SlideShare a Scribd company logo
1 of 64
Download to read offline
Leading Your HIPAA
Culture in 2016
Finished files are the re-
sult of years of scientif-
ic study combined with the
experience of many years.
Lance King
Vice President, Sales
Healthcare Compliance Solutions
Phone (801) 947-0183
lking@hcsiinc.com
What
to
expect
Lead Your Culture, Select Your Team, and Learn
✓ Create a Culture of Privacy, Security, and Safety
✓ HIPAA Breach – Identifying a Breach, Exceptions to a Breach
✓ HIPAA Protections – Security Risk Analysis, Social Media
✓ Compliance Training
Document Your Process, Your Findings, and Actions
✓ Documentation
✓ Policies and Procedures
✓ HIPAA Privacy & Security
Develop an Action Plan
✓ Audit Preparation
Mitigating Risk
✓ Ongoing Training & Culture Maintenance
Lead Your Culture
FUNSTAFF ACCOUNTING COMPLIANCEPATIENTS FRONT DESK
Healthcare Compliance (HIPAA, OSHA…)
Insurance
HR
Accounting
Front Desk
Patient Care
Staff Training
PHI
Day 1 Day 10 Day 30/90 Dependent on Completion of Fieldwork
AUDIT TIMELINE
5 COMMON CIRCUMSTANCES FOR AN AUDIT
1. Disgruntled ex-employee
2. A self-reported breach
3. Employee activists
4. Patient’s fear of breach
5. Random OCR visit
1)
2)
3)
1)
2)
3)
1)
2)
3)
CREATE A CULTURE OF PRIVACY &
SECURITY
• Communicate
• Guide
• Remind
IDENTIFYING A BREACH
1. Nature and extent of the PHI involved
2. The unauthorized person who used the PHI, or to whom it was
disclosed
3. Whether the PHI was actually viewed or acquired
4. The extent to which the risk to protect the PHI has been mitigated
“…unless the covered entity or business associate, as applicable,
demonstrates that there is a low probability that the protected health
information has been compromised based on a risk assessment of at
least the following factors”:
HIPAA BREACH
• Does your staff know who to go to
for leadership when there is a
HIPAA breach?
• Does your designated HIPAA
compliance officer know all of the
necessary steps to take in breach
notification?
• Does your HIPAA compliance
officer know where to receive
guidance?
EXCEPTIONS TO A BREACH
1.Unintentional
2.Inadvertent
3.Good faith
3 Exceptions to the definition of “breach”
HIPAA PROTECTIONS
• Ensure privacy
• Give patients more access
• Establish safeguards
• Hold violators accountable
• Strike a balance
• Enable patients
• Limit release of information
• Give patients the right to examine and obtain a copy
• Empower individuals to control certain uses and disclosures
Key Components of the HIPAA Privacy Rule:
HIPAA RISK PROTECTIONS
• Physical, Technical, and
Administrative measures
• Internal and External Security
threats
• Assessment of and
preparations for security risks
7 STEPS TO HIPAA COMPLIANCE
1. Understand the rules
2. Assign Responsibility
3. List your PHI systems
4. Conduct a Risk Analysis
5. Implement Policies and Procedures
6. Training program
7. Ongoing HIPAA progress and compliance
SECURITY RISK
• Identify where PHI exists
• Identify potential threats and vulnerabilities
to PHI
• Identify risks and their associated levels of
high, medium, or low
• Educate staff about process
• Make security a high priority
• Have an action plan
• Involve your EHR developer
• Specific to your practice
TIPS FOR A BETTER SECURITY RISK ANALYSIS
10 HIPAA SECURITY TIPS
1. Have A Written Security Policy
2. Encrypt Everything
3. Protect Your Website
4. Data Backups
5. Avoid Consumer Grade
6. Know Your Risks
7. Plan For BYOD
8. Who Is Guarding The Sheep
9. Physical Security Is Information Security
10. Know When To Call For Help
SECURITY RISK PRECAUTIONS
• Staff requests
• Hard drives
• Email
• Server
• Passwords
• Monitoring office staff
• Fire extinguishers
• Viruses and malware
Low-Cost Highly Effective Safeguards:
SOCIAL MEDIA
• Access Controls
• Personal
• Connecting with patients
• Patient waiver forms
• Training
To ensure your office remains in
HIPAA compliance, create policies
such as:
COMPLIANCE TRAINING
•Online
•In-office
•Outsourced
WORKFORCE EDUCATION &
TRAINING
• Hired or contracted
• Yearly retraining
• Changes in policies or procedures
• Changes in systems, location, or
infrastructure
• Responding to breach or disclosure
Educate and train your staff:
Documenting
the Process, the
Findings
& the Actions
DOCUMENTATION
• Policies and procedures
• Security Risk Analysis
• Training materials, and certificates of completion
• Current Business Associate Agreements
• EHR audit logs
• Risk management action plan
• Security incident and breach information
Examples of records to retain:
POLICIES AND PROCEDURES
• Establish protocols
• Training program
• Instruct your workforce
• Sanction policy for violations
• Detail enforcement
• Business Associates
Employee HIPAA Privacy & Security
• Name/ID badges
• Quiet Communication
• PHI access
Guidelines for employees:
Workstation HIPAA Privacy & Security
• Viewing PHI Documents
• Disposing of PHI
• Workstations
• Protect user ID’s and passwords
• Computers not in use
Guidelines for workstations:
Access HIPAA Privacy & Security
•Computer room access
•PHI Back-ups
•Limited office equipment
•Unoccupied Office equipment
Guidelines for access:
Environmental HIPAA Privacy & Security
•Smoke detectors and fire extinguishers
•Computer equipment
•Cyber security
•Emergency Action plan
Guidelines for environment:
Developing an
Action Plan
• All shapes and sizes
• Across-the-board compliance
• Document in advance
AUDIT PREPARATION
• Risk management plan
• Policies and procedures
• Business Associate agreements
• PHI inventory
• Mobile devices
• Documentation
• Compliance training records
• Evidence of encryption capabilities
Some of the areas the OCR audits will cover include:
AUDIT PREPARATION
Mitigating Risk
ONGOING TRAINING & CULTURE MAINTENANCE
• Patient-provider relationship
• Training on PHI safeguards
• Easy reference of Policies and
Procedures
• Addressing staff
• Re-assessing job functions
SECURITY
RISK
ANALYSIS
Options
Consultant
In-house
Online
_____________________________(-)(+)
What to Expect with HCSI
1. Membership Website Portal
2. Compliance Binders
3. Ongoing Support
Training
(New Employee & Retraining)
• HIPAA Privacy
• HIPAA Security
• OSHA
• Medicare
• Employment Law
Manuals
• Reference Guide
• Compliance Plans
• Certificate Binder
Consultation and Support
• Weekly and Monthly Updates
• Quarterly Newsletter
• Phone and E-mail Support
• Quarterly Assessment
Customizable Forms
• Notice of Privacy Practices
• Business Associate Agreement
• All HIPAA Privacy
• All HIPAA Security
• Gap/Risk Analysis
• HIPAA HITECH Breach Notification
• All OSHA
• All Medicare
• Employment Law
• RAC
• Posters
“Our HIPAA/OSHA compliance was a huge concern in our office, especially
after one of our employees filed a complaint with OSHA.
We started using HCSI 4 years ago and couldn't be happier with the program.
It's simple to set up and easier to use.
Do yourself a favor and sign up, it will make your life easier!”
-Dr. Kody Krause, DDS
Comfort Dental Thompson Valley, CO
Customer Testimonial
“HCSI kept my fanny out of the hoosekow with a cranky (bit
weirdo/psycho) patient who thought we had been naughty in multiple
ways.
Our association with you all made the difference. We passed the
inspection with flying colors and OCR told the "patient" to bug
off!! Loved It!”
-Lee Mecham Thrall, Clinic Administrator
Old Farm Obstetrics & Gynecology, L.L.C
Customer Testimonial
30 Day Money Back Guarantee!
Price Breakdown
• Compliance Officer Training ($250)
• Employee Training ($500)
• Risk Analysis ($250)
• Customized Compliance Plans ($1250)
• Customizable Forms ($100)
• Posters ($100)
• Compliance Updates: E-mail & Newsletters ($50)
• Phone & E-mail Support ($500)
$3500 Value
HCSIINC.COM
Early Bird Discount: $200 OFF
Compliance Officer Training
“Compliance Officer”
Customized Policies & Procedures
Quarterly Assessment Support Calls
Lance King
Vice President, Sales
Healthcare Compliance Solutions
Phone (801) 947-0183
lking@hcsiinc.com
Leading Your HIPAA
Culture in 2016

More Related Content

What's hot (20)

UNA HIPAA Training 8-13
UNA HIPAA Training   8-13UNA HIPAA Training   8-13
UNA HIPAA Training 8-13
 
Hipaa training
Hipaa trainingHipaa training
Hipaa training
 
HIPAA Audio Presentation
HIPAA  Audio PresentationHIPAA  Audio Presentation
HIPAA Audio Presentation
 
Hippa privacy and security awareness
Hippa privacy and security awarenessHippa privacy and security awareness
Hippa privacy and security awareness
 
Presentation hippa
Presentation hippaPresentation hippa
Presentation hippa
 
HIPAA
HIPAAHIPAA
HIPAA
 
HIPAA Complaince
HIPAA ComplainceHIPAA Complaince
HIPAA Complaince
 
Hippa
HippaHippa
Hippa
 
Hipaa slideshow
Hipaa slideshowHipaa slideshow
Hipaa slideshow
 
Personal Health Records & HIPAA
Personal Health Records & HIPAAPersonal Health Records & HIPAA
Personal Health Records & HIPAA
 
Hippa laws
Hippa lawsHippa laws
Hippa laws
 
HIPAA HITECH training 7-9-12
HIPAA HITECH training 7-9-12HIPAA HITECH training 7-9-12
HIPAA HITECH training 7-9-12
 
HIPAA for Dummies
HIPAA for DummiesHIPAA for Dummies
HIPAA for Dummies
 
Welcome to the hippa, privacy and security
Welcome to the hippa, privacy and securityWelcome to the hippa, privacy and security
Welcome to the hippa, privacy and security
 
Hippa 2021
Hippa 2021Hippa 2021
Hippa 2021
 
2017 HIPAA Clinical Research Training
2017 HIPAA Clinical Research Training2017 HIPAA Clinical Research Training
2017 HIPAA Clinical Research Training
 
Mandatory hippa and information security
Mandatory hippa and information securityMandatory hippa and information security
Mandatory hippa and information security
 
Welcome to HIPAA Training
Welcome to HIPAA TrainingWelcome to HIPAA Training
Welcome to HIPAA Training
 
HIPAA Training - 2011
HIPAA Training - 2011HIPAA Training - 2011
HIPAA Training - 2011
 
Hippa training 2017
Hippa training 2017Hippa training 2017
Hippa training 2017
 

Viewers also liked

PSOW 2016 - HIPAA Compliance for EMS Community
PSOW 2016 - HIPAA Compliance for EMS CommunityPSOW 2016 - HIPAA Compliance for EMS Community
PSOW 2016 - HIPAA Compliance for EMS CommunityPSOW
 
HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...Compliancy Group
 
HIPAA compliance tuneup 2016
HIPAA compliance tuneup 2016HIPAA compliance tuneup 2016
HIPAA compliance tuneup 2016Compliancy Group
 
SAMPLE HIPAA Security Rule Corrective Action Plan Project Charter
SAMPLE HIPAA Security Rule Corrective Action Plan Project CharterSAMPLE HIPAA Security Rule Corrective Action Plan Project Charter
SAMPLE HIPAA Security Rule Corrective Action Plan Project CharterDavid Sweigert
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceJim Anfield
 
(SEC304) Architecting for HIPAA Compliance on AWS
(SEC304) Architecting for HIPAA Compliance on AWS(SEC304) Architecting for HIPAA Compliance on AWS
(SEC304) Architecting for HIPAA Compliance on AWSAmazon Web Services
 
Application Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA ComplianceApplication Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA ComplianceTrueVault
 
HIPAA Compliance Checklist
HIPAA Compliance ChecklistHIPAA Compliance Checklist
HIPAA Compliance ChecklistLeigh-Ann Renz
 
Sample Business Associate Agreement
Sample Business Associate AgreementSample Business Associate Agreement
Sample Business Associate AgreementJorge M. Abril, P.A.
 
Tools for Financing Brownfields - Corrective Action Plan
Tools for Financing Brownfields - Corrective Action PlanTools for Financing Brownfields - Corrective Action Plan
Tools for Financing Brownfields - Corrective Action PlanDouglass Selby
 
Protecting PHI with encryption for HIPAA compliance
Protecting PHI with encryption for HIPAA complianceProtecting PHI with encryption for HIPAA compliance
Protecting PHI with encryption for HIPAA complianceTodd Merrill
 
A project approach to HIPAA
A project approach to HIPAAA project approach to HIPAA
A project approach to HIPAADaniel P Wallace
 
HIPAA HiTech Security Assessment
HIPAA HiTech Security AssessmentHIPAA HiTech Security Assessment
HIPAA HiTech Security Assessmentdata brackets
 
HIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceHIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceJay Hodes
 
HIPAA & HITECH Made Easy for Behavioral Health Professionals -- Marlene Maheu
HIPAA & HITECH Made Easy for Behavioral Health Professionals -- Marlene MaheuHIPAA & HITECH Made Easy for Behavioral Health Professionals -- Marlene Maheu
HIPAA & HITECH Made Easy for Behavioral Health Professionals -- Marlene MaheuMarlene Maheu
 
OFFENSIVE: Exploiting DNS servers changes BlackHat Asia 2014
OFFENSIVE: Exploiting DNS servers changes BlackHat Asia 2014OFFENSIVE: Exploiting DNS servers changes BlackHat Asia 2014
OFFENSIVE: Exploiting DNS servers changes BlackHat Asia 2014Leonardo Nve Egea
 
Offensive Security with Metasploit
Offensive Security with MetasploitOffensive Security with Metasploit
Offensive Security with Metasploitegypt
 
HIPAA Compliance for Developers
HIPAA Compliance for DevelopersHIPAA Compliance for Developers
HIPAA Compliance for DevelopersTrueVault
 

Viewers also liked (20)

PSOW 2016 - HIPAA Compliance for EMS Community
PSOW 2016 - HIPAA Compliance for EMS CommunityPSOW 2016 - HIPAA Compliance for EMS Community
PSOW 2016 - HIPAA Compliance for EMS Community
 
HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...
 
HIPAA compliance tuneup 2016
HIPAA compliance tuneup 2016HIPAA compliance tuneup 2016
HIPAA compliance tuneup 2016
 
SAMPLE HIPAA Security Rule Corrective Action Plan Project Charter
SAMPLE HIPAA Security Rule Corrective Action Plan Project CharterSAMPLE HIPAA Security Rule Corrective Action Plan Project Charter
SAMPLE HIPAA Security Rule Corrective Action Plan Project Charter
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA Compliance
 
(SEC304) Architecting for HIPAA Compliance on AWS
(SEC304) Architecting for HIPAA Compliance on AWS(SEC304) Architecting for HIPAA Compliance on AWS
(SEC304) Architecting for HIPAA Compliance on AWS
 
Application Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA ComplianceApplication Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA Compliance
 
HIPAA Compliance Checklist for Medical Practices
HIPAA Compliance Checklist for Medical PracticesHIPAA Compliance Checklist for Medical Practices
HIPAA Compliance Checklist for Medical Practices
 
2010 New Guidelines Hipaa Checklist V1
2010 New Guidelines Hipaa Checklist V12010 New Guidelines Hipaa Checklist V1
2010 New Guidelines Hipaa Checklist V1
 
HIPAA Compliance Checklist
HIPAA Compliance ChecklistHIPAA Compliance Checklist
HIPAA Compliance Checklist
 
Sample Business Associate Agreement
Sample Business Associate AgreementSample Business Associate Agreement
Sample Business Associate Agreement
 
Tools for Financing Brownfields - Corrective Action Plan
Tools for Financing Brownfields - Corrective Action PlanTools for Financing Brownfields - Corrective Action Plan
Tools for Financing Brownfields - Corrective Action Plan
 
Protecting PHI with encryption for HIPAA compliance
Protecting PHI with encryption for HIPAA complianceProtecting PHI with encryption for HIPAA compliance
Protecting PHI with encryption for HIPAA compliance
 
A project approach to HIPAA
A project approach to HIPAAA project approach to HIPAA
A project approach to HIPAA
 
HIPAA HiTech Security Assessment
HIPAA HiTech Security AssessmentHIPAA HiTech Security Assessment
HIPAA HiTech Security Assessment
 
HIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceHIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of Compliance
 
HIPAA & HITECH Made Easy for Behavioral Health Professionals -- Marlene Maheu
HIPAA & HITECH Made Easy for Behavioral Health Professionals -- Marlene MaheuHIPAA & HITECH Made Easy for Behavioral Health Professionals -- Marlene Maheu
HIPAA & HITECH Made Easy for Behavioral Health Professionals -- Marlene Maheu
 
OFFENSIVE: Exploiting DNS servers changes BlackHat Asia 2014
OFFENSIVE: Exploiting DNS servers changes BlackHat Asia 2014OFFENSIVE: Exploiting DNS servers changes BlackHat Asia 2014
OFFENSIVE: Exploiting DNS servers changes BlackHat Asia 2014
 
Offensive Security with Metasploit
Offensive Security with MetasploitOffensive Security with Metasploit
Offensive Security with Metasploit
 
HIPAA Compliance for Developers
HIPAA Compliance for DevelopersHIPAA Compliance for Developers
HIPAA Compliance for Developers
 

Similar to Leading your HIPAA Compliance Culture in 2016

HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...Skoda Minotti
 
Week1discussioncapstone
Week1discussioncapstoneWeek1discussioncapstone
Week1discussioncapstonebradbury234
 
Confidentiality in the healthcare system
Confidentiality in the healthcare systemConfidentiality in the healthcare system
Confidentiality in the healthcare systempfor2012
 
Achieving HIPAA Compliance: The Roadmap to Certification Success
Achieving HIPAA Compliance: The Roadmap to Certification SuccessAchieving HIPAA Compliance: The Roadmap to Certification Success
Achieving HIPAA Compliance: The Roadmap to Certification SuccessShyamMishra72
 
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...Polsinelli PC
 
Implementing Ethics in the Workplace: Creating the Process ppt
Implementing Ethics in the Workplace: Creating the Process pptImplementing Ethics in the Workplace: Creating the Process ppt
Implementing Ethics in the Workplace: Creating the Process pptOsama Yousaf
 
Privacy Compliance
Privacy CompliancePrivacy Compliance
Privacy Compliancemghuff
 
5 Documents to Prepare for a HIPAA Audit
5 Documents to Prepare for a HIPAA Audit5 Documents to Prepare for a HIPAA Audit
5 Documents to Prepare for a HIPAA AuditSecurityMetrics
 
Texting and e mail with patients 2020
Texting and e mail with patients 2020Texting and e mail with patients 2020
Texting and e mail with patients 2020RobertAByrdr
 
3 Steps to Automate Compliance for Healthcare Organizations
3 Steps to Automate Compliance for Healthcare Organizations3 Steps to Automate Compliance for Healthcare Organizations
3 Steps to Automate Compliance for Healthcare OrganizationsAvePoint
 
Importance of HIPAA Compliance for Small Healthcare Clinics.pptx
Importance of HIPAA Compliance for Small Healthcare Clinics.pptxImportance of HIPAA Compliance for Small Healthcare Clinics.pptx
Importance of HIPAA Compliance for Small Healthcare Clinics.pptxIT in DFW
 
Mha 690 week 1 discussion presentation
Mha 690 week 1 discussion presentationMha 690 week 1 discussion presentation
Mha 690 week 1 discussion presentationfalane
 
Navigating Healthcare Compliance: A Guide to HIPAA Certification
Navigating Healthcare Compliance: A Guide to HIPAA CertificationNavigating Healthcare Compliance: A Guide to HIPAA Certification
Navigating Healthcare Compliance: A Guide to HIPAA CertificationShyamMishra72
 
Simple Steps to HIPAA Compliance
Simple Steps to HIPAA ComplianceSimple Steps to HIPAA Compliance
Simple Steps to HIPAA ComplianceAtMyDeskTraining
 
HIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An OverviewHIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An OverviewClearDATACloud
 
Complying with HIPAA Security Rule
Complying with HIPAA Security RuleComplying with HIPAA Security Rule
Complying with HIPAA Security Rulecomplianceonline123
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Traininghimalya sharma
 
Health Information Technology_272_Presentation_CookDaryle.docx.
Health Information Technology_272_Presentation_CookDaryle.docx.Health Information Technology_272_Presentation_CookDaryle.docx.
Health Information Technology_272_Presentation_CookDaryle.docx.Daryle Cook
 
Mbm Hipaa Hitech Ss Compliance Risk Assessment
Mbm Hipaa Hitech Ss Compliance Risk AssessmentMbm Hipaa Hitech Ss Compliance Risk Assessment
Mbm Hipaa Hitech Ss Compliance Risk AssessmentMBMeHealthCareSolutions
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Traininghimalya sharma
 

Similar to Leading your HIPAA Compliance Culture in 2016 (20)

HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
 
Week1discussioncapstone
Week1discussioncapstoneWeek1discussioncapstone
Week1discussioncapstone
 
Confidentiality in the healthcare system
Confidentiality in the healthcare systemConfidentiality in the healthcare system
Confidentiality in the healthcare system
 
Achieving HIPAA Compliance: The Roadmap to Certification Success
Achieving HIPAA Compliance: The Roadmap to Certification SuccessAchieving HIPAA Compliance: The Roadmap to Certification Success
Achieving HIPAA Compliance: The Roadmap to Certification Success
 
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
HIPAA Audits Are Here to Stay – Key Preparation Strategies for Business Assoc...
 
Implementing Ethics in the Workplace: Creating the Process ppt
Implementing Ethics in the Workplace: Creating the Process pptImplementing Ethics in the Workplace: Creating the Process ppt
Implementing Ethics in the Workplace: Creating the Process ppt
 
Privacy Compliance
Privacy CompliancePrivacy Compliance
Privacy Compliance
 
5 Documents to Prepare for a HIPAA Audit
5 Documents to Prepare for a HIPAA Audit5 Documents to Prepare for a HIPAA Audit
5 Documents to Prepare for a HIPAA Audit
 
Texting and e mail with patients 2020
Texting and e mail with patients 2020Texting and e mail with patients 2020
Texting and e mail with patients 2020
 
3 Steps to Automate Compliance for Healthcare Organizations
3 Steps to Automate Compliance for Healthcare Organizations3 Steps to Automate Compliance for Healthcare Organizations
3 Steps to Automate Compliance for Healthcare Organizations
 
Importance of HIPAA Compliance for Small Healthcare Clinics.pptx
Importance of HIPAA Compliance for Small Healthcare Clinics.pptxImportance of HIPAA Compliance for Small Healthcare Clinics.pptx
Importance of HIPAA Compliance for Small Healthcare Clinics.pptx
 
Mha 690 week 1 discussion presentation
Mha 690 week 1 discussion presentationMha 690 week 1 discussion presentation
Mha 690 week 1 discussion presentation
 
Navigating Healthcare Compliance: A Guide to HIPAA Certification
Navigating Healthcare Compliance: A Guide to HIPAA CertificationNavigating Healthcare Compliance: A Guide to HIPAA Certification
Navigating Healthcare Compliance: A Guide to HIPAA Certification
 
Simple Steps to HIPAA Compliance
Simple Steps to HIPAA ComplianceSimple Steps to HIPAA Compliance
Simple Steps to HIPAA Compliance
 
HIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An OverviewHIPAA Compliant Cloud Computing, An Overview
HIPAA Compliant Cloud Computing, An Overview
 
Complying with HIPAA Security Rule
Complying with HIPAA Security RuleComplying with HIPAA Security Rule
Complying with HIPAA Security Rule
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Training
 
Health Information Technology_272_Presentation_CookDaryle.docx.
Health Information Technology_272_Presentation_CookDaryle.docx.Health Information Technology_272_Presentation_CookDaryle.docx.
Health Information Technology_272_Presentation_CookDaryle.docx.
 
Mbm Hipaa Hitech Ss Compliance Risk Assessment
Mbm Hipaa Hitech Ss Compliance Risk AssessmentMbm Hipaa Hitech Ss Compliance Risk Assessment
Mbm Hipaa Hitech Ss Compliance Risk Assessment
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Training
 

Recently uploaded

Text Neck Syndrome and its probable way out.pptx
Text Neck Syndrome and its probable way out.pptxText Neck Syndrome and its probable way out.pptx
Text Neck Syndrome and its probable way out.pptxProf. Satyen Bhattacharyya
 
2024 Compliatric Webinar Series - OSV Overview and Panel Discussion April 202...
2024 Compliatric Webinar Series - OSV Overview and Panel Discussion April 202...2024 Compliatric Webinar Series - OSV Overview and Panel Discussion April 202...
2024 Compliatric Webinar Series - OSV Overview and Panel Discussion April 202...Compliatric Where Compliance Happens
 
What are weight loss medication services?
What are weight loss medication services?What are weight loss medication services?
What are weight loss medication services?Optimal Healing 4u
 
Sustainable Living Practices For Better Health.pptx
Sustainable Living Practices For Better Health.pptxSustainable Living Practices For Better Health.pptx
Sustainable Living Practices For Better Health.pptxHealth 2Conf
 
Your Radiotherapy Destination Gokuldas Hospital.
Your Radiotherapy Destination Gokuldas Hospital.Your Radiotherapy Destination Gokuldas Hospital.
Your Radiotherapy Destination Gokuldas Hospital.Gokuldas Hospital
 
Latest Dr Ranjit Jagtap News In Healthcare Field
Latest Dr Ranjit Jagtap News In Healthcare  FieldLatest Dr Ranjit Jagtap News In Healthcare  Field
Latest Dr Ranjit Jagtap News In Healthcare FieldDr Ranjit Jagtap
 
Enhancing Health Through Personalized Nutrition
Enhancing Health Through Personalized NutritionEnhancing Health Through Personalized Nutrition
Enhancing Health Through Personalized NutritionNeighborhood Trainer
 
Discover the Art Deco Style at Spa Dental
Discover the Art Deco Style at Spa DentalDiscover the Art Deco Style at Spa Dental
Discover the Art Deco Style at Spa DentalA-dec Australia
 
Staying Safe in Hospitals: Fire Safety Guidelines for Hospitals in India
Staying Safe in Hospitals: Fire Safety Guidelines for Hospitals in IndiaStaying Safe in Hospitals: Fire Safety Guidelines for Hospitals in India
Staying Safe in Hospitals: Fire Safety Guidelines for Hospitals in IndiaBasic Elements
 
Presentation for Alzheimers Disease.pptx
Presentation for Alzheimers Disease.pptxPresentation for Alzheimers Disease.pptx
Presentation for Alzheimers Disease.pptxravisutar1
 
Field exchange, Issue 72 April 2024 FEX-72.pdf
Field exchange, Issue 72 April 2024 FEX-72.pdfField exchange, Issue 72 April 2024 FEX-72.pdf
Field exchange, Issue 72 April 2024 FEX-72.pdfMohamed Miyir
 
Incentive spirometry powerpoint presentation
Incentive spirometry powerpoint presentationIncentive spirometry powerpoint presentation
Incentive spirometry powerpoint presentationpratiksha ghimire
 
ANTIGEN- SECTION IMMUNOLOGY DEPARTMENT OF MICROBIOLOGY
ANTIGEN- SECTION IMMUNOLOGY  DEPARTMENT OF MICROBIOLOGYANTIGEN- SECTION IMMUNOLOGY  DEPARTMENT OF MICROBIOLOGY
ANTIGEN- SECTION IMMUNOLOGY DEPARTMENT OF MICROBIOLOGYDrmayuribhise
 
Lipid Profile test & Cardiac Markers for MBBS, Lab. Med. and Nursing.pptx
Lipid Profile test & Cardiac Markers for MBBS, Lab. Med. and Nursing.pptxLipid Profile test & Cardiac Markers for MBBS, Lab. Med. and Nursing.pptx
Lipid Profile test & Cardiac Markers for MBBS, Lab. Med. and Nursing.pptxRajendra Dev Bhatt
 
Champions of Health Spotlight On Leaders Shaping Denmark's Healthcare.pdf
Champions of Health Spotlight On Leaders Shaping Denmark's Healthcare.pdfChampions of Health Spotlight On Leaders Shaping Denmark's Healthcare.pdf
Champions of Health Spotlight On Leaders Shaping Denmark's Healthcare.pdfeurohealthleaders
 
Mental Health for physiotherapy and other health students
Mental Health for physiotherapy and other health studentsMental Health for physiotherapy and other health students
Mental Health for physiotherapy and other health studentseyobkaseye
 
Information about acne, detail description of their treatment by topical and ...
Information about acne, detail description of their treatment by topical and ...Information about acne, detail description of their treatment by topical and ...
Information about acne, detail description of their treatment by topical and ...mauryashreya478
 
Local Advanced Esophageal Cancer (T3-4N0-2M0): Artificial Intelligence, Syner...
Local Advanced Esophageal Cancer (T3-4N0-2M0): Artificial Intelligence, Syner...Local Advanced Esophageal Cancer (T3-4N0-2M0): Artificial Intelligence, Syner...
Local Advanced Esophageal Cancer (T3-4N0-2M0): Artificial Intelligence, Syner...Oleg Kshivets
 

Recently uploaded (20)

Text Neck Syndrome and its probable way out.pptx
Text Neck Syndrome and its probable way out.pptxText Neck Syndrome and its probable way out.pptx
Text Neck Syndrome and its probable way out.pptx
 
2024 Compliatric Webinar Series - OSV Overview and Panel Discussion April 202...
2024 Compliatric Webinar Series - OSV Overview and Panel Discussion April 202...2024 Compliatric Webinar Series - OSV Overview and Panel Discussion April 202...
2024 Compliatric Webinar Series - OSV Overview and Panel Discussion April 202...
 
What are weight loss medication services?
What are weight loss medication services?What are weight loss medication services?
What are weight loss medication services?
 
Sustainable Living Practices For Better Health.pptx
Sustainable Living Practices For Better Health.pptxSustainable Living Practices For Better Health.pptx
Sustainable Living Practices For Better Health.pptx
 
Your Radiotherapy Destination Gokuldas Hospital.
Your Radiotherapy Destination Gokuldas Hospital.Your Radiotherapy Destination Gokuldas Hospital.
Your Radiotherapy Destination Gokuldas Hospital.
 
Latest Dr Ranjit Jagtap News In Healthcare Field
Latest Dr Ranjit Jagtap News In Healthcare  FieldLatest Dr Ranjit Jagtap News In Healthcare  Field
Latest Dr Ranjit Jagtap News In Healthcare Field
 
Enhancing Health Through Personalized Nutrition
Enhancing Health Through Personalized NutritionEnhancing Health Through Personalized Nutrition
Enhancing Health Through Personalized Nutrition
 
Discover the Art Deco Style at Spa Dental
Discover the Art Deco Style at Spa DentalDiscover the Art Deco Style at Spa Dental
Discover the Art Deco Style at Spa Dental
 
Coping with Childhood Cancer - How Does it Hurt Today
Coping with Childhood Cancer - How Does it Hurt TodayCoping with Childhood Cancer - How Does it Hurt Today
Coping with Childhood Cancer - How Does it Hurt Today
 
Staying Safe in Hospitals: Fire Safety Guidelines for Hospitals in India
Staying Safe in Hospitals: Fire Safety Guidelines for Hospitals in IndiaStaying Safe in Hospitals: Fire Safety Guidelines for Hospitals in India
Staying Safe in Hospitals: Fire Safety Guidelines for Hospitals in India
 
Presentation for Alzheimers Disease.pptx
Presentation for Alzheimers Disease.pptxPresentation for Alzheimers Disease.pptx
Presentation for Alzheimers Disease.pptx
 
Field exchange, Issue 72 April 2024 FEX-72.pdf
Field exchange, Issue 72 April 2024 FEX-72.pdfField exchange, Issue 72 April 2024 FEX-72.pdf
Field exchange, Issue 72 April 2024 FEX-72.pdf
 
Incentive spirometry powerpoint presentation
Incentive spirometry powerpoint presentationIncentive spirometry powerpoint presentation
Incentive spirometry powerpoint presentation
 
Top Ajman Spa Jameela Spa massage center Ajman
Top Ajman Spa Jameela Spa massage center AjmanTop Ajman Spa Jameela Spa massage center Ajman
Top Ajman Spa Jameela Spa massage center Ajman
 
ANTIGEN- SECTION IMMUNOLOGY DEPARTMENT OF MICROBIOLOGY
ANTIGEN- SECTION IMMUNOLOGY  DEPARTMENT OF MICROBIOLOGYANTIGEN- SECTION IMMUNOLOGY  DEPARTMENT OF MICROBIOLOGY
ANTIGEN- SECTION IMMUNOLOGY DEPARTMENT OF MICROBIOLOGY
 
Lipid Profile test & Cardiac Markers for MBBS, Lab. Med. and Nursing.pptx
Lipid Profile test & Cardiac Markers for MBBS, Lab. Med. and Nursing.pptxLipid Profile test & Cardiac Markers for MBBS, Lab. Med. and Nursing.pptx
Lipid Profile test & Cardiac Markers for MBBS, Lab. Med. and Nursing.pptx
 
Champions of Health Spotlight On Leaders Shaping Denmark's Healthcare.pdf
Champions of Health Spotlight On Leaders Shaping Denmark's Healthcare.pdfChampions of Health Spotlight On Leaders Shaping Denmark's Healthcare.pdf
Champions of Health Spotlight On Leaders Shaping Denmark's Healthcare.pdf
 
Mental Health for physiotherapy and other health students
Mental Health for physiotherapy and other health studentsMental Health for physiotherapy and other health students
Mental Health for physiotherapy and other health students
 
Information about acne, detail description of their treatment by topical and ...
Information about acne, detail description of their treatment by topical and ...Information about acne, detail description of their treatment by topical and ...
Information about acne, detail description of their treatment by topical and ...
 
Local Advanced Esophageal Cancer (T3-4N0-2M0): Artificial Intelligence, Syner...
Local Advanced Esophageal Cancer (T3-4N0-2M0): Artificial Intelligence, Syner...Local Advanced Esophageal Cancer (T3-4N0-2M0): Artificial Intelligence, Syner...
Local Advanced Esophageal Cancer (T3-4N0-2M0): Artificial Intelligence, Syner...
 

Leading your HIPAA Compliance Culture in 2016

  • 2. Finished files are the re- sult of years of scientif- ic study combined with the experience of many years.
  • 3.
  • 4. Lance King Vice President, Sales Healthcare Compliance Solutions Phone (801) 947-0183 lking@hcsiinc.com
  • 5.
  • 6. What to expect Lead Your Culture, Select Your Team, and Learn ✓ Create a Culture of Privacy, Security, and Safety ✓ HIPAA Breach – Identifying a Breach, Exceptions to a Breach ✓ HIPAA Protections – Security Risk Analysis, Social Media ✓ Compliance Training Document Your Process, Your Findings, and Actions ✓ Documentation ✓ Policies and Procedures ✓ HIPAA Privacy & Security Develop an Action Plan ✓ Audit Preparation Mitigating Risk ✓ Ongoing Training & Culture Maintenance
  • 9. Healthcare Compliance (HIPAA, OSHA…) Insurance HR Accounting Front Desk Patient Care Staff Training
  • 10.
  • 11.
  • 12. PHI
  • 13. Day 1 Day 10 Day 30/90 Dependent on Completion of Fieldwork AUDIT TIMELINE
  • 14. 5 COMMON CIRCUMSTANCES FOR AN AUDIT 1. Disgruntled ex-employee 2. A self-reported breach 3. Employee activists 4. Patient’s fear of breach 5. Random OCR visit
  • 18. CREATE A CULTURE OF PRIVACY & SECURITY • Communicate • Guide • Remind
  • 19. IDENTIFYING A BREACH 1. Nature and extent of the PHI involved 2. The unauthorized person who used the PHI, or to whom it was disclosed 3. Whether the PHI was actually viewed or acquired 4. The extent to which the risk to protect the PHI has been mitigated “…unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment of at least the following factors”:
  • 20. HIPAA BREACH • Does your staff know who to go to for leadership when there is a HIPAA breach? • Does your designated HIPAA compliance officer know all of the necessary steps to take in breach notification? • Does your HIPAA compliance officer know where to receive guidance?
  • 21. EXCEPTIONS TO A BREACH 1.Unintentional 2.Inadvertent 3.Good faith 3 Exceptions to the definition of “breach”
  • 22. HIPAA PROTECTIONS • Ensure privacy • Give patients more access • Establish safeguards • Hold violators accountable • Strike a balance • Enable patients • Limit release of information • Give patients the right to examine and obtain a copy • Empower individuals to control certain uses and disclosures Key Components of the HIPAA Privacy Rule:
  • 23. HIPAA RISK PROTECTIONS • Physical, Technical, and Administrative measures • Internal and External Security threats • Assessment of and preparations for security risks
  • 24. 7 STEPS TO HIPAA COMPLIANCE 1. Understand the rules 2. Assign Responsibility 3. List your PHI systems 4. Conduct a Risk Analysis 5. Implement Policies and Procedures 6. Training program 7. Ongoing HIPAA progress and compliance
  • 25. SECURITY RISK • Identify where PHI exists • Identify potential threats and vulnerabilities to PHI • Identify risks and their associated levels of high, medium, or low
  • 26. • Educate staff about process • Make security a high priority • Have an action plan • Involve your EHR developer • Specific to your practice TIPS FOR A BETTER SECURITY RISK ANALYSIS
  • 27. 10 HIPAA SECURITY TIPS 1. Have A Written Security Policy 2. Encrypt Everything 3. Protect Your Website 4. Data Backups 5. Avoid Consumer Grade 6. Know Your Risks 7. Plan For BYOD 8. Who Is Guarding The Sheep 9. Physical Security Is Information Security 10. Know When To Call For Help
  • 28. SECURITY RISK PRECAUTIONS • Staff requests • Hard drives • Email • Server • Passwords • Monitoring office staff • Fire extinguishers • Viruses and malware Low-Cost Highly Effective Safeguards:
  • 29. SOCIAL MEDIA • Access Controls • Personal • Connecting with patients • Patient waiver forms • Training To ensure your office remains in HIPAA compliance, create policies such as:
  • 31. WORKFORCE EDUCATION & TRAINING • Hired or contracted • Yearly retraining • Changes in policies or procedures • Changes in systems, location, or infrastructure • Responding to breach or disclosure Educate and train your staff:
  • 33. DOCUMENTATION • Policies and procedures • Security Risk Analysis • Training materials, and certificates of completion • Current Business Associate Agreements • EHR audit logs • Risk management action plan • Security incident and breach information Examples of records to retain:
  • 34. POLICIES AND PROCEDURES • Establish protocols • Training program • Instruct your workforce • Sanction policy for violations • Detail enforcement • Business Associates
  • 35. Employee HIPAA Privacy & Security • Name/ID badges • Quiet Communication • PHI access Guidelines for employees:
  • 36. Workstation HIPAA Privacy & Security • Viewing PHI Documents • Disposing of PHI • Workstations • Protect user ID’s and passwords • Computers not in use Guidelines for workstations:
  • 37. Access HIPAA Privacy & Security •Computer room access •PHI Back-ups •Limited office equipment •Unoccupied Office equipment Guidelines for access:
  • 38. Environmental HIPAA Privacy & Security •Smoke detectors and fire extinguishers •Computer equipment •Cyber security •Emergency Action plan Guidelines for environment:
  • 40. • All shapes and sizes • Across-the-board compliance • Document in advance AUDIT PREPARATION
  • 41. • Risk management plan • Policies and procedures • Business Associate agreements • PHI inventory • Mobile devices • Documentation • Compliance training records • Evidence of encryption capabilities Some of the areas the OCR audits will cover include: AUDIT PREPARATION
  • 43. ONGOING TRAINING & CULTURE MAINTENANCE • Patient-provider relationship • Training on PHI safeguards • Easy reference of Policies and Procedures • Addressing staff • Re-assessing job functions
  • 44.
  • 45.
  • 47.
  • 49. What to Expect with HCSI 1. Membership Website Portal 2. Compliance Binders 3. Ongoing Support
  • 50. Training (New Employee & Retraining) • HIPAA Privacy • HIPAA Security • OSHA • Medicare • Employment Law
  • 51. Manuals • Reference Guide • Compliance Plans • Certificate Binder
  • 52. Consultation and Support • Weekly and Monthly Updates • Quarterly Newsletter • Phone and E-mail Support • Quarterly Assessment
  • 53. Customizable Forms • Notice of Privacy Practices • Business Associate Agreement • All HIPAA Privacy • All HIPAA Security • Gap/Risk Analysis • HIPAA HITECH Breach Notification • All OSHA • All Medicare • Employment Law • RAC • Posters
  • 54. “Our HIPAA/OSHA compliance was a huge concern in our office, especially after one of our employees filed a complaint with OSHA. We started using HCSI 4 years ago and couldn't be happier with the program. It's simple to set up and easier to use. Do yourself a favor and sign up, it will make your life easier!” -Dr. Kody Krause, DDS Comfort Dental Thompson Valley, CO Customer Testimonial
  • 55. “HCSI kept my fanny out of the hoosekow with a cranky (bit weirdo/psycho) patient who thought we had been naughty in multiple ways. Our association with you all made the difference. We passed the inspection with flying colors and OCR told the "patient" to bug off!! Loved It!” -Lee Mecham Thrall, Clinic Administrator Old Farm Obstetrics & Gynecology, L.L.C Customer Testimonial
  • 56. 30 Day Money Back Guarantee!
  • 57. Price Breakdown • Compliance Officer Training ($250) • Employee Training ($500) • Risk Analysis ($250) • Customized Compliance Plans ($1250) • Customizable Forms ($100) • Posters ($100) • Compliance Updates: E-mail & Newsletters ($50) • Phone & E-mail Support ($500)
  • 61. Customized Policies & Procedures
  • 63. Lance King Vice President, Sales Healthcare Compliance Solutions Phone (801) 947-0183 lking@hcsiinc.com