Category: #CCHIPAA

  • PHI – Striking Fear When It Comes to Being Compromised

    by Jay Hodes, Presidentย – Colington Consultingย 

    I am not sure if those tasked with securing protected health information lose sleep every night worrying if they did enough to safeguard the data their organizations maintain. If they are losing sleep, though, that may be a good thing, because it could show how seriously they take this responsibility. But for the rest, that obnoxious wake up alarm that we all hate at times should be the recent ransomware case that occurred at the Hollywood (CA) Presbyterian Medical Center.

    A letter released by Allen Stefanek, President and CEO of the Center, acknowledged that $17,000 in a ransom was paid to the alleged perpetrators to get their electronic health records back. Stefanek stated the โ€œquickest and most efficient way to restore our systems and administrative functions was to pay the ransom and obtain the decryption key.โ€

    If a hospital system can be put into a virtual shutdown, how vulnerable are millions of small to mid-size providers?

    When conducting HIPAA risk assessments, I ask required questions about contingency, emergency and disaster recovery plans. Some organizations do not realize these are critical elements for HIPAA compliance. Policies and procedures must be in place and address these potential vulnerabilities that could result in a high risk rating. Unless these providers are outsourcing IT services and secure backup is part of the arrangement, many fall short in making sure all PHI maintained is available at all times, regardless of emergency or disaster โ€“ or data being taken hostage, as was the case with Hollywood Presbyterian.

    One of the lessons I learned from my time in Federal law enforcement is to โ€œwhat ifโ€ scenarios to death. Try to determine all the negatives an operation or mission could face, and then have a contingency plan to address each particular scenario. Being prepared is crucial because if something does go bad, a plan is already in place to address it. When it comes to protecting healthcare data, the same philosophy should hold true. There are required HIPAA implementation specifications for the standard of developing and maintaining contingency plans. Policy and procedure must be in place to address areas like data backup, disaster recovery, system criticality analysis and emergency mode operations.

    Although not technically a HIPAA requirement, I always bring up continuity of business operations when talking with clients. It goes beyond needing access to protected health information in emergency conditions. I recommend timelines in cases where a facility cannot be occupied after a natural or man-made disaster and there is the need to assign roles and responsibilities to do certain things, such as locating temporary office space, procuring IT, telecom, and medical equipment and establishing a process to notify patients about the closure or relocation.

    Many larger organizations have procedures in place and routinely test and drill their contingency plans. Small to mid-size organizations must have the same protocols in place; albeit to a lesser extent because of the nature of their business operations.

    Fearing if your organization is going to be compromised is a reality that needs to be faced. Most experts agree it is not if, but when. Having addressed these issues before a breach occurs and having a game plan in place can go a long way in making sure any impact can be minimized as much as possible.

    • Reviewed on June 23, 2026 by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • MACRA โ€“ Are There Additional HIPAA Concerns for Providers?

    By Jay Hodes, President โ€“ Colington Consultingย 

    I am not claiming to be an expert on the Medicare Access and CHIP Reauthorization Act of 2015 (MACRA), other than the inherent emphasis this Act places on HIPAA requirements. The U.S. Department of Health and Human Services, which has a number of internal agencies that deal with patient privacy concerns, is starting to see the need to further enforce required health record safeguards. ย For better or worse, this is what HIPAA is all about. It appears parts of MACRA continue this trend.

    Here is a little background on MACRA. On April 14, 2015, a large bipartisan majority in Congress passed the MACRA. President Obama signed the MACRA into law on April 16, 2015. It repeals the Sustainable Growth Rate (SGR) formula, which linked Medicare annual payment updates for physicians and other professionals to prior year spending and gross domestic product (GDP) growth. MACRA contains scheduled Physician Fee Schedule (PFS) updates, a new Merit-Based Incentive Payment System (MIPS), a new Technical Advisory Committee for assessing Physician Focused Payment Model (PFPM) proposals, and incentive payments for participation in Alternative Payment Models (APMs).

    The Act also includes strict privacy and security requirements for all entities receiving Medicare analyses or data, as well as new annual reporting requirements.

    Obviously there is much more to this Act, but I wanted to address it from the HIPAA compliance perspective. Simply stated, MACRA requirements to maximize payments will require practitioners to meet certain requirements to protect the health information of patients by implementing certified electronic medical records technology. ย 

    If your healthcare organization already carries the designated title of being a Covered Entity, you should be doing this already. This is the foundation of the safeguards under the HIPAA Security Rule, and MACRA makes a number of strongly worded references to privacy and security requirements.ย 

    This means Covered Entities must be conducting HIPAA Risk Assessments and have an overall risk management plan in place. A HIPAA Risk Management Plan is the foundation of any compliance program. Regardless of the size of your practice, a plan is the most essential component for implementing compliance. Contained within the plan must be a policy and procedure on how your organization is going to conduct the risk assessment process. MACRA will put more emphasis on the assessment process in determining vulnerabilities and threats to electronic health information maintained, transmitted and created by Covered Entities. ย 

    If organizations have a comprehensive compliance program in place then there should be no additional HIPAA concerns that MACRA will pose. But for many small to mid-size healthcare providers, it is still a struggle meeting all the HIPAA compliance requirements. And now with some MACRA formulas designed to maximize payments tied to safeguards, the burden will be even greater for these providers.ย 

    With the MACRA roll out in place, there is still time for Covered Entities to have risk assessments conducted. Do not delay โ€” start the process soon to maximize those future payments.ย 

    This blog was previously posted August 10, 2016

  • OCR Announces Initiative to More Widely Investigate Breaches

    OCR Announces Initiative to More Widely Investigate Breaches Affecting Fewer than 500 Individuals

    by Jay Hodes, President – Colington Consulting

    Since the passage of the Health Information Technology for Economic and Clinical Health Act of 2009 and the subsequent implementation of the Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule, OCR has prioritized investigation of reported breaches of protected health information (PHI). The root causes of breaches may indicate entity-wide and industry-wide noncompliance with HIPAAโ€™s regulations, and investigation of breaches provides OCR with an opportunity to evaluate an entityโ€™s compliance programs, obtain correction of any deficiencies, and better understand compliance issues in HIPAA-regulated entities more broadly. ย OCRโ€™s Regional Offices investigate all reported breaches involving the PHI of 500 or more individuals. ย Regional Offices also investigate reports of smaller breaches (involving the PHI of fewer 500 individuals), as resources permit. ย 

    Beginning this month, OCR, through the continuing hard work of its Regional Offices, has begun an initiative to more widely investigate the root causes of breaches affecting fewer than 500 individuals. ย Regional Offices will still retain discretion to prioritize which smaller breaches to investigate, but each office will increase its efforts to identify and obtain corrective action to address entity and systemic noncompliance related to these breaches. ย Among the factors Regional Offices will consider include: ย 

    โ€ข The size of the breach;
    โ€ข Theft ย of or improper disposal of unencrypted PHI;
    โ€ข ย Breaches that involve unwanted intrusions to IT systems (for example, by hacking); The amount, nature and sensitivity of the PHI involved; ย orย 
    โ€ข ย Instances where numerous breach reports from a particular covered entity or business associate raise similar issues. ย ย 

    Regions may also consider the lack of breach reports affecting fewer than 500 individuals when comparing a specific covered entity or business associate to like-situated covered entities and business associates. ย 

    Take Action Now

    If HIPAA compliance assistance is needed for your organization, we specialize in putting compliance programs in place or assessing your current program. We provide a full range of services that include conducting the required HIPAA Risk Assessment, writing and customizing a HIPAA Risk Management Plan (HIPAA Policies and Procedures) for your organization, and providing your entire staff annual required HIPAA Security Awareness & Privacy Training through our web-based platform. Our fees are based on what specifically your organization will need to meet regulatory requirements and reasonably priced to accommodate any budget.

    Letโ€™s start the process with a free, initial consultation. In as little as 15 minutes, we can evaluate your current compliance program to determine if all mandatory privacy and security safeguards are in place to meet government regulations.

    This blog was previously posted August 19, 2016

  • How Prepared is Your Organization for a HIPAA Audit?

    by Jay Hodes, President – Colington Consulting

    Could your organization be prepared for an onsite HIPAA audit in ten days? Before you answer, let me explain what documentation you will need for the auditors, lawyers and investigators the U.S. Health and Human Services (HHS) Office for Civil Rights (OCR) will be sending to your office or business. ย 

    One of the first documents OCR will be asking for is a copy of your most recent HIPAA Risk Assessment. ย Conducting a risk assessment is a regulatory requirement to determine the vulnerabilities and threats to any electronic protected health information your organization accesses, stores, creates or transmits. A checklist is not sufficient, and a comprehensive risk assessment needs to be made available to OCR. ย  ย 

    OCR will be interested in seeing how your organization has attempted to mitigate those vulnerabilities and threats. Just conducting the assessment is not good enough. A remediation plan must be implemented. I always recommend a systematic approach to remediation by addressing high threats first, then on to moderates, and concluding with the lows if actionable items are needed. ย 

    Once the risk assessment is provided, be prepared to hand over any number of HIPAA policies and procedures that an organization must have in place. How do you know what OCR will ask for? That is a tough question to answer. Based on my knowledge from others who have been onsite during an audit or investigation, all bets are off as far as which of those policies and procedures will be requested.ย 

    When you look at the HIPAA Implementation Specifications, all of these must be covered with policies and procedures. As former Assistant Inspector General for Investigations in the HHS IGโ€™s office involved with the oversight of complex criminal investigations, my experience tells me OCR will ask for a lot, if not all, of policies and procedures generated by the organization. ย ย 

    If I were to pick a handful of policies that OCR would be interested in seeing, I would include the Mobile Device Management Policy; Breach Notification Policy; Facility Security Plan and Policy; Audit Control Policy; and the Sanction Policy. All of these are critical areas that must be addressed with not only policy, but procedures on how to implement the policy. ย ย 

    Expect OCR to request documentation regarding the annual HIPAA Security Awareness Training requirement. Your organization will need to show you provided this training to each member of your workforce. This includes all physicians, part-timers, interns and volunteers, along with the rest of the staff. ย 

    I can tell you from my expertise in compliance, if you do not have all the HIPAA requirements currently in place, there is no way an organization can be prepared for audit in ten days. OCR will look for specific dates for items, such as when an access audit was conducted or when a HIPAA Risk Assessment was conducted, as well as entry dates on a maintenance record log. Your organization must be prepared as if any day now a letter is going to arrive from HHS indicating you have been identified for an audit. This will make it easier having required compliance requirements in place and minimize any concerns if that letter does come.

    This blog was previously posted October 24, 2016

  • Training Staff in HIPAA Regulations

    In July 2017, Jay Hodes – President of Colington Consulting, provided comments to the Renal & Urology News regarding the effectiveness of HIPAA Security Awareness Training. ย The HIPAA Security Rule requires that all staff of Covered Entities receive annual HIPAA training. ย This training is also required for members of a Business Associate workforce that must access any protected health information in conducting services. ย 

    With 80% of HIPAA data breaches caused by human error, training your workforce can help to cut down in costly HIPAA fines and penalties and promote a culture of compliance within in your organization. โ€œAt the end of training, the person should walk away feeling like they understand HIPAA better,โ€ Hodes said. โ€œThere is nothing worse for an organization than to have someone say after aย breach, โ€˜No one ever told me I couldn’t take that laptop home’.” ย If your organization is investigated for a HIPAA violation or a data breach, documentation you trained your workforce will be asked for by the HHS Office for Civil Rights. ย 

    There are a number of ways training requirements can be accomplished. ย Whether using a video presentation, an instructor led class , or a web based program, the goal is being able to meet this annual requirement. ย 

    To read the complete article, click here.ย 

  • HIPAA Requirements for Web App Development for Medical Websites

    If you are part of the medical community, you are probably well aware of HIPAA, and the importance of maintaining compliance when it comes to Protected Health Information (PHI). But, do you really understand what you need to do to make sure your web application development for your website is HIPAA compliant?

    Web applications associated to your practice and your website are a great way for patients to interact with their healthcare providers. From accessing test results and paying bills to scheduling appointments, things like patient portals help free up medical staff and enhance productivity. Here are some things you need to be aware of regarding your web app development when it comes to HIPAA compliance.

    Is My Web App HIPAA Compliant?

    In order for your app to be HIPAA compliant, you need to make certain the following is in place:

    ยทย ย ย ย ย ย  Data Transport Encryption: Chances are that the data on your generic website is not encrypted before or during transmission. HIPAA requires that any ePHI (electronic Protected Health Information) be encrypted prior to being transmitted.

    ยทย ย ย ย ย ย  Backup: Your current website server might have a backup, as most web hosts provide backup and restoration features. HIPAA requires that ePHI is backed up for recovery and restoration, if needed. But, do you know if the location of those backup files is HIPAA compliant, too? If not, you may have just unlawfully shared PHI. Anybody hosting, maintaining, or monitoring server space containing PHI should adhere to the Business Associate Agreement, addressed below.

    ยทย ย ย ย ย ย  Authorization: You may already have authorization in place on your medical app, or you may not. This needs to be confirmed. The only people who should have access to ePHI are authorized staff members trained and versed in HIPAA compliance rules, or a serious breach could easily occur.

    ยทย ย ย ย ย ย  Data Integrity: On a generic website or app, there is no guarantee that data has not been modified. You must make certain that ePHI is not subject to unsanctioned changes.

    ยทย ย ย ย ย ย  Storage Encryption: Generic websites do not encrypt stored data. Stored data must be encrypted to ensure patient privacy.

    ยทย ย ย ย ย ย  Disposal: This might already exist on a generic website.ย  Just be aware that some web hosting providers store backups indefinitely. You must make sure that once ePHI is no longer needed, it can be safely and permanently disposed of.

    ยทย ย ย ย ย ย  Business Associate Agreement: Many web hosting providers do not know what HIPAA is, and will be reluctant to run any risks signing the HIPAA Business Associate Agreement, which might contradict their own business processes. It is imperative that your ePHI is hosted on servers of a company with whom a Business Associate Agreement is in place, and signed. The alternative is to host your ePHI on secure in-house servers.

    It is important to note that every vendor that deals with your patient health data must sign a Business Associate Agreement in order for you to be HIPAA compliant. It is imperative that your web hosting provider follows security requirements and provides infrastructure that is HIPAA compliant. The same is true for website design and functionality.

    Privacy Policy

    It is strongly encouraged that health app developers and any party associated with a website or app โ€“ that must be HIPAA compliant due to hosting patient health information โ€“ acknowledge and accept a well-defined privacy policy. This is not the same as a notice of privacy practices, as it signifies individual responsibility towards protecting patient rights.

    Need Help?

    HIPAA compliance can be complex, and breaches are messy and costly. It is important that your business understands what is necessary and appropriate to protect ePHI during the creation and maintenance of healthcare applications and websites.

    If you are concerned about your businessโ€™s privacy and security needs and HIPAA compliance, contact us at 800-733-6379. We are experts in the field of HIPAA rules and procedures. Colington Consulting can help you avoid reputation problems and steep fines, by bringing your business into complete HIPAA compliance. It is what we do best, allowing you to do what you do bestโ€ฆprovide health care to your patients.

    This blog was previously posted February 14, 2018

  • The Elements of a HIPAA Risk Analysis

    by Jay Hodes, President – Colington Consulting

    The Department of Health and Human Services (HHS) requires all Covered Entities and Business Associates handling protected health information to conduct a risk analysis as the first step toward implemented safeguards specified in The HIPAA (Health Insurance Portability and Accountability Act) Security Rule, and actively maintaining HIPAA compliance.

    At first glance, it may seem like a daunting task. But itโ€™s a necessary one that can help protect your practice from costly violations while โ€“ more importantly โ€“ protecting your patientsโ€™ privacy and personal security.

    Nine Key Components

    There are numerous methods of performing risk analysis and there is no single method or โ€œbest practiceโ€ that guarantees compliance with the Security Rule.

    However, the HHS Security Standards Guide outlines nine mandatory components of a risk analysis that healthcare organizations and healthcare-related organizations that store or transmit electronic protected health information (ePHI) must include in their document:

    • Scope of the Analysis โ€“ This addresses any potential risks and vulnerabilities to the privacy, availability, and integrity of ePHI. It includes all electronic media your organization uses to create, receive, maintain or transmit ePHI such as portable media, desktops, and networks. Network security between multiple locations is also important to include, and may include aspects of your HIPAA hosting terms with a third party or business associate.
    • Data Collection โ€“ This focuses on where the ePHI goes. You need to locate where data is being stored, received, maintained, or transmitted. If youโ€™re hosting at a HIPAA compliant data center, youโ€™ll need to contact your hosting provider to document where and how your data is stored.
    • Potential Threats and Vulnerabilities โ€“ Identify and document sensitive data and any vulnerabilities that may lead to the leaking of ePHI. By anticipating any potential HIPAA violations, you can help your organization reach a resolution swiftly and effectively.
    • Current Security Measures โ€“ Assess the kind of security measures youโ€™re taking to protect your data. This might include any encryption, two-factor authentication, or other security methods out in place by your HIPAA hosting provider.
    • Likelihood of Threat Occurrence โ€“ Determine the probability of potential risks to ePHI. This assessment allows for estimates on the likelihood of ePHI breaches.
    • Potential Impact of Threat Occurrence โ€“ Use qualitative or quantitative methods to assess the maximum impact of a data threat to your organization. Question how many people could be affected and to what extent private data โ€“ medical records or both health information and billing information –could be exposed.
    • Determine the Level of Risk โ€“ HHS suggest taking the average of the assigned likelihood and impact levels to determine the level of risk. Documented risk levels should be accompanied by a list of corrective actions that can be performed to mitigate risk.
    • Documentation Finalization โ€“ Compile everything in an organized document. Any format will suffice as long as the analysis is in writing.
    • Periodic Review and Updates to the Risk Assessment โ€“ One requirement is that the risk analysis process be conducted on a regular, ongoing basis. The Security Rule doesnโ€™t set a required timeline, but HHS recommends that organizations conduct another risk analysis whenever your company implements or plans to adopt new technology or business operations. This could include switching your data storage methods from managed servers to cloud computing, and updating after any ownership or key staff turnover.

    Take Action Now

    Performing a risk analysis is a complex process. The HIPAA compliance experts at Colington Consulting have conducted numerous compliance assessments. You can benefit from their expertise in knowing what is reasonable and appropriate for your organization. They understand the field of HIPAA rules and procedures and can help you avoid problems and steep fines by helping your organization maintain complete HIPAA compliance. It is what they do best, allowing you to do what you do best โ€ฆ provide health care to your patients. Contact Colington Consulting today at 800-773-6379.

    This blog was previously posted March 2, 2018

  • What is the HIPAA Privacy Rule?

    Part of the Heath Insurance Portability and Accountability Act (HIPAA) that became law in 1996, the HIPAA Privacy Rule defined the part of the law that protects patientsโ€™ protected health information (PHI). Among organizations this rule applies to are health plans and providers who use electronic medical records (EMR) either internally or to invoice insurance companies. The Privacy Rule defines safeguards to protect patient privacy, whether it is disclosed intentionally or not. What does that mean for you?

    The Standards for Privacy of Individually Identifiable Health Information (โ€œPrivacy Ruleโ€) established, for the first time, a set of national standards for the protection of certain health information. Before 1996, states had their own laws in place for patient information. Laws could vary in stringency and penalties for non-compliance were not equally severe. There were also some federal privacy laws in place, but it was a gray area, especially since the use of computers for holding the data of patient files or sending it to insurance companies for claims was not at all widespread until the late 90s.

    With new uses for electronic media, storage, and transmission, there was a need for new rules that every healthcare practitioner or institution would adhere to. Some doctors or health insurance companies were selling and distributing patientsโ€™ private health histories or medical records. HIPAA changed the rules to protect patient privacy; there must be a valid medical reason to transmit patient information and the patient must be informed of the intent and give permission in each case. It also mandates that a patient may access his or her own medical files at any time.

    What is protected health information?

    The Privacy Rule protects all individually identifiable health information (IIHI) held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information protected health information (PHI). This includes:

    ยทย ย ย ย ย ย  the individualโ€™s past, present or future physical or mental health orย condition

    ยทย ย ย ย ย ย  the provision of health care to the individual, or

    ยทย ย ย ย ย ย  the past, present, or future payment for the provision of health care to theย individual

    and that identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual. IIHI includes many common identifiers such as name, address, birth date, Social Security Number, and not so common identifiers like IP or URL addresses.

    Who needs to comply?

    The Privacy Rule, as well as all the Administrative Simplification rules, apply to health plans, health care clearinghouses, and to any health care provider who transmits health information in electronic form.ย  This includes Business Associates of those entities, which is any company or organization that may have access to PHI in the course of its business with the healthcare provider.ย  Business Associates must also comply with HIPAA rules. The laws regarding compliance are complex and the procedures and policies that are required should be reviewed every year. Even the smallest HIPAA violation may result in initiating a compliance investigation which can lead to civil and criminal penalties or the need for government imposes corrective action plans.ย  The government will not except any excuses for failing to comply with HIPAA.

    How to protect yourself

    Navigating and complying with HIPAA Privacy Rules takes serious resources. Rules can and do change as the landscape of electronic security evolves. Protecting patient data requires a forward-thinking and broad perspective. To mitigate risk of a data breach or accidental non-compliance, it makes sense to trust experienced experts who will guide you in all aspects of HIPAA compliance.

    Colington Consultants will help you implement and maintain a comprehensive HIPAA compliance program. We offer cost-effective consulting services for HIPAA Security and Privacy Rule compliance.ย Call us atย 844.740.7100ย today to schedule a free, initial consultation.

    This blog was previously posted May 11, 2018

  • The End of HIPAA Audits?

    Recently, Department of Health and Human Servicesโ€™ Office for Civil Rights Director Roger Severino signaled an end to the latest wave of HIPAA audits โ€“ but โ€œno slowdown in our enforcement efforts.โ€

    What does this mean for your medical practice and its liability under the Health Insurance Portability and Accountability Act of 1996 (HIPAA)?

    According to Severino, the Office for Civil Rights (OCR) is examining its regulations to determine whether โ€œundue burdenโ€ on the health care industry can be eased. Under the Trump administrationโ€™s executive order, two regulations need to be removed for every new regulation implemented. Acknowledging that โ€œwe are in a deregulatory environment,โ€ Severino disclosed that the U.S. Department of Health and Human Services (HHS), along with the OCR, are reviewing their regulations to see if benefits and outcomes are outweighing costs.

    As a result, the OCR has ended Phase 2 of the HIPAA audit program in which HHS had randomly requested documentation and evidence from organizations required to be HIPAA compliant. These โ€œdesk auditsโ€ were conducted to assess the overall compliance of both covered entities and business associates with plans to share the results gathered through the audit process and issue guidance identifying compliance challenges and best practices. The final phase of this audit program will be the compilation of those findings to be made public.

    However, Severino has warned that the OCR is โ€œstill looking for big, juicy egregious casesโ€ for enforcement of HIPAA rules and procedures, adding that entities large and small are still in the OCRโ€™s crosshairs. โ€œWeโ€™d like to put ourselves out of business [as an enforcement agency],โ€ Severino has said. โ€œUnfortunately, [cases] are growing steeply up.โ€

    In fact, since 2009, access to about 177 million medical records have been breached, resulting in 50 settlement agreements and three civil monetary penalty cases as a result. In 2016, the OCR collected nearly $25 million in HIPAA-related settlements and collected another $19.4 million in 2017.

    According to the OCR, 38 percent of reported cases of data breaches affecting 500 or more individuals were the result of theft, with about one in five of those breaches involving paper documents. Online hacking constituted 19 percent of reported security breaches and that number is growing.

    This is why due diligence when it comes to abiding by HIPAA rules and regulation remains a top priority for your practice โ€“ regardless of the desk audits being discontinued. The OCR is still focused on enforcement and issuing heavy fines to medical practices large and small that have experienced a breach of protected health information because of a violation of HIPAA privacy rules.

    To learn more about HIPAA compliance requirements and how it affects your practice, contact Colington Consulting at (800) 773-6379. We are experts in the field of HIPAA rules and procedures. Colington Consulting can help you avoid problems and steep fines by bringing your practice into complete HIPAA compliance. It is what we do best, allowing you to do what you do best โ€ฆ provide health care to your patients.

    This blog was previously posted June 1, 2018

  • The Danger of Disregarding Risk Analysis: The Anthem Case

    by Jay Hodes, President – Colington Consulting

    Anthem, Inc., a defined Business Associate that provided administrative support services for the Anthem Affiliated Covered Entities (Anthem ACE), has committed to a $16 million settlement to the U.S. Department of Health and Human Services, Office for Civil Rights (OCR). This is the largest settlement ever announced by OCR.ย  The outcome of this investigation determined a high risk of HIPAA Security Rule and HIPAA Privacy Rule violations due to a series of โ€œundetected continuous and targeted cyber attack[s] for the apparent purpose of extracting data, otherwise known as an advanced persistent threat attackโ€ that exposed the ePHI of approximately 79 million users between December 2, 2014 and January 27, 2015, including names, social security numbers, medical identification numbers, addresses, dates of birth, email addresses, and employment information.

    The risk was found to have originated via a malicious email phishing attack that at least one Anthem, Inc. employee responded to, thus allowing the cyber attackers easy access.

    The following are the potential violations uncovered by the HHS investigation:

    • The requirement to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI held by Anthem
    • The requirement to implement sufficient procedures to regularly review records of information system activity
    • The requirement to identify and respond to detection of the security incident leading to this breach
    • The requirement to implement sufficient technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights
    • The requirement to prevent unauthorized access to the ePHI of 78,800,000 individuals whose information was maintained in Anthem’s enterprise data warehouse

    The Corrective Action Plan (CAP) signed onto by Anthem includes the following terms:ย 

    • Conducting a detailed and thorough Risk Analysis within 90 days of the CAPโ€™s effective date, including a Statement of Work (SOW) submitted to HHS detailing the process of this Risk Analysis. After receiving appropriate or necessary feedback and input from HHS, then Anthem has 150 days to implement new or updated security measures based on the Risk Analysis findings as well as consequent responses made to the Analysis by HHS.
    • Conducting a thorough review of policies and procedures to ensure thorough compliance with the HIPAA Security Rule.
    • Distributing all updated policies and procedures throughout Anthemโ€™s network of employees and contractors, and ensuring proper transfer of training for this same content.

    As a CE or BA, not enough can be said about the dangers of storing ePHI without proper risk management and analysis.ย In my opinion, Anthem, Inc.โ€™s payment and CAP is considered disproportionate to the potential violations carried out due to this breach and the number of individuals affected.

    Consistent, periodic review of your organizationโ€™s security measures and risk management plan is key to ensuring ongoing compliance with the HIPAA Privacy Rule and HIPAA Security Rule.ย  Despite the size of your organization, effective overall HIPAA compliance program is vital and can help to prevent breaches from occurring.ย 

    This blog was previously posted November 13, 2018