
By Jay Hodes, President – Colington Consulting
Question: How can an organization avoid a large HIPAA settlement with the HHS Office for Civil Rights (OCR)?
Up to this point, the OCR has settled HIPAA violation cases with predominantly larger healthcare organizations. However, OCR’s enforcement priority and direction has changed and all healthcare providers, regardless of size, must be on guard for the “message sending cases” on which OCR is currently focusing.
As a case in point, on the first day of the recent National HIPAA Summit held in Arlington, Virginia, OCR announced a $100,000 settlement for a HIPAA violation case involving the practice of Steven A. Porter, M.D., a gastroenterological services provider and solo practitioner. This “message sending” was twofold: 1) Serena Mosley-Day, Senior Advisor for HIPAA Compliance and Enforcement for OCR, provided a presentation emphasizing that small providers are not immune to OCR scrutiny and must meet the same requirements under HIPAA as do larger healthcare organizations; and 2) Announcing the settlement at a Summit where attendees included attorneys, Chief Compliance Officers, HIPAA Security and Privacy Officials, IT and cybersecurity experts was timed for maximum impact.
According to the HIPAA Settlement’s press release, Dr. Porter “filed a breach report with OCR related to a dispute with a business associate. OCR’s investigation determined that Dr. Porter had never conducted a risk analysis at the time of the breach report, and despite significant technical assistance throughout the investigation, had failed to complete an accurate and thorough risk analysis after the breach and failed to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.”
OCR Director Roger Severino’s comments in the press release are especially noteworthy. He states that “All health care providers, large and small, need to take their HIPAA obligations seriously,” and “the failure to implement basic HIPAA requirements, such as an accurate and thorough risk analysis and risk management plan, continues to be an unacceptable and disturbing trend within the health care industry.”
OCR has previously said that 95% of reported breaches are resolved with technical guidance. The key to avoiding a costlier outcome is to demonstrate to OCR that your organization has a HIPAA compliance plan in place and to cooperate with the OCR breach investigation.
Answer: To reduce the risk of penalty or settlement or the cost of mitigating a breach, an organization MUST implement and maintain a HIPAA compliance program as follows:
- Develop and implement policies and procedures to address all the HIPAA Security Standards and Implementation Specifications.
- Prepare a HIPAA Risk Management Plan that includes policies and procedures, asset inventories, HIPAA-related forms and reports, a facility security plan, and a documented contingency plan.
- Conduct he required HIPAA Security Risk Assessment.
- Provide HIPAA Security Awareness Training to the entire workforce.
- Assign HIPAA Security and Privacy Officer(s) to manage a HIPAA compliance program. Regardless of size, an organization must designate a workforce member(s) to handle these required responsibilities.
Take Action Now
At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.