
By Jay Hodes, President – Colington Consulting
Recently, Buck, “an integrated HR and benefits consulting, technology, and administration services provider” based in New York, produced a 2019 HIPAA Readiness Survey. After reading the Survey, I was not surprised by the results, for its message is loud and clear: It is time to sound the alarm bells.
In my mission to help organizations achieve HIPAA compliance, I know where organizations typically struggle in complying with HIPAA regulations. Several of the Survey’s findings drive home that point:
- 42% of survey participants did not know when a risk/threat analysis was last conducted, or they last conducted one more than five years ago.
- 33% of survey respondents either have not inventoried their business associates or did not know if they had done so; 16% did not have current business associate agreements or did not know if they had them.
- 35% indicated they last offered HIPAA training between one and five years ago, 13% provide training only during onboarding, and 10% did not know when HIPAA training was last provided.
The Survey states that “strong governance is essential to protecting information” and “understanding the rules and complying with them in a way that protects your organization is the best way to prevent a breach and the only way to emerge successfully from a HIPAA audit.”
Governance, Risk, and Compliance (GRC) and Beyond
I recently had lunch with a GRC expert who pointed out that organizations are considered “negligent” if they disregard or plead ignorance of HIPAA compliance requirements and other industry-wide regulatory controls and standards. The HHS Office for Civil Rights continues an aggressive campaign of seeking civil monetary penalties from organizations for HIPAA violations. In addition, these same negligent organizations expose themselves to class action lawsuits from individuals seeking damages from breaches of personally identifiable information. In summary, HIPAA compliance should be driven by cost—the costs incurred from both government penalties as well as the time and money spent on re-mediating the damage caused by data breaches.
Sound the Alarm?
Rather than sound the alarm after the fact, organizations should focus their urgency on prevention and corrective measures before a violation or data breach. GRC is not meant to be a one-and-done approach to punch a regulatory ticket, but rather a systematic process to deal with risk management, including conducting audits and assessments; reviewing the results; and implementing the changes necessary to mitigate risk. This process will take effort, buy-in, and cooperation from all organizational levels, especially from the leadership team.
Take Action Now
At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.