Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
29
1
3
4
5
7
8
10
11
12
15
16
17
18
19
21
24
25
26
27
30
31
1
2
A Behavioral Health Collision At The EHR Intersection
2014-09-30    
2:00 pm - 3:30 pm
Date/Time Date(s) - 09/30/2014 2:00 pm Hear Why Many Organizations Are Changing EHRs In Order To Remain Competitive In The New Value-Based Health Care Environment [...]
Meaningful Use and The Rise of the Portals
2014-10-02    
12:00 pm - 12:45 pm
Meaningful Use and The Rise of the Portals: Best Practices in Patient Engagement Thu, Oct 2, 2014 10:30 PM - 11:15 PM IST Join Meaningful [...]
Adva Med 2014 The MedTech Conference
2014-10-06    
All Day
Adva Med 2014 The MedTech Conference October 6-8, 2014 McCormick Place Chicago, IL For more information, visit, advamed2014.com For Registration details, click here  
Public Health Measures Meaningful Use
2014-10-09    
12:00 pm - 12:45 pm
Public Health Measures Meaningful Use: Reporting on Public Health Measures Join Meaningful Use expert Jim Tate for a three part series of webinars addressing MU [...]
2014 Hospital & Healthcare I.T. Conference
2014-10-13    
All Day
Join us at our 2014 Hospital & Healthcare I.T. Conference and experience the following: Up to 125 Hospital & Healthcare I.T. executives from America’s most prestigious [...]
Connected Health Care 2014
Key Trends That will be Discussed at the Conference! Connected Healthcare 2014 is set to explore the crucial topics that are revolutionizing the connected health industry: [...]
HealthTech Conference
2014-10-14    
All Day
HealthTech Capital is a group of private investors dedicated to funding and mentoring new "HealthTech" start ups at the intersection of healthcare with the computer [...]
Health Informatics & Technology Conference (HITC-2014)
2014-10-20    
All Day
Information technology has ability to improve the quality, productivity and safety of health care mangement. However, relatively very few health care providers have adopted IT. [...]
HIMSS Amsterdam 2014
2014-10-20    
12:00 am
About HIMSS Amsterdam 2014 This year, the second annual HIMSS Amsterdam event will be taking place on 6-7 November 2014 at the Hotel Okura. The [...]
Patient Portal Functionality and EMR Integration Demonstration
2014-10-22    
2:00 pm - 3:30 pm
This purpose of this webcast is to present a demonstration to show how the Patient Portal integrates with EMR, as well as discuss how this [...]
Connected Health Symposium 2014
Symposium 2014 - Connected Health in Practice: Engaging Patients and Providers Outside of Traditional Care Settings Collaborating with industry visionaries, clinical experts, patient advocates and [...]
CHIME College of Healthcare Information Management Executives
2014-10-28 - 2014-10-31    
All Day
The Premier Event for Healthcare CIOs Hotel Accomodations JW Marriott San Antonio Hill Country 23808 Resort Parkway San Antonio, Texas 78761 Telephone: 210-276-2500 Guest Fax: [...]
The Myth of the Paperless EMR
2014-10-29    
2:00 pm - 3:00 pm
Is Paper Eluding Your Current Technologies; The Myth of the Paperless EMR Please join Intellect Resources as we present Is Paper Eluding Your Current Technologies; The Myth [...]
Events on 2014-09-30
Events on 2014-10-02
Events on 2014-10-06
Events on 2014-10-09
Events on 2014-10-13
Events on 2014-10-14
Connected Health Care 2014
14 Oct 14
San Diego
HealthTech Conference
14 Oct 14
San Mateo
Events on 2014-10-20
HIMSS Amsterdam 2014
20 Oct 14
Amsterdam
Events on 2014-10-23
Events on 2014-10-28
Events on 2014-10-29
Articles

Aug 25 : Eight dangers of HIPAA noncompliance

homeland security

If your business has any contact with electronic health records or medical information, HIPAA compliance should be on your mind. This includes the obvious medical professional organizations, as well as businesses like insurance agencies, information technology providers and many others.

The consequences of not following HIPAA regulations can threaten to dismantle the very business you worked on creating.

Here are eight reasons every business should care about HIPAA compliance:

1.The HITECH Act and HIPAA Omnibus Rule have substantially increased civil penalties for noncompliance. The penalty cap for HIPAA violations was increased from $25,000/year to $1,500,000/year per violation. Any complaint, breach or discovered violation can initiate mandatory investigations.

2.New breach notification rules will increase the number of HIPAA violations determined to be breaches. The HIPAA Omnibus Rule expands the definition of a breach and the consequences of failure to address it properly. The breach and failure to report it can trigger federal investigations and eventual fines and penalties, which can in turn financially cripple a business from running to its best ability.

3.All covered entities must have documented policies and procedures regarding HIPAA compliance. Recently, a dermatology practice in Concord, Mass., learned this lesson the hard way, getting slapped with a $150,000 fine for allowing the health information of just 2,200 individuals to be compromised via a stolen thumb drive. The company also had to incur the cost of implementing a corrective action plan to address privacy, security, and breach notification rules.

4.Business associates are now required to be compliant with HIPAA privacy and security rules. Covered entities (health care provider, health care plan or health care clearinghouse) are responsible of holding this standard toward their business associates (a person or entity that performs certain functions that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity) through a business associate agreement, which lays out the permitted and required uses of protected health information.

5.While meaningful use incentives for electronic health records (EHR) are optional, HIPAA compliance is not. If you manage protected health information (PHI), you must comply with federal regulations or face substantial civil and criminal penalties. If a covered entity accepts meaningful use funding, a security risk analysis is required — and any funding may have to be returned if adequate documentation is not provided upon request.

6.The Department of Human & Health Services’ (HHS) Office of Civil Rights (OCR) is expanding its Division of Health Information Privacy enforcement team. The federal bureau is stepping up hiring for HIPAA compliance activities, calling for professionals with experience in privacy and security compliance and enforcement.

7.HIPAA compliance requires staff privacy and security training on a regular basis. All clinicians and medical staff that access PHI must be trained and retrained on proper HIPAA procedures. Documentation of provided training is required to be kept for six years.

8.Protecting your practice means protecting your reputation. The list of health care organizations reporting major breaches and receiving substantial penalties is growing at an alarming rate. It has reached a point where there is a large risk in losing so many clients that a business is unable to bounce back.

In order to avoid the violations above, it is important to sign a business associate agreement with all partners, as well as implement regular internal training for every employee that comes into contact with health care documents. This agreement lays out the business associate’s obligations and activities, as well as the permitted uses and disclosures.

If this step is not taken, the consequences of a health care-related data breach can include not just civil and criminal penalties but also damage to your company’s reputation.

— Rich Szymanski is president of CMIT Solutions of Appleton, which offers technical support and IT services to businesses.

Source