SlideShare a Scribd company logo
1 of 33
HIPAA Compliance:
What Medical Practices &
Their Business Associates
Need to Know
August 29, 2013
PRESENTER
Brian Rosenfelt, CPA
Skoda Minotti Risk Advisory Services
• Former controller, CFO and operations
executive in a variety of industries
• Served as business process engineer with
Kaiser Permanente
• Leads Skoda Minotti’s HIPAA consulting
practice
• Deep understanding of accounting,
technology and compliance
AGENDA
•
•
•
•
•
•
•

HIPAA History
Definitions
Major Provisions
2013 Omnibus Rules
Compliance and Enforcement
Risk Assessment
Policies & Procedures
WHAT IS HIPAA?
• HIPAA: Health Insurance Portability & Accountability Act
• Signed into law in 1996
• Federal law protecting the privacy of Protected Health Information
(PHI)
• The overall purpose is to ensure the security and privacy of
individual health information
HIPAA HITECH ACT OF 2009
Origins
• Prior to 2009, HIPAA regulations were not
being enforced consistently (if at all)
• New act was meant to:
 Strengthen controls and oversight of PHI
 Improve breach notification requirements
 Expand the definition of covered entities and business associates

• Built on the heels of providing incentives for doctors and hospitals
to implement Electronic Medical Record (EMR) systems
DEFINITIONS
• Protected Health Information (PHI)
• Covered Entity
• Business Associate
PROTECTED HEALTH
INFORMATION (PHI)
What is PHI?
• Oral or written information created by a healthcare provider or other
entity that relates to someone’s health or condition, healthcare
received, or healthcare payment
• Unsecured PHI is data that is not encrypted

Examples of PHI
•
•
•
•

Medical information and records
Billing information and records
Medical insurance forms
Lab results
COVERED ENTITY VS.
BUSINESS ASSOCIATE
Covered Entities
• Health Care Provider (dentist, doctor,
nursing home, pharmacy)
• Health Plan (HMO, company health
plan, health insurance companies)
• Health Care Clearinghouse
COVERED ENTITY VS.
BUSINESS ASSOCIATE
Business Associates
•
•
•
•

Attorneys
Accountants
Consultants
Third Party Administrator
(claims processing, etc.)
• Anyone who does, or could come into
contact with PHI
• Others
 Document shredding company
 Cleaning company
 Software company

Business associates
can be anyone with
access to or potential
access to health
information.
MAJOR PROVISIONS
•
•
•
•
•

Privacy Rule
Security Rule
Breach Notification Rule
Enforcement Rule
Unique Identifiers Rule
PRIVACY RULE
• Applies to use and disclosure of PHI
• Reason for HIPAA language and
forms you sign at your doctor’s office
• Requires patient authorization for
certain disclosures (release of
medical information to employer,
relative, etc.)
• Disclosure permitted for treatment
and/or payment purposes
SECURITY RULE
• Applies to the securing of ePHI
(electronic protected health
information)
• Requires implementation of three
types of safeguards:
 Administrative (policies and
procedures)
 Physical (access to server room,
access to patient paper records)
 Technical (email encryption, password
policies, technical auditing)
BREACH NOTIFICATION
RULE
• Risk of Harm evaluation (old rule)
• Risk Assessment and “Low
Probability” (new rule)
• What should the Risk Assessment
look for?





Type of PHI compromised
Who compromised the PHI
Was the PHI actually viewed
How was the breach/violation
mitigated
A LONG TIME COMING …
• Health Information Technology for
Economic and Clinical Health (HITECH)
Act was enacted on February 17, 2009
• Proposed Regulations: July 14, 2010
• Final “Omnibus” HIPAA Regulations:
January 25, 2013
 Effective Date: March 26, 2013
 Compliance Date: September 23, 2013

• Copy of final regulations:
http://1.usa.gov/Wl60lE
 138 pages
MAJOR CHANGES
WITH THE NEW RULES
Business Associate Liability Increased
• Business Associates are now covered DIRECTLY under HIPAA
(same rules and regulations as Covered Entities)
• Security and privacy rules now apply to Business Associates
• Information can only be used per contract language
• Penalties now apply to Business Associates
• Business Associates are now responsible for sub-Business Associates
BUSINESS ASSOCIATE
CHANGES
KEY CHANGES
DUE TO HIPAA HITECH
Breach Notification Rules
• Requires Covered Entities and
Business Associates to provide
notification following a breach of unsecured
PHI
• Similar breach notification rules for
vendors of personal health records and
their 3rd party service providers
• Covered Entities must notify affected individuals within 60
calendar days of the discovery
• If the breach effects more than 500 individuals, the media and
Department of Health and Human Services must be notified
• Business Associates are obligated to report breaches to
Covered Entity
KEY CHANGES
DUE TO HIPAA HITECH
Business Associate Responsibilities
• Must implement applicable privacy provisions
• Must implement all of the HITECH security
provisions
• Now subject to the same civil and criminal
penalties as Covered Entities
• Contracts between Covered Entities and
Business Associates must be amended to
include new HITECH provisions
HIPAA COMPLIANCE
& ENFORCEMENT
Original Rule
• U.S. Department of Health & Human Services regulates and
enforces HIPAA through its Office of Civil Rights (OCR)
• Civil penalties: Fines start at $100 and can increase up to $25,000
• Criminal penalties: Could include up to 10 years in prison and
$250,000

HIPAA HITECH ACT of 2009
• State Attorneys General can also bring
civil action in federal court if the
interest of residents has been threatened
or affected by a HIPAA violation
HIPAA COMPLIANCE
& ENFORCEMENT
Potential Civil Penalties
Violation Category
Section 1176(a)(1)

Each Violation

All such violations of an
identical provision in a
calendar year

$100-$50,000

Up to $1,500,000

(B) Reasonable cause

$1,000-$50,000

Up to $1,500,000

(C)(i) Willful neglect –
Corrected

$10,000-$50,000

Up to $1,500,000

(C)(ii) Willful neglect – Not
Corrected

$50,000 or more

Up to $1,500,000

(A) Did not know

SUMMARY: Fines are mandatory when failure to have training
and reasonable procedures on proper disposal is discovered.
HHS goes on to say that had they found proper training in the
same case, the same incident would not have been deemed a
case of willful neglect.
HIPAA COMPLIANCE
& ENFORCEMENT
Potential Criminal Penalties
Type of Violation

Potential Jail Sentence

Unknowingly, or with
reasonable cause

Up to one year

Under false pretenses

Up to five years

For personal gain or
malicious reasons

Up to ten years
HIPAA COMPLIANCE
& ENFORCEMENT
Consequences
• October 26, 2009: (Little Rock, Arkansas)
sentencing of three healthcare workers who
pled guilty to misdemeanor HIPAA violations
based on accessing patient records without any
reason
• April 27, 2010: (California) press release
entitled “Ex-UCLA Healthcare Employee
Sentenced to Federal Prison for Illegally
Peeking at Patient Records” – first person to be
convicted and imprisoned for HIPAA offenses
based only on unauthorized access of PHI
HIPAA COMPLIANCE
& ENFORCEMENT
Consequences
• January 9, 2012: Minnesota Attorney General
brought action against Accretive Health, Inc.
(a business associate, NOT a covered entity), in
the wake of the theft of a company laptop
computer that contained over 23,500 patient
records
• April 17, 2012: Phoenix Cardiac Surgery, P.C.
agreed to pay $100,000 and take corrective
action after they were found to have posted a
patient appointment calendar online
HOW TO GET COMPLIANT
Begin with a thorough
RISK ASSESSMENT
• Essential component of HIPAA compliance
• Can help your organization identify its most
critical areas of vulnerability
• The Risk Assessment will form the basis of
determining how risks should be managed
and/or minimized
• This is a necessary strategy to identify
potential gaps in your security environment
(physical and electronic)
• Required by HIPAA
HOW TO GET COMPLIANT
• Risk exposure decreases significantly when an
organization knows where its PHI is stored and
what procedures are in place to access it
• A complete risk assessment examines four critical
areas:





Process
Governance
People
Technology
UPDATING
POLICIES & PROCEDURES
• Assess the current policies and procedures (if
they exist)
 Breach notification requirements
 Incident management procedures
 Training requirements and procedures

• Prior to HITECH, Business Associates did not
need to produce documentation
UPDATING
POLICIES & PROCEDURES
• Update documentation – address high risk areas
first
• A strong disciplinary policy is a necessity
 Training without enforcement is of little value
 Establish consequences for violation of HIPAA
security policies
 Take strong action against employees who violate
policies and procedures (especially those that
relate to security policies)
UPDATING
POLICIES & PROCEDURES
• Training on policies and procedures is critical
 Train based on the highest risk area according to
your assessment
 Regular, ongoing training for the entire workforce
(no exceptions) is a must
 Training focus on remote access and removable
media is important (movement of ePHI)
UPDATING
POLICIES & PROCEDURES
• Require all those with remote access or who use
portable media of any type, to sign an attestation
stating they:
 Received the education
 Agree to abide by the policies of the organization
 Understand the risk to ePHI inherent in electronic
use
 Know the degree of discipline they face for
violating the policies
UPDATING
POLICIES & PROCEDURES
• HIPAA requires documentation to be retained for
six years
• The organization must be able to show that the
documentation was available to the persons
responsible for implementing the procedure
• A procedure is required for reviewing
documentation and ensuring it remains up-todate
• Evidence of employee training and an
acknowledgement of policies and procedures are
also required
INVOLVE EVERYONE
• Interview department directors to
understand their risk concerns and
controls in place
• Including them in the HIPAA security
processes helps to ensure they will be
educated and “on-board” with the
controls you recommend
• People are the most important
component of an effective security
program
QUESTIONS?
For additional information about Skoda
Minotti’s HIPAA consulting and compliance
services, contact us at:

Brian Rosenfelt, CPA
Skoda Minotti Technology Partners
brosenfelt@skodaminotti.com
(440) 449-6800
Website: www.skodaminotti.com

Other Services:
• Audit
• Tax
• IT Consulting
• Phone
Systems
• Marketing
• Investments
• Security

More Related Content

What's hot

You and HIPAA - Get the Facts
You and HIPAA - Get the FactsYou and HIPAA - Get the Facts
You and HIPAA - Get the Factsresourceone
 
The HIPAA Security Rule: Yes, It's Your Problem
The HIPAA Security Rule: Yes, It's Your ProblemThe HIPAA Security Rule: Yes, It's Your Problem
The HIPAA Security Rule: Yes, It's Your ProblemSecurityMetrics
 
Keys To HIPAA Compliance
Keys To HIPAA ComplianceKeys To HIPAA Compliance
Keys To HIPAA ComplianceCBIZ, Inc.
 
Cyberinsurance 111006
Cyberinsurance 111006Cyberinsurance 111006
Cyberinsurance 111006JNicholson
 
Hipaa journal com - HIPAA compliance guide
Hipaa journal com - HIPAA compliance guideHipaa journal com - HIPAA compliance guide
Hipaa journal com - HIPAA compliance guideFelipe Prado
 
HIPAA Compliance for Developers
HIPAA Compliance for DevelopersHIPAA Compliance for Developers
HIPAA Compliance for DevelopersTrueVault
 
Do You Know How to Handle a HIPAA Breach?
Do You Know How to Handle a HIPAA Breach?Do You Know How to Handle a HIPAA Breach?
Do You Know How to Handle a HIPAA Breach?Compliancy Group
 
The New HIPAA: Rules and Responsibilitues
The New HIPAA: Rules and ResponsibilituesThe New HIPAA: Rules and Responsibilitues
The New HIPAA: Rules and Responsibilituescomplianceexpert
 
HIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceHIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceJay Hodes
 
HIPPA Security Presentation
HIPPA Security PresentationHIPPA Security Presentation
HIPPA Security PresentationRebecca Norman
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rssupportc2go
 
HIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability ActHIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability ActHarshit Trivedi
 
Hipaa101 updated
Hipaa101 updatedHipaa101 updated
Hipaa101 updatedkkurapat
 

What's hot (20)

You and HIPAA - Get the Facts
You and HIPAA - Get the FactsYou and HIPAA - Get the Facts
You and HIPAA - Get the Facts
 
The HIPAA Security Rule: Yes, It's Your Problem
The HIPAA Security Rule: Yes, It's Your ProblemThe HIPAA Security Rule: Yes, It's Your Problem
The HIPAA Security Rule: Yes, It's Your Problem
 
Keys To HIPAA Compliance
Keys To HIPAA ComplianceKeys To HIPAA Compliance
Keys To HIPAA Compliance
 
Hipaa
HipaaHipaa
Hipaa
 
Cyberinsurance 111006
Cyberinsurance 111006Cyberinsurance 111006
Cyberinsurance 111006
 
HIPAA and How it Applies to You
HIPAA and How it Applies to YouHIPAA and How it Applies to You
HIPAA and How it Applies to You
 
Hipaa journal com - HIPAA compliance guide
Hipaa journal com - HIPAA compliance guideHipaa journal com - HIPAA compliance guide
Hipaa journal com - HIPAA compliance guide
 
HIPAA Compliance for Developers
HIPAA Compliance for DevelopersHIPAA Compliance for Developers
HIPAA Compliance for Developers
 
Annual HIPAA Training
Annual HIPAA TrainingAnnual HIPAA Training
Annual HIPAA Training
 
HIPAA Compliance
HIPAA ComplianceHIPAA Compliance
HIPAA Compliance
 
UNA HIPAA Training 8-13
UNA HIPAA Training   8-13UNA HIPAA Training   8-13
UNA HIPAA Training 8-13
 
Do You Know How to Handle a HIPAA Breach?
Do You Know How to Handle a HIPAA Breach?Do You Know How to Handle a HIPAA Breach?
Do You Know How to Handle a HIPAA Breach?
 
The New HIPAA: Rules and Responsibilitues
The New HIPAA: Rules and ResponsibilituesThe New HIPAA: Rules and Responsibilitues
The New HIPAA: Rules and Responsibilitues
 
HIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceHIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of Compliance
 
HIPAA HITECH training 7-9-12
HIPAA HITECH training 7-9-12HIPAA HITECH training 7-9-12
HIPAA HITECH training 7-9-12
 
HIPPA Security Presentation
HIPPA Security PresentationHIPPA Security Presentation
HIPPA Security Presentation
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
 
What is hipaa
What is hipaaWhat is hipaa
What is hipaa
 
HIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability ActHIPPA-Health Insurance Portability and Accountability Act
HIPPA-Health Insurance Portability and Accountability Act
 
Hipaa101 updated
Hipaa101 updatedHipaa101 updated
Hipaa101 updated
 

Similar to HIPAA Compliance: What Medical Practices and Their Business Associates Need to Know

Protecting patient privacy
Protecting patient privacyProtecting patient privacy
Protecting patient privacydlemin919
 
Health IT Data Security – An Overview of Privacy, Compliance, and Technology ...
Health IT Data Security – An Overview of Privacy, Compliance, and Technology ...Health IT Data Security – An Overview of Privacy, Compliance, and Technology ...
Health IT Data Security – An Overview of Privacy, Compliance, and Technology ...M2SYS Technology
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rssupportc2go
 
HIPAA Boot Camp: A Step-by-Step Guide to Achieving Compliance
HIPAA Boot Camp: A Step-by-Step Guide to Achieving ComplianceHIPAA Boot Camp: A Step-by-Step Guide to Achieving Compliance
HIPAA Boot Camp: A Step-by-Step Guide to Achieving ComplianceConference Panel
 
HIPAA and Privacy for Researchers
HIPAA and Privacy for ResearchersHIPAA and Privacy for Researchers
HIPAA and Privacy for ResearchersJason Karn
 
MHA690 confidentiality training
MHA690 confidentiality trainingMHA690 confidentiality training
MHA690 confidentiality trainingsdavis49
 
Hitech changes-to-hipaa
Hitech changes-to-hipaaHitech changes-to-hipaa
Hitech changes-to-hipaageeksikh
 
Becoming HITECH - 9/2009
Becoming HITECH - 9/2009Becoming HITECH - 9/2009
Becoming HITECH - 9/2009rogersons
 
Privacy & security training.pptx
Privacy & security training.pptxPrivacy & security training.pptx
Privacy & security training.pptxQmcleod
 
Privacy & security training.pptx
Privacy & security training.pptxPrivacy & security training.pptx
Privacy & security training.pptxQmcleod
 
Ruggiero.hipaa training
Ruggiero.hipaa trainingRuggiero.hipaa training
Ruggiero.hipaa trainingGina Ruggiero
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceJim Anfield
 
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...Xiaoming Zeng
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxamartya2087
 
HIPAA Panel Discussion
HIPAA Panel Discussion HIPAA Panel Discussion
HIPAA Panel Discussion Dan Wellisch
 
Understanding HIPAA
Understanding HIPAAUnderstanding HIPAA
Understanding HIPAAManas Deep
 

Similar to HIPAA Compliance: What Medical Practices and Their Business Associates Need to Know (20)

HIPAA
HIPAAHIPAA
HIPAA
 
Protecting patient privacy
Protecting patient privacyProtecting patient privacy
Protecting patient privacy
 
Health IT Data Security – An Overview of Privacy, Compliance, and Technology ...
Health IT Data Security – An Overview of Privacy, Compliance, and Technology ...Health IT Data Security – An Overview of Privacy, Compliance, and Technology ...
Health IT Data Security – An Overview of Privacy, Compliance, and Technology ...
 
Dustin HIPAA
Dustin HIPAADustin HIPAA
Dustin HIPAA
 
Chapter 9
Chapter 9Chapter 9
Chapter 9
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
 
HIPAA Boot Camp: A Step-by-Step Guide to Achieving Compliance
HIPAA Boot Camp: A Step-by-Step Guide to Achieving ComplianceHIPAA Boot Camp: A Step-by-Step Guide to Achieving Compliance
HIPAA Boot Camp: A Step-by-Step Guide to Achieving Compliance
 
HIPAA and Privacy for Researchers
HIPAA and Privacy for ResearchersHIPAA and Privacy for Researchers
HIPAA and Privacy for Researchers
 
MHA690 confidentiality training
MHA690 confidentiality trainingMHA690 confidentiality training
MHA690 confidentiality training
 
Hitech changes-to-hipaa
Hitech changes-to-hipaaHitech changes-to-hipaa
Hitech changes-to-hipaa
 
Becoming HITECH - 9/2009
Becoming HITECH - 9/2009Becoming HITECH - 9/2009
Becoming HITECH - 9/2009
 
Privacy & security training.pptx
Privacy & security training.pptxPrivacy & security training.pptx
Privacy & security training.pptx
 
Privacy & security training.pptx
Privacy & security training.pptxPrivacy & security training.pptx
Privacy & security training.pptx
 
Ruggiero.hipaa training
Ruggiero.hipaa trainingRuggiero.hipaa training
Ruggiero.hipaa training
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA Compliance
 
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
Patient Privacy Provisions of the HITECH Act Implications for Patients and Sm...
 
How good we are in adhering HIPAA rules
How good we are in adhering HIPAA rulesHow good we are in adhering HIPAA rules
How good we are in adhering HIPAA rules
 
health insurance portability and accountability act.pptx
health insurance portability and accountability act.pptxhealth insurance portability and accountability act.pptx
health insurance portability and accountability act.pptx
 
HIPAA Panel Discussion
HIPAA Panel Discussion HIPAA Panel Discussion
HIPAA Panel Discussion
 
Understanding HIPAA
Understanding HIPAAUnderstanding HIPAA
Understanding HIPAA
 

More from Skoda Minotti

Navigating Tomorrow's Tax Landscape - 2020
Navigating Tomorrow's Tax Landscape - 2020Navigating Tomorrow's Tax Landscape - 2020
Navigating Tomorrow's Tax Landscape - 2020Skoda Minotti
 
Elevate 2019: Business Leader Slides
Elevate 2019: Business Leader SlidesElevate 2019: Business Leader Slides
Elevate 2019: Business Leader SlidesSkoda Minotti
 
Elevate 2019: Financial Professional Slides
Elevate 2019: Financial Professional SlidesElevate 2019: Financial Professional Slides
Elevate 2019: Financial Professional SlidesSkoda Minotti
 
Smart Manufacturing Workshop: An Interactive Improv Session
Smart Manufacturing Workshop: An Interactive Improv SessionSmart Manufacturing Workshop: An Interactive Improv Session
Smart Manufacturing Workshop: An Interactive Improv SessionSkoda Minotti
 
Navigating the Tax and Accounting Implications of Cryptocurrencies
Navigating the Tax and Accounting Implications of CryptocurrenciesNavigating the Tax and Accounting Implications of Cryptocurrencies
Navigating the Tax and Accounting Implications of CryptocurrenciesSkoda Minotti
 
Performance and Rewards
Performance and RewardsPerformance and Rewards
Performance and RewardsSkoda Minotti
 
Non-Qualified Deferred Compensation Programs for Private Companies
Non-Qualified Deferred Compensation Programs for Private CompaniesNon-Qualified Deferred Compensation Programs for Private Companies
Non-Qualified Deferred Compensation Programs for Private CompaniesSkoda Minotti
 
ABC Presents: Interviewing Skills
ABC Presents: Interviewing SkillsABC Presents: Interviewing Skills
ABC Presents: Interviewing SkillsSkoda Minotti
 
Valuation Issues in Developing and Executing Buy-Sell Agreements
Valuation Issues in Developing and Executing Buy-Sell AgreementsValuation Issues in Developing and Executing Buy-Sell Agreements
Valuation Issues in Developing and Executing Buy-Sell AgreementsSkoda Minotti
 
ABC Presents: Recruiting and Retaining Top Talent
ABC Presents: Recruiting and Retaining Top TalentABC Presents: Recruiting and Retaining Top Talent
ABC Presents: Recruiting and Retaining Top TalentSkoda Minotti
 
State and Local Tax Nexus Issues and the Impact on Mergers and Acquisitions
State and Local Tax Nexus Issues and the Impact on Mergers and AcquisitionsState and Local Tax Nexus Issues and the Impact on Mergers and Acquisitions
State and Local Tax Nexus Issues and the Impact on Mergers and AcquisitionsSkoda Minotti
 
Future-Proofing Your Business with Technology
Future-Proofing Your Business with TechnologyFuture-Proofing Your Business with Technology
Future-Proofing Your Business with TechnologySkoda Minotti
 
Manufacturing in Northeast Ohio: Where We Stand, Where We’re Headed
Manufacturing in Northeast Ohio: Where We Stand, Where We’re HeadedManufacturing in Northeast Ohio: Where We Stand, Where We’re Headed
Manufacturing in Northeast Ohio: Where We Stand, Where We’re HeadedSkoda Minotti
 
Recruiting and Retaining Top Talent
Recruiting and Retaining Top TalentRecruiting and Retaining Top Talent
Recruiting and Retaining Top TalentSkoda Minotti
 
New Ohio Cybersecurity Law Requirements
New Ohio Cybersecurity Law RequirementsNew Ohio Cybersecurity Law Requirements
New Ohio Cybersecurity Law RequirementsSkoda Minotti
 
Understanding Medicare
Understanding MedicareUnderstanding Medicare
Understanding MedicareSkoda Minotti
 
Five Digital Marketing Trends Your Company Needs to Know in 2019
Five Digital Marketing Trends Your Company Needs to Know in 2019Five Digital Marketing Trends Your Company Needs to Know in 2019
Five Digital Marketing Trends Your Company Needs to Know in 2019Skoda Minotti
 
Business Valuation Basics
Business Valuation BasicsBusiness Valuation Basics
Business Valuation BasicsSkoda Minotti
 
The Importance of State and Local Tax Nexus
The Importance of State and Local Tax NexusThe Importance of State and Local Tax Nexus
The Importance of State and Local Tax NexusSkoda Minotti
 

More from Skoda Minotti (20)

Navigating Tomorrow's Tax Landscape - 2020
Navigating Tomorrow's Tax Landscape - 2020Navigating Tomorrow's Tax Landscape - 2020
Navigating Tomorrow's Tax Landscape - 2020
 
Elevate 2019: Business Leader Slides
Elevate 2019: Business Leader SlidesElevate 2019: Business Leader Slides
Elevate 2019: Business Leader Slides
 
Elevate 2019: Financial Professional Slides
Elevate 2019: Financial Professional SlidesElevate 2019: Financial Professional Slides
Elevate 2019: Financial Professional Slides
 
Smart Manufacturing Workshop: An Interactive Improv Session
Smart Manufacturing Workshop: An Interactive Improv SessionSmart Manufacturing Workshop: An Interactive Improv Session
Smart Manufacturing Workshop: An Interactive Improv Session
 
Managing Risk
Managing RiskManaging Risk
Managing Risk
 
Navigating the Tax and Accounting Implications of Cryptocurrencies
Navigating the Tax and Accounting Implications of CryptocurrenciesNavigating the Tax and Accounting Implications of Cryptocurrencies
Navigating the Tax and Accounting Implications of Cryptocurrencies
 
Performance and Rewards
Performance and RewardsPerformance and Rewards
Performance and Rewards
 
Non-Qualified Deferred Compensation Programs for Private Companies
Non-Qualified Deferred Compensation Programs for Private CompaniesNon-Qualified Deferred Compensation Programs for Private Companies
Non-Qualified Deferred Compensation Programs for Private Companies
 
ABC Presents: Interviewing Skills
ABC Presents: Interviewing SkillsABC Presents: Interviewing Skills
ABC Presents: Interviewing Skills
 
Valuation Issues in Developing and Executing Buy-Sell Agreements
Valuation Issues in Developing and Executing Buy-Sell AgreementsValuation Issues in Developing and Executing Buy-Sell Agreements
Valuation Issues in Developing and Executing Buy-Sell Agreements
 
ABC Presents: Recruiting and Retaining Top Talent
ABC Presents: Recruiting and Retaining Top TalentABC Presents: Recruiting and Retaining Top Talent
ABC Presents: Recruiting and Retaining Top Talent
 
State and Local Tax Nexus Issues and the Impact on Mergers and Acquisitions
State and Local Tax Nexus Issues and the Impact on Mergers and AcquisitionsState and Local Tax Nexus Issues and the Impact on Mergers and Acquisitions
State and Local Tax Nexus Issues and the Impact on Mergers and Acquisitions
 
Future-Proofing Your Business with Technology
Future-Proofing Your Business with TechnologyFuture-Proofing Your Business with Technology
Future-Proofing Your Business with Technology
 
Manufacturing in Northeast Ohio: Where We Stand, Where We’re Headed
Manufacturing in Northeast Ohio: Where We Stand, Where We’re HeadedManufacturing in Northeast Ohio: Where We Stand, Where We’re Headed
Manufacturing in Northeast Ohio: Where We Stand, Where We’re Headed
 
Recruiting and Retaining Top Talent
Recruiting and Retaining Top TalentRecruiting and Retaining Top Talent
Recruiting and Retaining Top Talent
 
New Ohio Cybersecurity Law Requirements
New Ohio Cybersecurity Law RequirementsNew Ohio Cybersecurity Law Requirements
New Ohio Cybersecurity Law Requirements
 
Understanding Medicare
Understanding MedicareUnderstanding Medicare
Understanding Medicare
 
Five Digital Marketing Trends Your Company Needs to Know in 2019
Five Digital Marketing Trends Your Company Needs to Know in 2019Five Digital Marketing Trends Your Company Needs to Know in 2019
Five Digital Marketing Trends Your Company Needs to Know in 2019
 
Business Valuation Basics
Business Valuation BasicsBusiness Valuation Basics
Business Valuation Basics
 
The Importance of State and Local Tax Nexus
The Importance of State and Local Tax NexusThe Importance of State and Local Tax Nexus
The Importance of State and Local Tax Nexus
 

Recently uploaded

Call Girl Surat Madhuri 7001305949 Independent Escort Service Surat
Call Girl Surat Madhuri 7001305949 Independent Escort Service SuratCall Girl Surat Madhuri 7001305949 Independent Escort Service Surat
Call Girl Surat Madhuri 7001305949 Independent Escort Service Suratnarwatsonia7
 
Housewife Call Girls Bangalore - Call 7001305949 Rs-3500 with A/C Room Cash o...
Housewife Call Girls Bangalore - Call 7001305949 Rs-3500 with A/C Room Cash o...Housewife Call Girls Bangalore - Call 7001305949 Rs-3500 with A/C Room Cash o...
Housewife Call Girls Bangalore - Call 7001305949 Rs-3500 with A/C Room Cash o...narwatsonia7
 
Call Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknow
Call Girl Lucknow Mallika 7001305949 Independent Escort Service LucknowCall Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknow
Call Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknownarwatsonia7
 
Artifacts in Nuclear Medicine with Identifying and resolving artifacts.
Artifacts in Nuclear Medicine with Identifying and resolving artifacts.Artifacts in Nuclear Medicine with Identifying and resolving artifacts.
Artifacts in Nuclear Medicine with Identifying and resolving artifacts.MiadAlsulami
 
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort ServiceCollege Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort ServiceNehru place Escorts
 
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Bangalore Call Girls Majestic 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Majestic 📞 9907093804 High Profile Service 100% SafeBangalore Call Girls Majestic 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Majestic 📞 9907093804 High Profile Service 100% Safenarwatsonia7
 
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy Girls
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy GirlsCall Girls In Andheri East Call 9920874524 Book Hot And Sexy Girls
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy Girlsnehamumbai
 
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Sonagachi Call Girls Services 9907093804 @24x7 High Class Babes Here Call Now
Sonagachi Call Girls Services 9907093804 @24x7 High Class Babes Here Call NowSonagachi Call Girls Services 9907093804 @24x7 High Class Babes Here Call Now
Sonagachi Call Girls Services 9907093804 @24x7 High Class Babes Here Call NowRiya Pathan
 
Housewife Call Girls Hoskote | 7001305949 At Low Cost Cash Payment Booking
Housewife Call Girls Hoskote | 7001305949 At Low Cost Cash Payment BookingHousewife Call Girls Hoskote | 7001305949 At Low Cost Cash Payment Booking
Housewife Call Girls Hoskote | 7001305949 At Low Cost Cash Payment Bookingnarwatsonia7
 
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknow
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service LucknowVIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknow
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknownarwatsonia7
 
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls AvailableVip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls AvailableNehru place Escorts
 
VIP Call Girls Mumbai Arpita 9910780858 Independent Escort Service Mumbai
VIP Call Girls Mumbai Arpita 9910780858 Independent Escort Service MumbaiVIP Call Girls Mumbai Arpita 9910780858 Independent Escort Service Mumbai
VIP Call Girls Mumbai Arpita 9910780858 Independent Escort Service Mumbaisonalikaur4
 
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort ServiceCall Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Serviceparulsinha
 
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
College Call Girls Pune Mira 9907093804 Short 1500 Night 6000 Best call girls...
College Call Girls Pune Mira 9907093804 Short 1500 Night 6000 Best call girls...College Call Girls Pune Mira 9907093804 Short 1500 Night 6000 Best call girls...
College Call Girls Pune Mira 9907093804 Short 1500 Night 6000 Best call girls...Miss joya
 
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...narwatsonia7
 

Recently uploaded (20)

Call Girl Surat Madhuri 7001305949 Independent Escort Service Surat
Call Girl Surat Madhuri 7001305949 Independent Escort Service SuratCall Girl Surat Madhuri 7001305949 Independent Escort Service Surat
Call Girl Surat Madhuri 7001305949 Independent Escort Service Surat
 
Housewife Call Girls Bangalore - Call 7001305949 Rs-3500 with A/C Room Cash o...
Housewife Call Girls Bangalore - Call 7001305949 Rs-3500 with A/C Room Cash o...Housewife Call Girls Bangalore - Call 7001305949 Rs-3500 with A/C Room Cash o...
Housewife Call Girls Bangalore - Call 7001305949 Rs-3500 with A/C Room Cash o...
 
Call Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknow
Call Girl Lucknow Mallika 7001305949 Independent Escort Service LucknowCall Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknow
Call Girl Lucknow Mallika 7001305949 Independent Escort Service Lucknow
 
Artifacts in Nuclear Medicine with Identifying and resolving artifacts.
Artifacts in Nuclear Medicine with Identifying and resolving artifacts.Artifacts in Nuclear Medicine with Identifying and resolving artifacts.
Artifacts in Nuclear Medicine with Identifying and resolving artifacts.
 
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort ServiceCollege Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
College Call Girls Vyasarpadi Whatsapp 7001305949 Independent Escort Service
 
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
 
Bangalore Call Girls Majestic 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Majestic 📞 9907093804 High Profile Service 100% SafeBangalore Call Girls Majestic 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Majestic 📞 9907093804 High Profile Service 100% Safe
 
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy Girls
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy GirlsCall Girls In Andheri East Call 9920874524 Book Hot And Sexy Girls
Call Girls In Andheri East Call 9920874524 Book Hot And Sexy Girls
 
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
 
Sonagachi Call Girls Services 9907093804 @24x7 High Class Babes Here Call Now
Sonagachi Call Girls Services 9907093804 @24x7 High Class Babes Here Call NowSonagachi Call Girls Services 9907093804 @24x7 High Class Babes Here Call Now
Sonagachi Call Girls Services 9907093804 @24x7 High Class Babes Here Call Now
 
Housewife Call Girls Hoskote | 7001305949 At Low Cost Cash Payment Booking
Housewife Call Girls Hoskote | 7001305949 At Low Cost Cash Payment BookingHousewife Call Girls Hoskote | 7001305949 At Low Cost Cash Payment Booking
Housewife Call Girls Hoskote | 7001305949 At Low Cost Cash Payment Booking
 
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknow
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service LucknowVIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknow
VIP Call Girls Lucknow Nandini 7001305949 Independent Escort Service Lucknow
 
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jayanagar Just Call 7001305949 Top Class Call Girl Service Available
 
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls AvailableVip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
Vip Call Girls Anna Salai Chennai 👉 8250192130 ❣️💯 Top Class Girls Available
 
VIP Call Girls Mumbai Arpita 9910780858 Independent Escort Service Mumbai
VIP Call Girls Mumbai Arpita 9910780858 Independent Escort Service MumbaiVIP Call Girls Mumbai Arpita 9910780858 Independent Escort Service Mumbai
VIP Call Girls Mumbai Arpita 9910780858 Independent Escort Service Mumbai
 
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort ServiceCall Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
 
Escort Service Call Girls In Sarita Vihar,, 99530°56974 Delhi NCR
Escort Service Call Girls In Sarita Vihar,, 99530°56974 Delhi NCREscort Service Call Girls In Sarita Vihar,, 99530°56974 Delhi NCR
Escort Service Call Girls In Sarita Vihar,, 99530°56974 Delhi NCR
 
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
 
College Call Girls Pune Mira 9907093804 Short 1500 Night 6000 Best call girls...
College Call Girls Pune Mira 9907093804 Short 1500 Night 6000 Best call girls...College Call Girls Pune Mira 9907093804 Short 1500 Night 6000 Best call girls...
College Call Girls Pune Mira 9907093804 Short 1500 Night 6000 Best call girls...
 
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
Russian Call Girl Brookfield - 7001305949 Escorts Service 50% Off with Cash O...
 

HIPAA Compliance: What Medical Practices and Their Business Associates Need to Know

  • 1. HIPAA Compliance: What Medical Practices & Their Business Associates Need to Know August 29, 2013
  • 2.
  • 3. PRESENTER Brian Rosenfelt, CPA Skoda Minotti Risk Advisory Services • Former controller, CFO and operations executive in a variety of industries • Served as business process engineer with Kaiser Permanente • Leads Skoda Minotti’s HIPAA consulting practice • Deep understanding of accounting, technology and compliance
  • 4. AGENDA • • • • • • • HIPAA History Definitions Major Provisions 2013 Omnibus Rules Compliance and Enforcement Risk Assessment Policies & Procedures
  • 5. WHAT IS HIPAA? • HIPAA: Health Insurance Portability & Accountability Act • Signed into law in 1996 • Federal law protecting the privacy of Protected Health Information (PHI) • The overall purpose is to ensure the security and privacy of individual health information
  • 6. HIPAA HITECH ACT OF 2009 Origins • Prior to 2009, HIPAA regulations were not being enforced consistently (if at all) • New act was meant to:  Strengthen controls and oversight of PHI  Improve breach notification requirements  Expand the definition of covered entities and business associates • Built on the heels of providing incentives for doctors and hospitals to implement Electronic Medical Record (EMR) systems
  • 7. DEFINITIONS • Protected Health Information (PHI) • Covered Entity • Business Associate
  • 8. PROTECTED HEALTH INFORMATION (PHI) What is PHI? • Oral or written information created by a healthcare provider or other entity that relates to someone’s health or condition, healthcare received, or healthcare payment • Unsecured PHI is data that is not encrypted Examples of PHI • • • • Medical information and records Billing information and records Medical insurance forms Lab results
  • 9. COVERED ENTITY VS. BUSINESS ASSOCIATE Covered Entities • Health Care Provider (dentist, doctor, nursing home, pharmacy) • Health Plan (HMO, company health plan, health insurance companies) • Health Care Clearinghouse
  • 10. COVERED ENTITY VS. BUSINESS ASSOCIATE Business Associates • • • • Attorneys Accountants Consultants Third Party Administrator (claims processing, etc.) • Anyone who does, or could come into contact with PHI • Others  Document shredding company  Cleaning company  Software company Business associates can be anyone with access to or potential access to health information.
  • 11. MAJOR PROVISIONS • • • • • Privacy Rule Security Rule Breach Notification Rule Enforcement Rule Unique Identifiers Rule
  • 12. PRIVACY RULE • Applies to use and disclosure of PHI • Reason for HIPAA language and forms you sign at your doctor’s office • Requires patient authorization for certain disclosures (release of medical information to employer, relative, etc.) • Disclosure permitted for treatment and/or payment purposes
  • 13. SECURITY RULE • Applies to the securing of ePHI (electronic protected health information) • Requires implementation of three types of safeguards:  Administrative (policies and procedures)  Physical (access to server room, access to patient paper records)  Technical (email encryption, password policies, technical auditing)
  • 14. BREACH NOTIFICATION RULE • Risk of Harm evaluation (old rule) • Risk Assessment and “Low Probability” (new rule) • What should the Risk Assessment look for?     Type of PHI compromised Who compromised the PHI Was the PHI actually viewed How was the breach/violation mitigated
  • 15. A LONG TIME COMING … • Health Information Technology for Economic and Clinical Health (HITECH) Act was enacted on February 17, 2009 • Proposed Regulations: July 14, 2010 • Final “Omnibus” HIPAA Regulations: January 25, 2013  Effective Date: March 26, 2013  Compliance Date: September 23, 2013 • Copy of final regulations: http://1.usa.gov/Wl60lE  138 pages
  • 16. MAJOR CHANGES WITH THE NEW RULES Business Associate Liability Increased • Business Associates are now covered DIRECTLY under HIPAA (same rules and regulations as Covered Entities) • Security and privacy rules now apply to Business Associates • Information can only be used per contract language • Penalties now apply to Business Associates • Business Associates are now responsible for sub-Business Associates
  • 18. KEY CHANGES DUE TO HIPAA HITECH Breach Notification Rules • Requires Covered Entities and Business Associates to provide notification following a breach of unsecured PHI • Similar breach notification rules for vendors of personal health records and their 3rd party service providers • Covered Entities must notify affected individuals within 60 calendar days of the discovery • If the breach effects more than 500 individuals, the media and Department of Health and Human Services must be notified • Business Associates are obligated to report breaches to Covered Entity
  • 19. KEY CHANGES DUE TO HIPAA HITECH Business Associate Responsibilities • Must implement applicable privacy provisions • Must implement all of the HITECH security provisions • Now subject to the same civil and criminal penalties as Covered Entities • Contracts between Covered Entities and Business Associates must be amended to include new HITECH provisions
  • 20. HIPAA COMPLIANCE & ENFORCEMENT Original Rule • U.S. Department of Health & Human Services regulates and enforces HIPAA through its Office of Civil Rights (OCR) • Civil penalties: Fines start at $100 and can increase up to $25,000 • Criminal penalties: Could include up to 10 years in prison and $250,000 HIPAA HITECH ACT of 2009 • State Attorneys General can also bring civil action in federal court if the interest of residents has been threatened or affected by a HIPAA violation
  • 21. HIPAA COMPLIANCE & ENFORCEMENT Potential Civil Penalties Violation Category Section 1176(a)(1) Each Violation All such violations of an identical provision in a calendar year $100-$50,000 Up to $1,500,000 (B) Reasonable cause $1,000-$50,000 Up to $1,500,000 (C)(i) Willful neglect – Corrected $10,000-$50,000 Up to $1,500,000 (C)(ii) Willful neglect – Not Corrected $50,000 or more Up to $1,500,000 (A) Did not know SUMMARY: Fines are mandatory when failure to have training and reasonable procedures on proper disposal is discovered. HHS goes on to say that had they found proper training in the same case, the same incident would not have been deemed a case of willful neglect.
  • 22. HIPAA COMPLIANCE & ENFORCEMENT Potential Criminal Penalties Type of Violation Potential Jail Sentence Unknowingly, or with reasonable cause Up to one year Under false pretenses Up to five years For personal gain or malicious reasons Up to ten years
  • 23. HIPAA COMPLIANCE & ENFORCEMENT Consequences • October 26, 2009: (Little Rock, Arkansas) sentencing of three healthcare workers who pled guilty to misdemeanor HIPAA violations based on accessing patient records without any reason • April 27, 2010: (California) press release entitled “Ex-UCLA Healthcare Employee Sentenced to Federal Prison for Illegally Peeking at Patient Records” – first person to be convicted and imprisoned for HIPAA offenses based only on unauthorized access of PHI
  • 24. HIPAA COMPLIANCE & ENFORCEMENT Consequences • January 9, 2012: Minnesota Attorney General brought action against Accretive Health, Inc. (a business associate, NOT a covered entity), in the wake of the theft of a company laptop computer that contained over 23,500 patient records • April 17, 2012: Phoenix Cardiac Surgery, P.C. agreed to pay $100,000 and take corrective action after they were found to have posted a patient appointment calendar online
  • 25. HOW TO GET COMPLIANT Begin with a thorough RISK ASSESSMENT • Essential component of HIPAA compliance • Can help your organization identify its most critical areas of vulnerability • The Risk Assessment will form the basis of determining how risks should be managed and/or minimized • This is a necessary strategy to identify potential gaps in your security environment (physical and electronic) • Required by HIPAA
  • 26. HOW TO GET COMPLIANT • Risk exposure decreases significantly when an organization knows where its PHI is stored and what procedures are in place to access it • A complete risk assessment examines four critical areas:     Process Governance People Technology
  • 27. UPDATING POLICIES & PROCEDURES • Assess the current policies and procedures (if they exist)  Breach notification requirements  Incident management procedures  Training requirements and procedures • Prior to HITECH, Business Associates did not need to produce documentation
  • 28. UPDATING POLICIES & PROCEDURES • Update documentation – address high risk areas first • A strong disciplinary policy is a necessity  Training without enforcement is of little value  Establish consequences for violation of HIPAA security policies  Take strong action against employees who violate policies and procedures (especially those that relate to security policies)
  • 29. UPDATING POLICIES & PROCEDURES • Training on policies and procedures is critical  Train based on the highest risk area according to your assessment  Regular, ongoing training for the entire workforce (no exceptions) is a must  Training focus on remote access and removable media is important (movement of ePHI)
  • 30. UPDATING POLICIES & PROCEDURES • Require all those with remote access or who use portable media of any type, to sign an attestation stating they:  Received the education  Agree to abide by the policies of the organization  Understand the risk to ePHI inherent in electronic use  Know the degree of discipline they face for violating the policies
  • 31. UPDATING POLICIES & PROCEDURES • HIPAA requires documentation to be retained for six years • The organization must be able to show that the documentation was available to the persons responsible for implementing the procedure • A procedure is required for reviewing documentation and ensuring it remains up-todate • Evidence of employee training and an acknowledgement of policies and procedures are also required
  • 32. INVOLVE EVERYONE • Interview department directors to understand their risk concerns and controls in place • Including them in the HIPAA security processes helps to ensure they will be educated and “on-board” with the controls you recommend • People are the most important component of an effective security program
  • 33. QUESTIONS? For additional information about Skoda Minotti’s HIPAA consulting and compliance services, contact us at: Brian Rosenfelt, CPA Skoda Minotti Technology Partners brosenfelt@skodaminotti.com (440) 449-6800 Website: www.skodaminotti.com Other Services: • Audit • Tax • IT Consulting • Phone Systems • Marketing • Investments • Security