Health Information Management

Get upper management on board with the security rule

HIPAA Weekly Advisor, April 26, 2004

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

Q: Is there a way to convince management that security-rule compliance is just as important--if not more so--than privacy and transactions and code sets compliance?

A: Luckily, increased media coverage on hackers, viruses, and loss of confidential information is helping information security reach managers' radar screens. Also, many managers are seeing that protecting the information an organization couldn't survive without is the logical thing to do, and an all-around good way of running a business.

In addition to these general statements, there are two main HIPAA-related points you can make to managers who may still be hesitant:

* It's common knowledge--yet often overlooked--that it's technically impossible to achieve privacy-rule compliance without implementing many of the security measures outlined in the security rule.

* With all the time, effort, and money that has been and will be spent on privacy and transactions and code sets rule compliance, why throw it all away by not properly securing PHI where it's most vulnerable? Besides, the security rule is one of the three major parts of HIPAA.

If you meet resistance, simply treat it as requests for more information. Don't bug or overwhelm them, but certainly run some security tests, find some of the answers they're looking for, and return with that information in hand. Remember, with information security, knowledge is power (for you) and education is key (for your upper managers).

Editor's note: This question was answered by Kevin Beaver, CISSP, founder and principal consultant with Principle Logic, LLC, and coauthor of the book "The Practical Guide to HIPAA Privacy and Security Compliance" published by Auerbach Publications.



Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

  • Briefings on APCs

    Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

  • Medical Records Briefing

    Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

  • Briefings on Coding Compliance Strategies

    Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

  • Briefings on HIPAA

    How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

  • APCs Weekly Monitor

    This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

Most Popular

Related Articles