October 1, 2010
Briefings on HIPAA

You want your staff members to report incidents when they suspect a privacy or security violation involving PHI has occurred.

October 1, 2010
Briefings on HIPAA

Hospitals and provider networks account for the highest number of breaches on the OCR list of entities reporting breaches of unsecured PHI affecting 500 or more individuals, a new report indicates.

September 1, 2010
HIM Briefings

ARRA brought us an expanded version of HIPAA. Along with it came the clear message that if the last time you visited your HIPAA policies and procedures was April 15, 2005, you have a problem.

September 1, 2010
HIM Briefings

Use this Q&A to test staff members’ HIPAA knowledge.

September 1, 2010
HIM Briefings

On July 8, HHS released a proposed rule to modify the HIPAA Privacy, Security, and Enforcement Rules, extending HIPAA compliance requirements to subcontractors of business associates (BA) and strengthening patient rights to health information privacy. The rule is available for viewing at http://edocket.access.gpo.gov/2010/pdf/2010-16718.pdf.

September 1, 2010
Briefings on HIPAA

When HITECH was signed into law February 17, 2009, privacy and security officers predicted the provision that gives patients greater rights to accounting of disclosures on their electronic health records (EHR) would prove to be the most difficult.

September 1, 2010
Briefings on HIPAA

The cost of failure to comply with the HIPAA Security Rule has significantly increased during the past few years. This cost is not related solely to regulatory changes; it is also associated with data loss and corruption, legal risks, and damage to business image. Many healthcare organizations relegate disaster recovery planning and disaster preparedness to the back burner. This represents a regulatory compliance concern and a significant risk to organizations.

September 1, 2010
Briefings on HIPAA

Q. In the April issue of BOH, one of the Q&As discussed who must send out breach notification letters if the business associate (BA) was responsible for the breach. The answer was covered entities. Didn’t HITECH make BAs covered entities?

September 1, 2010
Briefings on HIPAA

OCR is seeking comments on the HIPAA proposed rule published July in the Federal Register through September 13.

September 1, 2010
Briefings on HIPAA

Dena Boggan, CPC, CMC, CCP, chuckled when someone recently suggested that her staff audit some patient records.

“I wish I had a staff,” laughed Boggan, HIPAA privacy/security officer at St. Dominic Jackson (MS) Memorial Hospital. 

However, this is fairly typical in many healthcare settings, where HIPAA privacy and security officers often are the only individuals who are responsible for compliance.
