Category: HIPAA Safeguards

  • Insider Threat โ€“ A Growing Concern in the Healthcare Sector

    by Jay Hodes, President – Colington Consulting

    As a healthcare provider or business associate, do you conduct a pre-employment background check on all potential new hires? Do you routinely conduct periodic background checks for the current workforce? If the answer to either of these questions is โ€œno,โ€ you may want to reconsider and implement a policy.

    There is a growing concern in the healthcare sector regarding insider threats. Being HIPAA compliant puts the necessary administrative, technical and physical safeguards in place. But most of these safeguards address how to ensure systems and the workforce properly manage risk. Even with the minimum necessary requirement of the HIPAA Privacy Rule, think about those in your practice or business who have access to protected health information, especially paper charts and records. Access to paper records, notes and charts poses a greater risk for a breach than electronic health records because, with paper records, there is the lack of an IT-based audit trail.

    In May, Beckerโ€™s Health IT & CIO Review reported that during a 14 day period, there were six insider threat cases the public was made aware of. In one case, a nurse at Albany (N.Y.) Medical Center was arrested at the hospital and charged with stealing patient information. In another case, an employee who processed billing for Baylor All Saints Medical Center in Fort Worth, Texas, may have stolen patient information over a seven month period. There was no information provided in either case indicating that background checks were conducted on these employees and if there was, how thorough the checks were.

    When the Ponemon Institute released its Fourth Annual Benchmark Study on Patient Privacy & Data Security last March, a significant finding stood out. According to the report, โ€œEmployee negligence is considered the biggest security riskโ€ when it comes to safeguarding health data. The report went to say, โ€œ75 percent of organizations (surveyed) say employee negligence is their biggest worry.โ€

    There appears to be a failure to exercise reasonable care when it comes to safeguarding protected health information, whether a compromise of records is intentional or unintentional. Background checks wonโ€™t help prevent human error and circumstances where the breach was unintentional. Better security awareness training can address that issue.

    But when the circumstances are intentional and an employee is to blame, you will need to look at the employee and hiring practices. As a hiring manager who has an employee arrested for theft, there is no worse feeling than when the police inform you about a prior criminal record that employee had. However, pre-employment background checks may not help if the employee has no criminal record and just goes rogue for financial gain. This is why I recommend a policy to conduct background checks on a regular basis for all employees, not just new hires. You may want to include a credit check as part of your background check policy.

    Stacy Skinner is the President of SCS Health and Security Associates, a company that offers background checks as part of their portfolio of services. According to Skinner, โ€œConducting background checks for all applicants is a great idea because you want to reduce the risk of a negligent hire. Every time an employer hires an employee, they take a risk and by conducting a background check, it helps to mitigated risk. It comes down to protecting sensitive information, patient confidentiality, patient safety, safety of the staff, and that of the business. Know more about who you are hiring. It can make a difference.โ€

    Here are 5 suggestions for implementing or modifying an existing background check policy.

    1. Be consistent with a background check policy. That is a must. Background checks must be conducted for the entire workforce, including contract and temporary employees. Consider using a tiered approach that is dependent on the position to be filled. For example, a doctor would warrant a more comprehensive check than a receptionist.
    2. Always check the U.S. Department of Health and Human Services, Office of Inspector General Excluded Individuals/Entities List (LEIE). The LEIE is an excellent way to see if an employee has previous sanctions preventing him/her from working in the healthcare sector.
    3. Consider conducting periodic background checks for those workforce members who have been on-board for a while. Rescreening workforce members can help to make sure an employee does not slip through the cracks by not notifying management of any recent criminal convictions.
    4. Drug screening – if a program is not in place, consider implementing one. The screening would be applicable to job applicants along with the current workforce.
    5. Consider contracting with a reputable investigations company that specializes in background checks. Leave this job to the professionals who know how to conduct background checks. Trying to obtain criminal background checks on your own can vary from state-to-state and be a time consuming process in some cases.

    Before implementing or updating a policy regarding background checks, credit checks and drug testing, it is always prudent to seek advice of legal counsel. For more information about background checks, visit the U.S. Equal Employment Opportunity Commission website.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • Why Should HIPAA Compliance Matter to You?

    by Jay Hodes, President – Colington Consulting

    Healthcare Professionals

    If you are a healthcare provider or business associate, HIPAA compliance should matter because it is the law. According to the Code of Federal Regulation (CFR), if you are a provider or business associate who utilizes electronic health records, you must ensure the confidentiality, integrity, and availability of all records created, received, maintained, or transmitted. Civil monetary penalties for noncompliance that cause a breach of electronic patient records can be assessed up to $2.2 million. Criminal penalties can range from one to ten years in prison.

    I believe one of the biggest issues facing small healthcare providers is lack of knowledge of exact requirements for HIPAA security compliance. Part of the problem for small providers is they often have an unclear understanding of what safeguards need to be in place for electronic health records. I see this as a huge concern. The U.S. Department of Health and Human Services (HHS) has done a better job providing specific guidance to small providers. Navigating through the HHS website to find particular HIPAA compliance information has improved, but can be daunting to find specific information.

    I should know because I used to work for HHS and had oversight of complex health care fraud investigations. We had teams of lawyers and analysts to guide us in the regulatory world, whereas a small healthcare provider, if lucky, maybe will find the necessary guidance on the HHS website. Even then, the information becomes subject to interpretation by a provider with limited exposure to HIPAA regulatory compliance. Ask yourself how comfortable you are with this.

    Patients

    With more and more healthcare providers utilizing electronic health records, consumers (patients) need to ask those providers if they are doing everything they can to secure their health information. For consumers, HIPAA compliance matters because it equals assurance that the proper safeguards are in place to prevent unauthorized access, tampering, and theft of medical records.

    A recent study by the Ponemon Institute found criminal attacks on healthcare providers have increased dramatically, up 100% since 2010. Unlike having credit information stolen where the bank or credit card company may notify the consumer about suspicious activity in a timely manner, health information compromises take longer to recognize. With all the recent emphasis on newsworthy data breaches, this is a wake-up call for patients who must treat their online health information as they would their credit information.

    Medical identity theft is a profitable industry for criminals who can make a lot more money selling health information than credit card numbers. According to Dell Secure Works, an information security services company, criminals can get paid $20 for a personโ€™s stolen health identity information, as compared to credit card numbers that may yield $1 to $2 apiece. As a former Assistant Inspector General for Investigations at HHS, I know that Medicare card numbers could be sold for up to $50 apiece. In addition, there is much more personal data at stake with health records, which can include sensitive information such as pre-existing conditions, full-blown medical histories, and prescriptions, along with a plethora of financial, employment, and family information.

    So the next time you go to your healthcare provider and you are asked to sign a HIPAA release form, read the fine print. Know your rights and expectations of privacy. Most importantly, ask your providers what they are doing to protect your electronic health records.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • The Elements of a HIPAA Risk Analysis

    by Jay Hodes, President – Colington Consulting

    The Department of Health and Human Services (HHS) requires all Covered Entities and Business Associates handling protected health information to conduct a risk analysis as the first step toward implemented safeguards specified in The HIPAA (Health Insurance Portability and Accountability Act) Security Rule, and actively maintaining HIPAA compliance.

    At first glance, it may seem like a daunting task. But itโ€™s a necessary one that can help protect your practice from costly violations while โ€“ more importantly โ€“ protecting your patientsโ€™ privacy and personal security.

    Nine Key Components

    There are numerous methods of performing risk analysis and there is no single method or โ€œbest practiceโ€ that guarantees compliance with the Security Rule.

    However, the HHS Security Standards Guide outlines nine mandatory components of a risk analysis that healthcare organizations and healthcare-related organizations that store or transmit electronic protected health information (ePHI) must include in their document:

    • Scope of the Analysis โ€“ This addresses any potential risks and vulnerabilities to the privacy, availability, and integrity of ePHI. It includes all electronic media your organization uses to create, receive, maintain or transmit ePHI such as portable media, desktops, and networks. Network security between multiple locations is also important to include, and may include aspects of your HIPAA hosting terms with a third party or business associate.
    • Data Collection โ€“ This focuses on where the ePHI goes. You need to locate where data is being stored, received, maintained, or transmitted. If youโ€™re hosting at a HIPAA compliant data center, youโ€™ll need to contact your hosting provider to document where and how your data is stored.
    • Potential Threats and Vulnerabilities โ€“ Identify and document sensitive data and any vulnerabilities that may lead to the leaking of ePHI. By anticipating any potential HIPAA violations, you can help your organization reach a resolution swiftly and effectively.
    • Current Security Measures โ€“ Assess the kind of security measures youโ€™re taking to protect your data. This might include any encryption, two-factor authentication, or other security methods out in place by your HIPAA hosting provider.
    • Likelihood of Threat Occurrence โ€“ Determine the probability of potential risks to ePHI. This assessment allows for estimates on the likelihood of ePHI breaches.
    • Potential Impact of Threat Occurrence โ€“ Use qualitative or quantitative methods to assess the maximum impact of a data threat to your organization. Question how many people could be affected and to what extent private data โ€“ medical records or both health information and billing information –could be exposed.
    • Determine the Level of Risk โ€“ HHS suggest taking the average of the assigned likelihood and impact levels to determine the level of risk. Documented risk levels should be accompanied by a list of corrective actions that can be performed to mitigate risk.
    • Documentation Finalization โ€“ Compile everything in an organized document. Any format will suffice as long as the analysis is in writing.
    • Periodic Review and Updates to the Risk Assessment โ€“ One requirement is that the risk analysis process be conducted on a regular, ongoing basis. The Security Rule doesnโ€™t set a required timeline, but HHS recommends that organizations conduct another risk analysis whenever your company implements or plans to adopt new technology or business operations. This could include switching your data storage methods from managed servers to cloud computing, and updating after any ownership or key staff turnover.

    Take Action Now

    Performing a risk analysis is a complex process. The HIPAA compliance experts at Colington Consulting have conducted numerous compliance assessments. You can benefit from their expertise in knowing what is reasonable and appropriate for your organization. They understand the field of HIPAA rules and procedures and can help you avoid problems and steep fines by helping your organization maintain complete HIPAA compliance. It is what they do best, allowing you to do what you do best โ€ฆ provide health care to your patients. Contact Colington Consulting today at 800-773-6379.

    This blog was previously posted March 2, 2018

  • Protect Our Health by Protecting our Healthcare

    Our healthcare system, while far from perfect, is an absolute necessity for living. It would make sense then to be sure that it was well-protected.

    Unfortunately, this is often not the case. As we have seen over and over again, database breaches are more common in the healthcare industry than anywhere else. Weโ€™re not just experiencing a loss of data, but a loss of trust as well. How can people live their lives and stay safe from data theft at the same time?

    HIPAA Compliance

    It starts with a set of rules. Such a set has already been put together: The Health Insurance Portability and Accountability Act of 1996 (HIPAA). But rules are meaningless if no one is following them. According to the HIPAA journal, breaches in patient records during 2018 doubled to more than 13 million records. This is unacceptable – both from a patient standpoint and a legal one. And itโ€™s only going to get worse as technology grows.

    Data Breaches and Technology

    Our healthcare technology has improved in leaps and bounds since the 1990โ€™s. This is terrific. The average lifespan of Americans has also increased thanks to amazing breakthroughs and wearable devices like smart inhalers and insulin pens. Patients can have their glucose levels monitored from almost anywhere. We have remote MRI machines and smart beds. These are all helpful things. They greatly improve our quality of life.

    But what happens when all of these terrific inventions are used for ill purpose?

    Each of these devices works because theyโ€™re connected in some way shape or form to a database. Every patient uploads a massive amount of data about themselves whenever theyโ€™re used. Then, attackers breach these databases, access patients records, steal them and sell them on the dark web. In countries like the U.S., attackers from anywhere in the world can access expensive medical services, products, and drugs with the help of stolen medical records. The healthcare sector has proven to be extremely profitable for attackers, with a single record costing an average of $408.

    Data Breaches and Ransomware

    Itโ€™s not always about buying, selling, and manipulating patient data. Disturbingly often, itโ€™s about holding hospitals hostage to fund criminals, political actors abroad and even terrorism. That might sound like an extremely bold declaration, but itโ€™s an unfortunate and well-known truth. Ransomware attacks account for 85% of all the cyber-attacks on the healthcare sector. In one example which we mention in a previous article, Indiana-based healthcare system, Hancock Health, was hit by a ransomware attack that completely locked down all of their computers. In many instances, those computers were depended upon for keeping critical hospital systems running. They felt they had no choice but to pay the ransom in order to keep their patients safe. That attack had cost the company about $55,000 in Bitcoin.

    It was a risky move either way. Historically, only 19% of ransomware victims who pay the ransom actually get their files back. And the worst part is, that money goes to places that are in no way good.

    Our healthcare system is possibly the most important institution in our country. It definitely has its flaws, but itโ€™s literally what keeps us alive. The absolute least we can do is follow the rules that were originally put in place to protect it. Weโ€™re here to help you make sense of those rules.ย  Call us today at 800-733-6379 to schedule a free, initial consultation.