If your organization experiences a data breach—an increasingly likely scenario—and PHI is exposed, chances are you will be hit with a lawsuit in short order.
There are times when state privacy and security laws trump HIPAA, and healthcare organizations and their business associates (BA) should have a clear understanding of their compliance obligations in the midst of what can be a complex web of regulations.
There are compelling reasons with which to make a case to company executives of the benefits of a good data security program. It starts with return on investment calculations.
Q: I realize that you cannot compel your staff to complete Occupational Safety and Health Administration training online on their own time. However, I am wondering whether the same applies for HIPAA training. Must this training be conducted during work hours, or can we provide workforce members with a deadline by which to complete training on their own time?