There are many tools available to organizations that help them perform the required HIPAA and Meaningful Use Risk Assessment. The problem with an organization doing their own Risk Assessment revolves around the saying What you put in is what you get out In order to get an accurate analysis of risks to patient information it...
You have been driving 45 mph on the same 25 mph road for years. There are never any police on the road and there is really no reason to drive 25 mph. Then after years of ignoring the posted speed limit, one day a police officer is waiting behind a tree and pulls you over...
There is a good article over at the Vormetric Security Blog that looks at restricting employee access to patient information. They argue that not all employees need full access and unless an employee can demonstrate that access is needed to perform their job function, no access to patient data should be given. The below paragraph...
The office of National Coordinator for Health Information Technology (ONC) has published a useful guide to Privacy and Security of Health Information (PDF). One of the sections looks at common myths and facts about a security risk analysis / assessment. Let’s take a look at it in more detail. Below are ONC’s myths and facts: Let’s look...
There are many threats to patient information and financial resources and one that seems to be popping up a lot lately is phishing scams. A phishing scam is basically an email that looks like a legitimate email from a bank, credit card company, retail stores, social networks (Facebook, Twitter, LinkedIn, etc.). The email usually has...
We have written about the $100,000 HIPAA fine that was handed down to Phoenix Cardiac Surgery. There is a very good article at AISHealth that details the case and provides some good insight by industry professionals. One quote by well respected HIPAA attorney Jeff Drummond really sheds light on what happens when you ignore compliance...
Many organizations are still using tapes to backup data. Those organizations that are still using backup tapes need to ensure that the tapes utilize encryption. Without encryption, a lost or stolen backup tape could result in a very large data breach. Best network practices call for performing a backup on all systems at least daily....
There should be no doubt that we are witnessing a changing landscape for healthcare IT. As the government gives billions of dollars in incentives to hospitals and medical practices to implement electronic health records the repercussions are being heard around the country. Medical practices are going from low-tech businesses that focused on paper charts and very little...
We are excited to announce our new Small Business Package. The Small Business Package is for organizations with 10 or fewer employees. We have reduced the price of the complete HIPAA Secure Now! service from $1,750.00 to $999.00. The Small Business Package is exactly the same as our regular service and includes custom policies and...
You’ve seen hundreds of companies selling HIPAA products. There are HIPAA training videos, policy templates, consultants, HIPAA books, HIPAA coffee mugs and the list goes on and on. And yet “become HIPAA compliant” is still on your long list of things to do. Have you asked yourself why you never seem to get to “become...
Recent Comments