E/M Coding Alert - 2016 Issue 28
Compliance: Worried About the Loss or Theft of PHI in Your Practice Due to Cyberattack?
Subscribe or sign in to view the full article.
Article Overview
This article discusses the compliance implications of lost or stolen protected health information (PHI) in the context of cyberattacks and other security incidents. It explains why breaches matter, references federal privacy and security guidance, and outlines broad preventive and response practices for covered entities and business associates. The content is relevant to providers, compliance staff, and organizations responsible for safeguarding electronic and paper health information.
Why This Topic Matters
PHI breaches can trigger reporting obligations, investigations, settlements, reputational harm, and potential civil or criminal exposure. Understanding the compliance landscape helps practices prepare for incidents and evaluate business associate relationships before a breach occurs.
Article Sections
-
Background and breach context
Introduces the compliance risk created when PHI is lost, stolen, or exposed through cyber incidents. It also references broader concerns about health care data breaches and federal attention to the issue.
-
Why this matters
Summarizes the importance of breach reporting and the involvement of federal agencies when unsecured PHI is compromised. It also notes the role of business associates and potential regulatory review.
-
Cyberattacks are happening more often
Discusses the increasing prevalence of cyberattacks and their impact on health care organizations and their partners. It mentions trends in settlement activity and industry data on breach frequency and cost.
-
What’s ahead
Addresses how evolving health care delivery models and more sophisticated health IT may affect privacy and security risk. It emphasizes the need to understand business associate relationships and related infrastructure dependencies.
-
Here’s what you can do to protect yourself
Provides broad preventive and response themes for reducing risk and handling a suspected breach. The section focuses on education, monitoring, incident reporting, and vendor due diligence.
-
Final note
Highlights the potential financial, legal, reputational, and patient-impact consequences of PHI loss. It reinforces the seriousness of cyber threats and insider-related risks.
What You Will Learn
- How PHI loss or theft can affect HIPAA compliance
- Which federal privacy and security topics are most relevant to breach response
- Why business associate oversight matters in a cyber incident context
- What broad preventive steps organizations should consider for PHI protection
- How breach-related enforcement risks can extend beyond monetary penalties
Who Should Read This
- Physicians and practice administrators
- Compliance officers
- Health information management professionals
- HIPAA privacy and security staff
- Business associates and health IT vendors
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com