ADVERTISEMENT
Wednesday, March 3, 2021
  • Contact Us
My blog
  • Home
  • Health
  • Medicine
  • Nutrition
  • Fitness
  • Diet
  • Weight Loss
  • More
    • Mental Health
    • Healthcare
No Result
View All Result
  • Home
  • Health
  • Medicine
  • Nutrition
  • Fitness
  • Diet
  • Weight Loss
  • More
    • Mental Health
    • Healthcare
No Result
View All Result
My blog
No Result
View All Result
Home Healthcare

Healthcare HIPAA Compliance Report Finds PHI Security Failures

Healthy by Healthy
December 18, 2020
in Healthcare
0
Healthcare HIPAA Compliance Report Finds PHI Security Failures
585
SHARES
3.3k
VIEWS
Share on FacebookShare on TwitterPin It

By Jessica Davis

December 18, 2020 – The Department of Health and Human Services Office for Civil Rights released an audit report on HIPAA compliance in the sector from 2016 to 2017 based on reviews of selected healthcare covered entities and business associates, which revealed several protected health information security failures.

You might also like

Hillsborough County to open new vaccination site for healthcare workers

Anti-Racism, Health Care Equity Initiative Launched – UBMD Physician’s Group

HEALTH CARE BRIEFING: Medicare Pay Change for Ambulances Eyed

Under HITECH, HHS is required to periodically conduct audits on industry compliance with the HIPAA rules. For its latest report, OCR conducted reviews of 166 covered entities and 41 business associates, which have been notified of the agency’s findings.

“The audits gave OCR an opportunity to examine mechanisms for compliance, identify promising practices for protecting the privacy and security of health information, and discover risks and vulnerabilities that may not have been revealed by OCR’s enforcement activities,” according to the report.

“Through the information gleaned from the audits, OCR has developed, and will continue to develop, tools and guidance to assist the industry in compliance, self-evaluation, and preventing breaches,” it added.

OCR’s auditing processes included comprehensive on-site reviews of documentation and implementation of HIPAA rules at the sites of audited entities. Phase two of the auditing process focused on testing the utility and cost effectiveness of desk audits and compliance with certain areas of the HIPAA rule.

READ MORE: 3 Compliance Considerations for HIPAA-Required Breach Response

The report sheds light on overall compliance with HIPAA, boasting positive findings on several key issues and a host of other privacy and security concerns.

The good news: most covered entities that maintained a website on provided customer services or benefits met the HIPAA requirement to prominently display a notice of privacy practices on the site. 

And many of these audited providers met the timeliness requirements for providing victims with breach notifications. Under HIPAA, breached entities are required to notify impacted patients within 60 days of discovering the incident.

OCR found that most covered entities demonstrated compliance in just two out of seven audited areas.

But overall, OCR found a range of security failures for most of these audited covered entities, with most of these covered entities failing to meet the compliance requirements for other selected provisions of the audit.

READ MORE: HIPAA Compliance: ONC Updates Security Risk Assessment Tool

Namely, most covered entities failed to adequately safeguard protected health information, in addition to failing to ensure an individual’s right to access their health data. HHS has made the HIPAA Right of Access a key priority for enforcement efforts in the last year.

In fact, 89 percent of the audited entities failed to comply with access requirements. Another 67 percent failed to comply with providing the necessary content and to document adequate compliance in their breach notifications.

The audit also found 98 percent of providers failed to provide appropriate content in the Notice of Privacy Practices, with two-thirds failing to or making minimal or negligible efforts to comply with the rule.

In particular, the biggest NPP failure centered around writing a notice written in plain language.

“Business associates achieved audit ratings similar to those achieved by covered entities in security risk analysis and risk management,” according to the report. “Most of the audited business associates (32 of 41) reported not having experienced any breaches of unsecured PHI.”

READ MORE: Ciitizen: ‘Significant Improvement’ in HIPAA Right of Access Compliance

“The audit results of business associates that had experienced a breach primarily identified minimal or negligible efforts to address audited requirements,” it added.

But perhaps the most concerning is that OCR determined most covered entities and businesses associates did not comply with the HIPAA Security Rule provision that requires entities to perform routine risk assessments and risk management practices.

Given the extent of threat sophistication, legacy platform use, and sheer volume of targeted attacks on the sector, failure to perform adequate, routine risk assessments leaves the front door wide open to threat actors.

What’s worse, is that HHS has a range of free support tools to help providers with these crucial tasks, including a security risk assessment tool, a privacy practice model from OCR, and OCR insights on complying with the risk analysis requirements under HIPAA.

“The audit results confirm the wisdom of OCR’s increased enforcement focus on hacking and OCR’s Right of Access initiative,” said OCR Director Roger Severino, in a statement.

“We will continue our HIPAA enforcement initiatives until health care entities get serious about identifying security risks to health information in their custody and fulfilling their duty to provide patients with timely and reasonable, cost-based access to their medical records,” he added.

A review of the audit report can prove useful to covered entities and business associates to strengthen their own HIPAA compliance, while shedding light on the OCR auditing process to bolster privacy and security practices across the enterprise.


Source link

Previous Post

Modelling the shape of the mental health crisis after COVID

Next Post

Global Oncology Precision Medicine Market: Focus on Application Area, Ecosystem Type, Country Data

Healthy

Healthy

Related Posts

Hillsborough County to open new vaccination site for healthcare workers
Healthcare

Hillsborough County to open new vaccination site for healthcare workers

by Healthy
March 2, 2021
Anti-Racism, Health Care Equity Initiative Launched – UBMD Physician’s Group
Healthcare

Anti-Racism, Health Care Equity Initiative Launched – UBMD Physician’s Group

by Healthy
March 2, 2021
HEALTH CARE BRIEFING: Medicare Pay Change for Ambulances Eyed
Healthcare

HEALTH CARE BRIEFING: Medicare Pay Change for Ambulances Eyed

by Healthy
March 2, 2021
Racial Barriers To Alzheimer’s Care Hurt Patients And Families : Shots
Healthcare

Racial Barriers To Alzheimer’s Care Hurt Patients And Families : Shots

by Healthy
March 2, 2021
Understanding the Terms of Health Care Directives | Adler Pollock & Sheehan P.C.
Healthcare

Understanding the Terms of Health Care Directives | Adler Pollock & Sheehan P.C.

by Healthy
March 2, 2021
Next Post
The Global Clinical Nutrition Market is expected to grow by $ 21.47 mn during 2020-2024 progressing at a CAGR of 8% during the forecast period

Global Oncology Precision Medicine Market: Focus on Application Area, Ecosystem Type, Country Data

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Comprehensive Report on Digital Fitness Market 2020 | Size, Growth, Demand, Opportunities & Forecast To 2026

Comprehensive Report on Digital Fitness Market 2020 | Size, Growth, Demand, Opportunities & Forecast To 2026

December 20, 2020
Mobile technology saving lives: changing healthcare systems with simple technological solutions – The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology

Mobile technology saving lives: changing healthcare systems with simple technological solutions – The European Sting – Critical News & Insights on European Politics, Economy, Foreign Affairs, Business & Technology

August 26, 2020

Categories

  • Diet
  • Fitness
  • Health
  • Healthcare
  • Medicine
  • Mental Health
  • Nutrition
  • Weight Loss

Don't miss it

Health Plans’ COVID-19 Coverage Obligations
Health

Health Plans’ COVID-19 Coverage Obligations

March 2, 2021
“A dose of her own medicine” | Dolly Parton receives COVID-19 vaccine after helping fund it
Medicine

“A dose of her own medicine” | Dolly Parton receives COVID-19 vaccine after helping fund it

March 2, 2021
Hillsborough County to open new vaccination site for healthcare workers
Healthcare

Hillsborough County to open new vaccination site for healthcare workers

March 2, 2021
Environmental Factor – March 2021: Environment and mental health — intimately connected, much to learn
Mental Health

Environmental Factor – March 2021: Environment and mental health — intimately connected, much to learn

March 2, 2021
Crim Fitness Foundation launching new Crim 365 healthy lifestyle program – nbc25news.com
Fitness

Crim Fitness Foundation launching new Crim 365 healthy lifestyle program – nbc25news.com

March 2, 2021
Study illuminates issue of childhood exercise vs. diet
Diet

Study illuminates issue of childhood exercise vs. diet

March 2, 2021
My blog

All the latest breaking news on Healthy Eating. Browse The Independent's complete collection of articles and commentary on Healthy Eating

Categories

  • Diet
  • Fitness
  • Health
  • Healthcare
  • Medicine
  • Mental Health
  • Nutrition
  • Weight Loss

Trending

COVID-19 relief, health care reform and more transparency: This week in Michigan politics

Jail officials will look for new mental health provider | News

CarboFix Reviews (Gold Vida)– Does Carbofix Supplement Really Effective For Weight Loss? Review By DietCare Reviews

Ergatta’s CEO reveals how the connected-fitness startup generated $2.5 million in monthly revenues within a year of launching

Recent News

Health Plans’ COVID-19 Coverage Obligations

Health Plans’ COVID-19 Coverage Obligations

March 2, 2021
“A dose of her own medicine” | Dolly Parton receives COVID-19 vaccine after helping fund it

“A dose of her own medicine” | Dolly Parton receives COVID-19 vaccine after helping fund it

March 2, 2021

© 2020 eathealthyandlivehealthy.com

No Result
View All Result
  • Home
  • Health
  • Medicine
  • Nutrition
  • Fitness
  • Diet
  • Weight Loss
  • More
    • Mental Health
    • Healthcare

© 2020 eathealthyandlivehealthy.com

//zuphaims.com/afu.php?zoneid=3399210