliance.

    Colington Consultants will help you implement and maintain a comprehensive HIPAA compliance program. We offer cost-effective consulting services for HIPAA Security and Privacy Rule compliance.ย Call us atย 844.740.7100ย today to schedule a free, initial consultation.

    This blog was previously posted May 11, 2018

  • The End of HIPAA Audits?

    Recently, Department of Health and Human Servicesโ€™ Office for Civil Rights Director Roger Severino signaled an end to the latest wave of HIPAA audits โ€“ but โ€œno slowdown in our enforcement efforts.โ€

    What does this mean for your medical practice and its liability under the Health Insurance Portability and Accountability Act of 1996 (HIPAA)?

    According to Severino, the Office for Civil Rights (OCR) is examining its regulations to determine whether โ€œundue burdenโ€ on the health care industry can be eased. Under the Trump administrationโ€™s executive order, two regulations need to be removed for every new regulation implemented. Acknowledging that โ€œwe are in a deregulatory environment,โ€ Severino disclosed that the U.S. Department of Health and Human Services (HHS), along with the OCR, are reviewing their regulations to see if benefits and outcomes are outweighing costs.

    As a result, the OCR has ended Phase 2 of the HIPAA audit program in which HHS had randomly requested documentation and evidence from organizations required to be HIPAA compliant. These โ€œdesk auditsโ€ were conducted to assess the overall compliance of both covered entities and business associates with plans to share the results gathered through the audit process and issue guidance identifying compliance challenges and best practices. The final phase of this audit program will be the compilation of those findings to be made public.

    However, Severino has warned that the OCR is โ€œstill looking for big, juicy egregious casesโ€ for enforcement of HIPAA rules and procedures, adding that entities large and small are still in the OCRโ€™s crosshairs. โ€œWeโ€™d like to put ourselves out of business [as an enforcement agency],โ€ Severino has said. โ€œUnfortunately, [cases] are growing steeply up.โ€

    In fact, since 2009, access to about 177 million medical records have been breached, resulting in 50 settlement agreements and three civil monetary penalty cases as a result. In 2016, the OCR collected nearly $25 million in HIPAA-related settlements and collected another $19.4 million in 2017.

    According to the OCR, 38 percent of reported cases of data breaches affecting 500 or more individuals were the result of theft, with about one in five of those breaches involving paper documents. Online hacking constituted 19 percent of reported security breaches and that number is growing.

    This is why due diligence when it comes to abiding by HIPAA rules and regulation remains a top priority for your practice โ€“ regardless of the desk audits being discontinued. The OCR is still focused on enforcement and issuing heavy fines to medical practices large and small that have experienced a breach of protected health information because of a violation of HIPAA privacy rules.

    To learn more about HIPAA compliance requirements and how it affects your practice, contact Colington Consulting at (800) 773-6379. We are experts in the field of HIPAA rules and procedures. Colington Consulting can help you avoid problems and steep fines by bringing your practice into complete HIPAA compliance. It is what we do best, allowing you to do what you do best โ€ฆ provide health care to your patients.

    This blog was previously posted June 1, 2018

  • The Danger of Disregarding Risk Analysis: The Anthem Case

    by Jay Hodes, President – Colington Consulting

    Anthem, Inc., a defined Business Associate that provided administrative support services for the Anthem Affiliated Covered Entities (Anthem ACE), has committed to a $16 million settlement to the U.S. Department of Health and Human Services, Office for Civil Rights (OCR). This is the largest settlement ever announced by OCR.ย  The outcome of this investigation determined a high risk of HIPAA Security Rule and HIPAA Privacy Rule violations due to a series of โ€œundetected continuous and targeted cyber attack[s] for the apparent purpose of extracting data, otherwise known as an advanced persistent threat attackโ€ that exposed the ePHI of approximately 79 million users between December 2, 2014 and January 27, 2015, including names, social security numbers, medical identification numbers, addresses, dates of birth, email addresses, and employment information.

    The risk was found to have originated via a malicious email phishing attack that at least one Anthem, Inc. employee responded to, thus allowing the cyber attackers easy access.

    The following are the potential violations uncovered by the HHS investigation:

    • The requirement to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI held by Anthem
    • The requirement to implement sufficient procedures to regularly review records of information system activity
    • The requirement to identify and respond to detection of the security incident leading to this breach
    • The requirement to implement sufficient technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights
    • The requirement to prevent unauthorized access to the ePHI of 78,800,000 individuals whose information was maintained in Anthem’s enterprise data warehouse

    The Corrective Action Plan (CAP) signed onto by Anthem includes the following terms:ย 

    • Conducting a detailed and thorough Risk Analysis within 90 days of the CAPโ€™s effective date, including a Statement of Work (SOW) submitted to HHS detailing the process of this Risk Analysis. After receiving appropriate or necessary feedback and input from HHS, then Anthem has 150 days to implement new or updated security measures based on the Risk Analysis findings as well as consequent responses made to the Analysis by HHS.
    • Conducting a thorough review of policies and procedures to ensure thorough compliance with the HIPAA Security Rule.
    • Distributing all updated policies and procedures throughout Anthemโ€™s network of employees and contractors, and ensuring proper transfer of training for this same content.

    As a CE or BA, not enough can be said about the dangers of storing ePHI without proper risk management and analysis.ย In my opinion, Anthem, Inc.โ€™s payment and CAP is considered disproportionate to the potential violations carried out due to this breach and the number of individuals affected.

    Consistent, periodic review of your organizationโ€™s security measures and risk management plan is key to ensuring ongoing compliance with the HIPAA Privacy Rule and HIPAA Security Rule.ย  Despite the size of your organization, effective overall HIPAA compliance program is vital and can help to prevent breaches from occurring.ย 

    This blog was previously posted November 13, 2018

  • Is a HIPAA Violation a Reportable Breach?

    Just because a member of an organizationโ€™s workforce violates HIPAA policies and procedures, it is not necessarily a breach reporting requirement. The significant determination is the extent to which any protected health information (PHI) may have been compromised based on breach rule guidance. So, before getting too technical regarding that determination, here are some cases to consider:

    1. An employee for a healthcare software company loses a computer containing the PHI of 2000 patients. Reportable breach?
    2. A hospital system is the victim of a ransomware attack. Reportable breach?

    A breach is generally an impermissible use or disclosure under the Privacy Rule that compromises the

    security or privacy of the PHI. An impermissible use or disclosure of PHI is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the PHI has been compromised based on a risk assessment of at least the following factors:

    • The nature and extent of the PHI involved, including the types of identifiers and the likelihood of re-identification;
    • The unauthorized person who used the PHI or to whom the disclosure was made;
    • Whether the PHI was actually acquired or viewed; and
    • The extent to which the risk to the PHI has been mitigated.

    Going through this type of breach โ€œrisk assessmentโ€ can be challenging, especially in trying to determine if any PHI was acquired or viewed. To further complicate this process, the guidance does not specify what exactly a โ€œlow probabilityโ€ is. So, this assessment process will take some work.

    Begin by using a decision tree and asking questions such as โ€œWas the PHI disclosure to a person who reasonably would have not been able to retain that information?โ€ and โ€œWas the PHI secured by encryption?โ€ The resulting series of yes or no responses will help to determine whether a breach notification is required.

    In most of these cases, the organizationโ€™s HIPAA Privacy and Security Officials should take the lead with this process. There may be a need to involve the organizationโ€™s healthcare and privacy attorney for advice. Experience and expertise with the process are clearly essential to helping determine probability.

    It is important to document the results, especially in those cases in which a determination was made that it was not a reportable breach. If, for some reason, any of the PHI was in fact compromised and a breach report was not made, demonstrating due diligence in the event an HHS Office for Civil Rights (OCR) investigation is necessary.

    Referencing the numbered case examples above:

    1. This would be a reportable breach if the PHI was not encrypted. However, if the PHI was encrypted, it could be an organizational HIPAA violation based on policies and procedures for mobile devices.
    2. This example is going to be a fact-specific determination. In 2016, OCR issued guidelines on the topic of ransomware attacks. If the PHI was encrypted, it may not be reportable. But any unsecured PHI will be a reportable breach. (See the full fact sheet.) In this case, the possibility exists that there may also be a HIPAA violation based on the cause of the attack and whether proper safeguards were followed by a workforce member or members.

    My advice is to make sure your organizationโ€™s HIPAA Sanction policies and procedures are clear for any violations, even for those cases that are not reportable. Ensure the organization has a comprehensive breach notification policy and accompanying procedures. Be familiar with the breach risk assessment process and be prepared should an impermissible use or disclosure occur.

    This blog was previously posted January 7, 2019

  • HIPAA Best Practices for Employee Termination

    On December 11, 2018, the HHS Office for Civil Rights (OCR) announced a settlement of $111,400 with Pagosa Springs Medical Center (PSMC) located in Colorado. The settlement was the outcome of a HIPAA enforcement action following the findings of an OCR investigation that was triggered by an allegation that a former employee of PSMC still had access to ePHI via a web scheduling client used by PSMC.

    According to OCR Director Roger Severino, โ€œitโ€™s common sense that former employees should immediately lose access to protected patient information upon their separation from employment.โ€ย 

    However, ensuring removal of access alone for the terminated employee would not have prevented PSMC as a Covered Entity (CE) from meeting other HIPAA requirements. OCRโ€™s investigation revealed that PSMC did not have a Business Associate Agreement (BAA) in place with either the web-based scheduling calendar vendor, nor with the employee, thus ensuring the ePHI of 557 individuals were made vulnerable to attacks.

    Under a two-year Corrective Action Plan, PSMC must now update its security management and business associate agreement, as well as its policies and procedures, and must now re-train its employees and workers so that they are up to speed on these changes.

    The takeaway from this settlement agreement is that organizations that do not have or follow procedures to terminate information access privileges upon employee separation that results in a breach face possible HIPAA enforcement action by OCR. It is also important to make sure any process that records, shares, transmits, or modifies ePHI is thoroughly detailed in the BAA. Some CEs attempt to save money and time by establishing a work-around, which involves anonymizing ePHI while using web-based scheduling or communication apps without a BAA. However, such an undertaking is difficult to standardize in the long run. It is ultimately more cost-effective for CEs to take the time and resources to set up a BAA with relevant vendors, in order to avoid an investigation for failing to enforce HIPAA privacy and security mandates.

    Best Practice Lessons from this case:

    • The CE representative facilitating an employeeโ€™s termination must also have the ability and training to revoke and remove any previous access authorizations held by the employee. This must take place at the same time as when the notice of termination is provided.
    • CEs must complete BAAs with any vendor who provides the CE with the ability to record, modify, transmit, or share ePHI.
    • At the time of onboarding, all employees must be made aware that their employer requires them to give up all access and authorizations upon termination or voluntary departure from the company.
    • Training materials for employee onboarding should include privacy and security awareness related to:

    a) use of third-party services and applications;

    b) terms and conditions that trigger the creation of a BAA;

    c) assurances provided by Bas regarding policies and procedures to secure ePHI;

    c) security incident reporting; and

    d) password management.

    • Supervisors and other responsible officials must be trained to undertake oversight of employees’ uses and disclosures of PHI, including ePHI, in order to ensure compliance with HIPAA regulations.

    This blog was previously posted January 14, 2019

  • What Comes Up, Must Go Down: Regulatory Trends and HIPAA

    Enforcement of HIPAA mandates by the HHS Office for Civil Rights (OCR) are more aggressive than ever before, โ€œtotaling $28.7 million from enforcement actionsโ€ in 2018, an increase of 22% from the last record total of $23.5 million in 2016. ย According to an OCR press release, 2018 saw that office establish โ€œan all-time record yearโ€ in HIPAA enforcement activity, settling โ€œ10 casesโ€ and being โ€œgranted summary judgment in a case before an Administrative Law Judge.โ€ One of these 10 cases was the watershed HIPAA settlement with Anthem, Inc. for $16 million.

    OCR Settlements* and Judgement** for 2018

    Jan – FileFax*ย  –ย  $100,000

    Jan – Fresenius Medical Care* – $3,500,000

    Jun – MD Anderson** – $4,348,000

    Augย  – Boston Medical Center*ย  –ย  $100,000

    Sep – Brigham & Womenโ€™s Hospital* – $384,000

    Sep – Mass. General Hospital* – $515,000

    Sep – Advanced Care Hospitalists* – $500,000

    Oct – Allergy Associates of Hartford* – $125,000

    Oct – Anthem, Inc* – $16,000,000

    Nov – Pagosa Springs* – $111,400

    Dec – Cottage Health* – $3,000,000

    Total โ€“ Settlements & Judgement:ย  $28,683,400

    While the current administration did and continues to tout a posture of deregulation, the reality on the ground for organizations that must comply with HIPAA is that OCR has only strengthened its enforcement mechanisms, showing very little tolerance for security and privacy breaches arising from:

    • The mismanagement, or lack of proper storage, transmission, or disposal of patient PHI and ePHI.
    • An incomplete or missing Business Associate Agreement (BAA) made with any and all vendors who might be considered a Business Associates (BA) under HIPAA.
    • Cyberattacks via successful email phishing attempts targeting not just Covered Entity (CE) workers or employees, but also workers or employees of any vendor affiliated with theย  CE.
    • Incompatible or insufficient risk analysis and risk management processes on the part of the CE.

    Out of these 11 instances of verified HIPAA violations,

    • 6 CEs were found to have mismanaged or improperly stored, transmitted, or disposed of patient PHI and ePHI (Fresenius Medical Care North America, FileFax, Inc., MD Anderson, Allergy Associates of Hartford, Pagosa Springs, and Cottage Health)
    • 3 CEs did not have a BAA in place to manage vendors who are considered to be BAs under HIPAA (Advanced Care Hospitalists, Pagosa Springs, and Cottage Health)ย ย 
    • 1 CE experienced an email phishing cyber-attack (Anthem, Inc.)ย 
    • 4 CEs made PHI or patient privacy vulnerable by exposing the same via TV shows, interviews, or recordings (Allergy Associates of Hartford, Boston Medical Center, Brigham and Womenโ€™s Hospital, and Massachusetts General Hospital)
    • 4 CEs lacked HIPAA-mandated risk assessment, risk analysis, risk notification, or risk management protocols (Cottage Health, MD Anderson, Advanced Care Hospitalists, and Fresenius Medical Care North America)

    From this analysis, it can be ascertained that CEs and BAs can avoid facing settlements and judgements due to violations of the HIPAA Privacy Rule and the HIPAA Security Rule by instituting the following โ€œgolden rulesโ€ and ensuring their staff are fully trained in the same:

    • Do have robust and comprehensive plan to assess, identify, report, respond, and manage all security or privacy risks.
    • Do ensure a signed and completed BAA is on file for all BAs
    • Do have highly specific protocols in place governing the collection, storage, transmission, and disposal of patient PHI and ePHI.

    Best practices include annual and periodic training for their workforce, conducting the required security risk assessment in an ongoing/periodic manner, and internally enforcing HIPAA policies and procedures to cover the organizationโ€™s security management processes.

    Organizations, large and small, must be aware of the aggressive posture of enforcement and record settlement amounts under OCR and this current administration. My advice for any organization is to conduct a thorough evaluation of the current HIPAA compliance in place. Make sure all the requirements are covered.ย  If a compliance program is not is place, consider outsourcing and let a consultant do the heavy lifting.ย Often times, a consultant can get the program in place much quicker than relying on the organizationโ€™s internal staff.

    This blog was previously posted February 12, 2019