Category: HIPAA Compliance

  • HIPAA Privacy Rule โ€“ What is Confusing About the Requirements

    by Jay Hodes – President, Colington Consulting

    A great deal of attention is given to protecting electronic health records. The HIPAA Security Rule defines all the administrative, technical and physical safeguards that must be in place in order to be compliant. But, what about paper documents containing protected health information (PHI), required verbal conversations that need to take place in a healthcare practice and marketing?

    These topics are all covered in the HIPAA Privacy Rule. The rule clearly defines the โ€œwhatโ€ of protected health information in terms of health care providersโ€™ responsibilities, when it comes to patient privacy.ย  Although the Privacy Rule includes what is covered in terms of electronic transfers of PHI, the rule is also very extensive about the handling of PHI. Let me address a couple important sections of the Privacy Rule where many providers struggle in understanding what is and is not required. When it comes to uses and disclosures of protected health information (PHI), in general, a health care provider does not need patient authorization to:

    • Use or disclose PHI for treatment, payment or health care operations.
    • Use or disclose PHI for the treatment activities of another health care provider.
    • Disclose PHI to another covered entity or health care provider for the payment of the entity that receives the information.
    • Disclose PHI to another covered entity for health care operations activities of the entity that receives the information, if both entities have a relationship with the individual and the disclosure is for the purpose of conducting quality assessment and improvement activities, reviewing the competence or qualifications of health care professionals or for fraud and abuse detection or compliance.

    However, the heath care provider must still provide the patient with its Notice of Privacy Practices (NPP) and make a good faith effort to obtain written acknowledgement that the patient received the NPP.

    A health care practice must always be aware of the minimum necessary standard. The standard, a key protection of the HIPAA Privacy Rule, is derived from confidentiality codes and practices in common use today. It is based on sound, current practice that protected health information should not be used or disclosed when it is not necessary to satisfy a particular purpose or carry out a function. The minimum necessary standard requires health care providers to evaluate their practices and enhance safeguards, as needed, to limit unnecessary or inappropriate access to and disclosure of protected health information. The Privacy Ruleโ€™s requirements for the minimum necessary standard are designed to be sufficiently flexible to accommodate the various circumstances of any covered entity.

    Another confusing area of the HIPAA Privacy Rule concerns marketing. The Privacy Rule defines โ€œmarketingโ€ as making โ€œa communication about a product or service that encourages recipients of the communication to purchase or use the product or service.โ€ Generally, if the communication is โ€œmarketing,โ€ then the communication can occur only if the health care provider first obtains an individualโ€™s authorization.

    The Privacy Rule exceptions to the definition of marketing fall into three categories:

    • A communication is not โ€œmarketingโ€ if it is made to describe a health-related product or service (or payment for such product or service) that is provided by, or included in a plan of benefits of, the covered entity making the communication, including communications about:
    • The entities participating in a health care provider network or health plan network; replacement of, or enhancements to, a health plan; and
    • Health-related products or services available only to a health plan enrollee that add value to, but are not part of, a plan of benefits.

    This exception to the marketing definition permits communications by a health care providerโ€™s own products or services.

    1. A communication is not โ€œmarketingโ€ if it is made for treatment of the individual.
    2. A communication is not โ€œmarketingโ€ if it is made for case management or care coordination for the individual, or to direct or recommend alternative treatments, therapies, health care providers or settings of care to the individual.
    • Reviewed on June 23, 2026 by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Source: The HIPAA Privacy Rule (45 CFR ยง 164.524): This is the core federal regulation that establishes a patient’s legal right to inspect and obtain a copy of their protected health information (PHI).
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • MACRA โ€“ Are There Additional HIPAA Concerns for Providers?

    By Jay Hodes, President โ€“ Colington Consultingย 

    I am not claiming to be an expert on the Medicare Access and CHIP Reauthorization Act of 2015 (MACRA), other than the inherent emphasis this Act places on HIPAA requirements. The U.S. Department of Health and Human Services, which has a number of internal agencies that deal with patient privacy concerns, is starting to see the need to further enforce required health record safeguards. ย For better or worse, this is what HIPAA is all about. It appears parts of MACRA continue this trend.

    Here is a little background on MACRA. On April 14, 2015, a large bipartisan majority in Congress passed the MACRA. President Obama signed the MACRA into law on April 16, 2015. It repeals the Sustainable Growth Rate (SGR) formula, which linked Medicare annual payment updates for physicians and other professionals to prior year spending and gross domestic product (GDP) growth. MACRA contains scheduled Physician Fee Schedule (PFS) updates, a new Merit-Based Incentive Payment System (MIPS), a new Technical Advisory Committee for assessing Physician Focused Payment Model (PFPM) proposals, and incentive payments for participation in Alternative Payment Models (APMs).

    The Act also includes strict privacy and security requirements for all entities receiving Medicare analyses or data, as well as new annual reporting requirements.

    Obviously there is much more to this Act, but I wanted to address it from the HIPAA compliance perspective. Simply stated, MACRA requirements to maximize payments will require practitioners to meet certain requirements to protect the health information of patients by implementing certified electronic medical records technology. ย 

    If your healthcare organization already carries the designated title of being a Covered Entity, you should be doing this already. This is the foundation of the safeguards under the HIPAA Security Rule, and MACRA makes a number of strongly worded references to privacy and security requirements.ย 

    This means Covered Entities must be conducting HIPAA Risk Assessments and have an overall risk management plan in place. A HIPAA Risk Management Plan is the foundation of any compliance program. Regardless of the size of your practice, a plan is the most essential component for implementing compliance. Contained within the plan must be a policy and procedure on how your organization is going to conduct the risk assessment process. MACRA will put more emphasis on the assessment process in determining vulnerabilities and threats to electronic health information maintained, transmitted and created by Covered Entities. ย 

    If organizations have a comprehensive compliance program in place then there should be no additional HIPAA concerns that MACRA will pose. But for many small to mid-size healthcare providers, it is still a struggle meeting all the HIPAA compliance requirements. And now with some MACRA formulas designed to maximize payments tied to safeguards, the burden will be even greater for these providers.ย 

    With the MACRA roll out in place, there is still time for Covered Entities to have risk assessments conducted. Do not delay โ€” start the process soon to maximize those future payments.ย 

    This blog was previously posted August 10, 2016

  • Training Staff in HIPAA Regulations

    In July 2017, Jay Hodes – President of Colington Consulting, provided comments to the Renal & Urology News regarding the effectiveness of HIPAA Security Awareness Training. ย The HIPAA Security Rule requires that all staff of Covered Entities receive annual HIPAA training. ย This training is also required for members of a Business Associate workforce that must access any protected health information in conducting services. ย 

    With 80% of HIPAA data breaches caused by human error, training your workforce can help to cut down in costly HIPAA fines and penalties and promote a culture of compliance within in your organization. โ€œAt the end of training, the person should walk away feeling like they understand HIPAA better,โ€ Hodes said. โ€œThere is nothing worse for an organization than to have someone say after aย breach, โ€˜No one ever told me I couldn’t take that laptop home’.” ย If your organization is investigated for a HIPAA violation or a data breach, documentation you trained your workforce will be asked for by the HHS Office for Civil Rights. ย 

    There are a number of ways training requirements can be accomplished. ย Whether using a video presentation, an instructor led class , or a web based program, the goal is being able to meet this annual requirement. ย 

    To read the complete article, click here.ย 

  • HIPAA Requirements for Web App Development for Medical Websites

    If you are part of the medical community, you are probably well aware of HIPAA, and the importance of maintaining compliance when it comes to Protected Health Information (PHI). But, do you really understand what you need to do to make sure your web application development for your website is HIPAA compliant?

    Web applications associated to your practice and your website are a great way for patients to interact with their healthcare providers. From accessing test results and paying bills to scheduling appointments, things like patient portals help free up medical staff and enhance productivity. Here are some things you need to be aware of regarding your web app development when it comes to HIPAA compliance.

    Is My Web App HIPAA Compliant?

    In order for your app to be HIPAA compliant, you need to make certain the following is in place:

    ยทย ย ย ย ย ย  Data Transport Encryption: Chances are that the data on your generic website is not encrypted before or during transmission. HIPAA requires that any ePHI (electronic Protected Health Information) be encrypted prior to being transmitted.

    ยทย ย ย ย ย ย  Backup: Your current website server might have a backup, as most web hosts provide backup and restoration features. HIPAA requires that ePHI is backed up for recovery and restoration, if needed. But, do you know if the location of those backup files is HIPAA compliant, too? If not, you may have just unlawfully shared PHI. Anybody hosting, maintaining, or monitoring server space containing PHI should adhere to the Business Associate Agreement, addressed below.

    ยทย ย ย ย ย ย  Authorization: You may already have authorization in place on your medical app, or you may not. This needs to be confirmed. The only people who should have access to ePHI are authorized staff members trained and versed in HIPAA compliance rules, or a serious breach could easily occur.

    ยทย ย ย ย ย ย  Data Integrity: On a generic website or app, there is no guarantee that data has not been modified. You must make certain that ePHI is not subject to unsanctioned changes.

    ยทย ย ย ย ย ย  Storage Encryption: Generic websites do not encrypt stored data. Stored data must be encrypted to ensure patient privacy.

    ยทย ย ย ย ย ย  Disposal: This might already exist on a generic website.ย  Just be aware that some web hosting providers store backups indefinitely. You must make sure that once ePHI is no longer needed, it can be safely and permanently disposed of.

    ยทย ย ย ย ย ย  Business Associate Agreement: Many web hosting providers do not know what HIPAA is, and will be reluctant to run any risks signing the HIPAA Business Associate Agreement, which might contradict their own business processes. It is imperative that your ePHI is hosted on servers of a company with whom a Business Associate Agreement is in place, and signed. The alternative is to host your ePHI on secure in-house servers.

    It is important to note that every vendor that deals with your patient health data must sign a Business Associate Agreement in order for you to be HIPAA compliant. It is imperative that your web hosting provider follows security requirements and provides infrastructure that is HIPAA compliant. The same is true for website design and functionality.

    Privacy Policy

    It is strongly encouraged that health app developers and any party associated with a website or app โ€“ that must be HIPAA compliant due to hosting patient health information โ€“ acknowledge and accept a well-defined privacy policy. This is not the same as a notice of privacy practices, as it signifies individual responsibility towards protecting patient rights.

    Need Help?

    HIPAA compliance can be complex, and breaches are messy and costly. It is important that your business understands what is necessary and appropriate to protect ePHI during the creation and maintenance of healthcare applications and websites.

    If you are concerned about your businessโ€™s privacy and security needs and HIPAA compliance, contact us at 800-733-6379. We are experts in the field of HIPAA rules and procedures. Colington Consulting can help you avoid reputation problems and steep fines, by bringing your business into complete HIPAA compliance. It is what we do best, allowing you to do what you do bestโ€ฆprovide health care to your patients.

    This blog was previously posted February 14, 2018

  • The Elements of a HIPAA Risk Analysis

    by Jay Hodes, President – Colington Consulting

    The Department of Health and Human Services (HHS) requires all Covered Entities and Business Associates handling protected health information to conduct a risk analysis as the first step toward implemented safeguards specified in The HIPAA (Health Insurance Portability and Accountability Act) Security Rule, and actively maintaining HIPAA compliance.

    At first glance, it may seem like a daunting task. But itโ€™s a necessary one that can help protect your practice from costly violations while โ€“ more importantly โ€“ protecting your patientsโ€™ privacy and personal security.

    Nine Key Components

    There are numerous methods of performing risk analysis and there is no single method or โ€œbest practiceโ€ that guarantees compliance with the Security Rule.

    However, the HHS Security Standards Guide outlines nine mandatory components of a risk analysis that healthcare organizations and healthcare-related organizations that store or transmit electronic protected health information (ePHI) must include in their document:

    • Scope of the Analysis โ€“ This addresses any potential risks and vulnerabilities to the privacy, availability, and integrity of ePHI. It includes all electronic media your organization uses to create, receive, maintain or transmit ePHI such as portable media, desktops, and networks. Network security between multiple locations is also important to include, and may include aspects of your HIPAA hosting terms with a third party or business associate.
    • Data Collection โ€“ This focuses on where the ePHI goes. You need to locate where data is being stored, received, maintained, or transmitted. If youโ€™re hosting at a HIPAA compliant data center, youโ€™ll need to contact your hosting provider to document where and how your data is stored.
    • Potential Threats and Vulnerabilities โ€“ Identify and document sensitive data and any vulnerabilities that may lead to the leaking of ePHI. By anticipating any potential HIPAA violations, you can help your organization reach a resolution swiftly and effectively.
    • Current Security Measures โ€“ Assess the kind of security measures youโ€™re taking to protect your data. This might include any encryption, two-factor authentication, or other security methods out in place by your HIPAA hosting provider.
    • Likelihood of Threat Occurrence โ€“ Determine the probability of potential risks to ePHI. This assessment allows for estimates on the likelihood of ePHI breaches.
    • Potential Impact of Threat Occurrence โ€“ Use qualitative or quantitative methods to assess the maximum impact of a data threat to your organization. Question how many people could be affected and to what extent private data โ€“ medical records or both health information and billing information –could be exposed.
    • Determine the Level of Risk โ€“ HHS suggest taking the average of the assigned likelihood and impact levels to determine the level of risk. Documented risk levels should be accompanied by a list of corrective actions that can be performed to mitigate risk.
    • Documentation Finalization โ€“ Compile everything in an organized document. Any format will suffice as long as the analysis is in writing.
    • Periodic Review and Updates to the Risk Assessment โ€“ One requirement is that the risk analysis process be conducted on a regular, ongoing basis. The Security Rule doesnโ€™t set a required timeline, but HHS recommends that organizations conduct another risk analysis whenever your company implements or plans to adopt new technology or business operations. This could include switching your data storage methods from managed servers to cloud computing, and updating after any ownership or key staff turnover.

    Take Action Now

    Performing a risk analysis is a complex process. The HIPAA compliance experts at Colington Consulting have conducted numerous compliance assessments. You can benefit from their expertise in knowing what is reasonable and appropriate for your organization. They understand the field of HIPAA rules and procedures and can help you avoid problems and steep fines by helping your organization maintain complete HIPAA compliance. It is what they do best, allowing you to do what you do best โ€ฆ provide health care to your patients. Contact Colington Consulting today at 800-773-6379.

    This blog was previously posted March 2, 2018

  • What is the HIPAA Privacy Rule?

    Part of the Heath Insurance Portability and Accountability Act (HIPAA) that became law in 1996, the HIPAA Privacy Rule defined the part of the law that protects patientsโ€™ protected health information (PHI). Among organizations this rule applies to are health plans and providers who use electronic medical records (EMR) either internally or to invoice insurance companies. The Privacy Rule defines safeguards to protect patient privacy, whether it is disclosed intentionally or not. What does that mean for you?

    The Standards for Privacy of Individually Identifiable Health Information (โ€œPrivacy Ruleโ€) established, for the first time, a set of national standards for the protection of certain health information. Before 1996, states had their own laws in place for patient information. Laws could vary in stringency and penalties for non-compliance were not equally severe. There were also some federal privacy laws in place, but it was a gray area, especially since the use of computers for holding the data of patient files or sending it to insurance companies for claims was not at all widespread until the late 90s.

    With new uses for electronic media, storage, and transmission, there was a need for new rules that every healthcare practitioner or institution would adhere to. Some doctors or health insurance companies were selling and distributing patientsโ€™ private health histories or medical records. HIPAA changed the rules to protect patient privacy; there must be a valid medical reason to transmit patient information and the patient must be informed of the intent and give permission in each case. It also mandates that a patient may access his or her own medical files at any time.

    What is protected health information?

    The Privacy Rule protects all individually identifiable health information (IIHI) held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information protected health information (PHI). This includes:

    ยทย ย ย ย ย ย  the individualโ€™s past, present or future physical or mental health orย condition

    ยทย ย ย ย ย ย  the provision of health care to the individual, or

    ยทย ย ย ย ย ย  the past, present, or future payment for the provision of health care to theย individual

    and that identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual. IIHI includes many common identifiers such as name, address, birth date, Social Security Number, and not so common identifiers like IP or URL addresses.

    Who needs to comply?

    The Privacy Rule, as well as all the Administrative Simplification rules, apply to health plans, health care clearinghouses, and to any health care provider who transmits health information in electronic form.ย  This includes Business Associates of those entities, which is any company or organization that may have access to PHI in the course of its business with the healthcare provider.ย  Business Associates must also comply with HIPAA rules. The laws regarding compliance are complex and the procedures and policies that are required should be reviewed every year. Even the smallest HIPAA violation may result in initiating a compliance investigation which can lead to civil and criminal penalties or the need for government imposes corrective action plans.ย  The government will not except any excuses for failing to comply with HIPAA.

    How to protect yourself

    Navigating and complying with HIPAA Privacy Rules takes serious resources. Rules can and do change as the landscape of electronic security evolves. Protecting patient data requires a forward-thinking and broad perspective. To mitigate risk of a data breach or accidental non-compliance, it makes sense to trust experienced experts who will guide you in all aspects of HIPAA compliance.

    Colington Consultants will help you implement and maintain a comprehensive HIPAA compliance program. We offer cost-effective consulting services for HIPAA Security and Privacy Rule compliance.ย Call us atย 844.740.7100ย today to schedule a free, initial consultation.

    This blog was previously posted May 11, 2018

  • The End of HIPAA Audits?

    Recently, Department of Health and Human Servicesโ€™ Office for Civil Rights Director Roger Severino signaled an end to the latest wave of HIPAA audits โ€“ but โ€œno slowdown in our enforcement efforts.โ€

    What does this mean for your medical practice and its liability under the Health Insurance Portability and Accountability Act of 1996 (HIPAA)?

    According to Severino, the Office for Civil Rights (OCR) is examining its regulations to determine whether โ€œundue burdenโ€ on the health care industry can be eased. Under the Trump administrationโ€™s executive order, two regulations need to be removed for every new regulation implemented. Acknowledging that โ€œwe are in a deregulatory environment,โ€ Severino disclosed that the U.S. Department of Health and Human Services (HHS), along with the OCR, are reviewing their regulations to see if benefits and outcomes are outweighing costs.

    As a result, the OCR has ended Phase 2 of the HIPAA audit program in which HHS had randomly requested documentation and evidence from organizations required to be HIPAA compliant. These โ€œdesk auditsโ€ were conducted to assess the overall compliance of both covered entities and business associates with plans to share the results gathered through the audit process and issue guidance identifying compliance challenges and best practices. The final phase of this audit program will be the compilation of those findings to be made public.

    However, Severino has warned that the OCR is โ€œstill looking for big, juicy egregious casesโ€ for enforcement of HIPAA rules and procedures, adding that entities large and small are still in the OCRโ€™s crosshairs. โ€œWeโ€™d like to put ourselves out of business [as an enforcement agency],โ€ Severino has said. โ€œUnfortunately, [cases] are growing steeply up.โ€

    In fact, since 2009, access to about 177 million medical records have been breached, resulting in 50 settlement agreements and three civil monetary penalty cases as a result. In 2016, the OCR collected nearly $25 million in HIPAA-related settlements and collected another $19.4 million in 2017.

    According to the OCR, 38 percent of reported cases of data breaches affecting 500 or more individuals were the result of theft, with about one in five of those breaches involving paper documents. Online hacking constituted 19 percent of reported security breaches and that number is growing.

    This is why due diligence when it comes to abiding by HIPAA rules and regulation remains a top priority for your practice โ€“ regardless of the desk audits being discontinued. The OCR is still focused on enforcement and issuing heavy fines to medical practices large and small that have experienced a breach of protected health information because of a violation of HIPAA privacy rules.

    To learn more about HIPAA compliance requirements and how it affects your practice, contact Colington Consulting at (800) 773-6379. We are experts in the field of HIPAA rules and procedures. Colington Consulting can help you avoid problems and steep fines by bringing your practice into complete HIPAA compliance. It is what we do best, allowing you to do what you do best โ€ฆ provide health care to your patients.

    This blog was previously posted June 1, 2018

  • HIPAA Best Practices for Employee Termination

    On December 11, 2018, the HHS Office for Civil Rights (OCR) announced a settlement of $111,400 with Pagosa Springs Medical Center (PSMC) located in Colorado. The settlement was the outcome of a HIPAA enforcement action following the findings of an OCR investigation that was triggered by an allegation that a former employee of PSMC still had access to ePHI via a web scheduling client used by PSMC.

    According to OCR Director Roger Severino, โ€œitโ€™s common sense that former employees should immediately lose access to protected patient information upon their separation from employment.โ€ย 

    However, ensuring removal of access alone for the terminated employee would not have prevented PSMC as a Covered Entity (CE) from meeting other HIPAA requirements. OCRโ€™s investigation revealed that PSMC did not have a Business Associate Agreement (BAA) in place with either the web-based scheduling calendar vendor, nor with the employee, thus ensuring the ePHI of 557 individuals were made vulnerable to attacks.

    Under a two-year Corrective Action Plan, PSMC must now update its security management and business associate agreement, as well as its policies and procedures, and must now re-train its employees and workers so that they are up to speed on these changes.

    The takeaway from this settlement agreement is that organizations that do not have or follow procedures to terminate information access privileges upon employee separation that results in a breach face possible HIPAA enforcement action by OCR. It is also important to make sure any process that records, shares, transmits, or modifies ePHI is thoroughly detailed in the BAA. Some CEs attempt to save money and time by establishing a work-around, which involves anonymizing ePHI while using web-based scheduling or communication apps without a BAA. However, such an undertaking is difficult to standardize in the long run. It is ultimately more cost-effective for CEs to take the time and resources to set up a BAA with relevant vendors, in order to avoid an investigation for failing to enforce HIPAA privacy and security mandates.

    Best Practice Lessons from this case:

    • The CE representative facilitating an employeeโ€™s termination must also have the ability and training to revoke and remove any previous access authorizations held by the employee. This must take place at the same time as when the notice of termination is provided.
    • CEs must complete BAAs with any vendor who provides the CE with the ability to record, modify, transmit, or share ePHI.
    • At the time of onboarding, all employees must be made aware that their employer requires them to give up all access and authorizations upon termination or voluntary departure from the company.
    • Training materials for employee onboarding should include privacy and security awareness related to:

    a) use of third-party services and applications;

    b) terms and conditions that trigger the creation of a BAA;

    c) assurances provided by Bas regarding policies and procedures to secure ePHI;

    c) security incident reporting; and

    d) password management.

    • Supervisors and other responsible officials must be trained to undertake oversight of employees’ uses and disclosures of PHI, including ePHI, in order to ensure compliance with HIPAA regulations.

    This blog was previously posted January 14, 2019

  • What Comes Up, Must Go Down: Regulatory Trends and HIPAA

    Enforcement of HIPAA mandates by the HHS Office for Civil Rights (OCR) are more aggressive than ever before, โ€œtotaling $28.7 million from enforcement actionsโ€ in 2018, an increase of 22% from the last record total of $23.5 million in 2016. ย According to an OCR press release, 2018 saw that office establish โ€œan all-time record yearโ€ in HIPAA enforcement activity, settling โ€œ10 casesโ€ and being โ€œgranted summary judgment in a case before an Administrative Law Judge.โ€ One of these 10 cases was the watershed HIPAA settlement with Anthem, Inc. for $16 million.

    OCR Settlements* and Judgement** for 2018

    Jan – FileFax*ย  –ย  $100,000

    Jan – Fresenius Medical Care* – $3,500,000

    Jun – MD Anderson** – $4,348,000

    Augย  – Boston Medical Center*ย  –ย  $100,000

    Sep – Brigham & Womenโ€™s Hospital* – $384,000

    Sep – Mass. General Hospital* – $515,000

    Sep – Advanced Care Hospitalists* – $500,000

    Oct – Allergy Associates of Hartford* – $125,000

    Oct – Anthem, Inc* – $16,000,000

    Nov – Pagosa Springs* – $111,400

    Dec – Cottage Health* – $3,000,000

    Total โ€“ Settlements & Judgement:ย  $28,683,400

    While the current administration did and continues to tout a posture of deregulation, the reality on the ground for organizations that must comply with HIPAA is that OCR has only strengthened its enforcement mechanisms, showing very little tolerance for security and privacy breaches arising from:

    • The mismanagement, or lack of proper storage, transmission, or disposal of patient PHI and ePHI.
    • An incomplete or missing Business Associate Agreement (BAA) made with any and all vendors who might be considered a Business Associates (BA) under HIPAA.
    • Cyberattacks via successful email phishing attempts targeting not just Covered Entity (CE) workers or employees, but also workers or employees of any vendor affiliated with theย  CE.
    • Incompatible or insufficient risk analysis and risk management processes on the part of the CE.

    Out of these 11 instances of verified HIPAA violations,

    • 6 CEs were found to have mismanaged or improperly stored, transmitted, or disposed of patient PHI and ePHI (Fresenius Medical Care North America, FileFax, Inc., MD Anderson, Allergy Associates of Hartford, Pagosa Springs, and Cottage Health)
    • 3 CEs did not have a BAA in place to manage vendors who are considered to be BAs under HIPAA (Advanced Care Hospitalists, Pagosa Springs, and Cottage Health)ย ย 
    • 1 CE experienced an email phishing cyber-attack (Anthem, Inc.)ย 
    • 4 CEs made PHI or patient privacy vulnerable by exposing the same via TV shows, interviews, or recordings (Allergy Associates of Hartford, Boston Medical Center, Brigham and Womenโ€™s Hospital, and Massachusetts General Hospital)
    • 4 CEs lacked HIPAA-mandated risk assessment, risk analysis, risk notification, or risk management protocols (Cottage Health, MD Anderson, Advanced Care Hospitalists, and Fresenius Medical Care North America)

    From this analysis, it can be ascertained that CEs and BAs can avoid facing settlements and judgements due to violations of the HIPAA Privacy Rule and the HIPAA Security Rule by instituting the following โ€œgolden rulesโ€ and ensuring their staff are fully trained in the same:

    • Do have robust and comprehensive plan to assess, identify, report, respond, and manage all security or privacy risks.
    • Do ensure a signed and completed BAA is on file for all BAs
    • Do have highly specific protocols in place governing the collection, storage, transmission, and disposal of patient PHI and ePHI.

    Best practices include annual and periodic training for their workforce, conducting the required security risk assessment in an ongoing/periodic manner, and internally enforcing HIPAA policies and procedures to cover the organizationโ€™s security management processes.

    Organizations, large and small, must be aware of the aggressive posture of enforcement and record settlement amounts under OCR and this current administration. My advice for any organization is to conduct a thorough evaluation of the current HIPAA compliance in place. Make sure all the requirements are covered.ย  If a compliance program is not is place, consider outsourcing and let a consultant do the heavy lifting.ย Often times, a consultant can get the program in place much quicker than relying on the organizationโ€™s internal staff.

    This blog was previously posted February 12, 2019

  • How Do HIPAA Breach Reporting Requirements Affect State Reporting

    For those of us involved in the world of HIPAA compliance, we are certainly aware by now that the Breach Notification Rule requires Covered Entities (CE) and Business Associates (BA) to notify affected parties of any breach that has occurred to their protected health information. Those notification requirements and timelines are based on the โ€œ500 ruleโ€ of individuals affected, and there are different rules based on whether more or fewer than 500 were affected by the breach.

    But another important factor to consider, besides the Federal requirement, is what do State breach reporting laws require? This is a topic that has been getting a lot of attention lately.

    According to the National Conference of State Legislatures (NCSL), all 50 U.S. states and its territories have enacted laws that require both private and public entities to notify anyone who has been affected by a security breach of their personally identifiable information.

    The NCSL website explains that these laws specify exactly who must comply with the law, what constitutes โ€œpersonal information,โ€ what constitutes a breach, requirements for notice (e.g., timing or method of notice, who must be notified), and any exemptions that may apply.

    HIPAA Data Breach Reporting at the State Level

    At the State level, there exists a somewhat different landscape of potential pitfalls compared to the compromise of any of the 18 HIPAA Identifiers. Also, State reporting is not in lieu of the Federal reporting but in conjunction. Both Federal HIPAA and State breach reporting requirements must be adhered to.

    It is important to remember that State reporting timelines may be shorter than what is mandated by the HIPAA Breach Notification Rule.

    As an example, the State of California Civil Code states that for medical information, โ€œAffected patients and the California Department of Health Services must be notified no later than 15 business days after the unauthorized access, use, or disclosure has been detected by the licensee.โ€ There is an exception to delay the notification for law enforcement purposes in accordance with the Code.

    When Business Associates Are Breached

    Further complications to the breach notification requirements kick in when CEs engage the services of vendors that are designated BAs. We know about the requirement to execute Business Associate Agreements (BAA) when these vendors have accesses to a Covered Entityโ€™s ePHI/PHI. What happens when CEs have hundreds of BAs and then some of those BAs have subcontractor BAs? How does an organization keep track of all the timelines in reporting? Oftentimes, this is done with a time-consuming manual review, causing organizations to spend excessive funds on complying โ€“ or, more commonly, not doing this exercise at all.

    Organizations commonly try and use โ€˜standard templatesโ€™ to standardize timelines, but reporting timeframes are often the center of agreement negotiations and are often changed.

    The 500 Rule

    According to the Breach Rule, if a breach affects 500 or more people, then the entity that is responsible for the breach must notify the Secretary of the applicable governmental entity as soon as possible, and no later than 60 days after the breach occurred.

    If the breach affects fewer than 500 people, however, then the responsible entity is only required to notify the Secretary annually, and no more than 60 days past the affected calendar year. Therefore, if a CE gives a BA 60 days to make the report but the breach affects 500 or more individuals, that CE will actually fail to meet the reporting deadline.

    Managing this process of timeline reporting is critical, especially with downstream BA vendors.

    โ€œUnderstanding reporting time frames, both contractual and regulatory, is critical for healthcare organizations. But many compliance teams struggle to keep up with changing laws and the growth of their organizations as it relates to obligations to regulators and business partners,โ€ says Jason Silverstein, COO, PHIflow. โ€œRather than depending on manual document review (which is expensive and time-consuming) to understand reporting timeframes, todayโ€™s leading compliance and privacy departments leverage innovative new technologies to automate many of the mundane tasks previously associated with antiquated compliance processes.โ€

    A summary of U.S. State Data Breach Notification Statutes per state provided by NCSL can be accessed here: http://www.ncsl.org/research/telecommunications-and-information-technology/security-breach-notification-laws.aspx

    Need Help with HIPAA Compliance?

    If you would like to discuss how Colington Consulting can help your organization meet these ever-changing governmental standards, call us at (800) 733-6379 today.