BC Advantage - 2013 Issue 6
The HIPAA Security Rule: Yes, It's Your Problem
Subscribe or sign in to view the full article.
Article Overview
This article discusses HIPAA Security Rule compliance for small covered entities and explains why simply having privacy-related paperwork is not enough. It is aimed at healthcare providers, clearinghouses, health plans, and others responsible for protecting electronic protected health information, with broad guidance on administrative, physical, and technical safeguards, organizational accountability, and risk reduction efforts. The piece also touches on related HIPAA and HITECH developments, compliance misconceptions, and the practical consequences of security failures.
Why This Topic Matters
It helps readers understand that HIPAA security obligations apply directly to their organization and that implementation, not just written policy, is central to compliance. The topic is especially relevant for practices trying to assess risk, allocate resources, and avoid penalties, audits, and reputation damage.
Article Sections
-
The big mix-up: HIPAA compliance is two-fold
Introduces the relationship between HIPAA’s major rule sets and why confusion between them can leave organizations with incomplete compliance coverage. It also notes the security-focused framework discussed later in the article.
-
Policy vs. implementation
Discusses the difference between having written policies and actually carrying out the associated operational measures. The section emphasizes that the article’s examples are meant to illustrate the broader implementation gap.
-
You have a lot to lose
Reviews the potential consequences of noncompliance, including regulatory, financial, and reputational impacts. It also references public breach reporting and enforcement-related concerns.
-
Why would anyone steal from me?
Addresses why smaller organizations can still be targets and why security lapses may go unnoticed. The section focuses on the threat environment and the vulnerability of electronic information.
-
Best practices
Outlines broad steps small covered entities can consider when organizing a security program. The section covers advisory support, responsibility assignment, budgeting, documentation review, technology evaluation, and gap remediation at a high level.
-
Delaying HIPAA means more work
Concludes with the challenge of postponing compliance efforts and the growing complexity that can come with delay. It reinforces the importance of addressing both privacy and security obligations.
What You Will Learn
- How HIPAA Security Rule concerns differ from general HIPAA privacy compliance
- Why implementation matters in addition to written policies
- What broad categories of risk and consequences are associated with security noncompliance
- What kinds of organizational roles and planning activities support a security program
- Why small healthcare organizations should not assume they are outside the scope of security obligations
Who Should Read This
- Small covered entities
- Healthcare providers
- Clearinghouses
- Health plans
- Compliance staff
- Practice managers
- Healthcare IT and security support personnel
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com