Category: HIPAA Rules

  • HIPAA: Then & Now

    A story about HIPAA that starts with once upon a time, in the late 1990s, the U.S. healthcare system was in dire need of a change. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) was created to address this need. The act aimed to improve the portability and accountability of health insurance coverage, guarantee coverage for employees with pre-existing conditions, and prevent โ€œjob lockโ€ โ€“ a scenario in which plan members stayed in a job to avoid losing health benefits.

    HIPAA introduced several measures to ensure the continuity of coverage between jobs, including the creation of national standards to protect sensitive patient health information from being disclosed without the patientโ€™s consent or knowledge. The U.S. Department of Health and Human Services (HHS) issued the HIPAA Privacy Rule to implement the requirements of HIPAA. The Privacy Rule standards address the use and disclosure of individualsโ€™ health information (known as protected health information or PHI) by entities subject to the Privacy Rule. These individuals and organizations are called โ€œcovered entitiesโ€. The Privacy Rule also contains standards for individualsโ€™ rights to understand and control how their health information is used.

    The story of HIPAA is not just about the creation of a law, but also about the implementation and enforcement of that law. The HIPAA Security Rule protects a subset of information covered by the Privacy Rule. The Security Rule requires appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and security of electronic protected health information.

    The implementation of HIPAA has not been without its challenges. There have been concerns about the cost of implementing the Privacy and Security Rules, as well as understanding what is reasonable and appropriate for an organization, based on size. However, the benefits of HIPAA are clear. The act has helped to ensure that patientsโ€™ health information is protected, and that they have greater control over how their information is used. The act also required that Covered Entities and Business Associates must do to protect that information and comply with the HIPAA Security Standards and Implementation Specifications.

    In 2009, the enforcement authority was delegated to the HHS Office for Civil Rights (OCR) by then U.S. Secretary of Health and Human Services, Kathleen Sebelius. Since then, OCR has settled or imposed a civil money penalty in 137 cases resulting in a total dollar amount of almost $137 million. OCR continues to investigate privacy and security complaints against numerous organizations and businesses, regardless of size.

    But legislative changes are needed, especially with the advancements in health technology applications and data analytics. The regulations have not kept pace with technical safeguard requirements. From a compliance standpoint, there are times when it feels like you are trying to stick a round peg into a square hole. It takes experienced compliance officers, HIPAA consultants, and lawyers to understand what the regulations call for, now almost 30 years since HIPAA was enacted. At some point, Congress will need to tackle the issue of updating the HIPAA regulations. For now, keep those round pegs available.

  • Survey Finds Lack of HIPAA Compliance Knowledge

    by Jay Hodes, President – Colington Consulting

    It came as no surprise to me when I reviewed a recent HIPAA survey conducted by NueMD, in conjunction with Porter Research and The Daniel Brown Law Group, which found that most healthcare providers and business associates that responded have a limited knowledge of compliance regulations. This was one of the most comprehensive surveys on HIPAA compliance that I have seen.

    Part of the survey asked over 1,000 providers, administrators and medical office staff a number of questions regarding their knowledge and awareness of HIPAA compliance requirements. Let me share some of those practice findings:

    • 68% of respondents were unaware that random HIPAA audits were going to be conducted.
    • Only 35% of respondents said they conducted a HIPAA-required risk analysis.
    • Only 24% of managers, owners and administrators reported that they evaluated all of their Business Associate Agreements.

    Why does it not come as a surprise to me? Well, for a number of reasons. Smaller medical practices do not have the in-house resources to handle the complexities of meeting all of their compliance requirements. Most donโ€™t realize what is involved. When I provide initial consultations with potential clients and explain all the areas that must be covered, I usually get the typical response that they did not think all the regulations applied to their practice or that their practice was too small and some of this compliance stuff was not necessary. Itโ€™s not that they donโ€™t want to be compliant; it is more that they do not know or understand what is entailed.

    Reinforcing this perception, when looking at โ€œpractices by size, (the survey) found that larger practices (particularly those with 10 or more providers) tended to do better when it came to compliance measures within the office – things like having a plan, training staff, appointing officers and conducting risk analyses. This wasn’t surprising, as larger organization usually have more resources to devote to regulatory compliance.โ€

    I feel part of the onus for so much confusion among smaller providers rests with my former agency, the U.S. Department of Health and Human Services. Although the Office for Civil Rights (OCR) has the primary responsibility to enforce HIPAA regulations, the Office of the National Coordinator for Health Information Technology (ONC) promotes the use of electronic exchanges of health information. ONC pushes out guidance on health information privacy, security and the implementation of electronic health records.

    Then there is the Centers for Medicare & Medicaid Services (CMS) that administers the EHR Incentive Program. CMS has started to conduct meaningful use attestation audits. One of the core objectives that must be attested to is that a HIPAA Risk Assessment was conducted, the same risk assessment that OCR requires and would review during their own audit or compliance review.

    A practice manager, already wearing so many hats, does not have the time to conduct the research, check the websites of three different agencies and find the necessary answers to what is reasonable and appropriate for that officeโ€™s environment. This leads to another survey finding from medical practices in that only 38% of respondents said โ€œthat someone at (the) business is actively ensuring (the) business’s compliance with HIPAA.โ€

    If you are unsure of where to start, have a HIPAA Risk Assessment conducted, especially if your practice or business has never done one. The assessment will identify vulnerabilities and threats to your current administrative, physical and technical safeguards for protected health information you maintain. A good assessment must provide an action plan or steps for remediation for all the vulnerabilities and threats that were detected. It provides a critical road map, based on the rated risk level, for what needs to be addressed immediately to meet compliance requirements.

    What is clear is the need to make HIPAA compliance an important part of the everyday operations for any healthcare practice or business, not just when there is a threat of an audit. Because compliance requirements can be such a time consuming process, consider outsourcing this responsibility. I know there are quite a few practice managers who need assistance and would relish having a consultant provide this service. In the end, it may be a cost saving measure to outsource HIPAA compliance assistance, saving workforce time and a lot of frustrating hours.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • HIPAA Compliance โ€“ Waiting for the Other Shoe to Drop

    by Jay Hodes, President – Colington Consulting

    The expression โ€œwaiting for the other shoe to dropโ€ appears to have originated in the early 1900โ€™s and is often associated with the arrival of a seemingly inevitable event. I speculate we are at that point in terms of ramped up HIPAA compliance enforcement. The recent Anthem data breach shined a significant spotlight on how vulnerable health information technology can be without the proper safeguards in place.

    The Office for Civil Rights (OCR), the U.S. Department of Health and Human Services agency responsible for HIPAA oversight, has made a lot of noise about being more aggressive in enforcement of the regulations. You would think it is time for the proverbial other shoe to drop. But not so fast. With limited resources, there is only so much OCR can do. That needs to change. It will and probably soon.

    There is now, and has been for a while, a lot at stake in terms of making sure healthcare providers and business associates have safeguards in place to properly secure patientsโ€™ protected health information. If major healthcare plans like Anthem are not making sure they are meeting all the HIPAA required implementation specifications, what can be said for smaller healthcare providers?

    The Ponemon Institute recently released its โ€œFifth Annual Study on Medical Identity Theft.โ€ Among the findings, the study discovered that โ€œconsumers expect healthcare providers to be proactive in preventing and detecting medical identity theft.โ€ What was surprising is that โ€œmany respondents are not confident in the security practices of their healthcare provider.โ€ Another interesting outcome of study was that โ€œ79 percent of respondents say it is important for healthcare providers to ensure the privacy of their health records,โ€ and almost half of those respondents said โ€œthey would consider changing healthcare providers if their medical records were lost or stolen.โ€

    The results of the Ponemon study must be a wakeup call for healthcare providers. Can you afford to have half of your patients leave your practice if a breach occurs? As a healthcare provider, donโ€™t be surprised if patients start asking about how you are securing their protected health information (PHI). With all the recent data breaches in retail stores like Target, Sony PSN and Home Depot, consumers realize the vulnerabilities associated with the use of credit cards. As these same consumers seek healthcare services, it will be only a matter of time before questions are asked about safeguarding PHI.

    As a healthcare provider or business associate, make sure you are doing everything you can to protect health information. It goes way beyond a checklist. A robust HIPAA compliance program must be in place, regardless of the size of your practice or business. If you cannot meet all the HIPAA requirements by doing it in-house, consider outsourcing this responsibility. Take the burden off the plate of your office or practice manager or designated HIPAA officer.

    There is still time before that other shoe drops.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • HIPAA Requirements โ€“ Time for a Major Regulatory Change

    by Jay Hodes, President – Colington Consulting

    It is only fitting that legislation that was created in the mid 1990โ€™s be considered, as most HIPAA experts would agree, outdated. Even with changes brought about by HITECH and the Omnibus Act, the implementation specifications remain relatively unchanged. It is still one-size-fits-all when it comes to meeting the requirements.

    Sure, you could argue what is reasonable and appropriate for one healthcare provider is not for another. Therefore, it comes down to how each implementation specification is interpreted, how you decipher what the Code of Federal Regulation (CFR) is asking for. After spending 27 years working for the Federal government and being involved in policy and regulatory oversight, even I sometimes struggle with how to make sense of a particular CFR.

    For larger healthcare providers that have regulatory and compliance staff, HIPAA compliance might be a bit easier. But for the smaller providers who are required to follow all of the same requirements, albeit what is โ€œreasonable and appropriate,โ€ this is a colossal struggle. I can see why some small providers just throw their hands up and say, โ€œThis is way too complex for us to figure out.โ€

    When the HIPAA legislation was created, the healthcare system in this country was really starting to transform. Today, with more and more specialty practices and other types of healthcare service providers tapping into this growing market, updating regulation requirements must be a priority. It cannot be a one-size-fits-all requirement anymore. The U.S. Congress needs to take into consideration how the healthcare industry has changed, in particular with the emergence of new health related mobile apps hitting the techno-sphere. HIPAA regulatory requirements must be adaptable to meet this changing environment.

    When I conduct a HIPAA risk assessment for a smaller healthcare provider and I ask a question in an attempt to adhere to the implementation specification, often I get a non-applicable response. The hard work for me is how to get that provider covered in meeting a required implementation specification if it is non-applicable. If a provider is truly making the effort with due diligence to follow the HIPAA regulations, then that should be factored into the equation.ย  The process must allow for more discretion when it comes to some of the implementation specifications.

    All of this will require legislative fixes. The U.S. Congress can rattle a few cages and give the impression there is real concern with making sure healthcare providers are doing everything they can to safeguard patient records, but until there is movement towards making necessary legislative changes, HIPAA requirements will remain as confusing to some as the U.S. tax code.

    Back in the mid 1990โ€™s, Senators Kasebaum and Kennedy, the sponsors of the insurance reform legislation that became known as HIPAA, clearly had a vision about the changing landscape of healthcare security in this country. Which current day senators will have that vision and want to undertake this monumental task in reforming HIPAA for the next decade remains to be seen.ย  The time is now to start down this road.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • Reviewed on June 23, 2026 by: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.