News & Analysis

October 1, 2013
HIM Briefings

It's a brave new world out there for business ­associates (BA). BAs needed to comply with the HIPAA Security Rule and the use and disclosure provisions of the Privacy Rule in February 2010 as a result of the ­HITECH Act. However, the Office for Civil Rights (OCR) held off on any enforcement activities-that is, until recently.

October 1, 2013
Briefings on HIPAA

Is someone in your organization making sure that PHI is not left on your digital photocopiers?

October 1, 2013
Briefings on HIPAA

The September 23 compliance deadline for most of the provisions of the HIPAA omnibus rule has come and gone.

September 1, 2013
Briefings on HIPAA

Reliable data backup is critical. If a backup is not in place and your system crashes, you not only have a HIPAA compliance problem, but you may not be able to support your critical operations. ­IDrive® is a secure backup service that provides "ready when you need it" backup restoration and meets the National Institute of Standards and Techno­logy safe harbor encryption standard.

September 1, 2013
Briefings on HIPAA

Trying to keep up with one of the Kardashians may have resulted in the firing of six people at Cedars-Sinai Medical Center in Los Angeles.

September 1, 2013
Briefings on HIPAA

Q. Is it a HIPAA violation if a hospital receives a faxed Healthcare Effectiveness Data and Information Set (HEDIS) request and the hospital cannot ­identify the patient by full name, last name, or date of birth? These requests contain name, date of birth, provider, and the HEDIS Measure (Chlamydia screening, cervical cancer screening, cholesterol management, etc.) and last date of service of the patient. Typically, these faxed requests are from business associates of the patient's health insurance, but occasionally they come directly from the insurance company.

Pages