Q&A: Documenting HIPAA compliance
Compliance Monitor, August 19, 2009
Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!
Q: What auditing and documentation is necessary to demonstrate HIPAA compliance?
A: The HIPAA security rule requires covered entities to conduct four types of audits. Three are periodic, and one is annual. The periodic audits include an information systems activity review, user login monitoring, and audit log review (from systems, databases, etc., for storage, use, and disclosure of PHI). The annual audit is called an evaluation and is more commonly known as a compliance audit.
Documentation is a primary requirement of demonstrating HIPAA compliance. Documentation includes retaining written or electronic results of a risk analysis, documenting the results of an audit, developing and implementing comprehensive privacy and security policies and procedures, and documenting staff training and security incident responses.
The nature of this column makes including a complete list of requirements and steps to follow to demonstrate HIPAA compliance difficult. HCPro, Inc., offers several tools to assist covered entities and business associates in complying with HIPAA, including addressing auditing and documentation requirements, at www. hcmarketplace.com.
Additionally, free tools and information are available from OCR for privacy matters and CMS for security matters.
Chris Apgar, CISSP, answered this question in the August 2009 issue of the HCPro newsletter Briefings on HIPAA. For more information about this newsletter visit the HCMarketplace.
Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!
Related Products
Most Popular
- Articles
-
- HealthDataInsights posts new issues for medical necessity claims
- HIPAA Q&A: Flu shot requirement for hospital employees
- New FAQ posted on storing laryngoscope blades
- Q&A: Incidental disclosures and patient privacy
- What does case-mix index mean to you?
- Sneak Peek: Effort underway to establish caseload benchmarks
- Tip of the Week: Treat faculty orientation like resident orientation
- Capturing all necessary codes for IUD insertion and removal can be challenging
- Topic: CMS, OESS post new security compliance review information, checklist
- Q/A: New device pass-through categories
- E-mailed
-
- What does case-mix index mean to you?
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HHS task force: Consider privacy, security with text messages
- HIPAA Q&A: Flu shot requirement for hospital employees
- Tip: Know the common bunionectomy procedure codes and how to use them
- Code changes should help ease the pain when coding for facet joint injections
- Documentation and coding for toxic metabolic encephalopathy
- News and briefs: UA study links lack of empathy in residents to long shifts
- OB services: Coding inside and outside of the package
- Correctly code for new cardiac, pulmonary rehab benefits
- Searched
