Category: HIPAA Compliance

  • Not Worried About Your Patients? Worry About Your Bottom Line?

    Weโ€™re always talking about how not complying with HIPAA regulations badly affects patients. Their data is exposed to malicious entities. Their trust in your organization wanes. Even if youโ€™re not worried about the moral implications or your public perception, the fact is youโ€™re not off the hook for noncompliance. There are severe penalties for not following the rules. And thatโ€™s what weโ€™ll be discussing in todayโ€™s article.

    A Breakdown of HIPAA Fines

    Penalties for HIPAA noncompliance are broken down into four categories of fines:

    1. Willful neglect with no corrective action taken.
    2. Willful neglect with corrective action taken.
    3. Reasonable cause for noncompliance.
    4. No knowledge of noncompliance.

    Each level of noncompliance comes with its own financial penalty for your company or organization. Letโ€™s take a closer look at what each one means, and what its penalty is.

    Willful Neglect with No Corrective Action

    This is by far the most severe form of noncompliance, and therefore comes tagged with the harshest of government fines. From a legal standpoint, willful neglect is defined as a “conscious, intentional failure or reckless indifference.โ€ If you work in the healthcare industry, thereโ€™s a good chance youโ€™ve at least heard of HIPAA. Weโ€™ve reached a point where it is very difficult for organizations to claim ignorance of it. If it looks as though you havenโ€™t even bothered to make the necessary changes, thereโ€™s a good chance you could be hit with this very serious charge. It comes with a nasty $50,000 minimum penalty for each violation, and can cost your organization up to a whopping $1,500,000 annually.

    Willful Neglect with Corrective Action

    If a company or organization is found guilty of willful neglect as defined above, resolving the noncompliance issue in a timely fashion will reduce the associated penalty. Itโ€™s still a hefty price thatโ€™s nothing to sneeze at however, and your best option of course is to comply with the regulations in the first place. After making the necessary changes, you could instead be hit with a $10,000 penalty for each violation, up to a maximum of $250,000 annually. The difference isnโ€™t negligible at least, and is greatly preferable to ignoring the problem – both for your patients and for your companyโ€™s bottom line.

    Reasonable Cause

    The legal definition for reasonable cause in regard to HIPAA compliance is as follows:

    โ€œAn act or omission in which a covered entity or business associate knew, or by exercising reasonable diligence would have known, that the act or omission violated an administrative simplification provision, but in which the covered entity or business associate did not act with willful neglect.โ€ While not as serious as โ€œwillful neglect,โ€ it still comes with a heavy price tag of $1,000 for each violation and up to $100,000 annually.

    No Knowledge

    Noncompliance is to be considered โ€œwithout knowledgeโ€ if the covered entity or individual did not know (and by exercising reasonable diligence would not have known) the action in question was a HIPAA violation. This is incredibly common, and is a huge culprit for many violations. This is why it is especially important to train your employees and make absolutely certain everyone knows and follows the regulations. Not rigorously training – and refreshing – your employees in HIPAA compliance can cost you $100 for every single violation, and up to $25,000 a year in damages. Teaching your staff the right way of doing things, taking the right precautions and putting processes in place will help you best to avoid these fines.

    Remember, there can be hefty fines for not following regulations. But most importantly, itโ€™s important to protect the people youโ€™re serving. Their lives are in your hands. Let us help you help them – and yourselves.ย  Give us a call today at 800-733-6379 for a free, no obligation, initial consultation.ย 

  • Protect Our Health by Protecting our Healthcare

    Our healthcare system, while far from perfect, is an absolute necessity for living. It would make sense then to be sure that it was well-protected.

    Unfortunately, this is often not the case. As we have seen over and over again, database breaches are more common in the healthcare industry than anywhere else. Weโ€™re not just experiencing a loss of data, but a loss of trust as well. How can people live their lives and stay safe from data theft at the same time?

    HIPAA Compliance

    It starts with a set of rules. Such a set has already been put together: The Health Insurance Portability and Accountability Act of 1996 (HIPAA). But rules are meaningless if no one is following them. According to the HIPAA journal, breaches in patient records during 2018 doubled to more than 13 million records. This is unacceptable – both from a patient standpoint and a legal one. And itโ€™s only going to get worse as technology grows.

    Data Breaches and Technology

    Our healthcare technology has improved in leaps and bounds since the 1990โ€™s. This is terrific. The average lifespan of Americans has also increased thanks to amazing breakthroughs and wearable devices like smart inhalers and insulin pens. Patients can have their glucose levels monitored from almost anywhere. We have remote MRI machines and smart beds. These are all helpful things. They greatly improve our quality of life.

    But what happens when all of these terrific inventions are used for ill purpose?

    Each of these devices works because theyโ€™re connected in some way shape or form to a database. Every patient uploads a massive amount of data about themselves whenever theyโ€™re used. Then, attackers breach these databases, access patients records, steal them and sell them on the dark web. In countries like the U.S., attackers from anywhere in the world can access expensive medical services, products, and drugs with the help of stolen medical records. The healthcare sector has proven to be extremely profitable for attackers, with a single record costing an average of $408.

    Data Breaches and Ransomware

    Itโ€™s not always about buying, selling, and manipulating patient data. Disturbingly often, itโ€™s about holding hospitals hostage to fund criminals, political actors abroad and even terrorism. That might sound like an extremely bold declaration, but itโ€™s an unfortunate and well-known truth. Ransomware attacks account for 85% of all the cyber-attacks on the healthcare sector. In one example which we mention in a previous article, Indiana-based healthcare system, Hancock Health, was hit by a ransomware attack that completely locked down all of their computers. In many instances, those computers were depended upon for keeping critical hospital systems running. They felt they had no choice but to pay the ransom in order to keep their patients safe. That attack had cost the company about $55,000 in Bitcoin.

    It was a risky move either way. Historically, only 19% of ransomware victims who pay the ransom actually get their files back. And the worst part is, that money goes to places that are in no way good.

    Our healthcare system is possibly the most important institution in our country. It definitely has its flaws, but itโ€™s literally what keeps us alive. The absolute least we can do is follow the rules that were originally put in place to protect it. Weโ€™re here to help you make sense of those rules.ย  Call us today at 800-733-6379 to schedule a free, initial consultation.

  • More Big Penalties for HIPAA Violations as the Year Comes to End

    Huge fines for HIPAA violations are making the news once again. And these are some doozies. The Office for Civil Rights (OCR) are two for two this time – Texas Health and Human Services Commission (TX HHSC) was hit for $1.6 million, and University of Rochester Medical Center (URMC) for $3 million.

    Large penalties like these are certainly newsworthy and further outline the seriousness of HIPAA noncompliance. Hereโ€™s what happened with both organizations and why itโ€™s such a big deal.

    TX HHSC HIPAA Violations – $1.6 Million Fine

    An investigation found that a division of TX HHSC had a data breach that enabled unauthorized users to view the electronically protected health information (ePHI) of 6,617 people. According to a press release from the Office for Civil Rights, the information exposed included names, addresses, social security numbers and treatment information.

    The OCR found that in addition to the data breach, TX HHSC failed to conduct an enterprise-wide security risk analysis, failed to implement access and audit controls on the information technology system, and was unable to determine how many people accessed the ePHI while it was publicly accessible.

    Although the OCR provided TX HHSC with the opportunity to provide โ€œwritten evidence of mitigating factors or affirmative defenses and/or written evidence in support of a waiver of a CMP within thirty (30) days from the date of the receipt of the letter,โ€ TX HHSC did not respond.

    OCR Director Roger Severino stated – and quite correctly – โ€œNo one should have to worry about their private health information being discoverable through a Google search.โ€

    URMC HIPAA Violations – $3 Million Fine

    In this case, the OCR imposed the fine on the University of Rochester Medical Center in response to multiple instances of the health system failing to encrypt mobile devices. This lack of encryption resulted in a breach of patients’ protected health information more than once. In one example, it was an unencrypted laptop that was lost. In two others, it was a lost flash drive.

    OCR’s investigation into the incidents found that URMC had โ€œneglected to utilize device controls and employ encryption for electronic protected health information,โ€ among other security measures. The health system had also failed to conduct a systemwide risk analysis. (In case you havenโ€™t noticed a pattern yet, performing said risk analysis is a big deal, and should be taken seriously.)

    In addition to the $3 million settlement, the URMC will also be forced to implement a corrective action plan which includes HHS monitoring the health system’s compliance with HIPAA for two years.

    How Can Your Organization Avoid Potential Penalties and Settlements?

    In about 95% of the cases when breaches are reported, OCR resolves non-compliance issues with technical guidance. However, organizations subject to these breach investigations must be able to demonstrate their comprehensive HIPAA compliance programs. This includes providing OCR documentation regarding policy and procedures; a copy of the most recent HIPAA Security Risk Assessment; training records; contingency/disaster recovery plans; and other records supporting a compliance program.

    Find Out if Your Organization is Meeting Regulatory Requirements

    If HIPAA compliance assistance is needed for your organization, we specialize in putting compliance programs in place or assessing your current program. We provide a full range of services that include conducting the required HIPAA Risk Assessment, writing and customizing a HIPAA Risk Management Plan (HIPAA Policies and Procedures) for your organization, and providing your entire staff annual required HIPAA Security Awareness & Privacy Training through our web-based platform.ย 

    Letโ€™s start the process with a free, initial consultation. In as little as 15 minutes, we can evaluate your current compliance program to determine if all mandatory privacy and security safeguards are in place to meet government regulations.