Showing posts with label risk assessment. Show all posts
Showing posts with label risk assessment. Show all posts

Tuesday, March 21, 2017

Delays in Breach Notification = OCR Fines

The first OCR fine for 2017 was issued to Presence Health for delay in notifying 836 patients of a breach experienced in 2013. Presence Health met the requirement of notifying HHS of the breach within 60 days after the end of the calendar year in which the breach is discovered (notification took place January 31, 2014).  

There have been many articles written about the need to investigate a potential breach, and establish what happened, how it happened and do a thorough job in getting as complete as possible, the names of all individual affected by the breach so that notification can take place. What you don't want to do is forget the breach notification rule that states that for a breach of any size, patients must be notified "without unreasonable delay, but in no case longer than 60 days." Certainly, there are a few exceptions like law enforcement delay and other rare situations, but the rule is clear.

The fine is significant enough, but remember that along with the OCR fine, generally comes a corrective action plan (CAP). In this particular case, there was a requirement to revise existing policies and procedures related to the Breach Notification rule. Training materials would also need to be updated and provided to appropriate workforce members with documentation of the date the training was provided. Evidence of compliance with the CAP is always required.

A couple of key takeaways include noting that the OCR will investigate all breaches and that it generally takes a good bit of time for the OCR to make their determination based on information requested and provided. The fine, if infractions are identified will follow and the CAP will take resources and an investment on the facility's part. Breaches and their impact are significant and the financial costs associated with them run deep.  

Read the full article here   

  

Wednesday, April 27, 2011

Privacy Officer Services

A new day and a new adventure begins. In working with MTSOs for a number of years, and with the requirements of HITECH making the headlines, I have decided to start something new and provide a number of services and solutions for business associates and covered entities in efficiently achieving compliance in the area of privacy and security. Privacy Officer Services officially begins today.

This new business is designed to support business associates and covered entities in the development of their customized policies and procedures for privacy and security, to assist with completing their required security risk analysis and a number of other services like employee training, education, monthly updates, quarterly updates for the business website, and weekly updates in news in and around privacy and security as well as technical developments. There are many more and there is a unique solution for every healthcare organization.

My goal is to help these business associates achieve the HITECH requirements in a cost-effective manner so that their current staff can continue on with the business at hand in delivering on-time services and provide the customer experience their clients expect.

By outsourcing their privacy officer reponsibilities to me, they will gain efficiencies in a number of ways like having a knowledgeable resource available every day without having to add to their employee count. Having someone who can attend meetings, and present to potential and existing clients on their privacy solutions can be a huge advantage in the world where we see and hear about costly security breaches nearly every day.

It's a new world filled with legal requirements and challenges for business associates and covered entities - this is a way to check a very important responsibility off the "must-do" list and put this into the hands of someone they know and can trust to provide the right solution today.