There has been a lot written recently about organizations that have received high profile HIPAA fines from the Office of Civil Rights (OCR). The Tennessee Blue Cross Blue Shield was handed a $1.5 million fine, Cignet Health was given a $4.3 million fine and Massachusetts General Hospital was awarded a $1 million fine. The only...
In the Ponemon 2011 Cost of Data Breach Study, 41% of breaches were due to third party mistakes. Take a step back and think about the impact of that number. The use of third party organizations are more and more common. According to the HHS.gov website, some examples of third party / business associates include:...
The proposed meaningful use stage 2 requirements were posted yesterday. The requirements are over 450 pages so we are still going through them and trying to digest them. As of now, two major IT related items jump out at us. The first IT related objective is focused on protecting and securing patient information. In stage...
As John Lynn and Neil Versel have both reported, it looks like the Meaningful Use (MU) Stage 2 proposal will be out in the next few weeks. One area of interest will be the wording around the use of encryption to protect patient information. Currently the HIPAA and HITECH regulations do not make the use...
There is a lot to know about HIPAA but let’s take a look at 6 things that you must know. HIPAA is not optional A lot of practices feel they are exempt from the HIPAA regulations. This may stem from the fact that “small practices” were granted a 1 year extension to comply with the...
Over at Healthcareinfosecurity.com there is an insightful article on the first HIPAA audits. Some highlights of the article include: In the pilot phase, OCR is auditing eight health plans, two claims clearinghouses plus 10 provider organizations, including three hospitals, three physicians’ offices, and a laboratory, a dental office, a nursing/custodial facility and a pharmacy. ...
2011 has been a great year for us and we couldn’t be more excited for 2012. We had the opportunity to work with some really great people at a lot of different medical practices throughout the United States. We got to show that the HIPAA Secure Now! process really works and can help practices with...
The National Institute of Standards and Technology (NIST) has recently released a HIPAA Security Rule Toolkit to help organizations comply with the HIPAA Security Rule. From their website: The NIST HIPAA Security Toolkit Application is intended to help organizations better understand the requirements of the HIPAA Security Rule, implement those requirements, and assess those implementations...
The Department of Health and Human Service (HHS) has announced that they will perform 150 HIPAA audits by the end of 2012. The chance of you getting audited is very small but what if you open up your mail one day and found a notice that your medical practice has been select to be audited?...
FierceEMR posted a story on how some providers are attesting to meaningful use measures but are actually not addressing all of the required measures. Specifically some providers are stating that they have performed a meaningful use risk assessment on how patient data is being protected but have not actually performed the risk assessment. The article...
Recent Comments