Compliance News - page 7

Fifty Ways to Lose Your Lover or PHI

Getting chosen for a HIPAA audit by HHS is a longer shot than winning the lottery, but there are other ways; lose a laptop, click on the wrong email link, sign a business associate agreement, expose PHI on the internet, toss paper records in the dumpster, etc., etc.

Finish Reading…

Posted September 26, 2016 by Jack Anderson

HIPAA Certification: Quarterly Risk Assessment

A quarterly risk assessment showing progress on compliance is your best HIPAA certification. Progress not perfection is what HHS and OCR seek and a quarterly risk assessment is the best certfication of progress.

Finish Reading…

Posted September 19, 2016 by Jack Anderson

OCR Steps Up Investigation of Smaller HIPAA Breaches

Beginning this month, OCR, _through the continuing hard work of its Regional Offices_, (my emphasis) has begun an initiative to more widely investigate the root causes of breaches affecting fewer than 500 individuals. OCR-Announcement-8-18-16.pdf

Finish Reading…

Posted August 22, 2016 by Jack Anderson

Business Associate Exposes 650,000 Patient Records

In a breach reminiscent of the Anthem HIPAA breach, a business associate left 650,000 patient records exposed on the Internet. R-C Healthcare Management a business associate of Bon Secour was adjusting their network settings and left the patient records exposed from April 18 through April 21.

Finish Reading…

Posted August 15, 2016 by Jack Anderson

Cybercriminals are after your HIPAA data

Almost 30% of health care data breaches in July attributed to cybercriminals, according to Health IT Smart Brief. Many of these records were posted on the dark net for sale by The Dark Overlord.

Finish Reading…

Posted August 10, 2016 by Jack Anderson

HIPAA Audits and Penalties for Business Associates

Huge fines and audits are the signal that HIPAA compliance is entering a new era for business associates. A $650,000 fine was assessed for a business associate that lost an unencrypted and non-password protected I-Phone and the audit letters are on their way.

Finish Reading…

Posted July 18, 2016 by Jack Anderson

Prevent Ransomware: Security Awareness Training

Hackers are taking advantage of the most vulnerable point of entry into your computer network; your staff. Security awareness training is the most important factor in preventing ransomware.

Finish Reading…

Posted June 22, 2016 by Jack Anderson

Revitalize Your HIPAA Program with a Risk Assessment

HIPAA compliance can be like an old battery that just loses it's spark over time. A risk assessment can help you Jumpstart that old tired HIPAA battery

Finish Reading…

Posted June 13, 2016 by Jack Anderson

Sorry Laura and ecfirst, Still No HIPAA Certification

"We are very excited about the recertification by ecfirst,” said Laura Huska, Head of IT. “HIPAA continues to be a critical certification for ISI as many of our healthcare clients rely on this standard to meet their compliance needs when using ISI’s UC Reporting application.” Sorry Laura, there is no such thing as HIPAA certification thus no HIPAA recertification.

Finish Reading…

Posted June 7, 2016 by Jack Anderson

BA Security is Worse Than You Think!

I changed the headline of this blog to reflect my personal observations in talking with hundreds of business associates (BAs). BA security is bad because most BAs don't know the requirements let alone how to meet them. CE security is bad because a lot of CEs are blase bout HIPAA or rely on outdated views of the requirements. _BA Security Is Probably a Lot Worse Than You Think Tally of Health Data Breaches Apparently Undercounts Incidents Involving BAs Marianne Kolbasuk McGee (HealthInfoSec) • May 13, 2016 _

Finish Reading…

Posted May 27, 2016 by Jack Anderson