{"id":4138,"date":"2020-03-03T15:45:44","date_gmt":"2020-03-03T20:45:44","guid":{"rendered":"https:\/\/www.kraftgrp.com\/?p=4138"},"modified":"2020-03-05T09:35:14","modified_gmt":"2020-03-05T14:35:14","slug":"hipaa-compliance-mistakes","status":"publish","type":"post","link":"https:\/\/www.kraftgrp.com\/hipaa-compliance-mistakes\/","title":{"rendered":"8 HIPAA Compliance Mistakes, And How To Avoid Them"},"content":{"rendered":"
HIPAA compliance is not an entirely straightforward process. Compliance is complex, and there is a critical element of assessment and planning that needs to go into your compliance strategy. HIPAA compliance has a long list of requirements, and overlooking even a single one can mean serious consequences for your business.<\/p>\n
<\/p>\n
By learning to avoid these most common HIPAA mistakes, you can eliminate the vast majority of compliance risks:<\/p>\n
1. Human Error<\/strong><\/p>\n It doesn’t matter which types of technical safeguards you have in place if your staff doesn’t know their role in compliance. You would be surprised how often staff members mishandle records – leaving a patient file in hard copy in a waiting area or open on a visible workstation screen.<\/p>\n An effective HIPAA compliance plan has to teach your staff how to handle a range of potential situations:<\/p>\n 2. Cloud Compliance<\/strong><\/p>\n The cloud can play an important role for both providers and patients in healthcare organizations. But that doesn’t mean you should just dive in without double-checking how it will affect your organization. After all, you have your HIPAA compliance to think of \u2013 how will your compliance be affected once you\u2019ve moved your electroni Protected Health Information (ePHI) into the cloud?<\/p>\n In fact, the OCR has released cloud computing<\/a> guidelines to help organizations stay compliant. They require that organizations make sure the cloud offers viable system availability, has a data backup solution in place, and proper security measures.<\/p>\n Remember – The easier it is for you to access ePHI, the easier it is for cybercriminals to do so as well. Don\u2019t make the mistake of assuming that just because you\u2019re not a major hospital or more active medical practice that you aren\u2019t a potential victim \u2013 data is data.<\/p>\n 3. Don\u2019t Forget About State Privacy Laws<\/strong><\/p>\n A key error many organizations make is thinking that since they\u2019re HIPAA compliant, that\u2019s all they need to worry about. However, depending on where you operate, you may also be subject to state-level data privacy laws.<\/p>\n In the case of Tennessee, however, healthcare organizations fall under a safe haven clause. If you\u2019re subject to HIPAA, you do not have to comply with Tennessee\u2019s state data privacy and breach notification laws, last updated in 2016<\/a>.<\/p>\n 4. No Complaint Procedure<\/strong><\/p>\n While you may not want to, you’re required to give your patients a method by which to lodge complaints about the protection (or lack thereof) of their medical data. You need to have a formal way for patients to make a complaint and a documented process for investigating and potentially validating the claim.<\/p>\n 5. No Privacy Notices<\/strong><\/p>\n Under HIPAA, you\u2019re required to send privacy notices to patients, detailing how their data is stored and used. Anytime these uses change, you must send an updated privacy notice. This must be done 60 days in advance of any changes to the process.<\/p>\n 6. No HIPAA Insurance<\/strong><\/p>\n Operating in the healthcare industry without HIPAA insurance is like playing with fire. Despite your best efforts, you can never know for sure that you\u2019re fully compliant. What are you going to do when you\u2019re hit with a massive fine?<\/p>\n Consider this – America’s second-largest health insurer, Anthem, was hit with a record-breaking $16 million fine<\/a> for exposing the medical data of more than 79 million Americans. Stories like that make it easy to assume that the OCR is only concerned with \u201cbig fish\u201d.<\/p>\n But that\u2019s not the case. The OCR is just as willing to investigate your minor data breach as they are major ones like Anthem\u2019s. Frensenius Medical Center was handed a $3.5 million fine after five data breaches<\/a>, each of which affected fewer than 300 patients.<\/p>\n That\u2019s why HIPAA insurance is such a wise investment. At the very least, it will help to cover costs of investigation and response to claims.<\/p>\n 7. Oral Privacy Concerns<\/strong><\/p>\n Just as a careless staff member can risk your compliance by leaving a file open and accessible to the public by accident, you assume the same risk every time a medical professional talks openly about a patient where they may be overheard. It’s forbidden to orally discuss the patient’s care in a situation where the identity of the patient can be known by other parties. Make sure to uphold best practices at your healthcare organization, reminding staff members only to discuss patient info in private.<\/p>\n 8. Trying To Handle HIPAA On Your Own<\/strong><\/p>\n As you well know, HIPAA compliance is a massive undertaking, with many obstacles and complications involved. Why would you try to manage it without expert help?<\/p>\n The Kraft Technology Group team understands how complicated HIPAA compliance is, and that organizations of your size need to focus their available personnel on treating patients. That\u2019s why we\u2019ll handle your HIPAA compliance for you.<\/p>\n When you choose to work with us, we will:<\/p>\n Want to double-check your HIPAA compliance right now? Download our HIPAA Compliancy Checklist here<\/a>.<\/strong><\/p>\n Like this article? Check out the following blogs to learn more:<\/p>\n The Need for Cybersecurity Expertise at the Board Level for Banking<\/a><\/p>\n The new Health Industry Cybersecurity Practices (HICP)<\/a><\/p>\n\n
\n
\n<\/strong><\/li>\n<\/ul>\n