{"id":244,"date":"2018-05-21T07:00:59","date_gmt":"2018-05-21T07:00:59","guid":{"rendered":"https:\/\/advantagehcconsulting.com\/blog\/?p=244"},"modified":"2018-05-15T15:10:53","modified_gmt":"2018-05-15T15:10:53","slug":"hipaa-cover-these-hipaa-basics-or-risk-hefty-penalties","status":"publish","type":"post","link":"https:\/\/advantagehcconsulting.com\/blog\/2018\/05\/21\/hipaa-cover-these-hipaa-basics-or-risk-hefty-penalties\/","title":{"rendered":"HIPAA: Cover These HIPAA Basics Or Risk Hefty Penalties"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter  wp-image-245\" src=\"https:\/\/advantagehcconsulting.com\/blog\/wp-content\/uploads\/2018\/05\/hipaa-compliance.png\" alt=\"\" width=\"552\" height=\"414\" srcset=\"https:\/\/advantagehcconsulting.com\/blog\/wp-content\/uploads\/2018\/05\/hipaa-compliance.png 300w, https:\/\/advantagehcconsulting.com\/blog\/wp-content\/uploads\/2018\/05\/hipaa-compliance-210x158.png 210w\" sizes=\"auto, (max-width: 552px) 100vw, 552px\" \/><\/p>\n<p><span style=\"color: #ffffff;\"><strong><em>Learn a valuable lesson from this $2.3 million HIPAA settlement.<\/em><\/strong><\/span><\/p>\n<p>If you skimp on risk management or other HIPAA core duties, you may have to pay big when a breach occurs. That\u2019s what one health care provider has recently discovered.<\/p>\n<p><strong><span style=\"color: #ffffff;\">Background:<\/span>\u00a0<\/strong>The\u00a0<strong>Federal Bureau of Investigation\u00a0<\/strong>warned physician practice\u00a0<strong>21st Century Oncology Inc.\u00a0<\/strong>twice about a cyber invasion of its systems in 2015, resulting in large-scale HIPAAviolations for failing to adequately secure its patients\u2019 electronic protected health information (ePHI) against an \u201cunauthorized third party,\u201d says an\u00a0<strong>HHS Office for Civil Rights\u00a0<\/strong>release.<\/p>\n<p>The Fort Myers, Florida, cancer treatment and oncology specialist with 179 locations in both the U.S. and Latin America left more than 2.2 million individuals exposed after internal investigations determined illegal access of its network SQL database through \u201cremote desktop protocol from an exchange server within 21CO\u2019s network,\u201d the OCR says. The report suggested evidence obtained from an FBI informant is what originally alerted the feds that the files with \u201cnames, social security numbers, physicians\u2019 names, diagnoses, treatment, and insurance information\u201d had been breached.<\/p>\n<p>OCR levied a $2.3 million monetary settlement against 21CO for its HIPAA violations and required the organization to put together a corrective action plan. \u201cPeople need to trust that their private health information will remain exactly that; private,\u201d says OCR Director\u00a0<strong>Roger Severino<\/strong>. \u201cIt\u2019s not just my hope that covered entities will learn from this example and proactively find and address their security risks, it\u2019s what the law requires.\u201d<\/p>\n<p>The OCR\u2019s biggest complaint pointed to repeated compliance basics blunders by 21CO. The provider missed opportunities to better assess and manage its risk. And with large-scale settlements like this one becoming the norm, providers cannot be too careful when devising their HIPAA protocols. It remains evident that a strong compliance foundation, which promotes and outlines in writing the HIPAA Privacy and Security rules, provides some insulation against steeper penalties.<\/p>\n<p>\u201cCovered entities and business associates must insulate their businesses with a comprehensive compliance plan and risk analysis addressing and mitigating any applicable privacy and security risks,\u201d advises attorney\u00a0<strong>John E. Morrone<\/strong>, a partner at\u00a0<strong>Frier Levitt Attorneys at Law\u00a0<\/strong>in Pine Brook, New Jersey. \u201cThrough recent settlements, OCR has demonstrated its propensity to impose significant fines on entities that fail to implement appropriate safeguards, independent of the number of affected individuals or the content of the protected health information included in a particular breach.\u201d<\/p>\n<p><span style=\"color: #ffffff;\"><strong>Do this:\u00a0<\/strong><\/span>If your agency is due for a HIPAA compliance plan update, consider adding these priorities that 21CO failed to implement \u2014 but that the OCR looks for after a breach occurs:<\/p>\n<ul>\n<li>Evaluate thoroughly the \u201cpotential risks and vulnerabilities to the confidentiality, integrity, and availability\u201d of your patients\u2019 ePHI, OCR says.<\/li>\n<li>Integrate the federally required security measures necessary after the risk assessment to reduce the chance of the loss of ePHI.<\/li>\n<li>Manage and review your protocols often to ensure that the safeguards are working.<\/li>\n<li>Utilize such tools as audit logs, multi-factor authentication, systems controls, certified vendors and software, and tracking devices and reports that show inconsistencies in your system.<\/li>\n<li>Use and insist upon business associate agreements (BAA) with all business partners, suppliers, and vendors.<\/li>\n<\/ul>\n<p><strong><span style=\"color: #ffffff;\">Tip:<\/span>\u00a0<\/strong>After you assess your risk and as part of your HIPAA-plan implementation and management, it is a great idea to create a list of all business associates that provide services to your organization and update this annually as changes arise and your agency evolves. It\u2019s easy to forget to alert BAs, and some may feel uncomfortable insisting that business partners, suppliers, and vendors follow HIPAA.<\/p>\n<p>Nonetheless, OCR insists your final steps include identifying BAs and setting up BAAs. They must understand what your 2018 initiative entails, why HIPAA is important to the integrity of your agency, and sign off on your principles in a BAA.<\/p>\n<p><a href=\"https:\/\/www.supercoder.com\/coding-newsletters\/my-homecare-week-alert\/hipaa-cover-these-hipaa-basics-or-risk-hefty-penalties-157610-article\"><i><span style=\"font-weight: 400;\">Source- SuperCoder<\/span><\/i><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn a valuable lesson from this $2.3 million HIPAA settlement. If you skimp on risk management or other HIPAA core duties, you may have to pay big when a breach &hellip; <a class=\"readmore\" href=\"https:\/\/advantagehcconsulting.com\/blog\/2018\/05\/21\/hipaa-cover-these-hipaa-basics-or-risk-hefty-penalties\/\">Continue Reading &rarr;<\/a><\/p>\n","protected":false},"author":1,"featured_media":245,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[11,12,13,14],"class_list":["post-244","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","tag-home-care","tag-hospice","tag-ltc","tag-snf"],"_links":{"self":[{"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/posts\/244","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/comments?post=244"}],"version-history":[{"count":3,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/posts\/244\/revisions"}],"predecessor-version":[{"id":248,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/posts\/244\/revisions\/248"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/media\/245"}],"wp:attachment":[{"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/media?parent=244"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/categories?post=244"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/advantagehcconsulting.com\/blog\/wp-json\/wp\/v2\/tags?post=244"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}