Avoid these five common pitfalls when preparing for security
HIPAA Weekly Advisor, October 3, 2003
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
The final security rule requires covered entities to analyze their risk to determine what unauthorized uses, disclosures, and data integrity losses would occur if security measures were not in place. Once a HIPAA team is formed and upper management sponsorship is obtained, a risk analysis is the first step towards security rule compliance. But before you begin your analysis, beware of the following common mistakes:
1. Avoid the urge to immediately solve known security problems. Wait until you have a complete assessment and you see the full picture. You may decide that other security issues are more urgent and deserve a higher priority, based on staff or budget resources, or you may find that solutions are interdependent. By prematurely applying a technical solution to one problem, you may have complicated or worsened other security flaws, or you may have missed an opportunity for an integrated solution. As with any project, and especially one this big, be sure to take time to plan before acting.
2. Avoid focusing primarily or exclusively on technology. Actually, much if not most of security is administrative work policies, standards, procedures, and training.
3. Avoid letting technology dictate policy. Ideally, set policy first-with available technology solutions in mind-and then implement the supporting procedures and technologies to fit the policy.
Go to http://www.himinfo.com/news/feature.cfm?content_id=35452 to read more.
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Related Products
Most Popular
- Articles
-
- HIPAA Q&A: Flu shot requirement for hospital employees
- Running an effective peer review committee meeting
- HealthDataInsights posts new issues for medical necessity claims
- Sneak Peek: Effort underway to establish caseload benchmarks
- Q/A: Coding for telescopic intraocular lens
- New FAQ posted on storing laryngoscope blades
- Tip: Perform your own internal investigation prior to government audit
- HIPAA 5010 deadline extended, but threat remains, says AMA
- HHS task force: Consider privacy, security with text messages
- What does case-mix index mean to you?
- E-mailed
-
- Running an effective peer review committee meeting
- HIPAA Q&A: Flu shot requirement for hospital employees
- HHS task force: Consider privacy, security with text messages
- What does case-mix index mean to you?
- Q/A: Coding for telescopic intraocular lens
- Q/A: Correct use of modifier -PT
- Tip: Correctly code bilateral pain management procedures
- "Wall fountains" may be spreading Legionnaires to patients, visitors
- 2012 CPT code changes for ASCs: Shoulder and knee scopes and pain management
- COT basics to best
- Searched