Part II: Heed lessons from high-dollar Security Rule settlement

Subscribe or sign in to view the full article.

Note:  The following article synopsis was NOT provided by HCPro. It was created by Find-A-Code/innoviHealth.

Article Overview

This article discusses operational guidance for organizations looking to strengthen HIPAA Security Rule compliance after a high-dollar settlement. It focuses on broad areas such as policy review, monitoring regulatory changes, vendor and contractor oversight, breach notification planning, incident response controls, and ongoing workforce training. The piece is aimed at compliance, privacy, security, and healthcare IT stakeholders evaluating their own policies and third-party relationships.

Why This Topic Matters

It helps organizations understand the kinds of governance, documentation, monitoring, and training practices that can affect security compliance and third-party risk management in healthcare settings.

Article Sections

  1. Policy and procedure updates

    Discusses maintaining and periodically reviewing organizational policies and procedures in response to changing regulations and threats. It also addresses compliance coordination, communication, and use of technology to support policy management.

  2. Vendor and contractor relationships

    Covers due diligence for outside relationships, including oversight practices, contractual planning, and ongoing monitoring of vendor compliance. The section also addresses how organizations may evaluate third-party security posture and related controls.

  3. Incident response and audit controls

    Reviews broad incident response planning, logging, audit practices, and access control considerations. It also touches on security monitoring tools and organizational safeguards for protected health information.

  4. Training never ends

    Focuses on employee training and continuing education as part of an ongoing compliance program. It mentions interactive training formats used to reinforce awareness and adherence.

What You Will Learn

  • How organizations can structure a proactive compliance maintenance process
  • What areas are commonly addressed in vendor oversight and contractual security management
  • Which broad components are involved in incident response and audit readiness
  • How ongoing workforce training supports privacy and security compliance efforts

Who Should Read This

  • Healthcare compliance professionals
  • Privacy and security officers
  • Healthcare IT leaders
  • Practice managers
  • Risk management teams

Subscribe or sign in to view the full article.

Official DecisionHealth® Newsletter Archives includes:

  • Includes over 25,000 articles from:
    • Coder Pink Sheets
    • Part B News
    • Answer Books newsletters
  • Current newsletters added each quarter
  • Timely news and guidance vital for your practice
  • Fully searchable through Find-A-Code's Comprehensive Search
  • Codes mentioned in articles are linked to the Find-A-Code Code Information pages
  • Code Information pages link back to related articles
  • Save yourself tons of research time, find everything in one place!
Access to this feature is available in the following products:
  • DecisionHealth Coding, Billing and Compliance Library

Related Articles

Articles are listed in order of calculated relevance.

demo
request yours today
subscribe
start today
newsletter
free subscription

Thank you for choosing Find-A-Code, please Sign In to remove ads.

Aimee- AI -powered coding assistant - Try it now for Free Would you like Aimee - AI
to help you with this?