Category: HIPAA Security Risk Assessment

  • How HIPAA Consultants Reduce Riskโ€”and Help You Avoid Penalties

    By Jay Hodes, President, Colington Consulting

    HIPAA enforcement isnโ€™t slowing down. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) continues to announce settlements and civil monetary penalties for organizations that fall short on foundational Privacy, Security, and Breach Notification Rule requirements.

    Recent OCR penalties for HIPAA violations have ranged from $25,000 to several million dollars. In most cases, and as part of the settlement agreement, OCR requires the implementation of a corrective action planโ€”often mandating the completion of a risk assessment. In some enforcement actions, smaller organizations were specifically targeted in what are often called โ€œmessageโ€‘sending cases.โ€ OCR uses these to emphasize that no organization, regardless of size, is exempt from its investigative authority.

    When you compare the cost of a proactive compliance program to the risk of an OCR settlement, the math favors prevention every time. Below is how experienced HIPAA consultants reduce riskโ€”mapped directly to the failures OCR highlights in its own enforcement announcements.

    1) Close the #1 Gap OCR Cites: Incomplete Risk Assessment

    Again and again, OCR settlements point to failures to conduct an โ€œaccurate and thoroughโ€ risk assessment as required under the Security Rule.

    Examples:

    • Syracuse ASC (NY): Ransomware breach affecting 24,891 individuals.
    • Comstar, LLC (MA): Ransomware attack affecting 585,621 individuals.
    • Guam Memorial Hospital Authority: Multiโ€‘year Corrective Action Plan after ransomware and hacking complaints.

    2) Build Policies and Procedures to Meet Required Standards & Specifications

    Consultants update or create Privacy, Security, and Breach Notification policies that reflect realโ€‘world workflows and withstand OCR document requests as part of an investigative followโ€‘up process.

    3) Reduce Human Error with Roleโ€‘Based Training

    OCRโ€™s Rightโ€‘ofโ€‘Access and other enforcement actions repeatedly show that many violations stem from inadequate training and poor compliance program management.

    4) Harden Technical Safeguards Before an Incident

    Consultants align access controls, encryption, audit requirements, cloud storage of ePHI, and monitoring with current OCR expectations.

    5) Prepare for Incident Response and Breach Management

    Consultants build incident response playbooks and ensure breach determinations and notifications meet HHS deadlines and documentation standards. This requirement sometimes gets overlooked by organizations.

    6) Provide Continuous Complianceโ€”Not a Oneโ€‘Time Fix

    Quarterly reviews, vendor oversight, annual risk assessments, and documented compliance metrics help organizations stay aligned with evolving OCR enforcement trends.

    Why Expertise Matters

    HIPAA is complex, and regulatory expectations evolve each year. OCRโ€™s enforcement data shows that the most common compliance failures include:

    • Impermissible disclosures
    • Inadequate safeguards
    • Insufficient risk assessments

    A HIPAA consultant brings deep knowledge of these requirements, current enforcement trends, and industry best practices. They understand how OCR interprets the Security and Privacy Rules, how to reduce liability, and which corrective actions are essential for compliance.

    More importantly, expert consultants provide tailored services based on an organizationโ€™s requirements, workflows, systems, and risk profileโ€”not generic checklists. They can identify vulnerabilities internal teams may miss and recommend practical, costโ€‘effective solutions that strengthen compliance while supporting operational efficiency.

    The Takeaway

    With OCR investigations increasingly focused on cyber incidents, risk assessment gaps, and failures to meet Security Rule standards, organizations cannot afford to take a reactive approach. The financial, operational, and reputational consequences of noncompliance far outweigh the investment in proper guidance.

    Engaging a HIPAA consultant is not just a compliance strategyโ€”it is a costโ€‘saving one. By proactively addressing risks, organizations can avoid multimillionโ€‘dollar penalties, maintain patient trust, and build a culture of privacy and security that supports longโ€‘term success.

    Colington Consulting

    HIPAA Compliance, Risk Assessment & Management

    Contact our office at 844.740.7100 to schedule a free initial consultation and learn how your organization can meet all compliance requirements with confidence. We are a fullโ€‘service consultancy providing a wide range of HIPAA compliance services. Ask about our Virtual HIPAA Compliance Officer service.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • CMS MIPS Requirement for Annual Security Risk Assessments

    CMS MIPS Requirement for Annual Security Risk Assessment Attestation: Why It Matters for Medicare Billing Organizations

    The Centers for Medicare & Medicaid Services (CMS) Merit-based Incentive Payment System (MIPS) is designed to improve care quality, promote interoperability, and ensure patient data security. One critical component of the Promoting Interoperability (PI) performance category is the annual attestation for a Security Risk Analysis (SRA). This requirement is not optionalโ€”any organization that bills Medicare and participates in MIPS must complete and attest to this assessment each performance year.

    What Is the Security Risk Analysis Requirement?

    Under the HIPAA Security Rule (45 CFR 164.308(a)(1)), covered entities and business associates must conduct a risk analysis to identify potential threats and vulnerabilities to the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI). For MIPS, clinicians and organizations must attest โ€œYESโ€ to having:

    • Conducted or reviewed a security risk analysis during the performance year.
    • Implemented security updates as needed.
    • Corrected identified deficiencies.

    This analysis must be unique for each year and updated after significant changes, such as implementing new EHR systems or workflows.

    Why Is This Requirement Important?

    If your organization bills Medicare, compliance with this requirement is essential for several reasons:

    1. Protecting Patient Data
      Healthcare organizations handle sensitive patient information daily. A security breach can lead to identity theft, financial fraud, and loss of trust. Conducting an annual risk assessment ensures that vulnerabilities are identified and mitigated before they can be exploited.
    2. Regulatory Compliance
      Failure to complete the SRA and attest accordingly can result in zero points for the PI category, significantly reducing your overall MIPS score. This can lead to negative payment adjustments, directly impacting on your Medicare reimbursements.
    3. Avoiding Penalties Beyond MIPS
      Non-compliance with HIPAA security requirements can trigger investigations and hefty fines from the Office for Civil Rights (OCR). An annual SRA demonstrates proactive compliance and reduces liability in the event of a breach.
    4. Supporting Organizational Resilience
      Cyber threats in healthcare are increasing, from ransomware attacks to phishing schemes. A thorough risk analysis helps organizations strengthen their security posture, ensuring continuity of care and operational stability.

    Key Steps for Compliance

    • Review your current security policies and procedures.
    • Assess technical safeguards, such as encryption and access controls.
    • Document findings and corrective actions.
    • Retain evidence of the assessment for audit purposes.

    Takeaway

    The annual Security Risk Analysis attestation is more than a checkboxโ€”it is a cornerstone of patient data protection and regulatory compliance. For organizations billing Medicare, completing this requirement safeguards revenue, reduces risk exposure, and reinforces trust in your ability to protect sensitive health information.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    If your organization must conduct a HIPAA Security Risk Assessment before the end of the year, contact our office today at 844.740.7100. We can get the assessment scheduled within days. Avoid negative payment adjustments, directly impacting on your Medicare reimbursements.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Why Organizations Must Conduct a HIPAA Risk Assessment

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    Data breaches targeting Electronic Protected Health Information (ePHI) are nothing new. In fact, with more healthcare organizations now storing patientsโ€™ medical records electronically, these attacks are at an all-time high. It is crucial that healthcare entities regularly conduct a HIPAA risk assessment to identify any threats or vulnerabilities that may put ePHI in jeopardy. A risk assessment, also known as a risk analysis, is not only useful in detecting data threats; itโ€™s also required by the Code of Federal Regulations (CFR). The HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) โ€œConduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the organization.โ€ The risk assessment process keeps your patientsโ€™ records safe and your organization on the right side of the CFR.

    Do Small Practices Need to Conduct a HIPAA Risk Assessment?

    Data breaches donโ€™t only occur in larger organizations; hackers can target small practices and businesses too. Regardless of the size of the organization, a HIPAA Risk Assessment must be conducted with the proper documentation of any gaps and weaknesses determined by the assessment. Itโ€™s essential and required.

    The Office of the National Coordinator for Health Information Technology (ONC), in partnership with the HHS Office for Civil Rights (OCR), saw the need to launch a Security Risk Assessment (SRA) Tool to help small and medium-sized healthcare organizations and BAs comply with the HIPAA Security Rule. The tool is meant to guide these entities in identifying security risks in their systems, policies, and processes and display results that they can use to mitigate any identified vulnerabilities. Since launching the original tool about ten years ago, revisions have been made and it is now more of a decision tree process.

    However, itโ€™s important to note that the CFRs do not make it mandatory for Covered Entities and Business Associates to use the SRA tool nor does it give specific guidelines on how risk assessment should be carried out. HHS recognizes that different sized businesses have different needs and vulnerabilities, as well as different levels of access to resources. The problem with the tool is it can become time consuming to use, leads to more questions about meeting compliance requirements, and inability to see all the questions until traversing through the process. Regardless of using the tool or outsourcing the assessment to a consultant or vendor, all CEs and BAs must have documented proof that they have conducted an accurate and thorough HIPAA security risk assessment.

    Failure to Perform a HIPAA Risk Assessment Can Result in Serious Penalties

    If just knowing that conducting a risk analysis is a HIPAA requirement isnโ€™t enough motivation to get you started with the process, then you should keep in mind that the fines for non-compliance can add up to hefty amounts. Some organizations like Excellus Health Plan, Inc., for instance, have had to pay up to $5.1 million to OCR for breaching ePHI. According to this press release, the penalty was attributed to the organizationโ€™s โ€œfailure to conduct an enterprise-wide risk analysis, and failures to implement risk management, information system activity review, and access controlsโ€, which put the privacy of millions of its patients in danger. So, carrying out a risk assessment does not only allow you to spot potential weaknesses in organizational information systems that contain ePHI; it also enables you to take the right actions as soon as possible to safeguard your ePHI data, which can protect your business from federal penalties and the need to enter into a resolution agreement with OCR.

    Need Help With Your HIPAA Compliance Program?

    HIPAA violations often stem from small, overlooked gaps in daily operations. Don’t wait for a patient complaint to trigger a federal investigation. Would Your Practice Pass a HIPAA Audit Tomorrow?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your practice.

  • The Elements of a HIPAA Risk Analysis

    by Jay Hodes, President – Colington Consulting

    The Department of Health and Human Services (HHS) requires all Covered Entities and Business Associates handling protected health information to conduct a risk analysis as the first step toward implemented safeguards specified in The HIPAA (Health Insurance Portability and Accountability Act) Security Rule, and actively maintaining HIPAA compliance.

    At first glance, it may seem like a daunting task. But itโ€™s a necessary one that can help protect your practice from costly violations while โ€“ more importantly โ€“ protecting your patientsโ€™ privacy and personal security.

    Nine Key Components

    There are numerous methods of performing risk analysis and there is no single method or โ€œbest practiceโ€ that guarantees compliance with the Security Rule.

    However, the HHS Security Standards Guide outlines nine mandatory components of a risk analysis that healthcare organizations and healthcare-related organizations that store or transmit electronic protected health information (ePHI) must include in their document:

    • Scope of the Analysis โ€“ This addresses any potential risks and vulnerabilities to the privacy, availability, and integrity of ePHI. It includes all electronic media your organization uses to create, receive, maintain or transmit ePHI such as portable media, desktops, and networks. Network security between multiple locations is also important to include, and may include aspects of your HIPAA hosting terms with a third party or business associate.
    • Data Collection โ€“ This focuses on where the ePHI goes. You need to locate where data is being stored, received, maintained, or transmitted. If youโ€™re hosting at a HIPAA compliant data center, youโ€™ll need to contact your hosting provider to document where and how your data is stored.
    • Potential Threats and Vulnerabilities โ€“ Identify and document sensitive data and any vulnerabilities that may lead to the leaking of ePHI. By anticipating any potential HIPAA violations, you can help your organization reach a resolution swiftly and effectively.
    • Current Security Measures โ€“ Assess the kind of security measures youโ€™re taking to protect your data. This might include any encryption, two-factor authentication, or other security methods out in place by your HIPAA hosting provider.
    • Likelihood of Threat Occurrence โ€“ Determine the probability of potential risks to ePHI. This assessment allows for estimates on the likelihood of ePHI breaches.
    • Potential Impact of Threat Occurrence โ€“ Use qualitative or quantitative methods to assess the maximum impact of a data threat to your organization. Question how many people could be affected and to what extent private data โ€“ medical records or both health information and billing information –could be exposed.
    • Determine the Level of Risk โ€“ HHS suggest taking the average of the assigned likelihood and impact levels to determine the level of risk. Documented risk levels should be accompanied by a list of corrective actions that can be performed to mitigate risk.
    • Documentation Finalization โ€“ Compile everything in an organized document. Any format will suffice as long as the analysis is in writing.
    • Periodic Review and Updates to the Risk Assessment โ€“ One requirement is that the risk analysis process be conducted on a regular, ongoing basis. The Security Rule doesnโ€™t set a required timeline, but HHS recommends that organizations conduct another risk analysis whenever your company implements or plans to adopt new technology or business operations. This could include switching your data storage methods from managed servers to cloud computing, and updating after any ownership or key staff turnover.

    Take Action Now

    Performing a risk analysis is a complex process. The HIPAA compliance experts at Colington Consulting have conducted numerous compliance assessments. You can benefit from their expertise in knowing what is reasonable and appropriate for your organization. They understand the field of HIPAA rules and procedures and can help you avoid problems and steep fines by helping your organization maintain complete HIPAA compliance. It is what they do best, allowing you to do what you do best โ€ฆ provide health care to your patients. Contact Colington Consulting today at 800-773-6379.

    This blog was previously posted March 2, 2018