Category: HIPAA Compliance

  • HIPAA and Home Health Care Providers

    by Jay Hodes, President – Colington Consulting

    Over the last few months, I attended a number of events with geriatric care managers and home health agency owners. It was extremely insightful learning about the tremendous services these professionals provide to our aging population. As more and more seniors consider aging in place and remain in their homes, the need for home health services is exploding.

    After speaking with some care managers, I subtly brought up the subject of HIPAA and how it may be applicable to certain aspects of the services they provide. Most those who provide non-medical care said that they were unaware of specific HIPAA requirements and admittedly did not know if it applied to what they do. I asked if they or their staff were maintaining client files that contained any protected health information (PHI). Most said yes, as this type of information is vital to the type of services provided to their clients.

    When I asked about taking the proper safeguards to protect client health information and other personally identifiable information (PII) they maintain, most if not all said they had no formal safeguards in place. What was even more unsettling was very few of these companies even had an employee policy and procedure manual that covered protecting client health information. From what I was told, a great deal of client health information is passed through unsecured means, including unsecured texting and email exchanges, along with the use of file sharing services.

    The HIPAA Privacy Rule requires healthcare providers, regardless of size, provide the proper safeguards of individually identifiable health information. Technically, a home health or geriatric care manager that does not provide skilled medical care does not meet the regulatory definition of a covered entity or business associate under this rule unless they are filing health insurance claims for clients. That poses a significant grey area in terms of mandating specific requirements for this category of professional caregiver. If a breach of client records did occur, the government would have no idea it happened. There are no notification requirements and no mandates to inform clients their health and personal information may have been compromised.

    Professional caregivers must be bound to protecting the confidentiality of client health information. Although there may not be a regulatory requirement, caregivers must be attentive to HIPAA regulations and use this guidance as a model to safeguard records. After all, they are dealing with and managing client health concerns every day on the job.

    I am usually asked, โ€œWhere do I start?โ€ Here are some suggestions to follow:

    1. Develop a Privacy Policy and Procedure Manual that is distributed to all staff. The manual needs to cover areas such as:
    • Notice of Privacy Practices
    • Uses and Disclosures of Protected Health Information Requiring Client Authorization
    • โ€œMinimum Necessaryโ€ Use and Disclosure of Protected Health Information
    • Uses and Disclosures of Protected Health Information where the Client has an Opportunity to Agree or Object
    • Access of Individuals to Protected Health Information
    • Accounting for Disclosure of Protected Health Information
    • Business Associate Agreements
    • How to Safeguard Protected Health and Personal Information
    • Complaints to Your Company or Business; Mitigation
    1. Require some type of security awareness training be conducted for all staff, regardless of their job function, on an annual basis and any time you take on a new employee.
    2. If you are currently using smartphones to text client health information, I would recommend against it. I know this may pose an inconvenience, but it is a prudent security measure. There are secure texting services available. If phones need to be used, it is best to call each other and discuss client health information in a private setting.
    3. From an IT perspective, the following safeguards should be in place:
    • Ensure there is full disc encryption on all laptops/computers used by the company staff. This includes all BYOD.
    • Implement a secure email service for exchanges between staff, providers and others who may need to view PHI and PII. This service includes the ability to securely upload attachments.
    • Ensure all computers/laptops have appropriate anti-malware and anti-virus software that is updated often.
    • Set auto log-off if the device is left unattended for a certain period of time, such as 10 or 15 minutes.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Updated on June 21, 2026 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Regulatory Sources: The HIPAA Privacy Rule (45 CFR ยง 164.524): This is the core federal regulation that establishes a set of national standards for the protection of certain health information. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) provides official regulatory guidance and actively enforces these timelines under its ongoing Right of Access Initiative, which targets covered entities that fail to provide timely access to records. 45 CFR 164.502(e), 164.504(e), 164.532(d) and (e), address Business Associates and when Business Associate Agreements are required.

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • Insider Threat โ€“ A Growing Concern in the Healthcare Sector

    by Jay Hodes, President – Colington Consulting

    As a healthcare provider or business associate, do you conduct a pre-employment background check on all potential new hires? Do you routinely conduct periodic background checks for the current workforce? If the answer to either of these questions is โ€œno,โ€ you may want to reconsider and implement a policy.

    There is a growing concern in the healthcare sector regarding insider threats. Being HIPAA compliant puts the necessary administrative, technical and physical safeguards in place. But most of these safeguards address how to ensure systems and the workforce properly manage risk. Even with the minimum necessary requirement of the HIPAA Privacy Rule, think about those in your practice or business who have access to protected health information, especially paper charts and records. Access to paper records, notes and charts poses a greater risk for a breach than electronic health records because, with paper records, there is the lack of an IT-based audit trail.

    In May, Beckerโ€™s Health IT & CIO Review reported that during a 14 day period, there were six insider threat cases the public was made aware of. In one case, a nurse at Albany (N.Y.) Medical Center was arrested at the hospital and charged with stealing patient information. In another case, an employee who processed billing for Baylor All Saints Medical Center in Fort Worth, Texas, may have stolen patient information over a seven month period. There was no information provided in either case indicating that background checks were conducted on these employees and if there was, how thorough the checks were.

    When the Ponemon Institute released its Fourth Annual Benchmark Study on Patient Privacy & Data Security last March, a significant finding stood out. According to the report, โ€œEmployee negligence is considered the biggest security riskโ€ when it comes to safeguarding health data. The report went to say, โ€œ75 percent of organizations (surveyed) say employee negligence is their biggest worry.โ€

    There appears to be a failure to exercise reasonable care when it comes to safeguarding protected health information, whether a compromise of records is intentional or unintentional. Background checks wonโ€™t help prevent human error and circumstances where the breach was unintentional. Better security awareness training can address that issue.

    But when the circumstances are intentional and an employee is to blame, you will need to look at the employee and hiring practices. As a hiring manager who has an employee arrested for theft, there is no worse feeling than when the police inform you about a prior criminal record that employee had. However, pre-employment background checks may not help if the employee has no criminal record and just goes rogue for financial gain. This is why I recommend a policy to conduct background checks on a regular basis for all employees, not just new hires. You may want to include a credit check as part of your background check policy.

    Stacy Skinner is the President of SCS Health and Security Associates, a company that offers background checks as part of their portfolio of services. According to Skinner, โ€œConducting background checks for all applicants is a great idea because you want to reduce the risk of a negligent hire. Every time an employer hires an employee, they take a risk and by conducting a background check, it helps to mitigated risk. It comes down to protecting sensitive information, patient confidentiality, patient safety, safety of the staff, and that of the business. Know more about who you are hiring. It can make a difference.โ€

    Here are 5 suggestions for implementing or modifying an existing background check policy.

    1. Be consistent with a background check policy. That is a must. Background checks must be conducted for the entire workforce, including contract and temporary employees. Consider using a tiered approach that is dependent on the position to be filled. For example, a doctor would warrant a more comprehensive check than a receptionist.
    2. Always check the U.S. Department of Health and Human Services, Office of Inspector General Excluded Individuals/Entities List (LEIE). The LEIE is an excellent way to see if an employee has previous sanctions preventing him/her from working in the healthcare sector.
    3. Consider conducting periodic background checks for those workforce members who have been on-board for a while. Rescreening workforce members can help to make sure an employee does not slip through the cracks by not notifying management of any recent criminal convictions.
    4. Drug screening – if a program is not in place, consider implementing one. The screening would be applicable to job applicants along with the current workforce.
    5. Consider contracting with a reputable investigations company that specializes in background checks. Leave this job to the professionals who know how to conduct background checks. Trying to obtain criminal background checks on your own can vary from state-to-state and be a time consuming process in some cases.

    Before implementing or updating a policy regarding background checks, credit checks and drug testing, it is always prudent to seek advice of legal counsel. For more information about background checks, visit the U.S. Equal Employment Opportunity Commission website.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • Substantial HIPAA Data Breaches: Only a Matter of Time

    by Jay Hodes, President – Colington Consulting

    With all the news about data breaches and the potential for personally identifiable information (PII) to make its way into the wrong hands of criminals or hackers, is it only a matter of time before there is a substantial breach of patient records? When checking the U.S. Department of Health and Human Services (HHS) Breach List, you will find these occurrences already happening on a regular basis. In June, the state of Montana announced 1.3 million people were affected by a recent health records data breach.

    Between March 1 and May 30, 2014, there were eight separate breach notifications made to HHS, each affecting 500 or more individuals, totaling almost 35,000 compromised patient records. The largest breach affected more than 8,800 individuals from an HMO and related insurance provider. But these breaches affect small healthcare providers, also. One of the reported breaches affecting 1,000 individuals was at a podiatry office and another at a dental practice that involved 6,900 individuals. There is no percipience with the size and type of healthcare practice, and most breaches appear to be theft related.

    There is usually limited press coverage of these breaches, except by those who track these industry occurrences. But when a newsworthy and extensive breach of millions of records does happen, it will be front page news. When will the tsunami of a health record breach occur? Regrettably, it may be sooner than later. When the FBI recently warned healthcare providers that their cybersecurity networks are more susceptible than retail and financial sectors, hopefully the alarm bells went off and proper information technology countermeasures are now being implemented.

    According to Chris Albright, network security expert and owner of CMIT Solutions of Centreville (VA), โ€œHackers, just like other predators, always go after the most vulnerable or โ€˜softโ€™ targets first. This approach guarantees the hacker greater success with the least amount of effort. More often than not, data breaches are not professional hackers in the traditional sense. Rather, it is members of the medical staff who know there are no policies or effective security measures in place, and they know the violation will go unnoticed. Healthcare offices that fail to address HIPAA head on are essentially sitting on a time bomb.โ€

    Conducting a HIPAA Risk Assessment is an excellent way to identify vulnerabilities and threats to patient electronic health records. Besides being a fundamental requirement of HIPAA compliance, the assessment helps professionals to recognize problem areas where the potential for unauthorized access, lack of proper internal protocols for tampering and outright theft of protected health information may occur.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Updated on June 21, 2025 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • Why Should HIPAA Compliance Matter to You?

    by Jay Hodes, President – Colington Consulting

    Healthcare Professionals

    If you are a healthcare provider or business associate, HIPAA compliance should matter because it is the law. According to the Code of Federal Regulation (CFR), if you are a provider or business associate who utilizes electronic health records, you must ensure the confidentiality, integrity, and availability of all records created, received, maintained, or transmitted. Civil monetary penalties for noncompliance that cause a breach of electronic patient records can be assessed up to $2.2 million. Criminal penalties can range from one to ten years in prison.

    I believe one of the biggest issues facing small healthcare providers is lack of knowledge of exact requirements for HIPAA security compliance. Part of the problem for small providers is they often have an unclear understanding of what safeguards need to be in place for electronic health records. I see this as a huge concern. The U.S. Department of Health and Human Services (HHS) has done a better job providing specific guidance to small providers. Navigating through the HHS website to find particular HIPAA compliance information has improved, but can be daunting to find specific information.

    I should know because I used to work for HHS and had oversight of complex health care fraud investigations. We had teams of lawyers and analysts to guide us in the regulatory world, whereas a small healthcare provider, if lucky, maybe will find the necessary guidance on the HHS website. Even then, the information becomes subject to interpretation by a provider with limited exposure to HIPAA regulatory compliance. Ask yourself how comfortable you are with this.

    Patients

    With more and more healthcare providers utilizing electronic health records, consumers (patients) need to ask those providers if they are doing everything they can to secure their health information. For consumers, HIPAA compliance matters because it equals assurance that the proper safeguards are in place to prevent unauthorized access, tampering, and theft of medical records.

    A recent study by the Ponemon Institute found criminal attacks on healthcare providers have increased dramatically, up 100% since 2010. Unlike having credit information stolen where the bank or credit card company may notify the consumer about suspicious activity in a timely manner, health information compromises take longer to recognize. With all the recent emphasis on newsworthy data breaches, this is a wake-up call for patients who must treat their online health information as they would their credit information.

    Medical identity theft is a profitable industry for criminals who can make a lot more money selling health information than credit card numbers. According to Dell Secure Works, an information security services company, criminals can get paid $20 for a personโ€™s stolen health identity information, as compared to credit card numbers that may yield $1 to $2 apiece. As a former Assistant Inspector General for Investigations at HHS, I know that Medicare card numbers could be sold for up to $50 apiece. In addition, there is much more personal data at stake with health records, which can include sensitive information such as pre-existing conditions, full-blown medical histories, and prescriptions, along with a plethora of financial, employment, and family information.

    So the next time you go to your healthcare provider and you are asked to sign a HIPAA release form, read the fine print. Know your rights and expectations of privacy. Most importantly, ask your providers what they are doing to protect your electronic health records.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • 56% of Employees Still Receive No Security Awareness Training

    With all the recent and notable attention to data breaches, on-line security, and preventative measures, the fact that more than half the employees surveyed did not receive security awareness training is cause for concern.

    When it comes to HIPAA Security Rule requirements, security awareness training is mandated. The more robust your training is, the better positioned your practice or office can be when it comes to early detection of a possible breach.

    Below is a repost of a recent article regarding security awareness training from Help Net Security. A new research survey by EMA takes you inside todayโ€™s organizations to reveal how employee decisions related to information security can significantly increase organizational risk. The report examines the implementation of security awareness training in government, public and private companies and non-profit groups.

    According to employee responses in the survey report:

    • 30% leave mobile devices unattended in their vehicle
    • 33% use the same password for both work and personal devices
    • 35% have clicked on a link in an email from an unknown sender
    • 58% have sensitive information on their mobile devices
    • 59% store work information in the cloud.

    Some of the reported behaviors present inherent risks, while others depend on contributory factors like the failure to use device or data encryption.

    Fifty-six percent of corporate employees, excluding security and information technology staff, have not had security or policy awareness training from their organization, while 45% of employees received training in one annual session. Without the foundation of on-going security awareness training, employees donโ€™t receive the critical security information they need to make secure choices.

    EMA Research Director David Monahan said: โ€œPeople repeatedly have been shown as the weak link in the security program. Without training, people will click on links in email and release sensitive information in any number of ways. In most cases they don’t realize what they are doing is wrong until a third-party makes them aware of it.”

    “In reality, organizations that fail to train their people are doing their business, their personnel and, quite frankly, the Internet as a whole a disservice because their employeesโ€™ not only make poor security decisions at work but also at home on their personal computing devices as well,” Monahan added.

    Sixty-six percent of employees responding to the survey said it is important that training materials are easy to understand; and 59% say that interactive activities are important.

    โ€œWhile todayโ€™s organizations continue to harden their infrastructure to protect against the latest cyber threats, this report reveals that they too often fail to arm their employees with the critical information needed to avoid a data breach, prevent phishing, or report a possible security incident,โ€ said Craig Kunitani, COO with Security Mentor. โ€œEvery organization should make security awareness training part of its defense in depth strategy. Many of our customers report theyโ€™ve had great success in educating their staff using our security awareness training program because of our brief, interactive, and informative lessons.โ€

    Need Help with Your HIPAA Compliance Program?

    Colington Consulting provides comprehensive HIPAA training courses that instruct members of your organization on protecting patient health information of all forms, including electronic health records. We offer a variety of HIPAA training courses designed to easily and affordably meet annual security and privacy requirements.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your training program and protect your organization.

    • This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Survey Finds Lack of HIPAA Compliance Knowledge

    by Jay Hodes, President – Colington Consulting

    It came as no surprise to me when I reviewed a recent HIPAA survey conducted by NueMD, in conjunction with Porter Research and The Daniel Brown Law Group, which found that most healthcare providers and business associates that responded have a limited knowledge of compliance regulations. This was one of the most comprehensive surveys on HIPAA compliance that I have seen.

    Part of the survey asked over 1,000 providers, administrators and medical office staff a number of questions regarding their knowledge and awareness of HIPAA compliance requirements. Let me share some of those practice findings:

    • 68% of respondents were unaware that random HIPAA audits were going to be conducted.
    • Only 35% of respondents said they conducted a HIPAA-required risk analysis.
    • Only 24% of managers, owners and administrators reported that they evaluated all of their Business Associate Agreements.

    Why does it not come as a surprise to me? Well, for a number of reasons. Smaller medical practices do not have the in-house resources to handle the complexities of meeting all of their compliance requirements. Most donโ€™t realize what is involved. When I provide initial consultations with potential clients and explain all the areas that must be covered, I usually get the typical response that they did not think all the regulations applied to their practice or that their practice was too small and some of this compliance stuff was not necessary. Itโ€™s not that they donโ€™t want to be compliant; it is more that they do not know or understand what is entailed.

    Reinforcing this perception, when looking at โ€œpractices by size, (the survey) found that larger practices (particularly those with 10 or more providers) tended to do better when it came to compliance measures within the office – things like having a plan, training staff, appointing officers and conducting risk analyses. This wasn’t surprising, as larger organization usually have more resources to devote to regulatory compliance.โ€

    I feel part of the onus for so much confusion among smaller providers rests with my former agency, the U.S. Department of Health and Human Services. Although the Office for Civil Rights (OCR) has the primary responsibility to enforce HIPAA regulations, the Office of the National Coordinator for Health Information Technology (ONC) promotes the use of electronic exchanges of health information. ONC pushes out guidance on health information privacy, security and the implementation of electronic health records.

    Then there is the Centers for Medicare & Medicaid Services (CMS) that administers the EHR Incentive Program. CMS has started to conduct meaningful use attestation audits. One of the core objectives that must be attested to is that a HIPAA Risk Assessment was conducted, the same risk assessment that OCR requires and would review during their own audit or compliance review.

    A practice manager, already wearing so many hats, does not have the time to conduct the research, check the websites of three different agencies and find the necessary answers to what is reasonable and appropriate for that officeโ€™s environment. This leads to another survey finding from medical practices in that only 38% of respondents said โ€œthat someone at (the) business is actively ensuring (the) business’s compliance with HIPAA.โ€

    If you are unsure of where to start, have a HIPAA Risk Assessment conducted, especially if your practice or business has never done one. The assessment will identify vulnerabilities and threats to your current administrative, physical and technical safeguards for protected health information you maintain. A good assessment must provide an action plan or steps for remediation for all the vulnerabilities and threats that were detected. It provides a critical road map, based on the rated risk level, for what needs to be addressed immediately to meet compliance requirements.

    What is clear is the need to make HIPAA compliance an important part of the everyday operations for any healthcare practice or business, not just when there is a threat of an audit. Because compliance requirements can be such a time consuming process, consider outsourcing this responsibility. I know there are quite a few practice managers who need assistance and would relish having a consultant provide this service. In the end, it may be a cost saving measure to outsource HIPAA compliance assistance, saving workforce time and a lot of frustrating hours.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Indiana Dentist Fined by State for HIPAA Violations

    by Jay Hodes, President – Colington Consulting

    According to an article published in the Kokomo (Indiana) Tribune, a former Kokomo dentist, Joseph Beck, โ€œagreed to pay the state $12,000 for disposing of patient files in an Indianapolis dumpster, the Attorney Generalโ€™s Office (recently) reported. The Attorney Generalโ€™s Office sued Beck for failing to protect personal information and for improperly disposing of records containing personal information of Indiana residents, which violates state privacy laws as well as the federal Health Insurance Portability and Accountability Act (HIPAA).โ€

    What is significant is, โ€œThis is the first time Indiana has sued for a violation of HIPAA.โ€ The article went on to say, โ€œMore than 60 boxes of patient records from Beckโ€™s former Comfort Dental clinic in Kokomo were found discarded in an Indianapolis dumpster in March of 2013. The files contained records from 2002-2007.โ€ Not only are the Feds involved with compliance oversight, but now the states have an active interest, especially when civil monetary penalties can be imposed. States may view this as a way to step up their game when it comes to conducting audits, investigations and prosecutions for HIPAA compliance. With more and more data breaches occurring, it makes perfect sense for this course of action.

    The Office for Civil Rights (OCR), which enforces Federal regulations and compliance for HIPAA, has been conducting training for State Attorneys General (AGs). OCR developed HIPAA enforcement training to state AGs and their staff on how to use this authority to enforce the HIPAA Privacy and Security Rules. The training course provides assistance on how to investigate HIPAA violations. But more importantly, the training shows AGs how to seek civil damages for HIPAA violations that affect residents of their respective states.

    With this recent case in Indiana, the dentist โ€œhired a private company, Just the Connection, Inc. to retrieve and dispose of his patient records, which included names, medical records, phone numbers, birth dates, Social Security numbers, insurance cards, insurance information and state ID numbers.โ€ It is unclear if Beck had a Business Associate Agreement (BAA) in place with the private company to properly dispose of the records. The BAA would have been required in this case.

    As a covered entity, this story reinforces the need not only to have a BAA in place with any vendor who is accessing your protected health information, but also make sure your own HIPAA policies and procedures cover proper record disposal. Any BAA must require that a business implement the proper safeguards to prevent unauthorized use or disclosure of protected health information (PHI) not only for electronic records, but also for any paper records or charts. This is especially critical for the document destruction process for PHI.

    Although smaller state civil settlements are not on par with the millions OCR seeks during a resolution agreement, it does allow the states to become more engaged in investigating these types of breaches. Just more one reason to be HIPAA compliant.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Anthem HIPAA Breach

    Setting the Stage for More Government Oversight

    by Jay Hodes, President – Colington Consulting

    The dust has settled, and more facts have been coming to light regarding the recent HIPAA data breach at Anthem Blue Cross Blue Shield. It was only a matter of time before the U.S. Congress started making some noise about cybersecurity. Within days of news reports of the Anthem breach, the U.S. Senate Committee on Health, Education, Labor and Pensions announced a bipartisan initiative to focus on the security of health information technology. This initiative will also look at the health industryโ€™s overall preparedness for cyber threats.

    Although the timing was ironic and clearly not related to the Anthem breach, the White House announced its 2016 proposed budget that includes an increase in funding for HIPAA compliance programs. The proposed budget indicates around a 10% percent increase in funding for the Office for Civil Rights (OCR). OCR is the agency within the U.S. Department of Health and Human Services (HHS) with HIPAA compliance and oversight responsibilities.

    As far as the possible budget increase for OCR, we will wait to see what type of mood Congress is in to approve this. And, even with this congressional initiative, any proposed fixes will take time and money. In the meantime, hopefully the Anthem case sends a loud and clear message to all healthcare providers to up their game when it comes to protecting patient health information. Healthcare providers, plans and clearinghouses need to go on the offensive and be proactive when it comes to having the proper information technology safeguards in place. The threat of Congressional action or a beefed up OCR must not be the incentive to do so.

    Regrettably, the use of encryption is not a requirement of the HIPAA Security Rule. As shocking as that sounds, that does not mean covered entities do not need to encrypt their patient data. What the guidelines call for, as provided by HHS, is this:

    The encryption implementation specification is addressable, and must therefore be implemented if, after a risk assessment, the entity has determined that the specification is a reasonable and appropriate safeguard in its risk management of the confidentiality, integrity and availability of e-PHI [electronic protected health information]. If the entity decides that the addressable implementation specification is not reasonable and appropriate, it must document that determination and implement an equivalent alternative measure, presuming that the alternative is reasonable and appropriate. If the standard can otherwise be met, the covered entity may choose to not implement the implementation specification or any equivalent alternative measure and document the rationale for this decision.

    It is incumbent on covered entities to conduct a HIPAA Risk Assessment in order to make the determination on whether it is reasonable and appropriate to their particular circumstance to use encryption software. The assessment must be the basis for the decision. And if the decision is made not to encrypt, then the justification must be made abundantly clear in documentation.

    So if there is a breach and OCR asks during an investigation why your organization did not encrypt its protected health information, the justification must be based on a low threat to your data. Make sure you can back that up with documentation that is solid and well-defined. Possible civil and criminal prosecution will be based on the proof you provide.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 23, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • HIPAA Compliance โ€“ Waiting for the Other Shoe to Drop

    by Jay Hodes, President – Colington Consulting

    The expression โ€œwaiting for the other shoe to dropโ€ appears to have originated in the early 1900โ€™s and is often associated with the arrival of a seemingly inevitable event. I speculate we are at that point in terms of ramped up HIPAA compliance enforcement. The recent Anthem data breach shined a significant spotlight on how vulnerable health information technology can be without the proper safeguards in place.

    The Office for Civil Rights (OCR), the U.S. Department of Health and Human Services agency responsible for HIPAA oversight, has made a lot of noise about being more aggressive in enforcement of the regulations. You would think it is time for the proverbial other shoe to drop. But not so fast. With limited resources, there is only so much OCR can do. That needs to change. It will and probably soon.

    There is now, and has been for a while, a lot at stake in terms of making sure healthcare providers and business associates have safeguards in place to properly secure patientsโ€™ protected health information. If major healthcare plans like Anthem are not making sure they are meeting all the HIPAA required implementation specifications, what can be said for smaller healthcare providers?

    The Ponemon Institute recently released its โ€œFifth Annual Study on Medical Identity Theft.โ€ Among the findings, the study discovered that โ€œconsumers expect healthcare providers to be proactive in preventing and detecting medical identity theft.โ€ What was surprising is that โ€œmany respondents are not confident in the security practices of their healthcare provider.โ€ Another interesting outcome of study was that โ€œ79 percent of respondents say it is important for healthcare providers to ensure the privacy of their health records,โ€ and almost half of those respondents said โ€œthey would consider changing healthcare providers if their medical records were lost or stolen.โ€

    The results of the Ponemon study must be a wakeup call for healthcare providers. Can you afford to have half of your patients leave your practice if a breach occurs? As a healthcare provider, donโ€™t be surprised if patients start asking about how you are securing their protected health information (PHI). With all the recent data breaches in retail stores like Target, Sony PSN and Home Depot, consumers realize the vulnerabilities associated with the use of credit cards. As these same consumers seek healthcare services, it will be only a matter of time before questions are asked about safeguarding PHI.

    As a healthcare provider or business associate, make sure you are doing everything you can to protect health information. It goes way beyond a checklist. A robust HIPAA compliance program must be in place, regardless of the size of your practice or business. If you cannot meet all the HIPAA requirements by doing it in-house, consider outsourcing this responsibility. Take the burden off the plate of your office or practice manager or designated HIPAA officer.

    There is still time before that other shoe drops.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • HIPAA Requirements โ€“ Time for a Major Regulatory Change

    by Jay Hodes, President – Colington Consulting

    It is only fitting that legislation that was created in the mid 1990โ€™s be considered, as most HIPAA experts would agree, outdated. Even with changes brought about by HITECH and the Omnibus Act, the implementation specifications remain relatively unchanged. It is still one-size-fits-all when it comes to meeting the requirements.

    Sure, you could argue what is reasonable and appropriate for one healthcare provider is not for another. Therefore, it comes down to how each implementation specification is interpreted, how you decipher what the Code of Federal Regulation (CFR) is asking for. After spending 27 years working for the Federal government and being involved in policy and regulatory oversight, even I sometimes struggle with how to make sense of a particular CFR.

    For larger healthcare providers that have regulatory and compliance staff, HIPAA compliance might be a bit easier. But for the smaller providers who are required to follow all of the same requirements, albeit what is โ€œreasonable and appropriate,โ€ this is a colossal struggle. I can see why some small providers just throw their hands up and say, โ€œThis is way too complex for us to figure out.โ€

    When the HIPAA legislation was created, the healthcare system in this country was really starting to transform. Today, with more and more specialty practices and other types of healthcare service providers tapping into this growing market, updating regulation requirements must be a priority. It cannot be a one-size-fits-all requirement anymore. The U.S. Congress needs to take into consideration how the healthcare industry has changed, in particular with the emergence of new health related mobile apps hitting the techno-sphere. HIPAA regulatory requirements must be adaptable to meet this changing environment.

    When I conduct a HIPAA risk assessment for a smaller healthcare provider and I ask a question in an attempt to adhere to the implementation specification, often I get a non-applicable response. The hard work for me is how to get that provider covered in meeting a required implementation specification if it is non-applicable. If a provider is truly making the effort with due diligence to follow the HIPAA regulations, then that should be factored into the equation.ย  The process must allow for more discretion when it comes to some of the implementation specifications.

    All of this will require legislative fixes. The U.S. Congress can rattle a few cages and give the impression there is real concern with making sure healthcare providers are doing everything they can to safeguard patient records, but until there is movement towards making necessary legislative changes, HIPAA requirements will remain as confusing to some as the U.S. tax code.

    Back in the mid 1990โ€™s, Senators Kasebaum and Kennedy, the sponsors of the insurance reform legislation that became known as HIPAA, clearly had a vision about the changing landscape of healthcare security in this country. Which current day senators will have that vision and want to undertake this monumental task in reforming HIPAA for the next decade remains to be seen.ย  The time is now to start down this road.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • Reviewed on June 23, 2026 by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.