Showing posts with label HIPPA. Show all posts
Showing posts with label HIPPA. Show all posts

Friday, December 17, 2021

Tips for staying off the HIPAA naughty list

Just in time for the Holiday Season, HHS Office for Civil Rights (“OCR”) announces five separate resolutions as part of its HIPAA Right of Access Initiative. This initiative focuses on providers and health plans who fail to provide individuals with the ability to view and receive copies of their protected health information (“PHI”) within 30 days unless an extension is provided. Importantly, the 30 day timeframe applies under federal HIPAA, states may have shorter timeframes to provide patients with their medical records. Here’s a recap of the five resolutions:


Advanced Spine & Pain Management (Ohio) – paid OCR $32,150 and agreed to take corrective actions that include two years of monitoring;
  • Denver Retina Center (Colorado) – paid OCR $30,000 and agreed to take corrective actions that includes one year of monitoring;
  • Robert Glaser, MD (New York) – OCR issued a civil monetary penalty of $100,000 after Dr. Glaser failed to cooperate with OCR’s investigation and waived his right to a hearing;
  • Rainrock Treatment Center, LLC (Oregon) - paid OCR $160,000 and agreed to take corrective actions that includes one year of monitoring; and
  • Wake Health Medical Group (North Carolina) - paid OCR $10,000 and agreed to take corrective actions.

To stay on OCR’s “nice list” providers should have adequate policies and procedures that staff are trained on, log the initial request date, and comply with both state and federal timeframes. If an extension is needed, notify the patient or representative.

Established under the Cybersecurity Act of 2015, the 405(d) program was established. On December 1st, HHS delivered a holiday gift – a new website - 405(d) Aligning Health Care Industry Security Approaches Program, which offers healthcare providers and public health officials cybersecurity and patient safety resources, as well as best practices. “Absence of Cybersecurity is a(n) Enterprise Risk, Patient Risk, Organization Risk, [and] Provider Risk.” Said another way, the 405(d) program’s motto that “Cyber Safety is Patient Safety” provides a variety of different resources, including cybersecurity posters, infographics, and a bi-monthly newsletter.

In sum, to avoid the ransomware Grinch, remain vigilant because ransomware criminals are ramping up.



15% Off Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)


VIEW ALL

Tuesday, September 21, 2021

Effective, HIPAA compliant communication for remote healthcare teams

The idea of remote work is not new; the transition to more flexible working arrangements has been gaining momentum for several decades, but the healthcare sector has been slow to embrace this growing trend. COVID-19 has changed that.


Siemens Healthineers argues that healthcare providers can and should integrate remote work solutions into their operations as part of their long-term strategy, not just as a short-term response to COVID-19.

There are plenty of benefits to remote or hybrid teams, but there are also communication and security issues that must be kept in mind.




Benefits of remote work


Organizations that thrive in work-from-home arrangements may see lasting benefits, even when teams return to the office setting. They may learn that they can be more flexible and remote-friendly than they thought while still maintaining standards and reaching goals.

Aside from the obvious benefits such as reduced commuting times, remote work arrangements have also been shown to increase productivity, improve employee morale, and reduce stress and burnout, thereby lowering the incidence of treatment errors.

Working remotely also increases safety. Avoiding the danger of infection from a virus such as COVID-19 is an obvious example, but other risks can also be minimized, (e.g., the risks associated with exposure to radiation during cardiovascular treatments). Expensive and time-consuming hygiene protocols can also be reduced or eliminated.


How to stay connected while working remotely


It is important to adjust for differences in the remote environment to maintain team productivity, collaboration, and company culture. Here are some things to consider.


There will be fewer face-to-face interactions and structured meetings. Replace them with predictable, scheduled check-ins.
Include social interactions in your routine to keep teams connected. Establish a culture of accountability and trust to foster stronger social bonds and better team dynamics.
Quick questions for the cube next door are no longer an option. Convert to instant messaging tools for quick questions and HIPAA compliant email for more involved conversations.



We recently covered this topic for Physicians Practice: Enabling effective internal healthcare communication with HIPAA compliant email


Using the right communication tools


For an industry as demanding and fast-paced as healthcare, mobile messaging has emerged as a particularly valuable communication tool.

Collaboration apps do a lot of good as well. Organizations across all sectors are using Slack and Microsoft Teams for remote communication. It’s easy to use these tools to increase collaboration across multiple locations and they can even act as a forum for levity and laughter during the workday.

This, once again, fosters teamwork and productivity, but it’s also a gold mine for hackers.


Security concerns


Major issues afflict platforms like Slack and Teams, as they are potentially huge sieves of electronic protected health information (ePHI). Although they can be configured for use in healthcare, they are not HIPAA compliant by default.

With one click, sensitive information can be forwarded outside the organization, either by mistake or deliberately. Because of the openness of these apps, and the ease in which you can connect other apps, there’s so much that hackers can access.

If hackers start in email, they can easily move to Teams, SharePoint, or OneDrive. Or they can start in Teams and move to email. Because the ecosystem is so tightly interwoven, it’s fairly easy to infiltrate just one and get access to all the rest. That’s why it’s so important to enable all security features available on these apps, such as requiring multi-factor authentication and adding inbound email security to your email client.



HIPAA compliant communication


Without a doubt, the first concern that comes to mind given the rise of mobile messaging across the healthcare industry is the security of transmitted patient data. HIPAA requires that covered entities and business associates acting on their behalf implement administrative, physical, and technical safeguards when transmitting or storing ePHI.

HIPAA’s Security Rule provides a helpful framework for assessing and mitigating risks associated with transmitting ePHI. It does allow covered entities to communicate electronically, such as through email or instant messaging, provided they apply reasonable safeguards when doing so.

Email or instant messaging are allowed under HIPAA if access is restricted to the appropriate parties and data integrity is maintained. Encryption is an “addressable” standard according to HIPAA, but since there is no adequate alternative to securing a message, it is de facto a requirement.


Conclusion


Sharing information freely is great and speeds up business processes and decision-making. But that same share-ability can lead to some bad outcomes as well. If you’re not protecting yourself against account compromise or takeover, then bad actors can easily infiltrate your netwo


15% Off Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)


VIEW ALL

Wednesday, September 15, 2021

Avoid these HIPAA mistakes when texting patients

Some of the highest-quality healthcare strategies nowadays include remote components and patients are increasingly wanting to communicate with their providers via text messages. Texting is a great way to keep up with matters such as payments, appointment scheduling, patient conversations, and earning valuable feedback for your practice.


Texting needs to be part of your patient communications, and you need to ensure that your healthcare organization meets the standards of the Health Insurance Portability and Accountability Act (HIPAA). While texting can make things a lot easier (and more profitable), it can also be easy to unknowingly violate HIPAA regulations.

So how do you stay compliant while texting with patients? Be sure to not make these five common mistakes.




Texting from a non-secure system


Patients and providers want to be able to text each other, but it can be unsafe to exchange sensitive information from just any old device. You will always want to avoid communicating with patients on a personal smartphone, or on a system where their information isn’t encrypted and can be accessed or intercepted.

Additionally, patients don’t want to download a separate app or log into a specific portal to ask questions or get updates—they just want to text you.

To text patients securely, you can implement a HIPAA-compliant text messaging platform that maintains government privacy and security standards.

A secure channel ensures that information is encrypted at every level, from physician to patient. Without a secure platform, you leave valuable patient information at risk.

Apart from encryption, it’s important that your texting solution will track the statuses of all messages, clearly identifying the sender and receiver, and safely integrating with your current practice management software.


Texting non-opt-in contacts


Before texting a patient, you need to make sure that they’ve given their consent to being texted by you. Texting patients who haven’t consented to text message communication can be a major violation of HIPAA standards, not to mention other regulations set by the Federal Communications Commission (FCC).

So how do you get patients to opt-in?

It’s easier than most people think. You can start by encouraging inbound traffic. Prompt patients to text you first, which you can do from your website. For example, use an SMS Chat on your homepage, or say “text us at [phone number]”.

Another way to get patients to opt-in is just to simply ask them.

On your web form, include a disclaimer that providing contact info gives you the right to communicate with them through those channels for an appointment and care-related communications. Add the same checkbox to any patient paperwork, and you’ll be surprised how quickly your opt-in list grows.

Patients also need to be able to opt-out of communications at any time. This holds true for text, but also for any other kind of communication. Most text systems include some sort of opt-out message or function.


Sharing PHI without permission


Patients want to be able to ask you questions and hold conversations through text, but you need to always make sure that they are confirmed and opted into sharing PHI via text.

Some patients will want to text with you just for scheduling and reminders, while others will want to text with you throughout their care (and after). PHI is sacred, so be sure to ask patients if they’re okay with texting you about their care.

How do you make sure this happens? You can start by adding it as a question on patient paperwork. For example: “Would you like us to text you about your care?”

As long as patients have opted in to receiving texts about care related to PHI, you're good to go.
Giving the wrong employees access

Without a secure platform, valuable PHI can be intercepted by anyone. An unattended mobile device can grant unauthorized employees access to your patient’s data, which can lead to consequences such as insurance fraud or identity theft.

Even a secure system can grant access to the wrong people. Make sure you are only granting access to authorized employees!

The “wrong employees” in this situation could be someone working in a different department or under a different provider.

For example, Employee X may be working in collections and doesn’t need to see the conversations Patient A had with the Provider about their patient care. Employee X just needs to text about collections.

Part of having a secure system is making sure users have the right permissions and access. It’s important to make sure that the appropriate personnel in your practice have access to those patient conversations.

Ensure that only authorized employees are communicating with patients. By assigning different phone numbers and different dashboards to each authorized employee, you can more confidently assume that patient communication will be secure.




Sending messages to the wrong contact


It can be easy to accidentally send messages to the wrong person when you are using a personal mobile device or even a secure platform, especially when you are in a rush.

Secure system or not, this is never acceptable. By the same token, you wouldn’t want to send an email to the wrong person or leave a voicemail on the wrong line.

This can result in unauthorized disclosure of PHI to the wrong people, violating HIPAA compliance.

To avoid these mishaps, it boils down to ensuring that your staff knows what they’re doing, and that you also have appropriate checks and balances in place. It’s imperative for them to exchange information with the correct person. Otherwise, you may be putting your patients and your practice at risk.

Confirm patient contact info every time they come into your office so that you always have their updated information. This way, you aren’t sending private information to the wrong person.


15% Off Medical Practice Supplies


VIEW ALL



Manual Prescription Pad (Large - Yellow)


Manual Prescription Pad (Large - Pink)

Manual Prescription Pads (Bright Orange)

Manual Prescription Pads (Light Pink)

Manual Prescription Pads (Light Yellow)

Manual Prescription Pad (Large - Blue)

Manual Prescription Pad (Large - White)


VIEW ALL