Category: HIPAA Compliance

  • Does HIPAA Require Employee Background Checks?

    Does HIPAA require organizations to conduct background checks on employees that have access to protected health information? What Regulated Entities Must Know

    Executive Summary:

    Technically, no. The Health Insurance Portability and Accountability Act (HIPAA) text does not explicitly mandate criminal background checks for employees. However, HIPAA does require strict data access controls, and the Department of Health and Human Services (HHS) penalizes organizations that hire individuals excluded from federal healthcare programs. Consequently, background and exclusion checks are considered an industry best practice for regulatory compliance.

    HIPAA Rules vs. Background Checks: Decoding CFR ยง 164.308

    While you wonโ€™t find the phrase “background check” written into the Code of Federal Regulations (CFR) for HIPAA, compliance is heavily implied under the HIPAA Security Rule.

    Specifically, 45 CFR ยง 164.308 (Administrative Safeguards) outlines Information Access Management. This standard requires covered entities and business associates to implement strict policies and procedures for authorizing access to electronic protected health information (ePHI).

    How “Authorized Access” Impacts Hiring

    • Role-Based Access: Access to PHI must be appropriate for the workforce member’s specific role.
    • The Trustworthiness Standard: To defend your authorization process during an OCR audit, your organization must prove it verified that the workforce member is trustworthy enough to handle sensitive data.
    • The Industry Best Practice: Conducting criminal background checks during the pre-employment phase is the most defensible way to demonstrate due diligence in vetting workforce trustworthiness.

    The OIG Exclusion List: A Mandatory Compliance Check

    While criminal background checks are a strong recommendation, checking the HHS Office of Inspector General (OIG) database is practically mandatory if you want to avoid massive civil fines.

    Organizations must screen all prospective hires against the List of Excluded Individuals/Entities (LEIE). If your organization employs an individual or entity on the LEIE to provide items or services funded by a federal healthcare program, you face severe Civil Monetary Penalties (CMP).

    Real-World Compliance Warning: In a recent enforcement case, Windham Eye Care Practice and its owners were forced to pay a $192,000 civil penalty solely for employing an “excluded” individual. Failing to run an OIG exclusion check can result in direct, devastating financial consequences.

    Frequently Asked Questions (FAQ)

    Is a criminal background check required by HIPAA?

    No, criminal background checks are not explicitly required by HIPAA regulations. However, they are highly recommended under HIPAA Administrative Safeguards to verify employee trustworthiness before granting access to protected health information (PHI).

    What background checks are recommended for healthcare employees?

    At a minimum, healthcare employers should conduct a criminal background check and a mandatory screening against the HHS OIG List of Excluded Individuals/Entities (LEIE).

    What happens if a healthcare company hires an excluded individual?

    Hiring an individual on the OIG exclusion list can result in massive civil monetary penalties, exclusion from federal funding (like Medicare and Medicaid), and an immediate investigation by the Office for Civil Rights (OCR) or OIG.

    Ready to Eliminate Your HIPAA Risks?

    Small, overlooked gaps in your hiring or information access workflows can trigger devastating federal audits.

    At Colington Consulting, we specialize in making HIPAA compliance painless and efficient. We can help your organization develop robust onboarding policies, structure your information access management, and ensure you are defensibly positioned for an OCR investigation.

    Schedule Your Free 30-Minute HIPAA Risk Review Now to identify your compliance gaps before they become costly violations.

    • Updated on June 9, 2026 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • HIPAA Breach Deadlines for Under 500 Affected People

    Quick Answer: For HIPAA breaches affecting fewer than 500 individuals, covered entities must notify the Secretary of the U.S. Department of Health and Human Services (HHS) no later than 60 days after the end of the calendar year in which the breach was discovered.

    If a data breach affects fewer than 500 individuals, your organization is permitted to track and report these incidents to the federal government on an annual basis rather than immediately.

    Reports for these smaller breaches must be submitted to the Secretary of the U.S. Department of Health and Human Services (HHS) within 60 days of the end of the calendar year. This annual reporting must be completed online through the official HHS Office for Civil Rights (OCR) Breach Reporting Portal.

    Crucial Exception: Individual Notifications

    While federal government reporting can wait until the end of the year, individual patient notifications cannot.

    You must notify affected individuals without unreasonable delay, and absolutely no later than 60 days following the initial discovery of the breach.

    What Must Be Included in a HIPAA Breach Notification?

    To remain fully compliant with the HIPAA Privacy and Security Rules, every breach notification sent to an individual must contain the following details:

    • A Brief Description: A short summary of what happened, including the date of the breach and the date it was discovered.
    • Types of PHI Involved: A description of the specific types of Protected Health Information involved (e.g., full name, social security number, date of birth, home address, or medical history).
    • Mitigation Steps for Individuals: Clear instructions on what steps affected individuals should take to protect themselves from potential harm (e.g., credit monitoring or changing passwords).
    • Your Investigation & Remediation: A brief summary of what your covered entity is doing to investigate the breach, mitigate ongoing harm, and prevent future security incidents.
    • Contact Information: Clear contact details for the covered entity or business associate so individuals can ask follow-up questions.

    Ensure Your Practice is Fully HIPAA Compliant

    Navigating the nuances of the HIPAA Security Rule and proactive risk management can be challenging. At Colington Consulting, our team of regulatory experts specializes in making HIPAA compliance strategies painless, efficient, and tailored to your specific organizational needs.

    Have questions about breach reporting or need a comprehensive risk assessment? Schedule a free HIPAA Risk Review now.

    • Updated on June 7, 2026, and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: Reporting to the Secretary of HHS (Under 500 Affected): Governed by 45 CFR ยง 164.408(c). This section states that for breaches affecting fewer than 500 individuals, a covered entity must maintain a log and notify the Secretary no later than 60 days after the end of the calendar year in which the breach was discovered. Reporting to Affected Individuals: Governed by 45 CFR ยง 164.404. Subsection (b) mandates that individual notifications must be made without unreasonable delay and strictly no later than 60 calendar days after the discovery of the breach. Subsection (c) outlines the exact content elements required in the notice (such as the description of PHI types and mitigation steps).
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Telehealth: Is Your Practice Adhering to the HIPAA Rules?

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    While the concept of telehealth has been around for years, it recently became the new normal for many healthcare providers. The coronavirus pandemic has created a situation where more medical offices and clinics are finding themselves conducting routine patient visits and follow-up appointments via a laptop or mobile device to limit office visits and the interaction between staff and patients.

    Unfortunately, implementing telehealth solutions that effectively provide distance care in the middle of a pandemic came with its own challenges. When the virus was spreading quickly, providers scrambled to find solutions that could help them better deliver medical services and efficiently cater to the fast-growing number of patients; many went for the first option they could find. While these solutions may be suitable for short-term use, some telemedicine platforms used today may not work in the long term. Why? They are not HIPAA compliant. Chances are if your organization is using a free version of a telecommunications product, it is not meeting HIPAA requirements.

    HIPAA Guidelines on Telehealth

    The U.S. Department of Health and Human Services (HHS) defines telehealth as โ€œthe use of electronic information and telecommunications technologies to support and promote long-distance clinical health care, patient and professional health-related education, and public health and health administrationโ€. Because of the security risks involved in delivering these services online, the HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) implement administrative, physical, and technical procedures to protect health information communicated electronically. Ideally, for telemedicine to be HIPAA compliant:

    • Only authorized users should have access to electronic Protected Health Information (ePHI).
    • A communications-monitoring system must be implemented to oversee communications containing ePHI and prevent accidental or malicious breaches.
    • The channels used to transmit ePHI must be secure enough to protect the integrity of patientsโ€™ data and communications. That said, non-secure, public facing platforms like Facebook Live, TikTok, or other video communication applications cannot be used. Because copies of communication can remain on the servers of these third parties, a CE is required to have a Business Associate Agreement (BAA) with, for example, Skype, Zoom, or Google to be compliant with HIPAA. However, because some service providers, whoโ€™s platforms were not designed for telehealth, will likely not enter into a BAA with a Covered Entity for telehealth services. The CE may be responsible for any penalties should there be an unauthorized disclosure of ePHI due to using these types of platforms that do not comply with HIPAA security guidelines.

    The good news? The HHS Office for Civil Rights has exercised its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. The bad? That wonโ€™t last, as there are obvious risks to continuing to use non-secure telemedicine solutions that may put ePHI in danger. As we enter the next phase of the pandemic, itโ€™s becoming clear that telemedicine will be an important part of patient care, which means healthcare organizations need to adopt platforms that can serve them for the long term. If your facility is operating a telehealth solution that is not HIPAA compliant, now itโ€™s time to set yourself up for success by investing in a platform or technology you will not have to abandon when the public health emergency ends. Remember, once your organization engages a telehealth delivery platform, an executed Business Associate Agreement must be in place with that vendor.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Why Organizations Must Conduct a HIPAA Risk Assessment

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    Data breaches targeting Electronic Protected Health Information (ePHI) are nothing new. In fact, with more healthcare organizations now storing patientsโ€™ medical records electronically, these attacks are at an all-time high. It is crucial that healthcare entities regularly conduct a HIPAA risk assessment to identify any threats or vulnerabilities that may put ePHI in jeopardy. A risk assessment, also known as a risk analysis, is not only useful in detecting data threats; itโ€™s also required by the Code of Federal Regulations (CFR). The HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) โ€œConduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the organization.โ€ The risk assessment process keeps your patientsโ€™ records safe and your organization on the right side of the CFR.

    Do Small Practices Need to Conduct a HIPAA Risk Assessment?

    Data breaches donโ€™t only occur in larger organizations; hackers can target small practices and businesses too. Regardless of the size of the organization, a HIPAA Risk Assessment must be conducted with the proper documentation of any gaps and weaknesses determined by the assessment. Itโ€™s essential and required.

    The Office of the National Coordinator for Health Information Technology (ONC), in partnership with the HHS Office for Civil Rights (OCR), saw the need to launch a Security Risk Assessment (SRA) Tool to help small and medium-sized healthcare organizations and BAs comply with the HIPAA Security Rule. The tool is meant to guide these entities in identifying security risks in their systems, policies, and processes and display results that they can use to mitigate any identified vulnerabilities. Since launching the original tool about ten years ago, revisions have been made and it is now more of a decision tree process.

    However, itโ€™s important to note that the CFRs do not make it mandatory for Covered Entities and Business Associates to use the SRA tool nor does it give specific guidelines on how risk assessment should be carried out. HHS recognizes that different sized businesses have different needs and vulnerabilities, as well as different levels of access to resources. The problem with the tool is it can become time consuming to use, leads to more questions about meeting compliance requirements, and inability to see all the questions until traversing through the process. Regardless of using the tool or outsourcing the assessment to a consultant or vendor, all CEs and BAs must have documented proof that they have conducted an accurate and thorough HIPAA security risk assessment.

    Failure to Perform a HIPAA Risk Assessment Can Result in Serious Penalties

    If just knowing that conducting a risk analysis is a HIPAA requirement isnโ€™t enough motivation to get you started with the process, then you should keep in mind that the fines for non-compliance can add up to hefty amounts. Some organizations like Excellus Health Plan, Inc., for instance, have had to pay up to $5.1 million to OCR for breaching ePHI. According to this press release, the penalty was attributed to the organizationโ€™s โ€œfailure to conduct an enterprise-wide risk analysis, and failures to implement risk management, information system activity review, and access controlsโ€, which put the privacy of millions of its patients in danger. So, carrying out a risk assessment does not only allow you to spot potential weaknesses in organizational information systems that contain ePHI; it also enables you to take the right actions as soon as possible to safeguard your ePHI data, which can protect your business from federal penalties and the need to enter into a resolution agreement with OCR.

    Need Help With Your HIPAA Compliance Program?

    HIPAA violations often stem from small, overlooked gaps in daily operations. Don’t wait for a patient complaint to trigger a federal investigation. Would Your Practice Pass a HIPAA Audit Tomorrow?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your practice.

  • Understanding the Role of a HIPAA Business Associate

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    The continued complexity of modern healthcare systems and growth of patientsโ€™ data mean that medical records can be stored in more places than just the doctorโ€™s office. The information may be kept and maintained offsite in a storage facility or on a cloud-based server operated by a third party. Any entity or individual that uses, processes, or discloses this data on behalf of the healthcare provider is called a HIPAA Business Associate. If an organization is contracted by a HIPAA Covered Entity (CE) to perform activities that involve accessing Protected Health Information (PHI) or electronic PHI (ePHI) in any way, they are considered a Business Associate (BA). Because Business Associates use protected patientsโ€™ data to support the operations of covered entities, the U.S. Department of Health and Human Services (HHS) requires adherence to the Code of Federal Regulations (CFR) to comply with HIPAA requirements.

    Business Associate Agreement (BAA)

    The HIPAA Privacy Rule states that, โ€œA covered entity must obtain satisfactory assurances from its Business Associate that the Business Associate will appropriately safeguard the protected health information it receives or creates on behalf of the covered entity. The satisfactory assurances must be in writing, whether in the form of a contract or other agreement between the covered entity and the business associate.โ€

    This means that before a covered entity can work with a Business Associate, the BA must sign a BAA stating that they will safeguard and treat PHI the way CFRs and the covered entity require them to. It does not matter whose version of the BAA is signed, whether provided by the CE or the BA, as long it is executed. According to the Health Information Technology for Economic and Clinical Health (HITECH) Act, a BAA must include specific information to meet HIPAA compliance such as a description of the required and allowed uses of PHI, declarations that the Business Associate will disclose information only as required by law, and proper safeguards to protect patientsโ€™ data from breach including steps to take should there be such security violations.

    Why are Some Business Associates Not Complying with HIPAA Regulations?

    One of the major reasons is that most of them have no idea that the law considers them Business Associates. Covered entities have made great strides in following HIPAA compliance requirements, but many Business Associates are still not aware of the need to comply or are just reluctant to do so. Under HITECH, the Office of Civil Rights (OCR) holds Business Associates liable for breaches, and it is imperative that these entities take the necessary steps to ensure HIPAA compliance. In this press release where a Business Associate pays $2.3 million to settle a breach, the OCR Director at the time, Roger Severino terms โ€œThe failure to implement the security protections required by the HIPAA Rules in an industry known as a target for hackers and cyber thievesโ€ inexcusable. Sure, following all the steps required to obtain HIPAA compliance may seem overwhelming, but it offers better protection for patientsโ€™ data, which helps Business Associates avoid these types of federal penalties.

    Helping Organizations Achieve HIPAA Complianceโ„ข

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Office for Civil Rights – Guidance on HIPAA IT Asset Inventories

    On August 25, 2020, OCR as part of its quarterly cybersecurity newsletter, provided outstanding guidance regarding HIPAA and IT Asset Inventories. As part of the risk assessment process at Colington Consulting, this is a critical area we address with all of our clients. We want to ensure there is a detailed asset inventory of all software, hardware, network or computing component that creates, receives, maintains, or transmits electronic protected health information (ePHI). Sometimes we find this information scattered into various documents or not centrally maintained. Our goal is to make sure there is a comprehensive list for software and hardware for these vital components throughout an organization.

    Here are some helpful sections from the newsletter:

    “The HIPAA Security Rule requires covered entities and business associates to ensure the confidentiality, integrity, and availability of all electronic protected health information (ePHI) that it creates, receives, maintains, or transmits. Conducting a risk analysis, which is an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI held by an organization, is not only a Security Rule requirement, but also is fundamental to identifying and implementing safeguards that comply with and carry out the Security Rule standards and implementation specifications. However, despite this long-standing HIPAA requirement, OCR investigations frequently find that organizations lack sufficient understanding of where all of the ePHI entrusted to their care is located. Although the Security Rule does not require it, creating and maintaining an up-to-date, information technology (IT) asset inventory could be a useful tool in assisting in the development of a comprehensive, enterprise-wide risk analysis, to help organizations understand all of the places that ePHI may be stored within their environment, and improve their HIPAA Security Rule compliance.”

    How to Create an IT Asset Inventory

    “An enterprise-wide IT asset inventory is a comprehensive listing of an organizationโ€™s IT assets with corresponding descriptive information, such as data regarding identification of the asset (e.g., vendor, asset type, asset name/number), version of the asset (e.g., application or OS version), and asset assignment (e.g., person accountable for the asset, location of the asset). When creating an IT asset inventory, organizations can include:

    • Hardware assets that comprise physical elements, including electronic devices and media, which make up an organizationโ€™s networks and systems. This can include mobile devices, servers, peripherals, workstations, removable media, firewalls, and routers.
    • Software assets that are programs and applications that run on an organizationโ€™s electronic devices. Well-known software assets include anti-malware tools, operating systems, databases, email, administrative and financial records systems, and electronic medical/health record systems. Though lesser known,there are other programs important to IT operations and security such as backup solutions, virtual machine managers/hypervisors, and other administrative tools that should be included in an organizationโ€™s inventory.
    • Data assets that include ePHI that an organization creates, receives, maintains, or transmits on its network, electronic devices, and media.”

    As part of this inventory process, we always recommend organizations have an accurate and up-to-date list of all vendors in which you have signed Business Associate Agreements in place with. You may also want to include a list of all types of physical, hard copy medical records, billing records, or any other paper documentation containing protected health information.

    All these asset inventory lists must be reviewed and confirmed during the risk assessment process.

    Not One and Done

    This should not be considered a “one and done” process. It is important to remember whoever is assigned this task, whether it is an individual or a department, that is an ongoing process. Lists must be updated as new equipment or software is added and legacy systems or devices are removed.

    Take Action Now

    If HIPAA compliance assistance is needed for your organization, we specialize in putting compliance programs in place or assessing your current program. We provide a full range of services that include conducting the required HIPAA Risk Assessment, ensuring critical asset inventory lists are in place, writing and customizing a HIPAA Risk Management Plan (HIPAA Policies and Procedures) for your organization, and providing your entire staff annual required HIPAA Security Awareness & Privacy Training through our web-based platform. Our fees are based on what specifically your organization will need to meet regulatory requirements and reasonably priced to accommodate any budget.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Best Practices for Teleworking & Telehealth Involving PHI/ePHI

    by Jay Hodes, President – Colington Consulting

    With the federal public health emergency in place as of January 31 to address COVID-19, many healthcare organizations have implemented teleworking options for their workforce. Providers are also using telehealth services to interact with their patients. For some organizations, this is a whole new world. If not already in place, organizations needed to implement policies and procedures to address these critical operational topics.

    The HHS Office for Civil Rights (OCR) has issued a number of guidance documents pertaining to this emergency. Here are some excerpts I feel are important:

    February 2020: โ€œIn an emergency situation, covered entities must continue to implement reasonable safeguards to protect patient information against intentional or unintentional impermissible uses and disclosures. Further, covered entities (and their business associates) must apply the administrative, physical, and technical safeguards of the HIPAA Security Rule to electronic protected health information.โ€

    As further stated in the guidance regarding PHI:

    โ€œThe HIPAA Privacy Rule protects the privacy of patientsโ€™ health information (protected health information) but is balanced to ensure that appropriate uses and disclosures of the information still may be made when necessary to treat a patient, to protect the nationโ€™s public health, and for other critical purposes.โ€

    March 2020: โ€œWhile the HIPAA Privacy Rule is not suspended during a public health or other emergency, the Secretary of HHS may waive certain provisions of the Privacy Rule under the Project Bioshield Act of 2004 (PL 108-276) and section 1135(b)(7) of the Social Security Act.โ€

    Although OCR has indicated some discretion with its enforcement authority and waiving some requirements, the HIPAA Privacy and Security Rules are still in place with very limited exceptions.

    With the OCR guidance clearly stated, there must be an operational balance and the need to apply a commonsense approach to minimize the risks for unauthorized disclosures in order for your workforce to be able to perform their jobs while teleworking and during telehealth sessions.

    Here are some best practices to consider implementing as part of your organizationโ€™s policies to address teleworking and telehealth sessions:

    • Staff should never leave any documents containing PHI in a vehicle overnight. Even if the vehicle is locked or the documents can be secured in a trunk, all PHI must be removed. No exceptions!
    • When working from home, the staff should follow the same protocols as if in an office, practice location, or providing services face-to-face. This means following the Minimum Necessary Requirement. If working from home and there are others in the house, such as family members or roommates, only have patient conversations where others cannot hear that conversation. Staff must try to make those conversations as private as possible. This includes VTC telehealth sessions and telephone calls.
    • Always keep documents containing PHI as secure as possible so others may not see them when performing work related duties.
    • Avoid having conversations with those in the house regarding any patient.
    • Never allow family members, roommates, or others in the house to access/use any organization issued devices including cell phones and laptops, unless personal use is approved by the organization.
    • If using a personal computer for organization business, make sure others in the home do not access while performing work related duties. If a computer needs to be utilized for non-organization business during the workday or shift, always log off from organization access or VPN.
    • If staff needs to leave an area in the home that is set up as a workstation to take a break, grab a coffee, or handle non-organization issues, always make sure to lock the computer and secure documents. Even for a few minutes.
    • At the end of the business day or shift, staff should log off from any computer they are using and properly secure any documents containing PHI.
    • If HIPAA compliant bags or containers are provided by the organization, then use those to secure the documents when not needed.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Additional Resources for Telehealth:

    OCR – FAQs on Telehealth and HIPAA during the COVID-19 nationwide public health emergency

    National Consortium of Telehealth Resource Centers

    The National Counsel – Best Practices for Telehealth During COVID-19 Public Health Emergency

    American Psychiatric Association – Best Practices in Videoconferencing-Based Telemental Health

    SAMHSA Telehealth Start-Up and Resource Guide

  • 6 More HIPAA Breaches Reported

    With healthcare attention clearly focused on combating the coronavirus, there were six more data breaches that occurred within a few days as the year began. The breaches reported by healthcare organizations, likely resulting in the unauthorized releases of patient data for at least 8,701 patients. As the sheer number of data breaches continues to rise, so too does your responsibility to protect the people who rely on your services. What happened in these latest occurrences, and what steps should you take to fulfil your obligation to prevent it from happening within your own organization?

    Kaiser Permanente is breached once again.

    Kaiser Permanente already had 4 data breaches by the time reports came out back in 2014. Then, in 2018, at least two more were reported. And then again in October of 2019. Now the latest breach occurred when Kaiser Permanente recently discovered letters have accidentally been mailed to patientsโ€™ former addresses. The HHSโ€™ Office for Civil Rights (OCR) breach portal indicates up to 500 patients may have been affected in this one. (This is not counting their prior breaches.)

    Riverview Health also experienced a mailing error.

    Much like Kaiser Permanenteโ€™s latest breach, this one also happened due to a mailing error. This time, however, the mix up exposed the names of 2,610 patients. Fortunately, no financial information – such as credit or debit card numbers – or medical data was exposed. However, the methods of patient notification used by Riverview are currently under review as a result of this incident.

    Harris Health System lost PHI during transport.

    On Friday, February 28th, Harris Health System announced that it was notifying 2,298 patients of a privacy breach that happened on December 30, 2019. Two envelopes that contained 143 pages of protected health information (PHI) were lost in transport to Ben Taub Hospital, which were being sent there for scanning and archiving in Harris Health’s electronic medical record system. The envelopes are thought to contain information on patients seen at Gulfgate Health Center from December 9, 2019 and December 27, 2019.

    Community Mental Health Council mental health records were found dumped in an alley.

    In 2012, the Community Mental Health Council was forced to permanently close its clinics due to lack of funding. Long after the fact, however, hundreds of medical records from CMHCl have been found abandoned in an alley in West Englewood, Chicago. The documents included full names, addresses, Social Security numbers, diagnosis information, medical records, and more. City officials are currently trying to determine who was responsible for dumping the records.

    Armada Physical Therapy had a server carried off.

    Data breaches through hacking, phishing scams, and mailing errors are nothing new. But what makes the breach of Armada Physical Therapy stand out is that this time around, someone actually broke into the building and stole an entire server. At the time of writing, the investigation is still ongoing, and the stolen server has not yet been recovered. The server holds intake forms that contain names, addresses, telephone numbers, email addresses, insurance numbers, and Social Security numbers for around 500 patients.

    Elk Ridge Dentistry had a hard drive stolen.

    Unlike the incident with Armada, one would imagine that stealing a portable hard drive is at least a bit easier than making off with an entire server. At least one such hard drive was stolen from Elk Ridge Dentistry. The hard drive in question was used to store backups, and was actually among several items taken from the practice. Much like Armadaโ€™s server, the hard drive has not yet been recovered. To make matters worse, it contained the records of 2,793 patients, which included names, addresses, dates of birth, healthcare information, X-ray images, Social Security numbers, treatment consent forms, referral letters, and emails.

    Take Action Now

    So many different occurrences all happening within such a short time should give anyone cause for serious alarm. The numbers are against you, and we here at Colington Consulting donโ€™t want you to become yet another statistic. Even as COVID-19 events have impacted healthcare organizations, we are still able to provide the majority of our services remotely. We are available and can set up an initial consultation to talk about our services and how we can assist your organization. Call us today at 844.740.7100 and find out how we can help you protect your patients from incidents like these.

  • How to Avoid a $100,000 HIPAA Settlement

    By Jay Hodes, President โ€“ Colington Consulting

    Question: How can an organization avoid a large HIPAA settlement with the HHS Office for Civil Rights (OCR)?

    Up to this point, the OCR has settled HIPAA violation cases with predominantly larger healthcare organizations. However, OCRโ€™s enforcement priority and direction has changed and all healthcare providers, regardless of size, must be on guard for the โ€œmessage sending casesโ€ on which OCR is currently focusing.

    As a case in point, on the first day of the recent National HIPAA Summit held in Arlington, Virginia, OCR announced a $100,000 settlement for a HIPAA violation case involving the practice of Steven A. Porter, M.D., a gastroenterological services provider and solo practitioner. This โ€œmessage sendingโ€ was twofold: 1) Serena Mosley-Day, Senior Advisor for HIPAA Compliance and Enforcement for OCR, provided a presentation emphasizing that small providers are not immune to OCR scrutiny and must meet the same requirements under HIPAA as do larger healthcare organizations; and 2) Announcing the settlement at a Summit where attendees included attorneys, Chief Compliance Officers, HIPAA Security and Privacy Officials, IT and cybersecurity experts was timed for maximum impact.

    According to the HIPAA Settlementโ€™s press release, Dr. Porter โ€œfiled a breach report with OCR related to a dispute with a business associate. OCRโ€™s investigation determined that Dr. Porter had never conducted a risk analysis at the time of the breach report, and despite significant technical assistance throughout the investigation, had failed to complete an accurate and thorough risk analysis after the breach and failed to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.โ€

    OCR Director Roger Severinoโ€™s comments in the press release are especially noteworthy. He states that โ€œAll health care providers, large and small, need to take their HIPAA obligations seriously,โ€ and โ€œthe failure to implement basic HIPAA requirements, such as an accurate and thorough risk analysis and risk management plan, continues to be an unacceptable and disturbing trend within the health care industry.โ€

    OCR has previously said that 95% of reported breaches are resolved with technical guidance. The key to avoiding a costlier outcome is to demonstrate to OCR that your organization has a HIPAA compliance plan in place and to cooperate with the OCR breach investigation.

    Answer: To reduce the risk of penalty or settlement or the cost of mitigating a breach, an organization MUST implement and maintain a HIPAA compliance program as follows:

    • Develop and implement policies and procedures to address all the HIPAA Security Standards and Implementation Specifications.
    • Prepare a HIPAA Risk Management Plan that includes policies and procedures, asset inventories, HIPAA-related forms and reports, a facility security plan, and a documented contingency plan.
    • Conduct he required HIPAA Security Risk Assessment.
    • Provide HIPAA Security Awareness Training to the entire workforce.
    • Assign HIPAA Security and Privacy Officer(s) to manage a HIPAA compliance program. Regardless of size, an organization must designate a workforce member(s) to handle these required responsibilities.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • The State of HIPAA Compliance in 2019 โ€“ Sound the Alarm Bells

    By Jay Hodes, President โ€“ Colington Consulting

    Recently, Buck, โ€œan integrated HR and benefits consulting, technology, and administration services providerโ€ based in New York, produced a 2019 HIPAA Readiness Survey. After reading the Survey, I was not surprised by the results, for its message is loud and clear: It is time to sound the alarm bells.

    In my mission to help organizations achieve HIPAA compliance, I know where organizations typically struggle in complying with HIPAA regulations. Several of the Surveyโ€™s findings drive home that point:

    • 42% of survey participants did not know when a risk/threat analysis was last conducted, or they last conducted one more than five years ago.
    • 33% of survey respondents either have not inventoried their business associates or did not know if they had done so; 16% did not have current business associate agreements or did not know if they had them.
    • 35% indicated they last offered HIPAA training between one and five years ago, 13% provide training only during onboarding, and 10% did not know when HIPAA training was last provided.

    The Survey states that โ€œstrong governance is essential to protecting informationโ€ and โ€œunderstanding the rules and complying with them in a way that protects your organization is the best way to prevent a breach and the only way to emerge successfully from a HIPAA audit.โ€

    Governance, Risk, and Compliance (GRC) and Beyond

    I recently had lunch with a GRC expert who pointed out that organizations are considered โ€œnegligentโ€ if they disregard or plead ignorance of HIPAA compliance requirements and other industry-wide regulatory controls and standards. The HHS Office for Civil Rights continues an aggressive campaign of seeking civil monetary penalties from organizations for HIPAA violations. In addition, these same negligent organizations expose themselves to class action lawsuits from individuals seeking damages from breaches of personally identifiable information. In summary, HIPAA compliance should be driven by costโ€”the costs incurred from both government penalties as well as the time and money spent on re-mediating the damage caused by data breaches.

    Sound the Alarm?

    Rather than sound the alarm after the fact, organizations should focus their urgency on prevention and corrective measures before a violation or data breach. GRC is not meant to be a one-and-done approach to punch a regulatory ticket, but rather a systematic process to deal with risk management, including conducting audits and assessments; reviewing the results; and implementing the changes necessary to mitigate risk. This process will take effort, buy-in, and cooperation from all organizational levels, especially from the leadership team.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.