OCR Gives Updates at HIMSS15 but no Timescale for Compliance Audits
The Department of Health and Human Services’ Office for Civil Rights has not used the HIMSS 2015 conference as a podium to announce the start of the long awaited second round of HIPAA compliance audits; although a number of OCR officials have given an insight into what it has in store for 2015. HIMSS 2015 is a time of learning for healthcare professionals. The protection of EHRs – and best practices and technology to adopt to protect them – is a major focus at this year’s conference. Cybersecurity is top of the agenda, and the recent high profile “mega-breaches” of recent months has got healthcare IT professionals looking for answers. The words “data breach” may be enough to bring out a cold sweat at the conference, although there were plenty in attendance on Monday for Marion Jenkins’s session – Chief Strategy Officer at 3t Systems- which gave a brief history of HIPAA, which examined a decade of data breaches. Jenkins recounted the enforcement actions already made by the OCR since it took charge of policing HIPAA, and pointed out that it has increased its enforcement...
Verizon 2015 Data Breach Investigations Report Released
The 2015 Verizon Data Breach Investigations Report puts the healthcare industry under the spotlight and reveals some of the major issues faced by the industry and the large gap that exists between where HIPAA-covered entities (CEs) are now with their data security protections and where they need to be to meet the minimum standards required by HIPAA. This is the eighth year that Verizon has released its security report and this year the data sample is bigger than ever, allowing greater faith to be placed in the report’s findings than in previous years. A total of 70 organizations contributed data for the report, an increase of 50% year on year. The company’s analysts looked at some 80,000 reported security incidents – up 26% from the previous year – and 2,100 reported data breaches, which is an increase of 55 percent from the previous year. The report goes into intricate detail about the data breaches that have been reported over the course of the past 12 months and offers advice on some measures that can be employed to improve security and protect confidential data. Verizon...
Faster Delivery of Lab Test Results Achieved by Pathology, Inc.
Privately owned pharmacies and laboratories are covered by HIPAA Rules, and they must therefore ensure that all Protected Health Information (PHI) stored and transmitted, is appropriately secured, with the security measures used dictated by the standards laid down in the HIPAA Security Rule. The privacy of patients must be assured at all times. Highly sensitive health information, such as medical test results, could cause patients to come to harm if accidentally disclosed to the wrong individuals. Efforts should therefore be made to ensure any transmission of data cannot be intercepted and read. To reduce the risk of HIPAA breaches, many laboratories stick to tried and tested delivery methods, and accept there will be a delay in data reaching physicians. Some companies have risen to the challenge, and now ensure faster delivery of lab test results by utilizing new technology. They have leveraged Smartphones to coordinate patient care more efficiently and ensure treatment to patients is provided more rapidly. This smart use of technology has allowed HIPAA-covered entities to improve...
You Ain’t Seen Nothing Yet – OCR Indicates Major Hike in HIPAA Audits
They were last seen in 2012, but the second round of HIPAA compliance audits have yet to commence, but they are apparently coming back this year with plans in place for them to be bigger and bolder than ever before. The Department of Health and Human Services’ Office for Civil Rights (OCR) indicated to Washington lawyer and HIPAA expert, Adam Greene – partner of Davis Wright Termaine – that compliance enforcement is set to significantly increase. OCR Has Already Increased Its Enforcement Actions In a presentation at HIMSS15 in Chicago on Tuesday, Greene pointed out that there had been an increase in enforcement actions involving financial penalties in recent years. Greene said there “was one or three fines levied in 2008-2011, five in 2012 and 2013 and seven last year in 2014”. The OCR has had to deal with more than 100,000 claims since it started enforcing HIPAA legislation and in the majority of cases these claims have been resolved without any investigation being necessary. In almost a quarter of cases (24%) the Covered Entity (CE) took voluntary corrective action...
Symantec Study Shows Data Breaches Increased 23% in 2014
It is April, which means the release of the Symantec Annual Internet Security Report. Each year the security software company releases a report compiled from the data that it collected during the course of the past year. The report provides an insight into the general state of cybersecurity. The figures show the number of security breaches rose 23% in 2014. The report covers all industries, including healthcare, with the bulk of data breach victims affected by retail industry security breaches. Hacking incidents caused data to be exposed on a monumental scale and while there were fewer “mega-breaches” in 2014 – 4 breaches of more than 10 million records compared to 8 the previous year – the report states that data breach incidents are still a major issue. Hackers were responsible for a large number of the additional 23% of security breaches. The report suggests that there were fewer cases of identity exposure in spite of the overall 23% rise. The report suggests ”this could indicate that many breaches— perhaps the majority—go unreported or undetected.” Some industries...



