Title: Importance of HIPAA Compliance for your practice
1(No Transcript)
2Importance of HIPAA Compliance for your
practice
As a physician, you start growing in your
practice you will realize that you need to
outsource part or all your billing routine tasks
to be more productive and efficient at
work. WHAT IS HIPAA? Health Insurance
Portability and Accountability (HIPAA) Act of
1996 is a law that intends to protect the privacy
of patient information. It establishes national
standards for processing electronic healthcare
transactions and requires healthcare
organizations to implement these. Why your
practice should be HIPAA-COMPLIANT? Non-compliant
of HIPAA regulations can cause big amount of
fines to your medical practice and the Medical
Billing Service Company working with you. This
also affects the reputation of you and
outsourcing medical billing company also it can
cost thousands of dollars.
3Importance of HIPAA Compliance for your
practice
- First step to take to becoming HIPAA compliant is
to have a BAA (Business Associate Agreement) in
place. BAA need to be submitted to all your
vendors such as medical billing service company.
This will help your practice to be updated HIPAA
compliant practice. As soon as all parties sign
the BAA agreement they are liable to follow all
HIPAA compliance rules and regulations. If they
fail to do so then they are subject to civil and
criminal penalties for action not authorized in
your BAA. - Recently in one of the USA state one facility
violated HIPAA compliance. A nursing home
patients physician texted the patients lab
reports to nurse. Both the physician and nurse
were the only authorized medical professionals to
see the message. The centers of Medicare and
Medicaid Services found the residential facility
to be violation. They used text message for the
communication instead of secure method of
communication. - Please find below is the Compliance Checklist
(Ref ComplianceHelper.com) - Have you formally designated a person(s) or
position(s) as your organizations privacy and
security officer? - Do you have documented privacy and information
security policies and procedures?
4Importance of HIPAA Compliance for your
practice
- Have they been reviewed and updated, where
appropriate, in the past 12 months? - Have the privacy and information security
policies and procedures been communicated to all
personnel, and made available for them to review
at any time? - Do you provide regular training and ongoing
awareness communications for information security
and privacy for all your workers? - Have you done a formal information security risk
assessment in the last 12 months? - Do you regularly make backups of business
information, and have documented
disaster recovery and business continuity plans? - Do you require all types of sensitive
information, including personal information
and health information, to be encrypted when it
is sent through public networks and when it
is stored on mobile computers and mobile storage
devices?
5Importance of HIPAA Compliance for your
practice
- Have you implemented controls to limit physical
access to all devices and areas - where PHI is accessed or stored?
- Do you limit access to PHI to only those who
need it to fulfill their job responsibilities? - Have you implemented technical security controls
to protect against unauthorized - access to electronic PHI?
- Have you identified all your business associates
(including subcontractors if you are - a BA) and ensured they have signed a BA
agreement and follow all HIPAA requirements? - Do you require information, in all forms, to be
disposed of using secure methods? - Do you have a documented breach response and
notification plan, and a team to - support the plan?
- If you are a covered entity (CE), do you
provide a Notice of Privacy Practices (NPP) - that meets all HIPAA requirements in
compliance with the Omnibus Rule changes?
6Importance of HIPAA Compliance for your
practice
- Have you established processes to document and
account for disclosures of PHI? - (Questions developed by Rebecca Herold, CIPM,
CISSP, CIPP/US, CIPP/IT, CISM, CISA, FLMI CEO,
The Privacy Professor http//www.privacyguidance.
com ) - If you answered NO to any of these questions
you are not in compliance with HIPAA and are at
risk of fines and other penalties. It is
important to know that a business partner or
regulatory agency can ask you, at any time, to
provide proof that you are HIPAA compliant. - If you need to bring your medical practice up to
HIPAAs standards, please contact
MedicalBillersandCoders.com today through email
info_at_medicalbillersandcoders.com or reach us at
our toll free number (888) 357 3226 and
well ensure that your medical practice is HIPAA
compliant. -