40
Accessible content is available upon request. Three Steps to Automate Compliance for Healthcare Organizations Dana Simberkoff, JD, CIPP/US Chief Compliance and Risk Officer, AvePoint Marc Dreyfus, CIPP/US, CIPP/T Director, Risk Management & Compliance, AvePoint

3 Steps to Automate Compliance for Healthcare Organizations

Embed Size (px)

Citation preview

Page 1: 3 Steps to Automate Compliance for Healthcare Organizations

Accessible content is available upon request.

Three Steps to Automate Compliance for Healthcare OrganizationsDana Simberkoff, JD, CIPP/US

Chief Compliance and Risk Officer, AvePoint

Marc Dreyfus, CIPP/US, CIPP/T

Director, Risk Management & Compliance, AvePoint

Page 2: 3 Steps to Automate Compliance for Healthcare Organizations

• State of IT Compliance

• HIPAA, HITECH - Why worry?

• Assessment: Knowing is Half the Battle

• Three Steps to Automate Compliance: Say it, Do it, Prove it

• Getting to Yes: Privacy & Security by Design

Page 3: 3 Steps to Automate Compliance for Healthcare Organizations

State of IT Compliance

Page 4: 3 Steps to Automate Compliance for Healthcare Organizations

Trust In: Individuals

Organizations

Policies

Procedures

Process

Technology

Transactions

Page 5: 3 Steps to Automate Compliance for Healthcare Organizations

Everyone is a contributor

Page 6: 3 Steps to Automate Compliance for Healthcare Organizations

How do we balance the business benefit of the free flow of information with the risk of inappropriate access and disclosure?

Page 7: 3 Steps to Automate Compliance for Healthcare Organizations
Page 8: 3 Steps to Automate Compliance for Healthcare Organizations

Broad application… to doctors, hospitals, pharmacies, medical billing services, health care plans, HMOs, and business associates of these entities such as their accountants and attorneys

Applies to all recordsRequires that all records regardless of format be managed as part of the organization’s official records management program

Carries hefty penaltiesMedical fraud has increased nearly 20 percent in the past year, affecting an estimated 1.84 million American adults and costing victims $12.3 billion in out-of-pocket medical expenditures.

Page 9: 3 Steps to Automate Compliance for Healthcare Organizations

Openness & transparencyEnsure all data sources link to privacy policies

Collection, use & disclosure limitationSecure methods used to collect PHI through websites and web applications

Safeguards Monitor, notify, and act when PHI is stored inappropriately

AccountabilityMulti-layer reporting to deliver visibility into HIPAA compliance status

Individual choiceAllow for review of privacy policy and opt-out prior to submitting PHI

CorrectionCreate an accessible, protected manner for disputing accuracy of information through secure web-enabled applications

Page 10: 3 Steps to Automate Compliance for Healthcare Organizations

Measurement and Verification are key components to a holistic system

• Policy

• Training

Page 11: 3 Steps to Automate Compliance for Healthcare Organizations

Measurement and Verification are key components to a holistic system

• Policy

• Training

• Technology

Page 12: 3 Steps to Automate Compliance for Healthcare Organizations

Assessment: Knowing is Half the Battle

Page 13: 3 Steps to Automate Compliance for Healthcare Organizations

• What kind of data is stored in your information and collaboration gateways and why?

• How business users within your organization are utilizing the IT systems that hold information that may be at risk.

File System

Cloud

Social

SharePoint

Page 14: 3 Steps to Automate Compliance for Healthcare Organizations
Page 15: 3 Steps to Automate Compliance for Healthcare Organizations

Three Steps for Compliance Automation

Page 16: 3 Steps to Automate Compliance for Healthcare Organizations

Say what you are

going to doDo it…

Prove that you did it

Page 17: 3 Steps to Automate Compliance for Healthcare Organizations

Incident Tracking

Prove It

Assess Prioritize

Say It Do It

1 2 3 4 5

Ongoing Monitoring

7

Incident Management

6

8

Page 18: 3 Steps to Automate Compliance for Healthcare Organizations
Page 19: 3 Steps to Automate Compliance for Healthcare Organizations
Page 20: 3 Steps to Automate Compliance for Healthcare Organizations

Say It: Discover Data & Define Enforceable Compliance Policies

Page 21: 3 Steps to Automate Compliance for Healthcare Organizations

Develop a service level agreement among your compliance officers, your IT team, and the business before you implement a compliance plan.

It’s important to understand:• What kinds of data your business handles and

uses

• How your co-workers are using it for their day-to-day jobs

• Why and how they need to handle protected data in the course of their work

Page 22: 3 Steps to Automate Compliance for Healthcare Organizations
Page 23: 3 Steps to Automate Compliance for Healthcare Organizations

What are you trying to protect and from whom?

Name

Address

Important dates

Telephone & fax numbers

Email address

Social Security number

Medical record number

Health plan beneficiary number

Account number

Certificate/license number

Vehicle/device serial numbers

Page 24: 3 Steps to Automate Compliance for Healthcare Organizations
Page 25: 3 Steps to Automate Compliance for Healthcare Organizations
Page 26: 3 Steps to Automate Compliance for Healthcare Organizations
Page 27: 3 Steps to Automate Compliance for Healthcare Organizations

Do It: Take Action on Risk-Defined Content and Systems to Ensure Compliance

Page 28: 3 Steps to Automate Compliance for Healthcare Organizations

Create common-sense policies, rules, and IT controls

Implement transparent and non-transparent controls to IT environments

Automate the process of regulated content protection

Page 29: 3 Steps to Automate Compliance for Healthcare Organizations

Trust your end users to appropriately identify and classify sensitive data they are handling and/or creating, but verify that they are doing so properly.

Page 30: 3 Steps to Automate Compliance for Healthcare Organizations
Page 31: 3 Steps to Automate Compliance for Healthcare Organizations

• Make it easier for your employees to do the right thing than the wrong thing

• Create a transparent security organization to discourage employees from working around security

“Culture eats strategy for lunch!”

Page 32: 3 Steps to Automate Compliance for Healthcare Organizations
Page 33: 3 Steps to Automate Compliance for Healthcare Organizations

Prove It: Monitor and Report on Compliance Initiatives

Page 34: 3 Steps to Automate Compliance for Healthcare Organizations

Compliance Improvement Measurement Over Time

Compliance Activity Tracking

Page 35: 3 Steps to Automate Compliance for Healthcare Organizations
Page 36: 3 Steps to Automate Compliance for Healthcare Organizations
Page 37: 3 Steps to Automate Compliance for Healthcare Organizations

Getting to Yes: Privacy & Security by Design

Page 38: 3 Steps to Automate Compliance for Healthcare Organizations

BusinessUsers

IT Colleagues

Page 39: 3 Steps to Automate Compliance for Healthcare Organizations

Download our free privacy impact assessment toolprivacyassociation.org/resources/apia

Learn more about Compliance Guardianavepoint.com/compliance-guardian

Sign up for a free consultationpages.avepoint.com/compliance-consultation

Article: Automation key to successful policy implementationow.ly/ENB13

Page 40: 3 Steps to Automate Compliance for Healthcare Organizations

Q & A