Category: HIPAA Best Practices

  • Does HIPAA Prohibit the Use of Patient Sign-In Sheets?

    A common misconception among medical practices, dental clinics, and physical therapy centers is that the HIPAA Privacy Rule completely outlaws physical or digital patient sign-in sheets.

    It does not.

    The U.S. Department of Health and Human Services (HHS) explicitly permits the use of patient sign-in sheets. However, they are classified under the “incidental disclosure” doctrine. This means that while a sign-in sheet is a permissible administrative tool, its usage is legal only if your practice implements reasonable physical and administrative safeguards to limit the exposure of Protected Health Information (PHI).

    Leaving a highly detailed running list of patient data exposed on a clipboard at the front desk is a compliance failure that invites complaints, OCR scrutiny, and potential penalties.

    The Core Rule: What Can (and Cannot) Be Visible

    Under the HIPAA Privacy Rule, a sign-in sheet cannot serve as a clinical history log. Other patients standing at the front desk should only see the bare minimum required to check someone in.

    Permissible Information on a Sign-In Sheet

    Under the HIPAA Privacy Rule, a sign-in sheet is allowed to capture the bare minimum required for basic administrative check-in. It is completely acceptable to ask for the patient’s name, their arrival time, and the name of the specific doctor or provider they are scheduled to see.

    Strictly Prohibited Data (HIPAA Violations)

    The line is crossed when a sign-in sheet begins to act as a clinical history log. To avoid a compliance violation, a sign-in sheet must never display the reason for the visit or medical symptoms, any medical conditions or diagnoses, insurance provider details, or sensitive personal identifiers like a Social Security Number or Date of Birth.

    The Red Line: A patient standing at the counter should never be able to look at the sheet and deduce why the person before them is visiting the clinic. Writing “John Doe โ€” 10:00 AM” is acceptable. Writing “John Doe โ€” 10:00 AM โ€” Chest Pain” or “John Doe โ€” Oncologist Dr. Smith” in a multi-specialty clinic crosses into non-compliant PHI exposure.

    Actionable Safeguards: Moving Beyond the Clipboard

    To ensure your sign-in process is legally defensible during a compliance review, your practice must implement operational controls. Relying on an open-face, continuous paper logbook is no longer a best practice.

    Implement these three physical and technical safeguards immediately:

    1. Peel-Off / Label Sign-In Sheets

    If your practice relies on paper, use a security sign-in sheet system featuring adhesive peel-off strips. When a patient signs in, the front desk receptionist peels off the strip containing the name and takes it to the back office. The next patient only sees a blank backing sheet, completely eliminating the risk of peer-to-peer data exposure.

    2. Physical Barrier Controls

    Position the sign-in area so it is entirely within the clear line of sight of your administrative staff, but shielded from waiting room occupants. Use privacy screens or desk geometry to ensure that patients standing in line cannot hover over or read the clipboard.

    3. Digital Intake Kiosks (Technical Safeguards)

    Many modern practices have shifted to tablets or digital kiosks. While an excellent alternative to paper, kiosks introduce technical safeguard requirements. Ensure that:

    • The screen automatically times out or clears after a brief period of inactivity.
    • Privacy filters are installed on the glass to prevent “shoulder surfing.”
    • The software does not display a rolling list of previously checked-in patients on the home screen.

    Workforce Compliance: Training the Front Desk

    Even the best physical safeguards fail without continuous workforce enforcement. Your administrative staff must understand that handling sign-in sheets requires active risk ownership.

    • Turn It Over: If utilizing a temporary paper sheet, staff must flip the clipboard face-down whenever they step away from the front desk.
    • Shred Daily: Once a paper sign-in sheet or the peeled backing strips have served their administrative purpose for the day, they must be disposed of in a locked shredding bin. They must never be thrown into a standard trash can.
    • Enforce Boundaries: Train front-desk personnel to gently instruct waiting patients to stand back behind a designated marker line until it is their turn to check in.

    Defend Your Process

    Using a patient sign-in sheet is an efficient workflow tool, but it requires deliberate management. Compliance fails when a practice treats day-to-day administrative routines as exempt from privacy standards.

    Is your front desk layout, digital intake process, or paper documentation protocol audit-ready? Colington Consulting provides operational, evidence-based compliance programs that protect your practice from penalties and risk.

    Schedule a 30-Minute HIPAA Risk Review and evaluate your clinic’s safeguards.

    • Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) Guidance on “Incidental Uses and Disclosures” (45 CFR 164.502(a)(1)(iii)).
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Hidden Risks in HIPAA Compliance: What Gets Missed

    The Hidden Risks in Everyday HIPAA Compliance: What Healthcare Organizations Often Miss

    When most healthcare organizations think about HIPAA compliance, they tend to focus on the obvious requirements: encrypting data, updating policies, and completing annual staff training. While these elements are essential, many HIPAA violations stem from everyday operational oversightsโ€”small, non-technical issues that organizations rarely notice until itโ€™s too late.

    Understanding these hidden risks can dramatically strengthen your compliance posture and reduce your exposure to fines, breaches, and reputational damage.

    The Human Element: Small Mistakes, Big Consequences

    Even with perfect policies in place, human behavior remains the biggest source of HIPAA violations. Simple actions like discussing patient information in hallways, leaving charts faceโ€‘up at a nurseโ€™s station, or forgetting to log out of an EHR can all constitute breaches.

    Why it matters:

    The Office for Civil Rights (OCR) penalizes organizations not only for malicious intent but also for preventable negligence. A staff member casually mentioning a patient case in a public area can trigger a breach investigation just as quickly as a sophisticated cyberattack.

    Reduce the risk:

    • Reinforce โ€œminimum necessaryโ€ guidelines.
    • Train staff using realistic, scenario-based examples.
    • Adopt a culture where privacy awareness is part of daily workflowโ€”not just an annual requirement.

    Business Associates: The Most Overlooked HIPAA Exposure Point

    Many breaches occur not within the healthcare organization itself but through its business associatesโ€”IT providers, billing companies, cloud vendors, shredding services, and others.

    Common gaps include:

    • Outdated Business Associate Agreements (BAAs)
    • Vendors accessing Protected Health Information (PHI) without documented authorization
    • Relying on verbal assurances instead of formal due diligence

    Strengthen this area by:

    • Conducting annual vendor risk assessments
    • Maintaining updated BAAs that reflect current services
    • Ensuring vendors have documented security controlsโ€”not just promises

    Device and Media Handling: Security Beyond the Computer Screen

    Lost or stolen devices remain a major cause of reportable breaches. Laptops, tablets, smartphones, and even USB drives are often used in clinical workflowsโ€”and too many of them are unencrypted.

    Key risks:

    • Portable devices left in cars or public areas
    • Clinicians taking photos on personal smartphones
    • Old hard drives discarded without proper sanitization

    Mitigation steps:

    • Enforce encryption on all mobile devices
    • Prohibit personal device photography unless under a compliant, approved process
    • Use certified destruction or wiping tools when disposing of hardware

    Documentation: The Compliance Safety Net

    HIPAA operates under a simple principle:

    If itโ€™s not documented, it didnโ€™t happen.

    You may conduct risk assessments, provide training, or follow proceduresโ€”but without written proof, OCR will assume the activities never occurred.

    Maintain clear documentation for:

    • Policies and procedures
    • Risk assessments
    • Security incident logs
    • Staff training and attestations
    • Vendor agreements and audits

    HIPAA compliance is not a one-time project, itโ€™s a continuous, evolving process. By focusing on daily habits, vendor oversight, mobile device management, and strong documentation, healthcare organizations can significantly improve their compliance readiness and reduce the likelihood of costly violations.

    Colington Consulting

    HIPAA Compliance, Risk Assessment & Management

    Contact our office at 844.740.7100 to schedule a free initial consultation and learn how your organization can meet all compliance requirements with confidence. We are a fullโ€‘service consultancy providing a wide range of HIPAA compliance services. Ask about our Virtual HIPAA Compliance Officer service.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • How HIPAA Consultants Reduce Riskโ€”and Help You Avoid Penalties

    By Jay Hodes, President, Colington Consulting

    HIPAA enforcement isnโ€™t slowing down. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) continues to announce settlements and civil monetary penalties for organizations that fall short on foundational Privacy, Security, and Breach Notification Rule requirements.

    Recent OCR penalties for HIPAA violations have ranged from $25,000 to several million dollars. In most cases, and as part of the settlement agreement, OCR requires the implementation of a corrective action planโ€”often mandating the completion of a risk assessment. In some enforcement actions, smaller organizations were specifically targeted in what are often called โ€œmessageโ€‘sending cases.โ€ OCR uses these to emphasize that no organization, regardless of size, is exempt from its investigative authority.

    When you compare the cost of a proactive compliance program to the risk of an OCR settlement, the math favors prevention every time. Below is how experienced HIPAA consultants reduce riskโ€”mapped directly to the failures OCR highlights in its own enforcement announcements.

    1) Close the #1 Gap OCR Cites: Incomplete Risk Assessment

    Again and again, OCR settlements point to failures to conduct an โ€œaccurate and thoroughโ€ risk assessment as required under the Security Rule.

    Examples:

    • Syracuse ASC (NY): Ransomware breach affecting 24,891 individuals.
    • Comstar, LLC (MA): Ransomware attack affecting 585,621 individuals.
    • Guam Memorial Hospital Authority: Multiโ€‘year Corrective Action Plan after ransomware and hacking complaints.

    2) Build Policies and Procedures to Meet Required Standards & Specifications

    Consultants update or create Privacy, Security, and Breach Notification policies that reflect realโ€‘world workflows and withstand OCR document requests as part of an investigative followโ€‘up process.

    3) Reduce Human Error with Roleโ€‘Based Training

    OCRโ€™s Rightโ€‘ofโ€‘Access and other enforcement actions repeatedly show that many violations stem from inadequate training and poor compliance program management.

    4) Harden Technical Safeguards Before an Incident

    Consultants align access controls, encryption, audit requirements, cloud storage of ePHI, and monitoring with current OCR expectations.

    5) Prepare for Incident Response and Breach Management

    Consultants build incident response playbooks and ensure breach determinations and notifications meet HHS deadlines and documentation standards. This requirement sometimes gets overlooked by organizations.

    6) Provide Continuous Complianceโ€”Not a Oneโ€‘Time Fix

    Quarterly reviews, vendor oversight, annual risk assessments, and documented compliance metrics help organizations stay aligned with evolving OCR enforcement trends.

    Why Expertise Matters

    HIPAA is complex, and regulatory expectations evolve each year. OCRโ€™s enforcement data shows that the most common compliance failures include:

    • Impermissible disclosures
    • Inadequate safeguards
    • Insufficient risk assessments

    A HIPAA consultant brings deep knowledge of these requirements, current enforcement trends, and industry best practices. They understand how OCR interprets the Security and Privacy Rules, how to reduce liability, and which corrective actions are essential for compliance.

    More importantly, expert consultants provide tailored services based on an organizationโ€™s requirements, workflows, systems, and risk profileโ€”not generic checklists. They can identify vulnerabilities internal teams may miss and recommend practical, costโ€‘effective solutions that strengthen compliance while supporting operational efficiency.

    The Takeaway

    With OCR investigations increasingly focused on cyber incidents, risk assessment gaps, and failures to meet Security Rule standards, organizations cannot afford to take a reactive approach. The financial, operational, and reputational consequences of noncompliance far outweigh the investment in proper guidance.

    Engaging a HIPAA consultant is not just a compliance strategyโ€”it is a costโ€‘saving one. By proactively addressing risks, organizations can avoid multimillionโ€‘dollar penalties, maintain patient trust, and build a culture of privacy and security that supports longโ€‘term success.

    Colington Consulting

    HIPAA Compliance, Risk Assessment & Management

    Contact our office at 844.740.7100 to schedule a free initial consultation and learn how your organization can meet all compliance requirements with confidence. We are a fullโ€‘service consultancy providing a wide range of HIPAA compliance services. Ask about our Virtual HIPAA Compliance Officer service.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Do Not Be on Santa’s Naughty HIPAA List

    What Your Organization Can Do in the Final Days of 2025 to Meet HIPAA Compliance Requirements

    As the year winds down and Santa is prepping his sleigh for the big night, your organization should be doing the sameโ€”except instead of reindeer and jingling bells, you need policies, procedures, and safeguards that keep you off the Naughty HIPAA List. Trust me, you donโ€™t want coal in your compliance stocking.

    Picture this: Santa slides down your chimney, ready to leave gifts under the tree. But instead of cookies and milk, he finds unsecured patient health information easily accessible and sitting out like yesterdayโ€™s fruitcake. Uh-oh! Thatโ€™s a fast track to the Naughty Listโ€”and possibly leading to a breach and resulting compliance investigation from the Office for Civil Rights (OCR). So, what can you do in these final days of 2025 to make sure your compliance sleigh is ready for takeoff?

    1. Check Your List (Twice!)

    Santa double-checks his list, and so should you. Review your HIPAA policies and procedures to ensure they are current and reflect any regulatory updates from this year. If your last risk assessment was done when flip phones were still cool, itโ€™s time for an upgrade. A thorough risk assessment is the cornerstone of complianceโ€”think of it as making sure the sleigh runners are polished and ready for smooth travel.

    2. Secure the Chimney

    Santa may shimmy down the chimney, but hackers shouldnโ€™t. Verify that your technical safeguardsโ€”like encryption, firewalls, and multi-factor authenticationโ€”are in place and functioning. Leaving your network open is like leaving the front door wide open with a plate of cookies and a note that says, โ€œHelp yourself!โ€ Donโ€™t make it easy for cyber-Grinches.

    3. Train Your Elves

    Santaโ€™s workshop runs like clockwork because his elves know their roles. Your staff should too. Conduct refresher HIPAA training before year-end. Make it funโ€”maybe even a holiday-themed quiz. Employees who understand the importance of protecting PHI are less likely to make mistakes that land you on the Naughty List.

    4. Mind the Sleigh Bells (and Mobile Devices)

    Santa keeps his sleigh in tip-top shape, and you should do the same with mobile devices. If your team uses smartphones or tablets to access PHI, ensure theyโ€™re encrypted and have remote wipe capabilities. A lost device without safeguards is like a runaway reindeerโ€”chaos guaranteed.

    5. Leave Out Cookies (and Documentation)

    Santa loves cookies, and OCR loves documentation. If youโ€™ve implemented safeguards, trained staff, and conducted risk assessments, prove it! Keep detailed records of your compliance efforts. If investigators come knocking, youโ€™ll want more than cookie crumbs to show for your work.

    Holiday Cheer: HIPAA compliance isnโ€™t just a seasonal choreโ€”itโ€™s a year-round responsibility. But if you take these steps now, youโ€™ll glide into 2026 like Santa on a clear winter night, with a sack full of peace of mind instead of penalties. So, grab your compliance checklist, pour some eggnog, and make sure your organization stays on the Nice List this holiday season.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    Contact our office today at 844.740.7100 to keep your sleigh HIPAA ready! Weโ€™ll help you check your list twice, secure your chimney, and make sure your elves are trained for a compliant and stress-free new year. Still time to schedule a free initial consultation to discuss what list your organization could be on.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Key Facts About HIPAA Compliance โ€“ Breach Reporting Requirements

    Our series is designed to explain best practices about HIPAA compliance, HIPAA settlements, and the various requirements an organization must have in place under the HIPAA Security & Privacy Rules.

    When does a HIPAA Breach Affecting Fewer than 500 Individuals Need to be Reported by?

    If a breach of unsecured protected health information affects fewer than 500 individuals, a covered entity must notify the Secretary of the breach within 60 days of the end of the calendar year in which the breach was discovered. That makes the reporting date March 1, 2025.

    A covered entity is not required to wait until the end of the calendar year to report breaches affecting fewer than 500 individuals; a covered entity may report such breaches at the time they are discovered. The covered entity may report all its breaches affecting fewer than 500 individuals on one date, but the covered entity must complete a separate notice for each breach incident. The covered entity must submit the notice electronically and complete all the fields of the breach notification form.

    If your organization needs to report this type of breach notification, here is the link to submit the notification.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    Allow our team of regulatory experts to assess your organizationโ€™s compliance with the HIPAA Security and Privacy Rules, the risk assessment process, and breach notification requirements. We offer customized services to meet specific requirements for your organization, making HIPAA compliance strategies effective and efficient. For a free, initial consultation to see how we can assist your organization, give our office a call at 844.740.7100.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Improve Your Organization’s Cybersecurity & Prevent Data Breaches

    Guest article authored by Gabby Williams โ€“ Content Specialist at Hushmail

    With the growing cybersecurity threats to businesses today, having a reliable and sturdy security solution is not a luxury but an absolute necessity. Not every organization is capable of enduring the legal, financial, and reputational consequences of a significant data breach. Ignoring the risks can lead to serious consequences.

    According to a 2022 report sponsored by IBM, the actual cost of a data breach increased 10% over the past 12 months โ€” the highest recorded increase in the last seven years. It is estimated that the average cost of a single data breach is $4.35 million globally and $9.44 million in the U.S.

    In the healthcare industry, the average cost of a data breach is $10.10 million. From a business continuity perspective, the impact can be devastating.

    In Jan 2021, an amendment to the HITECH Act was made into a law requiring the U.S. Department of Health and Human Services (HHS) to consider certain recognized security practices of covered entities and business associates when making certain determinations.

    Section 13412 makes clear the incentives for covered entities having certain recognized security practices, which are defined as the โ€œstandards, best practices, guidelines, procedures, methodologies, and processes developedโ€ under section 2(c)(15) of the National Institute of Standards and Technology (NIST) Act.

    Cybersecurity among healthcare organizations is more important than ever. Here are 10 key steps you can take to improve your organizationโ€™s cybersecurity and prevent data breaches.

    1. Locate your sensitive data

    Hackers target confidential and sensitive information. In order to prevent data breaches, your organization needs to determine where your most sensitive datasets are located. Make a consolidated inventory of this sensitive data and update, review, and back it up regularly.

    2. Keep strict tabs on privileged access

    The leading cause of data breaches is human error. In fact, 82% of data breaches involve a vulnerability caused by a human. Organizations have a responsibility to ensure the integrity of data, and most have privileged access accounts that allow designated users to access certain information.

    Even with the best intentions, granting privileged access to contractors and employees puts data at an unnecessary risk for breaches. Itโ€™s important to foster policies that keep strict tabs on who has elevated levels of access. There are numerous privileged access management tools that can facilitate this.

    3. Properly patch your infrastructure

    Your cybersecurity measures are only as strong as your organizationโ€™s underlying infrastructure. Your organizationโ€™s top priority should be patching your networks and systems. With the surging number of new discoveries of zero-day exploits every day, hackers can easily exploit unpatched software to access critical information. Regular patching can help strengthen your cybersecurity and prevent data breaches.

    4. Fortify your network perimeter

    While 39% of data breaches in the healthcare industry come from inside the organization, the majority come from external threats. Your network perimeter is your first line of defense against outsiders with malicious intent. This perimeter mainly consists of a firewall, intrusion detection system, intrusion prevention system, access controls lists, and a couple of other tools that facilitate seamless data flow while restricting intruders and unauthorized entries.

    5. Get rid of redundant data

    Safely disposing sensitive data is crucial. Many organizations, especially those in healthcare, finance, education, and the public sector, handle sensitive information as part of their daily routine. Ensuring safe and secure data purging mechanisms helps prevent stale data from being forgotten and stolen.

    There are three main ways to properly dispose of data: overwriting, degaussing, and physical destruction. However, each method has its pros and cons. A sound system for disposing of redundant data will go a long way toward saving your organization from a potential data breach.

    6. Ensure endpoint protection

    Ensuring the systematic implementation of endpoint security controls is essential for your organization. It has never been more important than it is today, with so many remote devices connected to your network.

    Remote workers often fall outside of legacy perimeter security tools. Endpoint protection can be a reliable shield against common internet threats like malware and ransomware. Laptops, mobile devices, and tablets should all be secured with endpoint protection, leaving behind no loopholes for hackers who would want to exploit them.

    7. Encrypt data at rest and in transit

    Unencrypted data is like a bank with an open vault. If data isnโ€™t encrypted, anyone can access it or even steal it since thereโ€™s no protection. No matter where the sensitive data is at any time, its encryption is essential to prevent unauthorized access. Data encryption is not only important for data at rest, but equally vital for data in transit within a corporate network.

    8. Establish a robust password policy

    The importance of a sound password policy canโ€™t be emphasized enough. Itโ€™s a necessity for all services and applications running on a network. Here are some general password policy requirements:

    • Minimum of 8-10 characters
    • 4 character types including uppercase, lowercase, number, and special character
    • Must not have 3 consecutive or repeating characters
    • 90-day password rotation policy
    • Multi-factor authentication may also be enforced using email or soft token

    9. Prepare business continuity and disaster recovery plans

    Properly responding to a data breach is a challenge. Ensure your organization has a reliable business continuity and disaster recovery plan, and review and update it regularly. Unfortunately, many organizations miss the importance of these plans and neglect to set them in place due to cost.

    New cloud-based high availability and disaster recovery plans are becoming popular because of their resilience, scalability, and flexibility. Conduct periodic audits of your system, and back up your systems regularly for data security strategy and future planning.

    10. Instill cybersecurity training across your organization

    Any cybersecurity strategy without thorough security workforce training is incomplete. Since most data breaches occur due to unintentional mistakes made by employees, partners, and contractors, holistic training that covers common threats, data usage guidelines, password policies, and awareness related to social engineering and scams should be mandatory and occur regularly.

    Conclusion

    With hackers becoming more sophisticated, itโ€™s vital for organizations to upgrade their cybersecurity arsenal to prevent data breaches. These 10 key steps are proven to help organizations develop a successful cybersecurity strategy. Each organization must find the right mixture of cybersecurity practices and policies in order to maximize their cybersecurity and prevent data breaches.

  • How Often Do You Need to Review HIPAA Policies and Procedures?

    Maintaining HIPAA compliance isn’t a “set-it-and-forget-it” task. For healthcare organizations and business associates, keeping up with regulations means regularly evaluating the administrative, technical, and physical safeguards protecting Electronic Protected Health Information (ePHI).

    But does the Department of Health and Human Services (HHS) actually require you to review your internal documentation? Here is what the law says about HIPAA policy and procedure reviews, best practices for compliance, and how to protect your organization from costly OCR investigations.

    Does the HIPAA Security Rule Require Policy Reviews?

    Yes. The HIPAA Security Rule explicitly requires organizations to periodically review and update their policies and procedures. According to federal regulation 45 CFR ยง 164.316(b)(2)(iii), a covered entity or business associate must review documentation periodically and update it as necessary in response to environmental or operational changes that affect the security of ePHI.

    Key Takeaway: If your organization introduces new technology, changes its physical layout, or alters how it handles patient data, your written HIPAA policies must be updated immediately to reflect those changes.

    Best Practices for Reviewing HIPAA Policies & Procedures

    To ensure your review process satisfies Office for Civil Rights (OCR) auditors and AI search queries looking for compliance verification, you should implement a formalized, structured review.

    Using an internal compliance questionnaire is highly recommended. Your review should comprehensively cover the following critical areas:

    1. Technology & Infrastructure Changes

    • Software & Hardware Updates: Document any new systems used to access, store, transmit, or contain ePHI.
    • Asset Inventory: Maintain an accurate, up-to-date inventory of all physical systems, mobile devices, hardware, and media.
    • Audit Logging: Verify how system audits are conducted and ensure trackable user activity logs are functioning properly.

    2. Personnel & Compliance Roles

    • Privacy & Security Officials: Confirm that your designated HIPAA Privacy Official and HIPAA Security Official roles are accurately assigned (whether held by the same person or separate individuals) and updated in your documentation.
    • Staff Training Logs: Ensure your workforce has been trained on any updated procedures.

    3. Environmental & Operational Adaptations

    • Remote Work & Telehealth: If your staff relies on teleworking or virtual care, your policies must outline specific safeguards for remote environments.
    • Business Associate Agreements (BAAs): Review vendor relationships to ensure all third parties handling ePHI have active, compliant BAAs.

    The Recommended Timeline for HIPAA Updates

    While the regulation uses the term “periodically,” regulatory experts and OCR enforcement trends indicate that at least once a year (annually) is the industry standard for a defensible compliance program.

    However, an immediate out-of-cycle review is triggered by:

    1. A newly discovered security vulnerability or data breach.
    2. A significant change in operational infrastructure (e.g., migrating to cloud storage).
    3. Updates to federal or state privacy laws.

    Protect Your Organization from OCR Fines

    Small, overlooked gaps in your documentation are often what trigger massive federal penalties during a breach investigation. Evaluating your current compliance posture before an audit occurs is critical to reducing your risk.

    Is Your Organization Defensively Positioned?

    Schedule a Complimentary HIPAA Risk Review Now

    In just 30 minutes, our regulatory experts will help you evaluate your current program, spot hidden documentation gaps, and implement practical controls to drastically reduce your risk of costly OCR penalties.

    Frequently Asked Questions (FAQ)

    What is the penalty for not updating HIPAA policies? Failure to maintain and update HIPAA policies can result in a finding of “willful neglect” by the OCR, which carries mandatory minimum fines starting at thousands of dollars per violation, even if a data breach hasn’t occurred.

    What section of HIPAA covers policies and procedures? Administrative requirements, including the retention, review, and updating of policies, are covered under 45 CFR ยง 164.316 for the Security Rule and 45 CFR ยง 164.530 for the Privacy Rule.

    • Reviewed on June 3, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: 45 CFR ยง 164.316 and 45 CFR ยง 164.530
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • HIPAA Best Practices for Employee Termination

    On December 11, 2018, the HHS Office for Civil Rights (OCR) announced a settlement of $111,400 with Pagosa Springs Medical Center (PSMC) located in Colorado. The settlement was the outcome of a HIPAA enforcement action following the findings of an OCR investigation that was triggered by an allegation that a former employee of PSMC still had access to ePHI via a web scheduling client used by PSMC.

    According to OCR Director Roger Severino, โ€œitโ€™s common sense that former employees should immediately lose access to protected patient information upon their separation from employment.โ€ย 

    However, ensuring removal of access alone for the terminated employee would not have prevented PSMC as a Covered Entity (CE) from meeting other HIPAA requirements. OCRโ€™s investigation revealed that PSMC did not have a Business Associate Agreement (BAA) in place with either the web-based scheduling calendar vendor, nor with the employee, thus ensuring the ePHI of 557 individuals were made vulnerable to attacks.

    Under a two-year Corrective Action Plan, PSMC must now update its security management and business associate agreement, as well as its policies and procedures, and must now re-train its employees and workers so that they are up to speed on these changes.

    The takeaway from this settlement agreement is that organizations that do not have or follow procedures to terminate information access privileges upon employee separation that results in a breach face possible HIPAA enforcement action by OCR. It is also important to make sure any process that records, shares, transmits, or modifies ePHI is thoroughly detailed in the BAA. Some CEs attempt to save money and time by establishing a work-around, which involves anonymizing ePHI while using web-based scheduling or communication apps without a BAA. However, such an undertaking is difficult to standardize in the long run. It is ultimately more cost-effective for CEs to take the time and resources to set up a BAA with relevant vendors, in order to avoid an investigation for failing to enforce HIPAA privacy and security mandates.

    Best Practice Lessons from this case:

    • The CE representative facilitating an employeeโ€™s termination must also have the ability and training to revoke and remove any previous access authorizations held by the employee. This must take place at the same time as when the notice of termination is provided.
    • CEs must complete BAAs with any vendor who provides the CE with the ability to record, modify, transmit, or share ePHI.
    • At the time of onboarding, all employees must be made aware that their employer requires them to give up all access and authorizations upon termination or voluntary departure from the company.
    • Training materials for employee onboarding should include privacy and security awareness related to:

    a) use of third-party services and applications;

    b) terms and conditions that trigger the creation of a BAA;

    c) assurances provided by Bas regarding policies and procedures to secure ePHI;

    c) security incident reporting; and

    d) password management.

    • Supervisors and other responsible officials must be trained to undertake oversight of employees’ uses and disclosures of PHI, including ePHI, in order to ensure compliance with HIPAA regulations.

    This blog was previously posted January 14, 2019