HIPAA Compliance Guide Released
Our 65-page HIPAA Compliance Guide for Privacy, Security and Compliance Officers provides useful advice on the main elements of the Health Insurance Portability and Accountability Act, including tips and best practice advice for Covered Entities (CEs) and their Business Associates (BAs). The guide can be downloaded here. HIPAA Compliance Will be put to the Test Three years have passed since the Department of Health and Human Services’ Office for Civil Rights completed its pilot round of HIPAA compliance audits and organizations covered by HIPAA do not have long before the audits will start again. The pilot phase did not result in any financial penalties being issued – only action plans – although the audits revealed HIPAA compliance was in a sorry state. The same is not expected to be true for the next round. CEs have had plenty of time to get procedures and policies updated, and if violations are discovered this time around, fines are likely to follow. The next round of audits will specifically test the areas of HIPAA Rules that were causing so many problems for CEs three years...
2014 HIPAA Privacy and Security Breach Report
The healthcare industry suffered a number of large scale data breaches in 2014, with Community Health Systems the hardest hit after hackers stole 4.5 million patient health records. 2014 HIPAA Privacy and Security Breaches Increase by 138% In 2014, HIPAA privacy and security breaches hit record highs with millions of patient health records exposed. Since 2012, security breaches have increased by 138% and the trend has continued into 2015. Colossal data breaches have already been reported by Anthem and Premera Health, which exposed 78.8 million and 11 million health plan member records respectively and that was before February had come to an end. The healthcare IT security focus has now shifted from compliance with HIPAA regulations to the prevention of data breaches according to a survey of healthcare IT professionals at HIMSS 2015 due to the staggering cost of data breaches. However, the data from last year suggests that hacking accounted for a relatively small proportion of the data breaches reported in 2014. When these incidents do occur, as we have seen over the course of the...
Human Error Main Cause of Data Breaches Says Baker Hostetler Report
The Ponemon institute released a study this week indicating that criminal activity was the main cause of HIPAA breaches, with OCR breach report data suggesting the same; however, according to a data security report produced by law firm BakerHostetler, human error is most often to blame. The legal firm analyzed data from more than 200 incidents that the firm advised on in 2014, with the clients coming from education, retail, insurance, technology, entertainment, hospitality, the financial services and the healthcare industry, with the latter accounting for the majority of data breaches dealt with by the firm. Over a third (36%) of the firm’s clients that had experienced a data security incident during 2014 attributed it to employee negligence. Data theft by outsiders caused 22% of security incidents with theft by insiders joint third with malware, both being implicated in 16% of incidents. Phishing attacks caused 14% of data breaches. Healthcare Industry Hardest Hit The high proportion of healthcare data breaches included in the report is partially due to the requirement to report...
HIPAA Compliance Audits: OCR Transmits Pre-Screening Surveys
According to a recent article in Lexology, the Department of Health and Human Services’ Office for Civil Rights has started transmitting pre-screening surveys to HIPAA-covered entities signaling the start of the long-awaited second round of HIPAA compliance audits. However, the OCR has yet to post a notice on its website to that effect. OCR Prepares for the Second Phase of Compliance Audits The OCR previously placed a notice in the Federal Register stating its intention to send out pre-audit screening questionnaires to up to 1200 covered entities and their Business Associates last year, allowing organizations to be contacted to assess their suitability for audit. The OCR must ensure that a representative sample of covered entities are audited, including both large and small healthcare providers, healthcare clearinghouses, insurers, health plans as well as Business Associates of covered entities. The audits must also be geographically representative, covering the whole of the United States. According to OCR’s Susan McAndrew, the screening questionnaires are to “assess the...
Orlando Health Notifies 68 After PHI Found in Neighborhood Driveway
An Orlando Health hospital has sent breach notification letters to 68 patients after a document containing their Protected Health Information (PHI) was found “in a neighborhood driveway”. The letters were sent “out of an abundance of caution”, although potentially that information could have been read by an unauthorized individual. According to a WFTV news report, Channel 9 was contacted by a man after his son received a breach notification letter in the post telling him that his confidential health information may have been exposed in a security incident, which prompted reporters to investigate. John Henderson told reporters that his son was sent a letter saying that a patient list was discovered in a driveway which was found to contain patient names, medical record numbers, account numbers and medical diagnoses, although no insurance information, financial details or Social Security numbers were included on the list. He said he “can’t believe Orlando Health is this irresponsible.” Hospitals must take great care to ensure that patient health information is properly...



