64
Leading Your HIPAA Culture in 2016

Leading your HIPAA Compliance Culture in 2016

Embed Size (px)

Citation preview

Page 1: Leading your HIPAA Compliance Culture in 2016

Leading Your HIPAA Culture in 2016

Page 2: Leading your HIPAA Compliance Culture in 2016

Finished files are the re-sult of years of scientif-ic study combined with the experience of many years.

Page 3: Leading your HIPAA Compliance Culture in 2016
Page 4: Leading your HIPAA Compliance Culture in 2016

Lance KingVice President, SalesHealthcare Compliance SolutionsPhone (801) 947-0183 [email protected]

Page 5: Leading your HIPAA Compliance Culture in 2016
Page 6: Leading your HIPAA Compliance Culture in 2016

Whattoexpect

Lead Your Culture, Select Your Team, and Learn

✓ Create a Culture of Privacy, Security, and Safety✓ HIPAA Breach – Identifying a Breach, Exceptions to a

Breach✓ HIPAA Protections – Security Risk Analysis, Social Media✓ Compliance TrainingDocument Your Process, Your Findings, and

Actions✓ Documentation✓ Policies and Procedures✓ HIPAA Privacy & Security

Develop an Action Plan

✓ Audit Preparation

Mitigating Risk✓ Ongoing Training & Culture

Maintenance

Page 7: Leading your HIPAA Compliance Culture in 2016

Lead Your Culture

Page 8: Leading your HIPAA Compliance Culture in 2016

168 Hours In a Week

FUNSTAFF ACCOUNTING COMPLIANCEPATIENTS FRONT DESK

Page 9: Leading your HIPAA Compliance Culture in 2016

Healthcare Compliance (HIPAA, OSHA…)

Insurance

HR

Accounting

Front Desk

Patient Care

Staff Training

Page 10: Leading your HIPAA Compliance Culture in 2016
Page 11: Leading your HIPAA Compliance Culture in 2016
Page 12: Leading your HIPAA Compliance Culture in 2016

PHI

Page 13: Leading your HIPAA Compliance Culture in 2016

Day 1 Day 10 Day 30/90 Dependent on Completion of Fieldwork

AUDIT TIMELINE

Page 14: Leading your HIPAA Compliance Culture in 2016

5 COMMON CIRCUMSTANCES FOR AN AUDIT

1. Disgruntled ex-employee2. A self-reported breach3. Employee activists4. Patient’s fear of breach5. Random OCR visit

Page 15: Leading your HIPAA Compliance Culture in 2016

1)

2)

3)

Page 16: Leading your HIPAA Compliance Culture in 2016

1)

2)

3)

Page 17: Leading your HIPAA Compliance Culture in 2016

1)

2)

3)

Page 18: Leading your HIPAA Compliance Culture in 2016

CREATE A CULTURE OF PRIVACY & SECURITY

• Communicate• Guide• Remind

Page 19: Leading your HIPAA Compliance Culture in 2016

IDENTIFYING A BREACH

1. Nature and extent of the PHI involved2. The unauthorized person who used the PHI, or to whom it

was disclosed3. Whether the PHI was actually viewed or acquired4. The extent to which the risk to protect the PHI has been

mitigated

“…unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment of at least the following factors”:

Page 20: Leading your HIPAA Compliance Culture in 2016

HIPAA BREACH• Does your staff know who to

go to for leadership when there is a HIPAA breach?

• Does your designated HIPAA compliance officer know all of the necessary steps to take in breach notification?

• Does your HIPAA compliance officer know where to receive guidance?

Page 21: Leading your HIPAA Compliance Culture in 2016

3EXCEPTIONS TO A BREACH

1.Unintentional2.Inadvertent 3.Good faith

3 Exceptions to the definition of “breach”

Page 22: Leading your HIPAA Compliance Culture in 2016

HIPAA PROTECTIONS• Ensure privacy• Give patients more access • Establish safeguards • Hold violators accountable• Strike a balance• Enable patients• Limit release of information• Give patients the right to examine and obtain a copy• Empower individuals to control certain uses and disclosures

Key Components of the HIPAA Privacy Rule:

Page 23: Leading your HIPAA Compliance Culture in 2016

HIPAA RISK PROTECTIONS• Physical, Technical, and Administrative measures

• Internal and External Security threats

• Assessment of and preparations for security risks

Page 24: Leading your HIPAA Compliance Culture in 2016

7 STEPS TO HIPAA COMPLIANCE1.Understand the rules 2.Assign Responsibility 3.List your PHI systems4.Conduct a Risk Analysis 5.Implement Policies and Procedures 6.Training program 7.Ongoing HIPAA progress and compliance

Page 25: Leading your HIPAA Compliance Culture in 2016

SECURITY RISK

• Identify where PHI exists• Identify potential threats and

vulnerabilities to PHI • Identify risks and their associated

levels of high, medium, or low

Page 26: Leading your HIPAA Compliance Culture in 2016

• Educate staff about process• Make security a high priority • Have an action plan • Involve your EHR developer • Specific to your practice

TIPS FOR A BETTER SECURITY RISK ANALYSIS

Page 27: Leading your HIPAA Compliance Culture in 2016

10 HIPAA SECURITY TIPS1. Have A Written Security Policy2. Encrypt Everything3. Protect Your Website4. Data Backups5. Avoid Consumer Grade6. Know Your Risks7. Plan For BYOD8. Who Is Guarding The Sheep9. Physical Security Is Information Security10. Know When To Call For Help

Page 28: Leading your HIPAA Compliance Culture in 2016

SECURITY RISK PRECAUTIONS• Staff requests• Hard drives• Email• Server• Passwords• Monitoring office staff• Fire extinguishers• Viruses and malware

Low-Cost Highly Effective Safeguards:

Page 29: Leading your HIPAA Compliance Culture in 2016

SOCIAL MEDIA

• Access Controls• Personal • Connecting with patients• Patient waiver forms• Training

To ensure your office remains in HIPAA compliance, create policies such as:

Page 30: Leading your HIPAA Compliance Culture in 2016

COMPLIANCE TRAINING•Online• In-office •Outsourced

Page 31: Leading your HIPAA Compliance Culture in 2016

WORKFORCE EDUCATION & TRAINING

• Hired or contracted• Yearly retraining• Changes in policies or procedures• Changes in systems, location, or

infrastructure• Responding to breach or disclosure

Educate and train your staff:

Page 32: Leading your HIPAA Compliance Culture in 2016

Documentingthe Process, the

Findings & the Actions

Page 33: Leading your HIPAA Compliance Culture in 2016

DOCUMENTATION• Policies and procedures• Security Risk Analysis• Training materials, and certificates of

completion• Current Business Associate Agreements• EHR audit logs• Risk management action plan• Security incident and breach information

Examples of records to retain:

Page 34: Leading your HIPAA Compliance Culture in 2016

POLICIES AND PROCEDURES• Establish protocols• Training program • Instruct your workforce• Sanction policy for violations • Detail enforcement• Business Associates

Page 35: Leading your HIPAA Compliance Culture in 2016

Employee HIPAA Privacy & Security

• Name/ID badges• Quiet Communication• PHI access

Guidelines for employees:

Page 36: Leading your HIPAA Compliance Culture in 2016

Workstation HIPAA Privacy & Security

• Viewing PHI Documents• Disposing of PHI• Workstations• Protect user ID’s and passwords• Computers not in use

Guidelines for workstations:

Page 37: Leading your HIPAA Compliance Culture in 2016

Access HIPAA Privacy & Security

• Computer room access• PHI Back-ups• Limited office equipment • Unoccupied Office equipment

Guidelines for access:

Page 38: Leading your HIPAA Compliance Culture in 2016

Environmental HIPAA Privacy & Security

• Smoke detectors and fire extinguishers

• Computer equipment• Cyber security • Emergency Action plan

Guidelines for environment:

Page 39: Leading your HIPAA Compliance Culture in 2016

Developing an Action Plan

Page 40: Leading your HIPAA Compliance Culture in 2016

• All shapes and sizes • Across-the-board compliance• Document in advance

AUDIT PREPARATION

Page 41: Leading your HIPAA Compliance Culture in 2016

• Risk management plan • Policies and procedures• Business Associate agreements• PHI inventory• Mobile devices• Documentation• Compliance training records• Evidence of encryption capabilities

Some of the areas the OCR audits will cover include:

AUDIT PREPARATION

Page 42: Leading your HIPAA Compliance Culture in 2016

Mitigating Risk

Page 43: Leading your HIPAA Compliance Culture in 2016

ONGOING TRAINING & CULTURE MAINTENANCE

• Patient-provider relationship• Training on PHI safeguards• Easy reference of Policies and

Procedures• Addressing staff• Re-assessing job functions

Page 44: Leading your HIPAA Compliance Culture in 2016
Page 45: Leading your HIPAA Compliance Culture in 2016
Page 46: Leading your HIPAA Compliance Culture in 2016

SECURITY RISK

ANALYSIS

Page 47: Leading your HIPAA Compliance Culture in 2016
Page 48: Leading your HIPAA Compliance Culture in 2016

Options

Consultant

In-house

Online

_____________________________(-)(+)

Page 49: Leading your HIPAA Compliance Culture in 2016

What to Expect with HCSI1. Membership Website Portal2. Compliance Binders3. Ongoing Support

Page 50: Leading your HIPAA Compliance Culture in 2016

Training(New Employee & Retraining)

• HIPAA Privacy• HIPAA Security• OSHA• Medicare• Employment Law

Page 51: Leading your HIPAA Compliance Culture in 2016

Manuals

• Reference Guide• Compliance Plans• Certificate Binder

Page 52: Leading your HIPAA Compliance Culture in 2016

Consultation and Support

• Weekly and Monthly Updates• Quarterly Newsletter• Phone and E-mail Support• Quarterly Assessment

Page 53: Leading your HIPAA Compliance Culture in 2016

Customizable Forms• Notice of Privacy Practices• Business Associate Agreement• All HIPAA Privacy• All HIPAA Security• Gap/Risk Analysis• HIPAA HITECH Breach Notification• All OSHA• All Medicare• Employment Law• RAC• Posters

Page 54: Leading your HIPAA Compliance Culture in 2016

“Our HIPAA/OSHA compliance was a huge concern in our office, especially after one of our employees filed a complaint with OSHA.

We started using HCSI 4 years ago and couldn't be happier with the program.

It's simple to set up and easier to use. Do yourself a favor and sign up, it will make your life easier!”

-Dr. Kody Krause, DDSComfort Dental Thompson Valley, CO

Customer Testimonial

Page 55: Leading your HIPAA Compliance Culture in 2016

“HCSI kept my fanny out of the hoosekow with a cranky (bit weirdo/psycho) patient who thought we had been naughty in multiple ways.

Our association with you all made the difference. We passed the inspection with flying colors and OCR told the "patient" to bug off!! Loved It!”

-Lee Mecham Thrall, Clinic AdministratorOld Farm Obstetrics & Gynecology, L.L.C

Customer Testimonial

Page 56: Leading your HIPAA Compliance Culture in 2016

30 Day Money Back Guarantee!

Page 57: Leading your HIPAA Compliance Culture in 2016

Price Breakdown

• Compliance Officer Training ($250)• Employee Training ($500)• Risk Analysis ($250)• Customized Compliance Plans ($1250)• Customizable Forms ($100)• Posters ($100)• Compliance Updates: E-mail & Newsletters ($50)• Phone & E-mail Support ($500)

Page 58: Leading your HIPAA Compliance Culture in 2016

$3500 Value

HCSIINC.COM

Page 59: Leading your HIPAA Compliance Culture in 2016

Early Bird Discount: $200 OFF

Page 60: Leading your HIPAA Compliance Culture in 2016

Compliance Officer Training

“Compliance Officer”

Page 61: Leading your HIPAA Compliance Culture in 2016

Customized Policies & Procedures

Page 62: Leading your HIPAA Compliance Culture in 2016

Quarterly Assessment Support Calls

Page 63: Leading your HIPAA Compliance Culture in 2016

Lance KingVice President, SalesHealthcare Compliance SolutionsPhone (801) 947-0183 [email protected]

Page 64: Leading your HIPAA Compliance Culture in 2016

Leading Your HIPAA Culture in 2016