Although HIPAA laws do not specify any time frame on updating policies and procedures, OCR has expectations. Here are three recent settlements where OCR has included mandates to update policies and procedures. You can apply some of these lessons in your organization.
The Office of Civil Rights (OCR) offered considerations to healthcare organizations for securing electronic devices and media in its August Cybersecurity Newsletter.
Q: I work at the front desk at a clinic. My neighbor is one of our patients, and recently he asked if I could see when some test results would be available. Since I already had access to his records, is it a HIPAA violation to fulfill his request?
HIPAA covered entities that maintain poor policies and procedures related to HIPAA compliance—those that are unfinished in draft form, not updated in years, and basically not followed to the letter—have cost them dearly.
The plaintiffs in a class action lawsuit against Premera Blue Cross over a 2015 data breach now allege that the health insurance company destroyed key evidence, according to new documents filed in August.
Q: If we hire temporary nursing staff through a staffing agency, do they need to complete our facility’s HIPAA training, or can we consider the training the agency provides sufficient?