HIPAA Audits and Compliance: What To Expect From Regulators and How to Comply



Similar documents
HIPAA Omnibus Rule Overview. Presented by: Crystal Stanton MicroMD Marketing Communication Specialist

How To Understand And Understand The Benefits Of A Health Insurance Risk Assessment

Selecting the Right ediscovery Solution for Your Company

Welcome to the Privacy and Security PowerPoint presentation in the Data Analytics Toolkit. This presentation will provide introductory information

WHAT MATTERS MOST TO CORPORATE COUNSEL IN E-DISCOVERY MANAGEMENT. Presenting the results from BDO s inaugural Inside E-Discovery Survey

HIPAA Omnibus Rule Practice Impact. Kristen Heffernan MicroMD Director of Prod Mgt and Marketing

Joe Dylewski President, ATMP Solutions

HIPAA Omnibus Compliance How A Data Loss Prevention Solution Can Help

COMPLIANCE ALERT 10-12

HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist.

Trust 9/10/2015. Why Does Privacy and Security Matter? Who Must Comply with HIPAA Rules? HIPAA Breaches, Security Risk Analysis, and Audits

Vendor Management Challenges and Solutions for HIPAA Compliance. Jim Sandford Vice President, Coalfire

Data Breach, Electronic Health Records and Healthcare Reform

Are You Ready for an OCR Audit? Tom Walsh, CISSP Tom Walsh Consulting, LLC Overland Park, KS. What would you do? Session Objectives

HIPAA Happenings in Hospital Systems. Donna J Brock, RHIT System HIM Audit & Privacy Coordinator

Business Associates, HITECH & the Omnibus HIPAA Final Rule

Faster, Smarter, More Secure: IT Services Geared for the Health Care Industry A White Paper by CMIT Solutions

6/17/2013 PRESENTED BY: Updates on HIPAA, Data, IT and Security Technology. June 25, 2013

Dissecting New HIPAA Rules and What Compliance Means For You

HIPAA Secure Now! How MSPs Can Profit From Selling HIPAA security services

Bridging the HIPAA/HITECH Compliance Gap

HIPAA: AN OVERVIEW September 2013

The HITECH Act: Implications to HIPAA Covered Entities and Business Associates. Linn F. Freedman, Esq.

HIPAA and HITECH Compliance for Cloud Applications

White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES

HITRUST CSF Assurance Program You Need a HITRUST CSF Assessment Now What?

THE STATE OF HEALTHCARE COMPLIANCE: Keeping up with HIPAA, Advancements in EHR & Additional Regulations

Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions

Isaac Willett April 5, 2011

EGUIDE BRIDGING THE GAP BETWEEN HEALTHCARE & HIPAA COMPLIANT CLOUD TECHNOLOGY

Texas House Bill 300 & HIPAA. A MainNerve Whitepaper

Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015

University Healthcare Physicians Compliance and Privacy Policy

Privacy Officer Job Description 4/28/2014. HIPAA Privacy Officer Orientation. Cathy Montgomery, RN. Presented by:

HIPAA Security Rule Compliance

Securing Patient Portals. What You Need to Know to Comply With HIPAA Omnibus and Meaningful Use

HIPAA Audits: How to Be Prepared. Lindsey Wiley, MHA, CHTS-IM, CHTS-TS HIT Manager Oklahoma Foundation for Medical Quality

Health Information Privacy Refresher Training. March 2013

HIPAA Compliance: Are you prepared for the new regulatory changes?

Meeting the HIPAA Training and Business Associate Requirements Questions and Answers, with HIPAA Security Expert Mike Semel

2012 HIPAA Privacy and Security Audits

Name of Other Party: Address of Other Party: Effective Date: Reference Number as applicable:

Somansa Data Security and Regulatory Compliance for Healthcare

HIPAA COMPLIANCE PLAN FOR 2013

Delivering Global Ediscovery Successfully. Emily A. Cobb, Ropes & Gray Andrew Szczech, Kroll Ontrack Thomas Sely, Kroll Ontrack

NEW PERSPECTIVES. Professional Fee Coding Audit: The Basics. Learn how to do these invaluable audits page 16

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc.

AHLA. B. HIPAA Compliance Audits. Marti Arvin Chief Compliance Officer UCLA Health System and David Geffen School of Medicine Los Angeles, CA

The Impact of HIPAA and HITECH

HIPAA and the HITECH Act Privacy and Security of Health Information in 2009

By Ross C. D Emanuele, John T. Soshnik, and Kari Bomash, Dorsey & Whitney LLP Minneapolis, MN

HIPAA in an Omnibus World. Presented by

Implementing Electronic Medical Records (EMR): Mitigate Security Risks and Create Peace of Mind

12/19/2014. HIPAA More Important Than You Realize. Administrative Simplification Privacy Rule Security Rule

Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview

Agenda. OCR Audits of HIPAA Privacy, Security and Breach Notification, Phase 2. Linda Sanches, MPH Senior Advisor, Health Information Privacy 4/1/2014

2/9/ HIPAA Privacy and Security Audit Readiness. Table of contents

Building Trust and Confidence in Healthcare Information. How TrustNet Helps

Presented by Jack Kolk President ACR 2 Solutions, Inc.

What s new In the News Data Breach Discussion The 5 W s Risk Analysis: Why, What, how, When, and Who Common Issues Observed Q / A Session Purdue

Business Associate Liability Under HIPAA/HITECH

Use & Disclosure of Protected Health Information by Business Associates

Data Security and Integrity of e-phi. MLCHC Annual Clinical Conference Worcester, MA Wednesday, November 12, :15pm 3:30pm

HIPAA Compliance and the Protection of Patient Health Information

AUDITING TECHNIQUES TO ASSESS FRAUD RISKS IN ELECTRONIC HEALTH RECORDS

OFFICE OF CONTRACT ADMINISTRATION PURCHASING DIVISION. Appendix A HEALTHCARE INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPPA)

Information Protection Framework: Data Security Compliance and Today s Healthcare Industry

OCR/HHS HIPAA/HITECH Audit Preparation

Transcription:

HIPAA Audits and Compliance: What To Expect From Regulators and How to Comply October 18, 2013

ACEDS Membership Benefits Training, Resources and Networking for the ediscovery Community Exclusive News and Analysis Weekly Web Seminars Podcasts On-Demand Training Networking Resources Jobs Board & Career Center bits + bytes Newsletter CEDS Certification And Much More! ACEDS provides an excellent, much needed forum to train, network and stay current on critical information. Kimarie Stratos, General Counsel, Memorial Health Systems, Ft. Lauderdale Join Today! aceds.org/join or Call ACEDS Member Services 786-517-2701 2

Crucial Training Through ACEDS Web Seminars Some Vital Topics We Cover Computer Assisted Review International E-Discovery Social Media Cloud-Based Discovery E-Discovery Malpractice Workplace Privacy State E-Discovery Rules And Many More! aceds.org/join 3

Presenters Abbie P. Maliniak Partner Fenton Nelson, LLP amaliniak@fentonnelson.com Allison J. Walton Chief Executive Officer Fortis Quay awalton@fortisquay.com Valarie E. Williams Managing Director, HIPAA Consulting Practice OnlineSecurityRX valarie@onlinesecurity.com

Agenda Introduction How to Comply HIPAA, HITECH, ARRA What To Expect from Auditors Fortis Quay

Agenda Introduction How to Comply HIPAA, HITECH, ARRA What To Expect from Auditors Fortis Quay

Health Insurance Portability and Accountability Act of 1996 ( HIPAA ) Ensures privacy protection for patients by limiting the ways covered entities can use patients protected health information ( PHI ) Protects PHI whether it is on paper, in computers or communicated orally- medium unimportant

HIPAA Key Provisions Access to Medical Records Notice of Privacy Practices Limits on Use of Personal Medical Information Prohibition on Marketing Stronger State Laws Will Trump Confidential Communications Complaints

Who Does HIPAA Apply to? Covered Entities (CEs) and Their Business Associates (BAs) Privacy Rule requires covered entities to establish policies and procedures to protect the confidentiality of Protected Health Information (PHI) about their patients Covered entities must provide protections for patients, such as providing notice of their privacy practices and limiting the use and disclosure of information as required under the rule

Health Plans and Providers Written Privacy Procedures Employee Training Privacy and Security Officer Designation Public Responsibilities Equivalent Requirements for Government

Health Information Technology for Economic and Clinical Health Act ( HITECH ) HITECH is a part of the American Recovery and Reinvestment Act of 2009 ( ARRA ) (Pub. L 111-5) Changes to the HIPAA Privacy and Security Rules: Apply the HIPAA privacy and security requirements directly to Business Associates ( BAs ); Establish mandatory federal security breach reporting requirements for HIPAA covered entities and their BAs; Create new privacy requirements for HIPAA covered entities and their BAs, including new accounting requirements and restrictions on marketing and fundraising; and Establish new criminal and civil penalties for noncompliance and new enforcement responsibilities.

HITECH (cont.) Security Requirements The HITECH Act expands the scope of the HIPAA Privacy and Security Rule by applying most of the rules provisions to BAs Privacy Requirements Section 13404 requires BAs to comply with privacy terms required in HIPAA BA agreements Criminal and Civil Penalties The Act makes HIPAA s criminal and civil penalties applicable to BAs Set Meaningful Use of Interoperable Electronic Health Record ( EHR ) adoption in the national health care system as a critical national goal and incentivized EHR adoption

Meaningful Use Inventive payments for Medicaid to those who adopt and use certified EHRS Starting in 2015, hospitals and doctors will be subject to financial penalties under Medicare if they are not using EHRs Three main components of Meaningful Use: Use of a certified EHR in a meaningful manner, such as e- prescribing Use of certified EHR technology for electronic exchange of PHI to improve quality of health care Use of certified EHR technology to submit clinical quality and other measures Provides grants for development of Health Information Exchange ( HIE )

Final Omnibus Rule Effective date March 26, 2013 Compliance date September 23, 2013 With the exception of the existing BA agreement must be revised by September 22, 2014 Implements privacy, security and enforcement measures under HIPAA and HITECH Affects both covered entities and BAs Burden of Proof and Presumption under Omnibus Rule

Relationships Between Regulations Privacy Security HIPPA Shift to Electronic Records and Information Exchanges Continuing Duty to Stay Current Compliance Training Covered Entities and Business Associates Must Address these challenges ARRA/HITECH OMNIBUS RULE

Agenda Introduction How to Comply HIPAA, HITECH, ARRA What To Expect from Auditors Fortis Quay

The Audits are Coming! How is the Office of Civil Rights (OCR) implementing this audit program? Audit program will be off & running in the beginning of 2014 Hiring internal auditors & coordinating efforts of contract auditors Will be leveraging civil penalties! Penalties will be used to fund audit activities $4.5 million in fines recovered so far

The Audits are Coming (cont d) What should be expected from an audit? Much more targeted audits, especially for repeat offenders Will be driven by vulnerabilities seen year to year Many breaches occur at the Business Associate (BA) level, not the Covered Entity (CE) level BAs should be prepared for audit per OCR!

The Audits are Coming (cont d) What should CEs and BAs do to prepare? Review all HIPAA related policies (Privacy, Security and Data Breach Communication) Update policies as needed and perform/document any needed training for staff Confirm that any State HIPAA requirements are addressed Confirm that staff are actually following the policies Confirm that Business Associate Agreements exist for all BAs and that Agreements include up to date language that includes the Omnibus Rule

The Audits are Coming (cont d) What should CEs and BAs do to prepare? Perform regular risk assessments Risk Analysis is weak throughout the Healthcare Industry Encourage CEs and BAs to encrypt PHI Their [OCR] analysis shows that the best, cost effective method to protect information and reduce risk is to encrypt. -Leon Rodriguez Director, Health and Human Services - Office of Civil Rights

Agenda Introduction How to Comply HIPAA, HITECH, ARRA What To Expect from Auditors Fortis Quay

Regulation/Initiativ e Review Policies Review BA Agreements Technology Implemented Compliance Training Security HIPAA/Omnibus Rule Both CEs and BAs liable- now is the time to review!!! DLP, Encryption, Penetration Testing Custom Training for your Organization - actionable Incident Response/Remediati on CMIA (Or state equivalent) Incident Response/Remediati on Information Governance/Record s Retention Know where all of your data is- cloud, on prem, for how long, how do you get it back? Etc. Archive, Classification, Records Management, Expiry, Cloud, Saas, Mobility, Virtualization Custom Training for your Organization - actionable Litigation Profile Know where all of your data is- cloud, on prem, for how Archive and in-house tools for collection/review ediscovery Best Practices Module

Compliance Training Self-reporting is still a duty, but secondary as the regulatory environment becomes more aggressive for CEs and BAs Out of the box compliance programs and policies do not necessarily consider a CE s unique environment and can be insufficient from a regulatory point of view The business processes and technologies organizations have are an integral part of compliance training, especially for emerging technologies that present erisk Granular reporting capabilities and easy content updates Remediation of risks through education and feedback from employees and BAs

Data Breach and Litigation

Data Breach and Litigation The Second District Court of Appeal ruled Tuesday October 15, 2013 that a hospital's negligent storage of medical data culminating in its loss during a burglary does not give rise to a private action if no unauthorized parties actually viewed or otherwise accessed the data. Regents v. Superior Court (Platter)The Second District Court of Appeal- Judge Perluss http://www.courts.ca.gov/opinions/documents/b249148.p DF

Recap for CEs and BAs Regulation/ Initiative Policy Creation Privacy Litigation Compliance Security Meaningful Use HIPAA/Omn ibus Rule HITECH CMIA (Or state equivalent) Information Governance /Records Retention

Key Trends to Watch Covered Entities and Their Business Associates will be forced into an Information Governance Overhaul via HIPAA Auditing and Enforcementhttp://www.clearwellsystems.com/e-discoveryblog/2012/04/11/take-two-and-call-me-in-the-morning-u-s-hospitals-need-an-information-governanceremedy/ Medical Fraud will Be Exposed Due to Heightened Sensitivity to Regulators and their Auditshttp://www.acfcs.org/regulators-perfect-storm-hippa-audits-and-more-medical-fraud/ HIPAA Assessments will Become a Common Business Process for CEs and BAs on a more frequent basis Increased Litigation Against CEs and BAs for Data Breach, HIPAA/State Equivalent violations, and Medical Fraud www.clearwellsystems.com/e-discovery-blog/2012/11/12/where-theres-smoke-theres-fire-poweringediscovery-with-data-loss-prevention/ Health and Human Services OCR Office WWW.HHS.GOV/OCR/PRIVACY/

http://lawatlas.org/preview?dataset=public-health-departments-andstate-patient-confidentiality-laws&id=524d6ce339fac3cd03d79295

Questions and Answers