One thing is certain: You don't want to wait until you receive a notification letter from OCR before you begin preparing for a HIPAA audit, says Dena Boggan, CPC, CMC, CCP, HIPAA privacy/security officer at St. Dominic Jackson (Miss.) Memorial Hospital.
There are six generic approaches to managing risk, and the approach an organization chooses to use will depend on many factors. For example, how real is this risk? Can it actually become a problem, or is it merely theoretical? Management will want to decide whether the risk is likely to happen and whether it is possible to determine when it may happen. This will also assist in appropriate allocation of resources to focus on material risk areas.
Despite efforts to prevent data breaches in healthcare, they continue to cause alarm. Almost 20 million patient health records have been compromised in the past two years, according to statistics from HHS.