Is Your Medical Practice HIPAA compliant? Better Get A Second Opinion.
Small medical practices and realities of HIPAA Security Compliance.
Raj Goel, CISSP, CTO Brainlink International, Inc.
/ 917-685-7731
The HIPAA regulations (Health Insurance Portability and Accountability Act) consists of 3 different sections. Each with a different compliance date:
Sections
Compliance Date
Privacy
April 14, 2003
Transactions and Code Sets
October 16, 2004
Security
April 21, 2005
Most physicians, small practices and small hospitals started their HIPAA compliance efforts in sometime between 2001 and 2003. Quite a few organizations stopped there as well.
Phased HIPAA compliance (Privacy in '03, Transactions in '04, Security in '05) led to HIPAA-overload. Many practitioners are confused about HIPAA compliance, and mistakenly assume that HIPAA Privacy compliance is the same as HIPAA Security compliance.
The HIPAA Security Requirements Checklist
Administrative Procedures
Certification
Formal Mechanism for Processing Records
Contingency Plans
Chain of Trust
Information Access Control
Internal Audit
Personnel Security
Security Configuration Management
Security Incident Procedures
Security Management Process
Termination Procedures
Training
Physical Safeguards
Assigned Security Responsibility
Media Controls
Physical Access Controls
Policy and Guidelines on Workstation Use
Secure Workstation Location
Security Awareness Training
Communications Controls and audits
Education & Training
Documentation of HIPAA Security Compliance
HIPAA Penalties
HIPAA compliance penalties for failure to comply with the standards or to rectify a security issue might result in:
$ 100 - $25,000/person for a single standard in a year per violation
Knowing misusing PHI up to $ 50,000 and/or 1 year in prison
Misuse under false pretenses up to $ 100,000 and/or 5 years in prison
Misuse with intent to sell or use for commercial gain $ 250,000 and/or up to 10 years in prison
Negative Publicity
Did you know that
HIPAA lawsuits have already been filed against hospitals, nursing homes, small practices and solo practitioners?
If your practice accepts credit cards, you need to meet CISP requirements as well?
Ask yourself, as Business Owner:
Do you have the people and skills required to meet these requirements?
Can you afford to pay the HIPAA penalties?
Who is accountable within your organization for civil penalties incurred?
You should focus on running your business and let Brainlink address your HIPAA compliancy.