Q&A: Documenting HIPAA compliance
Compliance Monitor, August 19, 2009
Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!
Q: What auditing and documentation is necessary to demonstrate HIPAA compliance?
A: The HIPAA security rule requires covered entities to conduct four types of audits. Three are periodic, and one is annual. The periodic audits include an information systems activity review, user login monitoring, and audit log review (from systems, databases, etc., for storage, use, and disclosure of PHI). The annual audit is called an evaluation and is more commonly known as a compliance audit.
Documentation is a primary requirement of demonstrating HIPAA compliance. Documentation includes retaining written or electronic results of a risk analysis, documenting the results of an audit, developing and implementing comprehensive privacy and security policies and procedures, and documenting staff training and security incident responses.
The nature of this column makes including a complete list of requirements and steps to follow to demonstrate HIPAA compliance difficult. HCPro, Inc., offers several tools to assist covered entities and business associates in complying with HIPAA, including addressing auditing and documentation requirements, at www. hcmarketplace.com.
Additionally, free tools and information are available from OCR for privacy matters and CMS for security matters.
Chris Apgar, CISSP, answered this question in the August 2009 issue of the HCPro newsletter Briefings on HIPAA. For more information about this newsletter visit the HCMarketplace.
Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!
Related Products
Most Popular
- Articles
-
- Q/A: Billing telemetry daily monitoring
- Credentialing monthly: What is the role of the credentials committee in addressing unprofessional conduct?
- Radiologist indicted for fraudulently signing reports
- New report reveals $47 billion in Medicare fraud
- 2010 ICD-9 code updates now available online
- National Quality Forum creates standardized set of data for electronic health records
- Master modifiers to ensure accurate reimbursement
- H1N1 hits Maine facility
- Don’t be scared into silence: Affiliation letter safeguards allow you to disclose more
- Understand the H1N1 Flu and how to code it
- E-mailed
-
- Radiologist indicted for fraudulently signing reports
- Credentialing monthly: What is the role of the credentials committee in addressing unprofessional conduct?
- Q/A: Billing telemetry daily monitoring
- National Quality Forum creates standardized set of data for electronic health records
- New report reveals $47 billion in Medicare fraud
- Hospice group to pay U.S. $1.83 million in False Claims Act suit
- Q/A: Billing for DME
- Revised MS.1.20 'huge improvement', out for comment again
- H1N1 hits Maine facility
- Providers report first RAC denials in Florida, South Carolina
- Searched
