In my years working with 'Covered Entities' (or clients who fall under the HIPAA 'umbrella' of compliance), I have met hundreds of people who should know how HIPAA Security impacts them, but they just don't get it...don't get me wrong…I know you're out there. I know there are many who grasp all the details of the rule, I just haven't had the luxury of meeting you, yet.
When it comes to HIPAA Security Rule Compliance, we often find that many clients are hoping that if they don't know the law, they don't have to worry about it. I'm sorry to say, that won't work for long!
The session was supposed to "answer your nagging questions" about the Security Rule. Yet, every question from the audience seemed to be met with ambiguity. Toward the end of the session, the presenter (a lawyer) got what I thought was a softball question, "How often should we change our passwords?". Incredibly, after some impressive tap dancing, the session ended with no questions being answered. I wanted to scream out, "The answer is....
There are many, many things that medical practices (and anyone handling ePHI) has to do in order to maintain 'HIPAA Compliance'. Most of them are, appropriately, aimed at making your data and all patient information safer and more secure. But as much money as we all spend to buy firewalls, pay for security tests and subscribe to network management companies, we tend to miss some of the easiest places to help ourselves.
When working with HIPAA Security with our clients, I find that they often misunderstand what, exactly, it means to be 'HIPAA Compliant'. Especially, when dealing with the Security Rule. Not helping the problem, many vendors will make it sound like all you need to do is buy their product and you'll be 'HIPAA Compliant'.
With audits and investigations on the rise, there is growing sense of foreboding among those who need to be HIPAA compliant. Many are scrambling to "button up" any loose ends before the Feds show up with a ticket book. But there is one thing you really must do if you have any chance to survive an audit or investigation.
Documentation is a major part of HIPAA Security Rule compliance. Aside from your policies and procedures, there are many actions, activities, reviews, logs, assessments and evaluations that must be documented. Get this right and your chances of surviving an audit or investigation will be much higher.
In conversations with health care professionals, I'm often shocked at how little they truly understand about HIPAA Security. Too often, I realize that I'm asking questions that they can't answer (and they should be able to!). I've found that there are 3 areas that most medical practices and managers are missing:
I hear HIPAA Security Rule compliance often referred to with groans and even references to preferring bodily harm than having to deal with it. No doubt, being required to comply with any government regulation is a burden that brings a cost in time, energy and dollars. That cost can be a hard sell to the business owners if they can't see a return (and if they think they can get away with non-compliance). But when you step back and look at what is really required, there are some very positive benefits your business can realize if compliance is done properly.
When technology drives the process, you will end up hitting certain areas and overlooking others. Worse, you miss out on the spirit of what the Security Rule is all about. Find out why and what to do about it.
So, you're feeling good about your level of compliance with the HIPAA Security Rule. That's nice, I suppose. But that feeling is essentially irrelevant.
It doesn’t really matter how you feel about. Nor does it matter how you feel about it. What matters is this -- can you demonstrate it? Can you clearly show how you are complying and that you have been complying for a period of time? Just saying you have will not go very far.
You need to be thinking about....
In all the frenzy to chase meaningful use (MU) stage one dollars, there's one major concern that I have seen. Core objective #15 is too easy to say "Yes" to. Most of the MU Core Objectives require some attestation information or stats. But not #15…simply say "yes" or "no". Say no, and you don't get the dollars.
It seems that a number of folks glaze right over this one with a perspective like, "Yeah, we're securing our network with passwords, antivirus and such…so sure, we're good on #15". Or, they believe that by having performed some semblance of a risk analysis, they're all set. I am sorry to say, if you're in one of these categories, you're likely treading on some very thin ice and flirting with something called fraud.
Security Awareness Ranks 3rd Among Most Investigated Compliance Issues
In the HHS annual report to Congress for years 2009 & 2010, Security Awareness made the department's Top 6 list of compliance issues investigated. The report outlined many of the enforcement activities including complaint investigations, compliance reviews and audits. From the original compliance date through December 31, 2010, the compliance issues investigated most by OCR with regard to the Security Rule, compiled cumulatively in order of frequency, were:

So…you're looking at the HIPAA Security Rule and thinking, "This has been around since 2005!?". Yep, it sure has. It just hasn't been enforced until recently (you can thank ARRA & HITECH for that). But don't fret, you can do this. You should do this…in fact, it's actually pretty good stuff.
If you previously thought the HIPAA Security Rule was just making sure you have network passwords, antivirus, a decent data backup and doing something called a "risk analysis", but are now coming to realize that it's a pretty significant component of HIPAA, then welcome aboard friend. It doesn't get better until you grab the bull by the horns. So grab a pair of gloves, cowboy, and let's get started!