HIPAA compliance questions regarding HITECH
HIPAA Weekly Advisor, February 22, 2010
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
As a HIPAA covered entity, you should watch HITECH closely.
But HITECH compliance is really about HIPAA privacy and security rule compliance.
So as your organization works to comply with breach notification regulations and sets up a “harm threshold” risk analysis team, per HITECH, it should also go back to HIPAA security 101.
“HITECH did include significant changes, but the bottom line is, and what especially security officers need to do, is make sure they actually comply with the HIPAA Security Rule,” says Chris Apgar, CISSP, president, Apgar & Associates, LLC, in Portland, OR.
BAs had to comply by February 17 with the HIPAA Security Rule and the use and disclosure provisions of the privacy rule. In reality, Apgar says BAs should have been compliant since 2003 for privacy and 2005 for security, by contract.
“Yes, the new requirements [especially breach notification] need to be addressed, but the bottom line is many covered entities and business associates have consistently failed to comply with the HIPAA Security Rule,” Apgar says. “I find this over and over when conducting compliance audits.”
Read the full story on HIPAA Update.
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- What does case-mix index mean to you?
- HIPAA Q&A: Level of encryption needed for email
- QA:Coding multiple initial infusions
- News and briefs: Oklahoma Osteopathic Association against residency bill change
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HIPAA Q&A: Level of encryption needed for email
- CMS has reformulated payments for some bilateral procedures
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- Hospitals are not bound by InterQual criteria for determining patient status
- ED-to-inpatient transfers are flawed with safety gaps
- Searched
