Category: HIPAA Compliance

  • Can the Government Review PHI During a HIPAA Investigation?

    When the U.S. Department of Health and Human Services (HHS) investigates a potential privacy violation, healthcare providers often wonder about the rules regarding Protected Health Information (PHI). Does the HIPAA Privacy Rule allow organizations to turn over sensitive patient health data to government investigators?

    The short answer is yes. The HIPAA Privacy Rule explicitly allows covered entities to disclose PHI to the government during compliance reviews and investigations. However, this access is not an open-ended blank check.

    Here is exactly how federal investigators access PHI, what triggers these reviews, and how the “minimum necessary” standard applies.

    Why the HHS Office for Civil Rights (OCR) Reviews PHI

    An essential part of enforcing HIPAA compliance is the government’s responsibility to investigate patient complaints and follow up on data breaches. To determine whether an organization has violated the Privacy or Security Rules, the HHS Office for Civil Rights (OCR) must routinely review specific patient medical records and internal documentation.

    However, the Privacy Rule strictly limits OCRโ€™s access to information that is “pertinent to ascertaining compliance.” Depending on the nature of the allegation, investigators will only look at data directly related to the potential violation. In some cases, no personal health information is required at all. For example, if the OCR is checking whether a health plan properly vetted an outside vendor, they may only need to review a Business Associate Agreement (BAA) rather than individual patient charts.

    Examples of Investigations Requiring PHI Access

    There are several common scenarios where the OCR must review actual patient records to verify compliance:

    • Patient Right of Access Violations: If a patient alleges that a healthcare provider refused to provide copy of their medical records, or failed to note a requested correction in their file, investigators must review the patient’s record and access logs to verify the timeline and actions taken.
    • Unauthorized Marketing and Disclosures: If a provider is accused of using patient data for marketing purposes without explicit authorization, the OCR will audit marketing department records containing PHI to check for valid patient signatures.
    • Data Breaches and Ransomware Incidents: Following a cyberattack or data leak, investigators review affected PHI data sets to determine the scope of the breach and evaluate if proper technical safeguards were in place.

    How to Prepare Your Organization for an OCR Audit

    The best defense against an enforcement action is a proactive compliance strategy. Identifying gaps early prevents standard compliance reviews from turning into costly penalties.

    1. Conduct Regular Security Risk Assessments

    Regular risk assessments are the foundation of a defensible HIPAA program. They help you identify administrative, physical, and technical vulnerabilities before a breach occurs.

    2. Implement Clear Policies and Procedures

    Ensure your staff is trained on handling patient requests, managing vendor relationships with proper Business Associate Agreements, and executing proper protocols during data requests.

    3. Seek Expert Compliance Guidance

    HIPAA violations often stem from small, overlooked gaps in documentation or staff training.

    Need Help Evaluating Your Risk? Get a free 30-minute HIPAA risk review with our regulatory experts to evaluate your current program and identify gaps before they turn into federal violations. Schedule your HIPAA Risk Review Now.

    Frequently Asked Questions

    Does HIPAA prevent the government from looking at my medical records?

    No. Under the HIPAA Privacy Rule, healthcare providers are permittedโ€”and requiredโ€”to share relevant Protected Health Information (PHI) with the HHS Office for Civil Rights (OCR) during an official compliance investigation or audit.

    What information can the OCR request during a HIPAA investigation?

    The OCR can only request information that is pertinent to determining compliance. This can range from internal administrative contracts (like Business Associate Agreements) to specific patient medical records, depending entirely on the nature of the alleged violation.

    What triggers an OCR HIPAA investigation?

    Most OCR investigations are triggered by patient complaints regarding privacy violations, data breaches affecting 500 or more individuals, or self-reported compliance gaps.

    • Updated and Reviewed on June 4, 2026, by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources:

    The Core Compliance Directive: 45 CFR ยง 160.310. This is the specific regulation that mandates covered entities and business associates to hand over information to federal investigators.

    • Section 160.310(b): Expressly states that organizations must cooperate with complaint investigations and compliance reviews led by the Secretary of HHS.
    • Section 160.310(c)(1): Mandates that organizations permit access to their facilities, books, records, accounts, and “other sources of information, including protected health information, that are pertinent to ascertaining compliance.”

    The General Privacy Rule Exception: 45 CFR ยง 164.502(a)(2)(ii). While 45 CFR ยง 164.502 generally prohibits disclosing PHI without explicit patient authorization, it lists precise exceptions where a disclosure is required.

    • Under 45 CFR ยง 164.502(a)(2)(ii), a covered entity or business associate is required to disclose PHI to the Secretary of HHS specifically when requested to investigate or determine compliance with the HIPAA Privacy and Security Rules
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Helping Organizations Achieve HIPAA Compliance

    Jay Hodes, President of Colington Consulting, was recently interviewed by Best Startup. Topics covered the inspiration behind the business, facing challenges, buying into the vision of compliance, and what the magic sauce is in running the company. Click here to read the full article.

  • Does HIPAA Require Employee Background Checks?

    Does HIPAA require organizations to conduct background checks on employees that have access to protected health information? What Regulated Entities Must Know

    Executive Summary:

    Technically, no. The Health Insurance Portability and Accountability Act (HIPAA) text does not explicitly mandate criminal background checks for employees. However, HIPAA does require strict data access controls, and the Department of Health and Human Services (HHS) penalizes organizations that hire individuals excluded from federal healthcare programs. Consequently, background and exclusion checks are considered an industry best practice for regulatory compliance.

    HIPAA Rules vs. Background Checks: Decoding CFR ยง 164.308

    While you wonโ€™t find the phrase “background check” written into the Code of Federal Regulations (CFR) for HIPAA, compliance is heavily implied under the HIPAA Security Rule.

    Specifically, 45 CFR ยง 164.308 (Administrative Safeguards) outlines Information Access Management. This standard requires covered entities and business associates to implement strict policies and procedures for authorizing access to electronic protected health information (ePHI).

    How “Authorized Access” Impacts Hiring

    • Role-Based Access: Access to PHI must be appropriate for the workforce member’s specific role.
    • The Trustworthiness Standard: To defend your authorization process during an OCR audit, your organization must prove it verified that the workforce member is trustworthy enough to handle sensitive data.
    • The Industry Best Practice: Conducting criminal background checks during the pre-employment phase is the most defensible way to demonstrate due diligence in vetting workforce trustworthiness.

    The OIG Exclusion List: A Mandatory Compliance Check

    While criminal background checks are a strong recommendation, checking the HHS Office of Inspector General (OIG) database is practically mandatory if you want to avoid massive civil fines.

    Organizations must screen all prospective hires against the List of Excluded Individuals/Entities (LEIE). If your organization employs an individual or entity on the LEIE to provide items or services funded by a federal healthcare program, you face severe Civil Monetary Penalties (CMP).

    Real-World Compliance Warning: In a recent enforcement case, Windham Eye Care Practice and its owners were forced to pay a $192,000 civil penalty solely for employing an “excluded” individual. Failing to run an OIG exclusion check can result in direct, devastating financial consequences.

    Frequently Asked Questions (FAQ)

    Is a criminal background check required by HIPAA?

    No, criminal background checks are not explicitly required by HIPAA regulations. However, they are highly recommended under HIPAA Administrative Safeguards to verify employee trustworthiness before granting access to protected health information (PHI).

    What background checks are recommended for healthcare employees?

    At a minimum, healthcare employers should conduct a criminal background check and a mandatory screening against the HHS OIG List of Excluded Individuals/Entities (LEIE).

    What happens if a healthcare company hires an excluded individual?

    Hiring an individual on the OIG exclusion list can result in massive civil monetary penalties, exclusion from federal funding (like Medicare and Medicaid), and an immediate investigation by the Office for Civil Rights (OCR) or OIG.

    Ready to Eliminate Your HIPAA Risks?

    Small, overlooked gaps in your hiring or information access workflows can trigger devastating federal audits.

    At Colington Consulting, we specialize in making HIPAA compliance painless and efficient. We can help your organization develop robust onboarding policies, structure your information access management, and ensure you are defensibly positioned for an OCR investigation.

    Schedule Your Free 30-Minute HIPAA Risk Review Now to identify your compliance gaps before they become costly violations.

    • Updated on June 9, 2026 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • HIPAA Breach Deadlines for Under 500 Affected People

    Quick Answer: For HIPAA breaches affecting fewer than 500 individuals, covered entities must notify the Secretary of the U.S. Department of Health and Human Services (HHS) no later than 60 days after the end of the calendar year in which the breach was discovered.

    If a data breach affects fewer than 500 individuals, your organization is permitted to track and report these incidents to the federal government on an annual basis rather than immediately.

    Reports for these smaller breaches must be submitted to the Secretary of the U.S. Department of Health and Human Services (HHS) within 60 days of the end of the calendar year. This annual reporting must be completed online through the official HHS Office for Civil Rights (OCR) Breach Reporting Portal.

    Crucial Exception: Individual Notifications

    While federal government reporting can wait until the end of the year, individual patient notifications cannot.

    You must notify affected individuals without unreasonable delay, and absolutely no later than 60 days following the initial discovery of the breach.

    What Must Be Included in a HIPAA Breach Notification?

    To remain fully compliant with the HIPAA Privacy and Security Rules, every breach notification sent to an individual must contain the following details:

    • A Brief Description: A short summary of what happened, including the date of the breach and the date it was discovered.
    • Types of PHI Involved: A description of the specific types of Protected Health Information involved (e.g., full name, social security number, date of birth, home address, or medical history).
    • Mitigation Steps for Individuals: Clear instructions on what steps affected individuals should take to protect themselves from potential harm (e.g., credit monitoring or changing passwords).
    • Your Investigation & Remediation: A brief summary of what your covered entity is doing to investigate the breach, mitigate ongoing harm, and prevent future security incidents.
    • Contact Information: Clear contact details for the covered entity or business associate so individuals can ask follow-up questions.

    Ensure Your Practice is Fully HIPAA Compliant

    Navigating the nuances of the HIPAA Security Rule and proactive risk management can be challenging. At Colington Consulting, our team of regulatory experts specializes in making HIPAA compliance strategies painless, efficient, and tailored to your specific organizational needs.

    Have questions about breach reporting or need a comprehensive risk assessment? Schedule a free HIPAA Risk Review now.

    • Updated on June 7, 2026, and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: Reporting to the Secretary of HHS (Under 500 Affected): Governed by 45 CFR ยง 164.408(c). This section states that for breaches affecting fewer than 500 individuals, a covered entity must maintain a log and notify the Secretary no later than 60 days after the end of the calendar year in which the breach was discovered. Reporting to Affected Individuals: Governed by 45 CFR ยง 164.404. Subsection (b) mandates that individual notifications must be made without unreasonable delay and strictly no later than 60 calendar days after the discovery of the breach. Subsection (c) outlines the exact content elements required in the notice (such as the description of PHI types and mitigation steps).
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Telehealth: Is Your Practice Adhering to the HIPAA Rules?

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    While the concept of telehealth has been around for years, it recently became the new normal for many healthcare providers. The coronavirus pandemic has created a situation where more medical offices and clinics are finding themselves conducting routine patient visits and follow-up appointments via a laptop or mobile device to limit office visits and the interaction between staff and patients.

    Unfortunately, implementing telehealth solutions that effectively provide distance care in the middle of a pandemic came with its own challenges. When the virus was spreading quickly, providers scrambled to find solutions that could help them better deliver medical services and efficiently cater to the fast-growing number of patients; many went for the first option they could find. While these solutions may be suitable for short-term use, some telemedicine platforms used today may not work in the long term. Why? They are not HIPAA compliant. Chances are if your organization is using a free version of a telecommunications product, it is not meeting HIPAA requirements.

    HIPAA Guidelines on Telehealth

    The U.S. Department of Health and Human Services (HHS) defines telehealth as โ€œthe use of electronic information and telecommunications technologies to support and promote long-distance clinical health care, patient and professional health-related education, and public health and health administrationโ€. Because of the security risks involved in delivering these services online, the HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) implement administrative, physical, and technical procedures to protect health information communicated electronically. Ideally, for telemedicine to be HIPAA compliant:

    • Only authorized users should have access to electronic Protected Health Information (ePHI).
    • A communications-monitoring system must be implemented to oversee communications containing ePHI and prevent accidental or malicious breaches.
    • The channels used to transmit ePHI must be secure enough to protect the integrity of patientsโ€™ data and communications. That said, non-secure, public facing platforms like Facebook Live, TikTok, or other video communication applications cannot be used. Because copies of communication can remain on the servers of these third parties, a CE is required to have a Business Associate Agreement (BAA) with, for example, Skype, Zoom, or Google to be compliant with HIPAA. However, because some service providers, whoโ€™s platforms were not designed for telehealth, will likely not enter into a BAA with a Covered Entity for telehealth services. The CE may be responsible for any penalties should there be an unauthorized disclosure of ePHI due to using these types of platforms that do not comply with HIPAA security guidelines.

    The good news? The HHS Office for Civil Rights has exercised its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. The bad? That wonโ€™t last, as there are obvious risks to continuing to use non-secure telemedicine solutions that may put ePHI in danger. As we enter the next phase of the pandemic, itโ€™s becoming clear that telemedicine will be an important part of patient care, which means healthcare organizations need to adopt platforms that can serve them for the long term. If your facility is operating a telehealth solution that is not HIPAA compliant, now itโ€™s time to set yourself up for success by investing in a platform or technology you will not have to abandon when the public health emergency ends. Remember, once your organization engages a telehealth delivery platform, an executed Business Associate Agreement must be in place with that vendor.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Why Organizations Must Conduct a HIPAA Risk Assessment

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    Data breaches targeting Electronic Protected Health Information (ePHI) are nothing new. In fact, with more healthcare organizations now storing patientsโ€™ medical records electronically, these attacks are at an all-time high. It is crucial that healthcare entities regularly conduct a HIPAA risk assessment to identify any threats or vulnerabilities that may put ePHI in jeopardy. A risk assessment, also known as a risk analysis, is not only useful in detecting data threats; itโ€™s also required by the Code of Federal Regulations (CFR). The HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) โ€œConduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the organization.โ€ The risk assessment process keeps your patientsโ€™ records safe and your organization on the right side of the CFR.

    Do Small Practices Need to Conduct a HIPAA Risk Assessment?

    Data breaches donโ€™t only occur in larger organizations; hackers can target small practices and businesses too. Regardless of the size of the organization, a HIPAA Risk Assessment must be conducted with the proper documentation of any gaps and weaknesses determined by the assessment. Itโ€™s essential and required.

    The Office of the National Coordinator for Health Information Technology (ONC), in partnership with the HHS Office for Civil Rights (OCR), saw the need to launch a Security Risk Assessment (SRA) Tool to help small and medium-sized healthcare organizations and BAs comply with the HIPAA Security Rule. The tool is meant to guide these entities in identifying security risks in their systems, policies, and processes and display results that they can use to mitigate any identified vulnerabilities. Since launching the original tool about ten years ago, revisions have been made and it is now more of a decision tree process.

    However, itโ€™s important to note that the CFRs do not make it mandatory for Covered Entities and Business Associates to use the SRA tool nor does it give specific guidelines on how risk assessment should be carried out. HHS recognizes that different sized businesses have different needs and vulnerabilities, as well as different levels of access to resources. The problem with the tool is it can become time consuming to use, leads to more questions about meeting compliance requirements, and inability to see all the questions until traversing through the process. Regardless of using the tool or outsourcing the assessment to a consultant or vendor, all CEs and BAs must have documented proof that they have conducted an accurate and thorough HIPAA security risk assessment.

    Failure to Perform a HIPAA Risk Assessment Can Result in Serious Penalties

    If just knowing that conducting a risk analysis is a HIPAA requirement isnโ€™t enough motivation to get you started with the process, then you should keep in mind that the fines for non-compliance can add up to hefty amounts. Some organizations like Excellus Health Plan, Inc., for instance, have had to pay up to $5.1 million to OCR for breaching ePHI. According to this press release, the penalty was attributed to the organizationโ€™s โ€œfailure to conduct an enterprise-wide risk analysis, and failures to implement risk management, information system activity review, and access controlsโ€, which put the privacy of millions of its patients in danger. So, carrying out a risk assessment does not only allow you to spot potential weaknesses in organizational information systems that contain ePHI; it also enables you to take the right actions as soon as possible to safeguard your ePHI data, which can protect your business from federal penalties and the need to enter into a resolution agreement with OCR.

    Need Help With Your HIPAA Compliance Program?

    HIPAA violations often stem from small, overlooked gaps in daily operations. Don’t wait for a patient complaint to trigger a federal investigation. Would Your Practice Pass a HIPAA Audit Tomorrow?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your practice.

  • Understanding the Role of a HIPAA Business Associate

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    The continued complexity of modern healthcare systems and growth of patientsโ€™ data mean that medical records can be stored in more places than just the doctorโ€™s office. The information may be kept and maintained offsite in a storage facility or on a cloud-based server operated by a third party. Any entity or individual that uses, processes, or discloses this data on behalf of the healthcare provider is called a HIPAA Business Associate. If an organization is contracted by a HIPAA Covered Entity (CE) to perform activities that involve accessing Protected Health Information (PHI) or electronic PHI (ePHI) in any way, they are considered a Business Associate (BA). Because Business Associates use protected patientsโ€™ data to support the operations of covered entities, the U.S. Department of Health and Human Services (HHS) requires adherence to the Code of Federal Regulations (CFR) to comply with HIPAA requirements.

    Business Associate Agreement (BAA)

    The HIPAA Privacy Rule states that, โ€œA covered entity must obtain satisfactory assurances from its Business Associate that the Business Associate will appropriately safeguard the protected health information it receives or creates on behalf of the covered entity. The satisfactory assurances must be in writing, whether in the form of a contract or other agreement between the covered entity and the business associate.โ€

    This means that before a covered entity can work with a Business Associate, the BA must sign a BAA stating that they will safeguard and treat PHI the way CFRs and the covered entity require them to. It does not matter whose version of the BAA is signed, whether provided by the CE or the BA, as long it is executed. According to the Health Information Technology for Economic and Clinical Health (HITECH) Act, a BAA must include specific information to meet HIPAA compliance such as a description of the required and allowed uses of PHI, declarations that the Business Associate will disclose information only as required by law, and proper safeguards to protect patientsโ€™ data from breach including steps to take should there be such security violations.

    Why are Some Business Associates Not Complying with HIPAA Regulations?

    One of the major reasons is that most of them have no idea that the law considers them Business Associates. Covered entities have made great strides in following HIPAA compliance requirements, but many Business Associates are still not aware of the need to comply or are just reluctant to do so. Under HITECH, the Office of Civil Rights (OCR) holds Business Associates liable for breaches, and it is imperative that these entities take the necessary steps to ensure HIPAA compliance. In this press release where a Business Associate pays $2.3 million to settle a breach, the OCR Director at the time, Roger Severino terms โ€œThe failure to implement the security protections required by the HIPAA Rules in an industry known as a target for hackers and cyber thievesโ€ inexcusable. Sure, following all the steps required to obtain HIPAA compliance may seem overwhelming, but it offers better protection for patientsโ€™ data, which helps Business Associates avoid these types of federal penalties.

    Helping Organizations Achieve HIPAA Complianceโ„ข

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Office for Civil Rights – Guidance on HIPAA IT Asset Inventories

    On August 25, 2020, OCR as part of its quarterly cybersecurity newsletter, provided outstanding guidance regarding HIPAA and IT Asset Inventories. As part of the risk assessment process at Colington Consulting, this is a critical area we address with all of our clients. We want to ensure there is a detailed asset inventory of all software, hardware, network or computing component that creates, receives, maintains, or transmits electronic protected health information (ePHI). Sometimes we find this information scattered into various documents or not centrally maintained. Our goal is to make sure there is a comprehensive list for software and hardware for these vital components throughout an organization.

    Here are some helpful sections from the newsletter:

    “The HIPAA Security Rule requires covered entities and business associates to ensure the confidentiality, integrity, and availability of all electronic protected health information (ePHI) that it creates, receives, maintains, or transmits. Conducting a risk analysis, which is an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI held by an organization, is not only a Security Rule requirement, but also is fundamental to identifying and implementing safeguards that comply with and carry out the Security Rule standards and implementation specifications. However, despite this long-standing HIPAA requirement, OCR investigations frequently find that organizations lack sufficient understanding of where all of the ePHI entrusted to their care is located. Although the Security Rule does not require it, creating and maintaining an up-to-date, information technology (IT) asset inventory could be a useful tool in assisting in the development of a comprehensive, enterprise-wide risk analysis, to help organizations understand all of the places that ePHI may be stored within their environment, and improve their HIPAA Security Rule compliance.”

    How to Create an IT Asset Inventory

    “An enterprise-wide IT asset inventory is a comprehensive listing of an organizationโ€™s IT assets with corresponding descriptive information, such as data regarding identification of the asset (e.g., vendor, asset type, asset name/number), version of the asset (e.g., application or OS version), and asset assignment (e.g., person accountable for the asset, location of the asset). When creating an IT asset inventory, organizations can include:

    • Hardware assets that comprise physical elements, including electronic devices and media, which make up an organizationโ€™s networks and systems. This can include mobile devices, servers, peripherals, workstations, removable media, firewalls, and routers.
    • Software assets that are programs and applications that run on an organizationโ€™s electronic devices. Well-known software assets include anti-malware tools, operating systems, databases, email, administrative and financial records systems, and electronic medical/health record systems. Though lesser known,there are other programs important to IT operations and security such as backup solutions, virtual machine managers/hypervisors, and other administrative tools that should be included in an organizationโ€™s inventory.
    • Data assets that include ePHI that an organization creates, receives, maintains, or transmits on its network, electronic devices, and media.”

    As part of this inventory process, we always recommend organizations have an accurate and up-to-date list of all vendors in which you have signed Business Associate Agreements in place with. You may also want to include a list of all types of physical, hard copy medical records, billing records, or any other paper documentation containing protected health information.

    All these asset inventory lists must be reviewed and confirmed during the risk assessment process.

    Not One and Done

    This should not be considered a “one and done” process. It is important to remember whoever is assigned this task, whether it is an individual or a department, that is an ongoing process. Lists must be updated as new equipment or software is added and legacy systems or devices are removed.

    Take Action Now

    If HIPAA compliance assistance is needed for your organization, we specialize in putting compliance programs in place or assessing your current program. We provide a full range of services that include conducting the required HIPAA Risk Assessment, ensuring critical asset inventory lists are in place, writing and customizing a HIPAA Risk Management Plan (HIPAA Policies and Procedures) for your organization, and providing your entire staff annual required HIPAA Security Awareness & Privacy Training through our web-based platform. Our fees are based on what specifically your organization will need to meet regulatory requirements and reasonably priced to accommodate any budget.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Best Practices for Teleworking & Telehealth Involving PHI/ePHI

    by Jay Hodes, President – Colington Consulting

    With the federal public health emergency in place as of January 31 to address COVID-19, many healthcare organizations have implemented teleworking options for their workforce. Providers are also using telehealth services to interact with their patients. For some organizations, this is a whole new world. If not already in place, organizations needed to implement policies and procedures to address these critical operational topics.

    The HHS Office for Civil Rights (OCR) has issued a number of guidance documents pertaining to this emergency. Here are some excerpts I feel are important:

    February 2020: โ€œIn an emergency situation, covered entities must continue to implement reasonable safeguards to protect patient information against intentional or unintentional impermissible uses and disclosures. Further, covered entities (and their business associates) must apply the administrative, physical, and technical safeguards of the HIPAA Security Rule to electronic protected health information.โ€

    As further stated in the guidance regarding PHI:

    โ€œThe HIPAA Privacy Rule protects the privacy of patientsโ€™ health information (protected health information) but is balanced to ensure that appropriate uses and disclosures of the information still may be made when necessary to treat a patient, to protect the nationโ€™s public health, and for other critical purposes.โ€

    March 2020: โ€œWhile the HIPAA Privacy Rule is not suspended during a public health or other emergency, the Secretary of HHS may waive certain provisions of the Privacy Rule under the Project Bioshield Act of 2004 (PL 108-276) and section 1135(b)(7) of the Social Security Act.โ€

    Although OCR has indicated some discretion with its enforcement authority and waiving some requirements, the HIPAA Privacy and Security Rules are still in place with very limited exceptions.

    With the OCR guidance clearly stated, there must be an operational balance and the need to apply a commonsense approach to minimize the risks for unauthorized disclosures in order for your workforce to be able to perform their jobs while teleworking and during telehealth sessions.

    Here are some best practices to consider implementing as part of your organizationโ€™s policies to address teleworking and telehealth sessions:

    • Staff should never leave any documents containing PHI in a vehicle overnight. Even if the vehicle is locked or the documents can be secured in a trunk, all PHI must be removed. No exceptions!
    • When working from home, the staff should follow the same protocols as if in an office, practice location, or providing services face-to-face. This means following the Minimum Necessary Requirement. If working from home and there are others in the house, such as family members or roommates, only have patient conversations where others cannot hear that conversation. Staff must try to make those conversations as private as possible. This includes VTC telehealth sessions and telephone calls.
    • Always keep documents containing PHI as secure as possible so others may not see them when performing work related duties.
    • Avoid having conversations with those in the house regarding any patient.
    • Never allow family members, roommates, or others in the house to access/use any organization issued devices including cell phones and laptops, unless personal use is approved by the organization.
    • If using a personal computer for organization business, make sure others in the home do not access while performing work related duties. If a computer needs to be utilized for non-organization business during the workday or shift, always log off from organization access or VPN.
    • If staff needs to leave an area in the home that is set up as a workstation to take a break, grab a coffee, or handle non-organization issues, always make sure to lock the computer and secure documents. Even for a few minutes.
    • At the end of the business day or shift, staff should log off from any computer they are using and properly secure any documents containing PHI.
    • If HIPAA compliant bags or containers are provided by the organization, then use those to secure the documents when not needed.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Additional Resources for Telehealth:

    OCR – FAQs on Telehealth and HIPAA during the COVID-19 nationwide public health emergency

    National Consortium of Telehealth Resource Centers

    The National Counsel – Best Practices for Telehealth During COVID-19 Public Health Emergency

    American Psychiatric Association – Best Practices in Videoconferencing-Based Telemental Health

    SAMHSA Telehealth Start-Up and Resource Guide

  • 6 More HIPAA Breaches Reported

    With healthcare attention clearly focused on combating the coronavirus, there were six more data breaches that occurred within a few days as the year began. The breaches reported by healthcare organizations, likely resulting in the unauthorized releases of patient data for at least 8,701 patients. As the sheer number of data breaches continues to rise, so too does your responsibility to protect the people who rely on your services. What happened in these latest occurrences, and what steps should you take to fulfil your obligation to prevent it from happening within your own organization?

    Kaiser Permanente is breached once again.

    Kaiser Permanente already had 4 data breaches by the time reports came out back in 2014. Then, in 2018, at least two more were reported. And then again in October of 2019. Now the latest breach occurred when Kaiser Permanente recently discovered letters have accidentally been mailed to patientsโ€™ former addresses. The HHSโ€™ Office for Civil Rights (OCR) breach portal indicates up to 500 patients may have been affected in this one. (This is not counting their prior breaches.)

    Riverview Health also experienced a mailing error.

    Much like Kaiser Permanenteโ€™s latest breach, this one also happened due to a mailing error. This time, however, the mix up exposed the names of 2,610 patients. Fortunately, no financial information – such as credit or debit card numbers – or medical data was exposed. However, the methods of patient notification used by Riverview are currently under review as a result of this incident.

    Harris Health System lost PHI during transport.

    On Friday, February 28th, Harris Health System announced that it was notifying 2,298 patients of a privacy breach that happened on December 30, 2019. Two envelopes that contained 143 pages of protected health information (PHI) were lost in transport to Ben Taub Hospital, which were being sent there for scanning and archiving in Harris Health’s electronic medical record system. The envelopes are thought to contain information on patients seen at Gulfgate Health Center from December 9, 2019 and December 27, 2019.

    Community Mental Health Council mental health records were found dumped in an alley.

    In 2012, the Community Mental Health Council was forced to permanently close its clinics due to lack of funding. Long after the fact, however, hundreds of medical records from CMHCl have been found abandoned in an alley in West Englewood, Chicago. The documents included full names, addresses, Social Security numbers, diagnosis information, medical records, and more. City officials are currently trying to determine who was responsible for dumping the records.

    Armada Physical Therapy had a server carried off.

    Data breaches through hacking, phishing scams, and mailing errors are nothing new. But what makes the breach of Armada Physical Therapy stand out is that this time around, someone actually broke into the building and stole an entire server. At the time of writing, the investigation is still ongoing, and the stolen server has not yet been recovered. The server holds intake forms that contain names, addresses, telephone numbers, email addresses, insurance numbers, and Social Security numbers for around 500 patients.

    Elk Ridge Dentistry had a hard drive stolen.

    Unlike the incident with Armada, one would imagine that stealing a portable hard drive is at least a bit easier than making off with an entire server. At least one such hard drive was stolen from Elk Ridge Dentistry. The hard drive in question was used to store backups, and was actually among several items taken from the practice. Much like Armadaโ€™s server, the hard drive has not yet been recovered. To make matters worse, it contained the records of 2,793 patients, which included names, addresses, dates of birth, healthcare information, X-ray images, Social Security numbers, treatment consent forms, referral letters, and emails.

    Take Action Now

    So many different occurrences all happening within such a short time should give anyone cause for serious alarm. The numbers are against you, and we here at Colington Consulting donโ€™t want you to become yet another statistic. Even as COVID-19 events have impacted healthcare organizations, we are still able to provide the majority of our services remotely. We are available and can set up an initial consultation to talk about our services and how we can assist your organization. Call us today at 844.740.7100 and find out how we can help you protect your patients from incidents like these.