
Recent HIPAA Activity Underscores Importance of Compliance
Two recent HIPAA violations, and a looming compliance date, mean now is the time to ensure privacy and security policies are in place at your medical practice.
With the September 23, 2013, HIPAA compliance date looming - expressed in the January 2013 Omnibus Rules -now is a good time to get things in order.
This month, officials at Stanford University’s Lucile Packard Children’s Hospital
Approximately one week later, HHS' Office for Civil Rights (OCR) "reached a settlement with a California medical center, [Shasta Medical Center] …
Specifically, the medical center "impermissibly used the patient’s diagnosis, treatment, and medical condition by including it in an e-mail to its entire workforce of more than 700 people." In its press release, HHS identified key aspects of the Resolution Agreement, in addition to the $275,000 settlement agreement. Key takeaways include: designating compliance representatives, developing policies and procedures, establishing safeguards to protect PHI from disclosure, and submitting different reports to HHS.
In sum, now is a good time to make sure privacy and security policies and procedures comply with the requisite standards. Also, review business associate agreements, notice of privacy policies, and HIPAA authorization forms. Assessing the situation now can prevent adverse enforcement actions in the future.
Newsletter
Optimize your practice with the Physicians Practice newsletter, offering management pearls, leadership tips, and business strategies tailored for practice administrators and physicians of any specialty.













