Friday, October 14, 2016

Disaster Recovery Planning Under HIPAA - Ep 75


Everything going on today with hurricanes and such makes it is a great time to talk about this. We mention it all the time but this episode is going to be just about what DR/BC means and what you can do to be prepared in advance.  So, this episode covers disaster recovery planning under HIPAA but any business can learn from our topics!

  • What is DR/BC Planning?
  • Who should do it?
  • Is this another big expense?
  • What is involved in building and maintaining DR/BC plans?
  • General elements of a plan

Get more details at http://HelpMeWithHIPAA.com/75


Check out the latest episode!

Friday, October 7, 2016

HIPAA Security Updates Recommended In New Report - Ep 74


Last year Lamar Alexander and Patty Murray asked for answers to some questions concerning cybersecurity in healthcare.  They were interested in understanding what CMS and HHS were doing to protect patients from fraud.  It seems as though they were wondering if HIPAA security updates where needed.

 

We discussed the Senators request in episode 31 : https://helpmewithhipaa.com/episode-31-enforcement-efforts-ocr-increase-2016/

Their letter asked:

  • What CMS and HHS is doing to monitor medical identity fraud
  • What is CMS and/or OCR actually doing, if anything, to track cases of ID theft and fraud
  • OCR uses the data collected from covered-entities to monitor potential breach victims and find out if their data have in fact been used by criminals
  • They also want to know whether any education materials or help are offered to breach victims by the CMS and OCR

The report was presented to the committee on August 6, 2016 and made public on Sept 26.


Check out the latest episode!

Friday, September 30, 2016

Business Associate Security Issues - EP 73


BAs are in the HIPAA spotlight now more than ever.

  • TheDarkOverlord was clearly using some BA applications to infiltrate networks and exfiltrate PHI.
  • OIG reviewed Alaska VA system after breaches and the report specifically points to the need to monitor BAs
  • OCR audits of BAs are about to start. Previously said end of September but now saying October

In this episode we discuss what all this means.

More at HelpMeWithHIPAA.com/73


Check out the latest episode!

Friday, September 23, 2016

HIPAA Penalties Increasing - Ep 72


Did you hear that maximum penalties for HIPAA violations are being adjusted for inflation? It has quietly happened. Here is how.

Check out the Federal Register entry from September 6, 2016. If you aren't in to reading yourself, don't worry, you know Donna did it. Well, at least the HIPAA parts.

Learn more at: HelpMeWithHIPAA.com/72


Check out the latest episode!

Friday, September 16, 2016

OCR small breach investigations increasing - Ep 71


OCR recently released another memo concerning compliance enforcement efforts.  They say effective August 2016, they have started an initiative to more widely investigate breaches involving under 500 patients.  That means that OCR small breach investigations will begin happening immediately.  In the past, the policy had been to investigate all breaches over 500 patients but not under.  

More information at HelpMeWithHIPAA.com/71

 


Check out the latest episode!

Friday, September 9, 2016

Insider Threats: Do you know who your employees are? - Ep 70


OCR published a memo on Aug 1, 2016.  The title is "Do you know who your employees are?".  It is a great reminder about insider threats that we should all worry about regularly.

Quoted directly from the memo.
============================
Although all insider threats are not malicious or intentional, the effect of these threats can be damaging to a Covered Entity and Business Associate and have a negative impact on the confidentiality, integrity, and availability of its ePHI.

According to a survey recently conducted by Accenture and HfS Research, 69% of organization representatives surveyed had experienced an insider attempt or success at data theft or corruption. Further, it was reported by a Covered Entity that one of their employees had unauthorized access to 5,400 patient’s ePHI for almost 4 years.

For more visit: HelpMeWithHIPAA.com/70


Check out the latest episode!

Friday, September 2, 2016

OCR 2016 settlements keep coming - Ep 69


So far in 2016 there have been 10 resolution agreements announced. One more and this year will equal the number of agreements in all of 2015 & 2014!

The latest two also include the largest one announced yet - $5.5m with Advocate Health.

Before that though was The University of Mississippi Medical Center - Ole Missto those of us in the SEC world. It wasn't something to "shake a stick at" with a$2.75m resolution amount.

The total amount for those 10 announcements so far in 2016 = $20,314,800

Of course the details are what we usually pay more attention to since it tells us exactly what OCR has a problem with in each case. It makes it clear what OCR wants all of us to learn from these folks mistakes.

For more visit HelpMeWithHIPAA.com/69


Check out the latest episode!