SlideShare a Scribd company logo
1 of 6
Download to read offline
Can Your

Health IT
Service Provider
Ensure Security
For ePHI?

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809
Outsourcing your healthcare documentation, medical
coding and billing, and other back office tasks can help
save time and money and improve your productivity and
efficiency. However, as a physician, there’s one question
that you should ask yourself – is my health IT service
provider conscious about the safety of my data? Poor IT
security policies can land you in troublesome and costly
penalties for HIPAA (Health Insurance Portability and
Accountability

Act)

violations.

Even

a

well

known

institution like the Idaho State University was recently
penalized for a health information security breach. So
before

you

outsource

your

back

office

tasks,

it’s

important to ensure that your health IT service provider
has the following policies in place to ensure security of
electronic protected health information:

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809
Check whether the IT provider offers encryption for both active (in
use) and inactive (not in use) ePHI. Otherwise, the ePHIs are at risk

Encryption for ePHI

of security breaches and HIPAA violations. Suppose that your

medical billing

service

provider

accesses

your

ePHI

via

an

unencrypted network. There is a chance that someone can intrude
the network and access the information when it is being transferred.
The same applies to the ePHI stored in a computer, laptop or USB
drive. If the device is stolen, misplaced or lost, ePHI confidentiality
is at stake. In 2012, BlueCross BlueShield of Tennessee, a leading
Health Benefit Plan company in Tennessee paid around $1.5 million
to the Department of Health and Human Services (HHS) when 57
unencrypted computer hard drives containing the protected health
information of more than 1 million people was stolen.

Business Continuity &
Disaster Recovery Plans

The service provider that you select should have business
continuity and disaster recovery plans. Even though most service
providers plan how to handle an immediate service interruption,
testing usually doesn’t take place until an emergency occurs! This
is a bad practice. So ensure that your service provider has a
tested and proven disaster recovery plan system in place. This will
reduce wait time for updates – for you as well as your patients.

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809
Data breaches may occur if the patients’ health information is not

Proper Shredding of

disposed off safely and securely. For data stored electronically, the

ePHI

potential for unauthorized access, erasing, altering, or losing, is high.
Even if documents are deleted from the recycle bin, they are prone to
unauthorized access via hard disk recovery. When disposing of data
stored on computer disks, the disks need to be erased several times
and it should be ascertained that the data cannot be recovered from
them. The service provider should be able to recognize when, how and
in what circumstances the ePHIs were destroyed.

Identify Data Breaches
Most data breaches are difficult to detect. As per the Verizon
Data Breach Investigations Report 2013, around 66 percent of
data breaches would take even months or years to discover.
So you should ensure that your service provider has an
efficient system (anti-virus software, malware detection tools,
advanced analytic tools) to identify different types of data
breaches.

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809
Regular Risk

Make sure that your service provider performs risk assessments

Assessment

regularly to address changing threats and policies so that effective and
stringent security measures can be implemented. For example, the
HIPAA Omnibus Final Rule effective from March, 2013 considers even
the risk of data breach as a violation. Changes in technology can bring
about new risks. It’s important that your service provider stays up-todate with such changes and conducts regular risk adjustments to
detect and deal with security violation threats.

HIPAA Business Associate
Agreement

If your service provider is willing to sign a HIPAA business
associate agreement (BBA) with you, this is an indication of their
commitment to security for your ePHI. The contract ensures safety
for

personal

health

information

in

accordance

with

HIPAA

guidelines. The agreement should clearly show how your health IT
service provider will report and respond to any kind of data
breach. Also, make sure that the provider can produce evidence
for routine audits such as SSAE 16 reports or PCI certification.

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809
The bottom line: when you outsource your
documentation or medical coding or billing
tasks, look for a medical transcription company
or medical billing company that is HIPAA
complaint.

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809

More Related Content

More from Outsource Strategies International

ed Understanding the Challenges in Physical Therapy Medical Billing
ed Understanding the Challenges in Physical Therapy Medical Billinged Understanding the Challenges in Physical Therapy Medical Billing
ed Understanding the Challenges in Physical Therapy Medical BillingOutsource Strategies International
 
How Medical Billing Services Can Maximize Reimbursement and Minimize Denials
How Medical Billing Services Can Maximize Reimbursement and Minimize DenialsHow Medical Billing Services Can Maximize Reimbursement and Minimize Denials
How Medical Billing Services Can Maximize Reimbursement and Minimize DenialsOutsource Strategies International
 
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....Understanding the Significance of Outsourcing Medical Billing and Coding (3)....
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....Outsource Strategies International
 
Optimizing Medical Billing: Strategies to Prevent Claim Denials
Optimizing Medical Billing: Strategies to Prevent Claim DenialsOptimizing Medical Billing: Strategies to Prevent Claim Denials
Optimizing Medical Billing: Strategies to Prevent Claim DenialsOutsource Strategies International
 
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdf
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdfMedical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdf
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdfOutsource Strategies International
 
Medical Codes to Report Cystitis – A Common Bladder Infection
Medical Codes to Report Cystitis – A Common Bladder InfectionMedical Codes to Report Cystitis – A Common Bladder Infection
Medical Codes to Report Cystitis – A Common Bladder InfectionOutsource Strategies International
 

More from Outsource Strategies International (20)

Tips to Handle Prior Authorizations Effectively
Tips to Handle Prior Authorizations EffectivelyTips to Handle Prior Authorizations Effectively
Tips to Handle Prior Authorizations Effectively
 
Minimize Denials with Accurate & Compliant Coding
Minimize Denials with Accurate & Compliant CodingMinimize Denials with Accurate & Compliant Coding
Minimize Denials with Accurate & Compliant Coding
 
ed Understanding the Challenges in Physical Therapy Medical Billing
ed Understanding the Challenges in Physical Therapy Medical Billinged Understanding the Challenges in Physical Therapy Medical Billing
ed Understanding the Challenges in Physical Therapy Medical Billing
 
Tips to Ensure Accurate Health Insurance Verification
Tips to Ensure Accurate Health Insurance VerificationTips to Ensure Accurate Health Insurance Verification
Tips to Ensure Accurate Health Insurance Verification
 
How Medical Billing Services Can Maximize Reimbursement and Minimize Denials
How Medical Billing Services Can Maximize Reimbursement and Minimize DenialsHow Medical Billing Services Can Maximize Reimbursement and Minimize Denials
How Medical Billing Services Can Maximize Reimbursement and Minimize Denials
 
Best Practices for Medical Billing Documentation
Best Practices for Medical Billing DocumentationBest Practices for Medical Billing Documentation
Best Practices for Medical Billing Documentation
 
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....Understanding the Significance of Outsourcing Medical Billing and Coding (3)....
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....
 
Optimizing Medical Billing: Strategies to Prevent Claim Denials
Optimizing Medical Billing: Strategies to Prevent Claim DenialsOptimizing Medical Billing: Strategies to Prevent Claim Denials
Optimizing Medical Billing: Strategies to Prevent Claim Denials
 
Gastroparesis – Causes, Symptoms and ICD-10 Coding.pdf
Gastroparesis – Causes, Symptoms and ICD-10 Coding.pdfGastroparesis – Causes, Symptoms and ICD-10 Coding.pdf
Gastroparesis – Causes, Symptoms and ICD-10 Coding.pdf
 
Medical Codes to Report Epilepsy
Medical Codes to Report Epilepsy Medical Codes to Report Epilepsy
Medical Codes to Report Epilepsy
 
Common Medical Billing Mistakes and How to Avoid Them.pptx
Common Medical Billing Mistakes and How to Avoid Them.pptxCommon Medical Billing Mistakes and How to Avoid Them.pptx
Common Medical Billing Mistakes and How to Avoid Them.pptx
 
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdf
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdfMedical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdf
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdf
 
What are the ICD-10 Codes for Osteomalacia ed.pdf
What are the ICD-10 Codes for Osteomalacia ed.pdfWhat are the ICD-10 Codes for Osteomalacia ed.pdf
What are the ICD-10 Codes for Osteomalacia ed.pdf
 
ICD-10 Codes to Report Meningitis.pptx
ICD-10 Codes to Report Meningitis.pptxICD-10 Codes to Report Meningitis.pptx
ICD-10 Codes to Report Meningitis.pptx
 
Medical Codes to Report Cystitis – A Common Bladder Infection
Medical Codes to Report Cystitis – A Common Bladder InfectionMedical Codes to Report Cystitis – A Common Bladder Infection
Medical Codes to Report Cystitis – A Common Bladder Infection
 
ICD-10 Codes for Multiple sclerosis (MS)
ICD-10 Codes for Multiple sclerosis (MS)ICD-10 Codes for Multiple sclerosis (MS)
ICD-10 Codes for Multiple sclerosis (MS)
 
CDT Codes to Report Dental Bridges.pdf
CDT Codes to Report Dental Bridges.pdfCDT Codes to Report Dental Bridges.pdf
CDT Codes to Report Dental Bridges.pdf
 
Coding Pregnancy Related Rheumatic Conditions
Coding Pregnancy Related Rheumatic ConditionsCoding Pregnancy Related Rheumatic Conditions
Coding Pregnancy Related Rheumatic Conditions
 
Patient Eligibility Verification
Patient Eligibility VerificationPatient Eligibility Verification
Patient Eligibility Verification
 
A Review of Top 10 OSI Blog Posts of 2022.pptx
A Review of Top 10 OSI Blog Posts of 2022.pptxA Review of Top 10 OSI Blog Posts of 2022.pptx
A Review of Top 10 OSI Blog Posts of 2022.pptx
 

Recently uploaded

Chapter 2ppt Entrepreneurship freshman course.pptx
Chapter 2ppt Entrepreneurship freshman course.pptxChapter 2ppt Entrepreneurship freshman course.pptx
Chapter 2ppt Entrepreneurship freshman course.pptxtekalignpawulose09
 
Pitch Deck Teardown: Terra One's $7.5m Seed deck
Pitch Deck Teardown: Terra One's $7.5m Seed deckPitch Deck Teardown: Terra One's $7.5m Seed deck
Pitch Deck Teardown: Terra One's $7.5m Seed deckHajeJanKamps
 
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptxBlinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptxSaksham Gupta
 
Event Report - IBM Think 2024 - It is all about AI and hybrid
Event Report - IBM Think 2024 - It is all about AI and hybridEvent Report - IBM Think 2024 - It is all about AI and hybrid
Event Report - IBM Think 2024 - It is all about AI and hybridHolger Mueller
 
What is paper chromatography, principal, procedure,types, diagram, advantages...
What is paper chromatography, principal, procedure,types, diagram, advantages...What is paper chromatography, principal, procedure,types, diagram, advantages...
What is paper chromatography, principal, procedure,types, diagram, advantages...srcw2322l101
 
What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...AnaBeatriz125525
 
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot ReportFuture of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot ReportDubai Multi Commodity Centre
 
stock price prediction using machine learning
stock price prediction using machine learningstock price prediction using machine learning
stock price prediction using machine learninggauravwankar27
 
Special Purpose Vehicle (Purpose, Formation & examples)
Special Purpose Vehicle (Purpose, Formation & examples)Special Purpose Vehicle (Purpose, Formation & examples)
Special Purpose Vehicle (Purpose, Formation & examples)linciy03
 
Toyota Kata Coaching for Agile Teams & Transformations
Toyota Kata Coaching for Agile Teams & TransformationsToyota Kata Coaching for Agile Teams & Transformations
Toyota Kata Coaching for Agile Teams & TransformationsStefan Wolpers
 
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdfDaftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdfAgusHalim9
 
Elevate Your Online Presence with SEO Services
Elevate Your Online Presence with SEO ServicesElevate Your Online Presence with SEO Services
Elevate Your Online Presence with SEO ServicesHaseebBashir5
 
Stages of Startup Funding - An Explainer
Stages of Startup Funding - An ExplainerStages of Startup Funding - An Explainer
Stages of Startup Funding - An ExplainerAlejandro Cremades
 
Engagement Rings vs Promise Rings | Detailed Guide
Engagement Rings vs Promise Rings | Detailed GuideEngagement Rings vs Promise Rings | Detailed Guide
Engagement Rings vs Promise Rings | Detailed GuideCharleston Alexander
 
Series A Fundraising Guide (Investing Individuals Improving Our World) by Accion
Series A Fundraising Guide (Investing Individuals Improving Our World) by AccionSeries A Fundraising Guide (Investing Individuals Improving Our World) by Accion
Series A Fundraising Guide (Investing Individuals Improving Our World) by AccionAlejandro Cremades
 
A Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob BadgettA Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob BadgettJacobBadgett
 
بروفايل شركة ميار الخليج للاستشارات الهندسية.pdf
بروفايل شركة ميار الخليج للاستشارات الهندسية.pdfبروفايل شركة ميار الخليج للاستشارات الهندسية.pdf
بروفايل شركة ميار الخليج للاستشارات الهندسية.pdfomnme1
 
Copyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to KnowCopyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to KnowMiriam Robeson
 
NewBase 17 May 2024 Energy News issue - 1725 by Khaled Al Awadi_compresse...
NewBase   17 May  2024  Energy News issue - 1725 by Khaled Al Awadi_compresse...NewBase   17 May  2024  Energy News issue - 1725 by Khaled Al Awadi_compresse...
NewBase 17 May 2024 Energy News issue - 1725 by Khaled Al Awadi_compresse...Khaled Al Awadi
 
PitchBook’s Guide to VC Funding for Startups
PitchBook’s Guide to VC Funding for StartupsPitchBook’s Guide to VC Funding for Startups
PitchBook’s Guide to VC Funding for StartupsAlejandro Cremades
 

Recently uploaded (20)

Chapter 2ppt Entrepreneurship freshman course.pptx
Chapter 2ppt Entrepreneurship freshman course.pptxChapter 2ppt Entrepreneurship freshman course.pptx
Chapter 2ppt Entrepreneurship freshman course.pptx
 
Pitch Deck Teardown: Terra One's $7.5m Seed deck
Pitch Deck Teardown: Terra One's $7.5m Seed deckPitch Deck Teardown: Terra One's $7.5m Seed deck
Pitch Deck Teardown: Terra One's $7.5m Seed deck
 
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptxBlinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
 
Event Report - IBM Think 2024 - It is all about AI and hybrid
Event Report - IBM Think 2024 - It is all about AI and hybridEvent Report - IBM Think 2024 - It is all about AI and hybrid
Event Report - IBM Think 2024 - It is all about AI and hybrid
 
What is paper chromatography, principal, procedure,types, diagram, advantages...
What is paper chromatography, principal, procedure,types, diagram, advantages...What is paper chromatography, principal, procedure,types, diagram, advantages...
What is paper chromatography, principal, procedure,types, diagram, advantages...
 
What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...
 
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot ReportFuture of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
Future of Trade 2024 - Decoupled and Reconfigured - Snapshot Report
 
stock price prediction using machine learning
stock price prediction using machine learningstock price prediction using machine learning
stock price prediction using machine learning
 
Special Purpose Vehicle (Purpose, Formation & examples)
Special Purpose Vehicle (Purpose, Formation & examples)Special Purpose Vehicle (Purpose, Formation & examples)
Special Purpose Vehicle (Purpose, Formation & examples)
 
Toyota Kata Coaching for Agile Teams & Transformations
Toyota Kata Coaching for Agile Teams & TransformationsToyota Kata Coaching for Agile Teams & Transformations
Toyota Kata Coaching for Agile Teams & Transformations
 
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdfDaftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
Daftar Rumpun, Pohon, dan Cabang Ilmu (2024).pdf
 
Elevate Your Online Presence with SEO Services
Elevate Your Online Presence with SEO ServicesElevate Your Online Presence with SEO Services
Elevate Your Online Presence with SEO Services
 
Stages of Startup Funding - An Explainer
Stages of Startup Funding - An ExplainerStages of Startup Funding - An Explainer
Stages of Startup Funding - An Explainer
 
Engagement Rings vs Promise Rings | Detailed Guide
Engagement Rings vs Promise Rings | Detailed GuideEngagement Rings vs Promise Rings | Detailed Guide
Engagement Rings vs Promise Rings | Detailed Guide
 
Series A Fundraising Guide (Investing Individuals Improving Our World) by Accion
Series A Fundraising Guide (Investing Individuals Improving Our World) by AccionSeries A Fundraising Guide (Investing Individuals Improving Our World) by Accion
Series A Fundraising Guide (Investing Individuals Improving Our World) by Accion
 
A Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob BadgettA Brief Introduction About Jacob Badgett
A Brief Introduction About Jacob Badgett
 
بروفايل شركة ميار الخليج للاستشارات الهندسية.pdf
بروفايل شركة ميار الخليج للاستشارات الهندسية.pdfبروفايل شركة ميار الخليج للاستشارات الهندسية.pdf
بروفايل شركة ميار الخليج للاستشارات الهندسية.pdf
 
Copyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to KnowCopyright: What Creators and Users of Art Need to Know
Copyright: What Creators and Users of Art Need to Know
 
NewBase 17 May 2024 Energy News issue - 1725 by Khaled Al Awadi_compresse...
NewBase   17 May  2024  Energy News issue - 1725 by Khaled Al Awadi_compresse...NewBase   17 May  2024  Energy News issue - 1725 by Khaled Al Awadi_compresse...
NewBase 17 May 2024 Energy News issue - 1725 by Khaled Al Awadi_compresse...
 
PitchBook’s Guide to VC Funding for Startups
PitchBook’s Guide to VC Funding for StartupsPitchBook’s Guide to VC Funding for Startups
PitchBook’s Guide to VC Funding for Startups
 

Can Your Health IT Service Provider Ensure Security for ePHI?

  • 1. Can Your Health IT Service Provider Ensure Security For ePHI? Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809
  • 2. Outsourcing your healthcare documentation, medical coding and billing, and other back office tasks can help save time and money and improve your productivity and efficiency. However, as a physician, there’s one question that you should ask yourself – is my health IT service provider conscious about the safety of my data? Poor IT security policies can land you in troublesome and costly penalties for HIPAA (Health Insurance Portability and Accountability Act) violations. Even a well known institution like the Idaho State University was recently penalized for a health information security breach. So before you outsource your back office tasks, it’s important to ensure that your health IT service provider has the following policies in place to ensure security of electronic protected health information: Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809
  • 3. Check whether the IT provider offers encryption for both active (in use) and inactive (not in use) ePHI. Otherwise, the ePHIs are at risk Encryption for ePHI of security breaches and HIPAA violations. Suppose that your medical billing service provider accesses your ePHI via an unencrypted network. There is a chance that someone can intrude the network and access the information when it is being transferred. The same applies to the ePHI stored in a computer, laptop or USB drive. If the device is stolen, misplaced or lost, ePHI confidentiality is at stake. In 2012, BlueCross BlueShield of Tennessee, a leading Health Benefit Plan company in Tennessee paid around $1.5 million to the Department of Health and Human Services (HHS) when 57 unencrypted computer hard drives containing the protected health information of more than 1 million people was stolen. Business Continuity & Disaster Recovery Plans The service provider that you select should have business continuity and disaster recovery plans. Even though most service providers plan how to handle an immediate service interruption, testing usually doesn’t take place until an emergency occurs! This is a bad practice. So ensure that your service provider has a tested and proven disaster recovery plan system in place. This will reduce wait time for updates – for you as well as your patients. Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809
  • 4. Data breaches may occur if the patients’ health information is not Proper Shredding of disposed off safely and securely. For data stored electronically, the ePHI potential for unauthorized access, erasing, altering, or losing, is high. Even if documents are deleted from the recycle bin, they are prone to unauthorized access via hard disk recovery. When disposing of data stored on computer disks, the disks need to be erased several times and it should be ascertained that the data cannot be recovered from them. The service provider should be able to recognize when, how and in what circumstances the ePHIs were destroyed. Identify Data Breaches Most data breaches are difficult to detect. As per the Verizon Data Breach Investigations Report 2013, around 66 percent of data breaches would take even months or years to discover. So you should ensure that your service provider has an efficient system (anti-virus software, malware detection tools, advanced analytic tools) to identify different types of data breaches. Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809
  • 5. Regular Risk Make sure that your service provider performs risk assessments Assessment regularly to address changing threats and policies so that effective and stringent security measures can be implemented. For example, the HIPAA Omnibus Final Rule effective from March, 2013 considers even the risk of data breach as a violation. Changes in technology can bring about new risks. It’s important that your service provider stays up-todate with such changes and conducts regular risk adjustments to detect and deal with security violation threats. HIPAA Business Associate Agreement If your service provider is willing to sign a HIPAA business associate agreement (BBA) with you, this is an indication of their commitment to security for your ePHI. The contract ensures safety for personal health information in accordance with HIPAA guidelines. The agreement should clearly show how your health IT service provider will report and respond to any kind of data breach. Also, make sure that the provider can produce evidence for routine audits such as SSAE 16 reports or PCI certification. Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809
  • 6. The bottom line: when you outsource your documentation or medical coding or billing tasks, look for a medical transcription company or medical billing company that is HIPAA complaint. Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809