E/M Coding Alert - 2016 Issue 27
HIPAA: Are Your EHR-Contingency Plans HIPAA-Ready?
Subscribe or sign in to view the full article.
Article Overview
This article covers HIPAA contingency planning for electronic health record disruptions and explains why disaster readiness matters for covered entities. It summarizes an OIG report, references guidance from HHS, NIST, and ONC, and outlines general areas practices and hospitals should consider when evaluating their emergency preparedness processes.
Why This Topic Matters
Health care organizations rely on EHR access during emergencies, so contingency planning affects patient safety, continuity of operations, and compliance readiness. The article is relevant to practices, hospitals, compliance staff, and health IT teams looking for a high-level understanding of federal expectations and preparedness resources.
Article Sections
-
Background
Introduces the HIPAA contingency planning context for covered entities and discusses the federal security-rule framework for EHR disruption preparedness. It also references the related OIG review and the types of disruptions considered.
-
Results
Summarizes findings from the OIG report and describes the survey and site-visit context used to evaluate hospital contingency planning practices. It also notes the role of federal guidance in the review.
-
What The Report Uncovered
Discusses general shortcomings found in contingency planning and the impact those gaps can have on care delivery during EHR disruption. The section remains focused on the report’s broad observations rather than detailed instructions.
-
Five important rules
Outlines the broad categories of policy and process elements the report says should be reflected in a complete contingency plan. The section frames these as planning areas for compliance and operational readiness.
-
Here Are Some Quick Tips to Help You Plan Accordingly
Provides general preparedness themes for organizations developing or reviewing contingency strategies. It includes high-level considerations involving guidance resources, staff readiness, equipment, communication, and ongoing review.
-
Physician Approved
Addresses clinical continuity considerations within contingency planning, including care-related concerns during EHR disruption. The section is presented as part of broader preparedness guidance.
-
Training and Practice
Covers staff awareness and preparation for disaster scenarios affecting EHR availability. It emphasizes planning and readiness as organizational responsibilities.
-
Back-up and Machinery
Discusses backup planning for systems and auxiliary equipment that may support operations during emergencies. The focus is on resilience planning rather than technical implementation details.
-
Communication and Audit
Highlights communication continuity and periodic testing or review of contingency plans. It addresses ongoing maintenance of preparedness processes.
What You Will Learn
- How HIPAA contingency planning relates to EHR disruption preparedness
- What broad areas federal guidance and reports emphasize for disaster readiness
- Which organizations are referenced as sources of guidance on contingency planning
- What general topics are commonly included in hospital and practice emergency planning reviews
Who Should Read This
- Health care providers
- Hospitals and medical practices
- Compliance staff
- Health information technology teams
- Medical office administrators
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com