HIPAA Enforcement Update Provided by OCR’s Iliana Peters

by | May 27, 2017

Iliana Peters, Office for Civil Rights Senior Advisor for HIPAA Compliance and Enforcement, has given an update on OCR’s enforcement activities in a recent Health Care Compliance Association ‘Compliance Perspectives’ podcast.

OCR reviews all data breaches involving the exposure of theft of greater than 500 healthcare records at one time. The body also investigates official complaints about potential HIPAA violations. Those reviews continue to reveal similar non-compliance issues. Ms Peters said many issues occur on a recurring basis.

She said one of the most commonly experienced problems is the failure to carry out a comprehensive, organization-wide risk assessment and ensure any vulnerabilities discovered are addressed through a HIPAA-compliant risk management process. Many recent settlements have highlighted just how frequently HIPAA covered entities get risk assessments incorrect, either failing to conduct them in the first place, not conducting them frequently enough or not conducting them to the standard demanded by HIPAA.

Ms Peters stated out that privacy violations are occurring on a regular basis, with many HIPAA-covered entities still not certain of the allowable uses and disclosures of PHI. OCR recently revealed that two settlements have been agreed with covered entities that have  disclosed patients’ health information to employers and the media within proper permission.

Peters described how the healthcare industry is not doing a good job at preventing cybersecurity incidents. She said that  and that warrants attention, but it is important for OCR not to just focus on the currently ‘sexy’ issues. OCR is also concentrating efforts on addressing the lack of safeguards for paper records and the failure to secure removable media.

In the case of the latter, there have been many instances where ePHI has been shown up due to the failure to use encryption. Peters said that if “[a device] can walk away from your enterprise, it will walk away.” OCR has settled cases with many organizations in recent months as a result of the lack of appropriate safeguards and policies and adequate procedures covering removable devices.

Peters stated that OCR has been working on sharing penalties with individuals that have been harmed by privacy violations, although that has been a challenging process as it is difficult to define and quantify harm. OCR is working on an advanced notice of proposed rule making and will be seeking direction from the public as to how funds should be shared.

The OCR is also working on initiatives to enhance privacy protections at non-HIPAA covered entities. For instance, patients are being advised to share their health data with research organizations and through the “All of Us” initiative. For those programs to make a difference, patients need to be sure their data will be protected. OCR is providing guidance to organizations and partners to ensure that patient data is protected, even if they are collected and stored by non-HIPAA-covered entities.

Peters also spoke of working with Certified EHR technology and how HIPAA applies to cloud computing, malware, and ransomware.

The Compliance Perspectives podcast can be listened to at this link.

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

COMPREHENSIVE HIPAA TRAINING

Ryan Coyne

Ryan Coyne is a results-driven leader in the healthcare compliance industry, specializing in regulatory compliance, compliance training, and assisting healthcare organizations and business associates in achieving and maintaining compliance. With a deep knowledge of healthcare regulations and a keen understanding of the challenges faced by the industry, Ryan has developed a reputation as a trusted advisor and advocate for ethical and compliant practices in healthcare. Ryan has successfully advised and guided numerous healthcare organizations, business associates, and healthcare professionals on achieving and maintaining compliance with regulatory training requirements. Ryan's professional focus is using his in-depth expertise and leading a world class team of subject matter experts at ComplianceJunction in regulatory compliance to help organisations navigate the complex landscape of ensuring staff adhere to healthcare regulations. You can connect with Ryan via LinkedIn and follow on Twitter

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

Comprehensive HIPAA Training

Used in 1000+ Healthcare Organizations and 100+ Universities

    Full Course - Immediate Access

    Privacy Policy