You’ve seen hundreds of companies selling HIPAA products. There are HIPAA training videos, policy templates, consultants, HIPAA books, HIPAA coffee mugs and the list goes on and on. And yet “become HIPAA compliant” is still on your long list of things to do. Have you asked yourself why you never seem to get to “become...
We have written about the HIPAA fine and reputation damage to Phoenix Cardiac Surgery. Phoenix Cardiac Surgery is a small 5 physician specialist in Phoenix, AZ. Let’s quickly review why the Office of Civil Rights fined Phoenix Cardiac Surgery $100,000. Lack of HIPAA Policies and Procedures Lack of HIPAA training for all workforce members Lack...
The Phoenix Cardiac Surgery medical practice was handed a $100,000 fine for failing to protect patient information. The resulting resolution agreement from the Office of Civil Rights (OCR) is very interesting. Let’s take a look at is. The full resolution agreement can be found here (PDF). Lack of training for employees (a) From April 14,...
There has been a lot written recently about organizations that have received high profile HIPAA fines from the Office of Civil Rights (OCR). The Tennessee Blue Cross Blue Shield was handed a $1.5 million fine, Cignet Health was given a $4.3 million fine and Massachusetts General Hospital was awarded a $1 million fine. The only...
In the Ponemon 2011 Cost of Data Breach Study, 41% of breaches were due to third party mistakes. Take a step back and think about the impact of that number. The use of third party organizations are more and more common. According to the HHS.gov website, some examples of third party / business associates include:...
There is a lot to know about HIPAA but let’s take a look at 6 things that you must know. HIPAA is not optional A lot of practices feel they are exempt from the HIPAA regulations. This may stem from the fact that “small practices” were granted a 1 year extension to comply with the...
Over at Healthcareinfosecurity.com there is an insightful article on the first HIPAA audits. Some highlights of the article include: In the pilot phase, OCR is auditing eight health plans, two claims clearinghouses plus 10 provider organizations, including three hospitals, three physicians’ offices, and a laboratory, a dental office, a nursing/custodial facility and a pharmacy. ...
The Department of Health and Human Service (HHS) has announced that they will perform 150 HIPAA audits by the end of 2012. The chance of you getting audited is very small but what if you open up your mail one day and found a notice that your medical practice has been select to be audited?...
Susan McAndrew, deputy director of The HHS Office of Civil Rights (OCR) gives a very insightful interview to Howard Anderson, Executive Editor, HealthcareInfoSecurity.com. There are a lot of good points and I suggest reading the whole interview. I will point out a few of the highlights. When asked about who will be audited, McAndrew was...
Working with clients over the years, we have come to the conclusion that most people hate HIPAA. There we said it! Fortunately we don’t take it personally because we actually understand why people hate HIPAA. Here are a few valid reasons. HIPAA is confusing HIPAA is boring HIPAA is expensive HIPAA gets in the way...
Recent Comments