Compliance News - page 8

Automated Risk Assessment: Best Value

Combining sophisticated Internet tools with experienced consultants can deliver a HIPAA risk assessment based on the NIST protocol quickly and at a reasonable cost. "Automated HIPAA Risk Assessment " Thu, Jun 9, 2016 12:00 PM - 1:00 PM PDT 1. Click the link to join the webinar at the specified time and date: https://global.gotowebinar.com/eojoin/8852590702394920194/4062226347872620034

Finish Reading…

Posted May 25, 2016 by Jack Anderson

No BA Agreement: $750,000 Fine

An orthopedic clinic failed to get a BA agreement before sharing PHI with a business associate and got a $750,000 fine. Jocelyn Samuels, director of OCR, said in the statement. "It is critical for entities to know to whom they are handing PHI and to obtain assurances that the information will be protected."

Finish Reading…

Posted April 25, 2016 by Jack Anderson

Ransomware is a HIPAA Breach

A recent article in Health IT Security made the point that crminal control of PHI is a HIPAA breach and that in ramsomware that occurs. Here is the full article: http://healthitsecurity.com/news/why-healthcare-ransomware-attacks-are-hipaa-data-breaches

Finish Reading…

Posted April 20, 2016 by Jack Anderson

HIPAA Audit Questionnaire

If you were lucky enough to not receive one, here is the questionnaire that is going out to all potential audit winners. http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/audit/questionnaire/index.html

Finish Reading…

Posted April 6, 2016 by Jack Anderson

The BA Agreement Is Not Sufficient for "Satisfactory Assurances"

Just getting your business associates to sign a BA agreement is not enough. You need "satisfactory assurances" such as documented HIPAA security awareness training, to protect you.

Finish Reading…

Posted April 5, 2016 by Jack Anderson

Progress Key To HIPAA Compliance

Demonstrating progress is the key to HIPAA compliance. Periodic HIPAA risk assessments that meet the NIST protocol are the proof.

Finish Reading…

Posted March 10, 2016 by Jack Anderson

25% of Providers Audited for MU Compliance in Midwest, will Fail

Figliozzi has just started desk audits in the Midwest for covered entities who received meaningful use funds. 25% of providers audited for MU compliance in the past have failed. A frequent cause is lack of an updated risk assessment meeting HHS standards.

Finish Reading…

Posted March 8, 2016 by Jack Anderson

OCR says: Comprehensive HIPAA Risk Assessment Required

OCR Director, Jocelyn Samuels, reinforced the need for an enterprise-wide assessment when she stated, “[a]ll too often we see covered entities with a limited risk analysis that focuses on a specific system such as the electronic medical record or that fails to provide appropriate oversight and accountability for all parts of the enterprise.”

Finish Reading…

Posted March 7, 2016 by Jack Anderson

How to Get HIPAA Compliant In 3 Days

To get HIPAA compliant in three days and prove it, you need; a risk assessment, updated policies, and documented staff training, which can be done with the investment of a few hundred dollars and a few hours over three days.

Finish Reading…

Posted March 3, 2016 by Jack Anderson

Covered Entities and Business Associates Linked in Audits

If a covered entity is audited, their business associates will be included in the audit, and if the business associate fails, so does the covered entity.

Finish Reading…

Posted February 17, 2016 by Jack Anderson