Category: OCR

  • How Prepared is Your Organization for a HIPAA Audit?

    by Jay Hodes, President – Colington Consulting

    Could your organization be prepared for an onsite HIPAA audit in ten days? Before you answer, let me explain what documentation you will need for the auditors, lawyers and investigators the U.S. Health and Human Services (HHS) Office for Civil Rights (OCR) will be sending to your office or business. ย 

    One of the first documents OCR will be asking for is a copy of your most recent HIPAA Risk Assessment. ย Conducting a risk assessment is a regulatory requirement to determine the vulnerabilities and threats to any electronic protected health information your organization accesses, stores, creates or transmits. A checklist is not sufficient, and a comprehensive risk assessment needs to be made available to OCR. ย  ย 

    OCR will be interested in seeing how your organization has attempted to mitigate those vulnerabilities and threats. Just conducting the assessment is not good enough. A remediation plan must be implemented. I always recommend a systematic approach to remediation by addressing high threats first, then on to moderates, and concluding with the lows if actionable items are needed. ย 

    Once the risk assessment is provided, be prepared to hand over any number of HIPAA policies and procedures that an organization must have in place. How do you know what OCR will ask for? That is a tough question to answer. Based on my knowledge from others who have been onsite during an audit or investigation, all bets are off as far as which of those policies and procedures will be requested.ย 

    When you look at the HIPAA Implementation Specifications, all of these must be covered with policies and procedures. As former Assistant Inspector General for Investigations in the HHS IGโ€™s office involved with the oversight of complex criminal investigations, my experience tells me OCR will ask for a lot, if not all, of policies and procedures generated by the organization. ย ย 

    If I were to pick a handful of policies that OCR would be interested in seeing, I would include the Mobile Device Management Policy; Breach Notification Policy; Facility Security Plan and Policy; Audit Control Policy; and the Sanction Policy. All of these are critical areas that must be addressed with not only policy, but procedures on how to implement the policy. ย ย 

    Expect OCR to request documentation regarding the annual HIPAA Security Awareness Training requirement. Your organization will need to show you provided this training to each member of your workforce. This includes all physicians, part-timers, interns and volunteers, along with the rest of the staff. ย 

    I can tell you from my expertise in compliance, if you do not have all the HIPAA requirements currently in place, there is no way an organization can be prepared for audit in ten days. OCR will look for specific dates for items, such as when an access audit was conducted or when a HIPAA Risk Assessment was conducted, as well as entry dates on a maintenance record log. Your organization must be prepared as if any day now a letter is going to arrive from HHS indicating you have been identified for an audit. This will make it easier having required compliance requirements in place and minimize any concerns if that letter does come.

    This blog was previously posted October 24, 2016

  • Office for Civil Rights (OCR) – Two Significant Announcements

    The U.S. Department of Health and Human Services, Office for Civil Rights (OCR) had two significant announcements this past week resulting in total of $4.6 million for a settlement and imposed penalty.ย  The two cases, one involving a public agency, the Texas Health and Human Services Commission (TX HHSC) and the second, a university medical center, the University of Rochester Medical Center (URMC).

    Both cases demonstrate OCR is continuing on an aggressive path to address reported breaches and investigate how organizations are just not being proactive with HIPAA compliance requirements.These investigations uncovered a slew of problems, especially in the Texas case.ย  What was troubling about this case, is the TX HHSC had such poor audit controls, it could not determine the number of persons who inappropriately accessed the protected health information in question.

    In the URMC case, it determined โ€œidentification of a lack of encryption as a high risk to ePHI, URMC [still] permitted the continued use of unencrypted mobile devices.โ€ย  This is a clear case of somebody dropping the ball due to reasons one can only speculate about.ย 

    If OCRโ€™s track record is similar to recent years, expect more settlement announcements to be made before the end of the year.ย  With the holidays quickly approaching, OCR may not be spreading good cheer for some.

    Read the TX HHSC Press Release

    Read the URMC Press Release