Protect ePHI in light of new OIG report
HIM Connection, November 11, 2008
Want to receive articles like this one in your inbox? Subscribe to HIM Connection!
The Office of Inspector General (OIG) issued a final report October 27 reviewing CMS’ HIPAA security rule oversight, implementation, and enforcement. The largely critical report ("Nationwide Review of the Centers for Medicare & Medicaid Services Health Insurance Portability and Accountability Act of 1996 Oversight [A-04-07~05064]") describes the OIG’s findings and recommendations for CMS, but it also sends a message to covered entities.
"This is a formalized wakeup call for CMS; as an enforcement arm, it will be held accountable to fulfill its duties," says John C. Parmigiani, MS, BES, president of John C. Parmigiani & Associates, LLC, in Ellicott City, MD, and former chairperson of the team that created the HIPAA security rule. "But it also says to the healthcare industry that CMS is going to be coming after you."
According to the report, OIG audits of several hospitals showed "numerous, significant vulnerabilities" in security systems intended to protect electronic protected health information (ePHI), leaving it at high risk. Further, it determined that complaints would not have exposed many of the vulnerabilities the OIG has since found. As a result of its findings, the OIG recommended that CMS conduct compliance reviews. CMS contracted with PricewaterhouseCoopers to conduct reviews following the OIG investigation but prior to the release of the OIG report.
To view the report, visit www.oig.hhs.gov/oas/reports/region4/40705064.pdf.
Want to receive articles like this one in your inbox? Subscribe to HIM Connection!
Comments
0 comments on “Protect ePHI in light of new OIG report ”
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- HIPAA Q&A: Level of encryption needed for email
- Identify potential Medicaid RAC target areas
- Capturing all necessary codes for IUD insertion and removal can be challenging
- What does case-mix index mean to you?
- QA:Coding multiple initial infusions
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HIPAA Q&A: Level of encryption needed for email
- Q&A: Follow CMS' coding guidelines when using modifier -25
- Catch up on what's new with injections and infusions
- CMS has reformulated payments for some bilateral procedures
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- ED-to-inpatient transfers are flawed with safety gaps
- Searched
