Health Information Management

HIPAA auditing tools: tests

HIPAA Weekly Advisor, February 9, 2004

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

HIPAA auditing tools: tests

When you prepare an audit of your security and privacy procedures, you'll need to narrow the focus of the audit, plan your course of action, and select your audit tools. Below are some of the testing tools you may want to use to gather information:

A variety of test formats may be used collect data. Although a test may be similar to a questionnaire in some respects, a questionnaire typically surveys opinions or beliefs, while a test requires an answer that can be deemed correct or incorrect. In addition to a paper-and-pencil type of test (even if administered electronically), tests can also be constructed as more invasive processes. A security test that is becoming popular is the social engineering test, which emulates a social engineer attempting to charm information from someone.

Other security tests are highly technical. They include the following: war dialing, in which a computer is programmed to systematically dial phone numbers until it finds one that connects to a modem; war driving, in which a hacker drives around searching for a wireless access point to tap into; scans to determine vulnerabilities in a network; or penetration tests where active attempts are made to hack a system.

Borrowing from the financial accounting sector, tests may also be statistical in nature, such as cross-footing or hash totals if the data to be collected would lend themselves to such. An example of a less numerically oriented test may be to construct a call-back procedure to verify the identity and authority of someone requesting information.

The preceding excerpt is adapted from the Guide to HIPAA Auditing: Practical Tools and Tips to Ensure Compliance, by HIPAA expert and author Margret Amatayakul, RHIA, CHPS, FHIMSS.



Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

  • Briefings on APCs

    Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

  • Medical Records Briefing

    Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

  • Briefings on Coding Compliance Strategies

    Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

  • Briefings on HIPAA

    How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

  • APCs Weekly Monitor

    This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

Most Popular

Related Articles