HIPAA Q&A: You’ve got questions. We’ve got answers!
HIM-HIPAA Insider, September 8, 2014
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
Submit your HIPAA questions to Editor Jaclyn Fitzgerald at jfitzgerald@hcpro.com and we will work with our experts to provide you with the information you need.
Q: I work at a skilled nursing facility and I want to ensure that the organization is HIPAA compliant. What requirements and safeguards are necessary to ensure HIPAA compliance at our facility? Is there a document we can or should use to help us maintain compliance?
A: The best place to find out more about HIPAA privacy and security requirements is from OCR, which has published a wealth of information about HIPAA requirements, including guidance for small practices and health plans. OCR has also made available a sample business associate agreement and a model Notice of Privacy Practices.
To ensure your security program is up to date, you must conduct a risk analysis. A risk analysis is the foundation of any good security program and is mandated by the HIPAA Security Rule. A risk analysis should be conducted annually and when any major business or IT system change occurs. OCR and the Office of the National Coordinator for Health Information Technology has made available a risk analysis tool. You can conduct the risk analysis yourself or find a reputable vendor to assist you.
Editor’s note: Chris Apgar, CISSP, president of Apgar & Associates, LLC, in Portland, Oregon, answered this question for HCPro’s Briefings on HIPAA newsletter.
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
Related Products
Most Popular
- Articles
-
- CMS seeks comment on quality measures
- Practice the six rights of medication administration
- Don't forget the three checks in medication administration
- Note similarities and differences between HCPCS, CPT® codes
- ICD-10-CM coma, stroke codes require more specific documentation
- Nursing responsibilities for managing pain
- OB services: Coding inside and outside of the package
- Q&A: Primary, principal, and secondary diagnoses
- Clearing up the confusion: CPT codes 76376 and 76377
- CMS creates web portal for questions about 1135 waivers, PHE
- E-mailed
-
- Coronavirus vaccination: 4 best practices for communicating with patients
- Grievances, Complaints, and Patients’ Rights
- Including 46600 in E/M leveling systems
- How to get reimbursed for restorative nursing
- Five keys to creating a CHF disease management program
- Fetal non-stress tests represent important part of maternal and fetal health
- Coding, billing, and documentation tips for teaching physicians, interns, residents, and students
- Coding tip: Know how to correctly code each procedure an otolaryngologist can perform on turbinates
- Coding Clinic reiterates guidelines for provider documentation
- CMS creates web portal for questions about 1135 waivers, PHE
- Searched