Category: HIPAA Audits

  • OCRโ€™s 2024 HIPAA Audits & Clarification on Breach Reporting

    By Jay Hodes, President โ€“ Colington Consulting

    In February of this year, the U.S. Department of Health and Human Services (HHS) published an Agency Information Collection Request in the Federal Register. The request indicates the HHS Office for Civil Rights (OCR), the agency that enforces HIPAA compliance, is looking to initiate a HIPAA Audit Review Survey. OCR, according to the request, โ€œis conducting a review of the 2016-2017 HIPAA Audits to determine its efficacy in assessing the HIPAA compliance efforts of covered entities.โ€ The abstract states โ€œinformation collection consists of 39 online survey questions that will be sent to 207 covered entities and business associates that participated in the 2016-2017 OCR HIPAA Audits. The survey will gather information relating to the effect of the audits on the audited entities and the entities’ opinions about the audit process.โ€

    The good news, at least from the early indication in the request, is that these new audits will only affect organizations that participated in the prior audits. With a limited budget and lack of staffing, OCR will be hard pressed to go beyond what is indicated in the request. In the past, OCR contracted out parts of the audit program and it remains to be seen if that will also occur with this new round of audits. Publicly, OCR has not provided any information as to when the audits would begin.

    When the audits do begin, OCR will use an online survey to:

    • Measure the effect of the 2016-2017 HIPAA Audits on covered entities’ and business associates’ subsequent actions to comply with the HIPAA Rules.
    • Provide entities with an opportunity to give feedback on the Audit and its features, such as the helpfulness of HHS’ guidance materials and communications, the utility of the online submission portal, whether the Audit helped improve entity compliance, and the entities’ responses to the Audit-report findings and recommendations.
    • Provide OCR with information on the burden imposed on entities to collect audit-related documents and to respond to audit-related requests; and
    • Seek feedback on the effect of the HIPAA Audit program on the entities’ day-to-day business operations.
    • The information, opinions, and comments collected using the online survey will be used to improve future OCR HIPAA Audits.

    The limited scope of these planned audits does not mean organizations that must comply with HIPAA regulations are off the hook because they were not included in the initial group. Organizations are still required to comply with all HIPAA regulatory compliance requirements, including a self-reporting breach notification to HHS OCR if any PHI or ePHI is compromised, regardless of how many individuals were affected. If the breach affects 500 individuals or more, the likelihood of an OCR investigation is probable.

    Last week, OCR sent out through their listserv, a FAQ regarding updated clarification on Change Healthcare Cybersecurity Incident. As part of one of the FAQs, OCR provided a summary of breach notification requirements and reporting procedures for covered entities.

    As an important reminder, if a breach of unsecured PHI or ePHI affects 500 or more individuals, a covered entity must notify the HHS OCR of the breach without unreasonable delay and in no case later than 60 calendar days from the discovery of the breach. The notification clock starts the day the breach is discovered.

    OCR also indicated if the number of individuals affected by a breach is uncertain at the time of notification submission, the covered entity should provide an estimate, and, if it discovers additional information, submit updates in the manner specified below. If only one option is available in a particular submission category, the covered entity should pick the best option, and may provide additional details in the free text portion of the submission.

    Organizations should use the planned HIPAA Audit Review Survey as a proactive exercise to determine compliance with all aspects of HIPAA, including breach notification requirements.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    Allow our team of regulatory experts to assess your organizationโ€™s compliance with the HIPAA Security and Privacy Rules, the risk assessment process, and breach notification requirements. We offer customized services to meet specific requirements for your organization, making HIPAA compliance strategies effective and efficient. For a free, initial consultation to see how we can assist your organization, give our office a call at 844.740.7100.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • How Prepared is Your Organization for a HIPAA Audit?

    by Jay Hodes, President – Colington Consulting

    Could your organization be prepared for an onsite HIPAA audit in ten days? Before you answer, let me explain what documentation you will need for the auditors, lawyers and investigators the U.S. Health and Human Services (HHS) Office for Civil Rights (OCR) will be sending to your office or business. ย 

    One of the first documents OCR will be asking for is a copy of your most recent HIPAA Risk Assessment. ย Conducting a risk assessment is a regulatory requirement to determine the vulnerabilities and threats to any electronic protected health information your organization accesses, stores, creates or transmits. A checklist is not sufficient, and a comprehensive risk assessment needs to be made available to OCR. ย  ย 

    OCR will be interested in seeing how your organization has attempted to mitigate those vulnerabilities and threats. Just conducting the assessment is not good enough. A remediation plan must be implemented. I always recommend a systematic approach to remediation by addressing high threats first, then on to moderates, and concluding with the lows if actionable items are needed. ย 

    Once the risk assessment is provided, be prepared to hand over any number of HIPAA policies and procedures that an organization must have in place. How do you know what OCR will ask for? That is a tough question to answer. Based on my knowledge from others who have been onsite during an audit or investigation, all bets are off as far as which of those policies and procedures will be requested.ย 

    When you look at the HIPAA Implementation Specifications, all of these must be covered with policies and procedures. As former Assistant Inspector General for Investigations in the HHS IGโ€™s office involved with the oversight of complex criminal investigations, my experience tells me OCR will ask for a lot, if not all, of policies and procedures generated by the organization. ย ย 

    If I were to pick a handful of policies that OCR would be interested in seeing, I would include the Mobile Device Management Policy; Breach Notification Policy; Facility Security Plan and Policy; Audit Control Policy; and the Sanction Policy. All of these are critical areas that must be addressed with not only policy, but procedures on how to implement the policy. ย ย 

    Expect OCR to request documentation regarding the annual HIPAA Security Awareness Training requirement. Your organization will need to show you provided this training to each member of your workforce. This includes all physicians, part-timers, interns and volunteers, along with the rest of the staff. ย 

    I can tell you from my expertise in compliance, if you do not have all the HIPAA requirements currently in place, there is no way an organization can be prepared for audit in ten days. OCR will look for specific dates for items, such as when an access audit was conducted or when a HIPAA Risk Assessment was conducted, as well as entry dates on a maintenance record log. Your organization must be prepared as if any day now a letter is going to arrive from HHS indicating you have been identified for an audit. This will make it easier having required compliance requirements in place and minimize any concerns if that letter does come.

    This blog was previously posted October 24, 2016

  • The End of HIPAA Audits?

    Recently, Department of Health and Human Servicesโ€™ Office for Civil Rights Director Roger Severino signaled an end to the latest wave of HIPAA audits โ€“ but โ€œno slowdown in our enforcement efforts.โ€

    What does this mean for your medical practice and its liability under the Health Insurance Portability and Accountability Act of 1996 (HIPAA)?

    According to Severino, the Office for Civil Rights (OCR) is examining its regulations to determine whether โ€œundue burdenโ€ on the health care industry can be eased. Under the Trump administrationโ€™s executive order, two regulations need to be removed for every new regulation implemented. Acknowledging that โ€œwe are in a deregulatory environment,โ€ Severino disclosed that the U.S. Department of Health and Human Services (HHS), along with the OCR, are reviewing their regulations to see if benefits and outcomes are outweighing costs.

    As a result, the OCR has ended Phase 2 of the HIPAA audit program in which HHS had randomly requested documentation and evidence from organizations required to be HIPAA compliant. These โ€œdesk auditsโ€ were conducted to assess the overall compliance of both covered entities and business associates with plans to share the results gathered through the audit process and issue guidance identifying compliance challenges and best practices. The final phase of this audit program will be the compilation of those findings to be made public.

    However, Severino has warned that the OCR is โ€œstill looking for big, juicy egregious casesโ€ for enforcement of HIPAA rules and procedures, adding that entities large and small are still in the OCRโ€™s crosshairs. โ€œWeโ€™d like to put ourselves out of business [as an enforcement agency],โ€ Severino has said. โ€œUnfortunately, [cases] are growing steeply up.โ€

    In fact, since 2009, access to about 177 million medical records have been breached, resulting in 50 settlement agreements and three civil monetary penalty cases as a result. In 2016, the OCR collected nearly $25 million in HIPAA-related settlements and collected another $19.4 million in 2017.

    According to the OCR, 38 percent of reported cases of data breaches affecting 500 or more individuals were the result of theft, with about one in five of those breaches involving paper documents. Online hacking constituted 19 percent of reported security breaches and that number is growing.

    This is why due diligence when it comes to abiding by HIPAA rules and regulation remains a top priority for your practice โ€“ regardless of the desk audits being discontinued. The OCR is still focused on enforcement and issuing heavy fines to medical practices large and small that have experienced a breach of protected health information because of a violation of HIPAA privacy rules.

    To learn more about HIPAA compliance requirements and how it affects your practice, contact Colington Consulting at (800) 773-6379. We are experts in the field of HIPAA rules and procedures. Colington Consulting can help you avoid problems and steep fines by bringing your practice into complete HIPAA compliance. It is what we do best, allowing you to do what you do best โ€ฆ provide health care to your patients.

    This blog was previously posted June 1, 2018