Failing to Implement HIPAA Causes Large Fine

Failing to ImplementFailing to implement HIPAA causes a large fine for a small town North Carolina health services provider. They were fined $25,000 for multiple, easily avoidable, HIPAA violations for “longstanding, systemic noncompliance” with the HIPAA Security Rule. [Note: The provider is a part of a health center which offers discounted medical services to the underserved population in rural NC, and the fines were reduced in consideration of this, but it still resulted in a significant monetary loss].

In 2011, Metropolitan Community Health Services (Metro), doing business as Agape Health Services, filed a breach report regarding “the impermissible disclosure of protected health information to an unknown email account.” The breach affected over 1,200 patients!

In addition to the large monetary penalty, the practice is required to develop and adopt a corrective action plan (which includes two years of thorough monitoring) after the Office for Civil Rights (OCR) discovered that Metro failed to conduct a thorough and comprehensive HIPAA Security Risk Assessment and Analysis. In addition, Metro did not implement a single HIPAA Security Rule Policy and Procedure for the health center. Possibly worst of all, Metro failed to provide workforce members with HIPAA Privacy and Security Awareness training until 2016!

Patients must trust who they share their personal, private, and protected health information with. A breach such as this, is obviously devastating for the patient, in addition to their doctor’s reputation. So, how can physicians ensure that they are meeting the HIPAA requirements and have proper safeguards in place to avoid this sort of breach?

First off, an accurate and thorough Security Risk Assessment and Analysis must be conducted to expose and target any potential administrative, physical, and technical vulnerabilities. Doing so  highlights any major flaws in a practice’s administrative and technical safeguards, and accentuates the policies and procedures that the practice needs to implement.

In addition to that, the designated HIPAA Privacy and Security Officer must ensure that ALL employees complete HIPAA Workforce training. All employees of the practice, including the physicians, must take HIPAA training to ensure employees have a clear understanding of the HIPAA Privacy Rule and actionable policies and procedures.

So, remember, healthcare organizations and their vendors have a responsibility to be HIPAA compliant, and that starts by performing, updating, or reviewing an accurate and thorough Security Risk Assessment covering your technical, administrative, and physical safeguards. This will help uncover any vulnerabilities, and help you understand what information is being transmitted, shared, and how it is being transmitted.

 

TAKE AWAYS AND THINGS TO CONSIDER:

  • Complete a Security Risk Assessment and establish a Corrective Action Plan that is accurate and thorough.
 Remediate any potential risks or vulnerabilities.
  • A Security Risk Assessment will target vulnerabilities related to what is potentially exposing Protected Health Information (PHI)
  • Develop actionable policies and procedures that clearly outline disclosures of PHI
  • Ensure all employees have a clear understanding of the HIPAA Privacy rule and its policies and procedures

 

Live Compliance provides everything you need to become and maintain your organization’s HIPAA compliance requirements. All policies and procedures can be edited and shared directly with staff from your staff portal. Trainings are delivered and monitored within your portal, can be customized, role-based, and be accessed anytime and from anywhere. You can also easily send and monitor HIPAA training with one click.

Failing to implement HIPAA can cause tremendous problems and use precious resources and time to implement. Live Compliance makes it 10X easier than trying to do it on your own.

So, take advantage of Live Compliance’s FREE Organization Needs Assessment to understand your immediate compliance needs. For additional details, e-mail Jim Johnson (at jim@livecompliance.com), call (980) 999-1585, or visit their website at livecompliance.com/oa

Live Compliance is a partner of EZClaim, a medical billing software company. For more details about their solutions, visit their website at ezclaim.com.

[ Written by Jim Johnson, President of Live Compliance ]

New Compliance Regulations for Working at Home

Whether you and your workforce are back in the office, or still working from home, there are new compliance regulations, and your HIPAA Compliance program may be a bit different.

New Compliance RegulationsReliable and Effective Compliance

Completely online, our role-based courses make training easy for remote or in-office employees.

Contact-free and accurate Security Risk Assessments are conducted remotely. All devices are thoroughly analyzed regardless of location.

Policies and Procedures curated to fit your organization ensuring employees are updated on all Workstation Use and Security Safeguards in or out of the office, and  updated in real time.

Electronic, prepared document sending and signing to employees and business associates.

Don’t risk your company’s future, especially when we are offering a FREE Organization Assessment to help determine your company’s status regarding the new compliance regulations. [ Click here to download a “HIPAA Compliance Requirements” document ].

Live Compliance is a partner of EZClaim, and you can contact them directly by either calling them at (980) 999-1585, e-mail Jim Johnson at Jim@LiveCompliance.com, or visit them at LiveCompliance.com

[ Written by Jim Johnson, President of Live Compliance ]

CONTACT INFO

337 S. Main Street
Ste 200
Rochester, MI 48307

877.650.0904

FOLLOW US ON

CONTACT INFO

337 S. Main Street
Ste 200
Rochester, MI 48307

877.650.0904

FOLLOW US ON

CONTACT INFO

337 S. Main Street
Ste 200
Rochester, MI 48307

877.650.0904

FOLLOW US ON

CONTACT INFO

337 S. Main Street
Ste 200
Rochester, MI 48307

877.650.0904

FOLLOW US ON

SALES

337 S. Main Street
Ste 200
Rochester, MI 48307

877.650.0904

CUSTOMER SUPPORT

337 S. Main Street
Ste 200
Rochester, MI 48307

877.650.0904

FOLLOW US ON