Pages

Showing posts with label HIPAA Fines. Show all posts
Showing posts with label HIPAA Fines. Show all posts

Friday, August 10, 2018

Potential Changes to HIPAA in 2018




The director of the Health and Human Services Office for Civil Rights (OCR), Roger Severino, has suggested that there are potential changes to HIPAA regulations currently being considered. OCR intends to get rid of some of the more laborious aspects of HIPAA, in particular those that have shown to provide little benefit to patients.  Before any changes are made however, OCR will solicit feedback and suggestions stakeholders in the healthcare industry. While the complete list of possible changes under consideration have not been released to the public, Severino did indicate the changes that are currently being focused upon for 2018.

Changes being considered will attempt to get rid of obstacles to value based care and provide support for efforts addressing the opioid epidemic. Increasing the ability to share data to improve care and make it more efficient is also being discussed. Continued efforts to expand the use of electronic health technology will be formalized with specific steps required to receive monetary incentives.

While changes are being discussed, given President Trumps push to decrease government regulation, it is unlikely many new, stricter regulations will be put into place. Instead HHS has stated that it's goals are 'reducing the burden of compliance and streamlining its regulations while promotion meaningful information sharing." At the same time, Severino stated that enforcement efforts will continue to be a major focus in the coming year, and OCR will not slowdown its pursuit of settlements with HIPAA covered entities for "egregious violations of HIPAA Rules."
There are three changes to HIPAA currently in the works:
The first involved the HIPAA Enforcement Rule. OCR has the ability to impose fines on covered entities that violate HIPAA rules or who can't show that they have put sufficient effort into compliance, conducting risk assessments or remediation of identified non-compliance. OCR can also use a portion of the find to cover the expenses of future enforcement efforts and for restitution of victims. However, they have not yet done this. The Office is currently considering the best way the money can be used to compensate victims of unauthorized disclosure of private health information and other HIPAA violations.
Currently covered entities are required to keep copies of forms their patients sign that attest that they are received the covered entities notice of privacy practices.  OCR has determined this is unwieldy both in terms of requiring patients to sign the forms every time they see a doctor but also in expecting covered entities to find the space to store the forms.  They also are concerned that this practice means that many patients don't actually read them before signing. Instead, OCR is considering getting rid of this requirement and allowing covered entities to display a notice in a prominent place where patients are likely to see it. 


The third proposed change is related to good faith disclosures of PHI. Director Severino told about OCR’s plans to clarify to the public the disclosure of PHI to family or close friends in particular circumstances without the need for patient consent. This is suggested in cases when a patient is incapacitated or involved in opioid drug abuse.  Although the HIPAA rules does allow the disclosure of PHI in cases when a patient is in imminent harm, there is a need for rulemaking to cover good faith disclosures.

Although these potential changes to HIPAA have been presented by Severino at the 2018 HIPAA Summit and are currently under consideration, it is likely that any actual changes that result will not be implemented until 2019.

For more information about about your rights under HIPAA, click here.



Thursday, January 11, 2018

Health Care Provider Fined Millions for Failure to Protect Health Records

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has settled a lawsuit with 21st Century Oncology, Inc. (21CO) involving their failure to protect health care records of millions of people.  The settlement includes a has $2.3 million fine which has been agreed to instead of possible civil money penalties which could have amounted to much more.  21CO has also agreed to put into place a complete corrective action plan to remediate current problems and prevent future violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules.
The case was initiated by the Federal Bureau of Investigation (FBI) who informed 21CO that they had determined that patient information had been illegally accessed by an unauthorized third party. They provided 21CO with patient files that an FBI informant had illegally bought. 21CO conducted an internal investigation, through an outside forensic auditing firm.  It was determined that the attacker accessed health care records through a Remote Desktop Protocol from an Server housed within 21CO’s internal network. The company learned that more than 2.2 million people had their medical information illegally accessed.  Information obtained by the attacker included patient names, social security numbers, physicians’ names, diagnoses, treatment and insurance information.

The HHS subsequent investigation determined that 21CO engaged in the following illegal activities:
  • Unauthorized disclosure of Personal Health Information (PHI)
  • Failure to thoroughly evaluate possible risks to confidentiality of PHI
  • Failure to impose security measure that were effective in reducing the risk to PHI and to comply with HHS requirements
  • Failure to hold regular review of system information activity including audit logs, access reports, and security incident tracking reports
  • Disclosed information to individuals and entities it allowed to act as business associates without written business associate agreements

21CO provides cancer care and oncological radiation services. While their headquarters is located in Fort Myers, Florida, the company has 179 treatment centers which operate in 17 states and seven countries in Latin America.  Filing for Chapter 11 bankruptcy protection in May 2017, 21CO received permission from the bankruptcy court to agree to the settlement agreement.

Wednesday, June 7, 2017

Where Are All of These HIPAA Violations Coming From?

Image result for hipaa training



It seems like a pretty easy thing to avoid - HIPAA Violations.  Don’t gossip about patients, show records or disclose private information to those who shouldn’t see them and make sure you have the proper set up on your home computer or phone if either are used to access medical records.

If it’s really this simple (with a few other guidelines), then why was there in excess of $22,855,300 paid out in fines for HIPAA violations last year alone, a number of which were over $1,000,000?  Plus, this doesn’t include other remediation efforts for violations where it was determined a fine was not warranted.  So what’s going on?

Avoiding HIPAA violations means commitment to a number of things to prevent breaches and ensure appropriate confidentiality.   Of these, one of the most important boils down to training.  Now that we have been held responsible for following HIPAA regulations and documenting appropriately, some organizations that have been doing this for four of five years may have  become complacent in ensuring everyone in the organization knows what the need to in order to satisfy HIPAA regulations.  
One of the most frequently cited HIPAA violation is the failure to train  all individuals who have access to patient information.  This includes — interns, volunteers, contractors and other employees.  One problem is the failure to understand that all employees who can access medical information even when there is no plausible reason for them to do so must be fully trained on HIPAA compliance and avoiding breaches.  

The best way to avoid a breach based on lack of training is the train everyone.  It might seem inconvenient to train absolutely everyone with access to the ePHI in your company, but try to view it as an investment.  The time you put in now will pay off big when the auditors come your way.  Deciding your time frame for training lets you train in logical groups you choose to maintain the highest level of operation with the remaining employees.

Once you receive notification of an audit there is no time to do remedial work with every employee and stop gap measures are usually detectable during an audit.  This also leaves staff feeling anxious about information they have barely had time to learn which can lead to mistakes.  And where HIPAA compliance is concerned, mistakes can be costly.  

Image result for hipaa training

Image result for it's the law