decisionhealth Newsletters, Part B News - 2013 Issue 2 (February)
OCR to providers: Watch for ‘human frailty’ breaches, encryption issues
Subscribe or sign in to view the full article.
Article Overview
This piece covers guidance shared by OCR leadership at the Annual HIPAA Summit about what enforcement staff may focus on under the updated HIPAA framework. It is relevant to providers, compliance teams, privacy/security officers, and other healthcare stakeholders who need a broad view of current HIPAA enforcement themes, audit observations, and consumer-facing privacy requirements. The article discusses breach patterns, training expectations, encryption-related findings, marketing and fundraising restrictions, and issues that may arise when outside surveyors or oversight-related entities request access to patient information.
Why This Topic Matters
Healthcare organizations need to understand current HIPAA enforcement priorities so they can align compliance efforts with areas most likely to draw scrutiny. The article highlights operational and privacy risk topics that affect security programs, workforce practices, and patient communication workflows.
Article Sections
-
Compliance
An overview of the enforcement context and the general HIPAA privacy and security topics discussed at the summit.
-
Train on breaches
Discussion of breach-related observations and the importance of workforce training and compliance culture.
-
What’s OCR looking for?
Remarks on enforcement focus areas, patterns of noncompliance, and examples discussed by OCR leadership.
-
Encrypt or not, but do something
Summary of OCR audit observations related to encryption and related security assessment considerations.
-
Patient power
Consumer-facing privacy topics, including marketing communications, fundraising, and access requests from outside entities.
What You Will Learn
- The general HIPAA privacy and security themes emphasized by OCR leadership
- How breach prevention and workforce training were framed as compliance priorities
- What types of organizational privacy and security issues were discussed in connection with enforcement
- How OCR presented encryption-related audit observations at a high level
- Which patient communication and outside-access topics were highlighted under the mega-rule
Who Should Read This
- Healthcare providers
- HIPAA compliance professionals
- Privacy officers
- Security officers
- Health system administrators
- Medical practice managers
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com