E/M Coding Alert - 2011 Issue 10
Patient Privacy: Keep HIPAA Concerns at Bay With Simple Risk Analysis
Subscribe or sign in to view the full article.
Article Overview
This article covers HIPAA privacy and security risk management in the context of HITECH-era enforcement changes. It discusses why risk analysis matters, the types of information systems and workflows that should be reviewed, and broad operational areas that can increase exposure, such as portable devices, encrypted data handling, remote access, and audit preparation. It is relevant to healthcare providers, compliance staff, and organizations that manage electronic protected health information.
Why This Topic Matters
Organizations handling electronic protected health information need to understand where privacy and security risks can arise and why enforcement attention may increase when risks are not identified and addressed. The article helps readers gauge whether the topic is relevant to their HIPAA compliance and security practices.
Article Sections
-
Willful Neglect Penalties and HITECH Background
Introduces the enforcement context surrounding HIPAA privacy and security violations and the HITECH-era changes discussed in the article.
-
Nail Down the Essentials for Risk Analysis
Outlines the article’s discussion of general risk analysis concepts and the systems and information flows that should be reviewed.
-
Target These 2 High-Risk Areas
Covers broad categories of operational risk involving portable devices, electronic communication, and related safeguards.
-
Watch Out for Remote Access
Discusses remote work and offsite access as compliance and security concerns for organizations handling sensitive electronic information.
-
Don't Forget a Crucial Compliance Step: Auditing
Summarizes the article’s attention to auditing and oversight as part of ongoing HIPAA compliance efforts.
What You Will Learn
- How the article frames HIPAA privacy and security risk analysis
- Which general operational areas are highlighted as higher risk
- Why auditing is part of the broader compliance discussion
- How HITECH-era enforcement is presented in relation to HIPAA
- What kinds of organizational workflows the article says to review
Who Should Read This
- Healthcare providers
- Compliance officers
- Privacy and security staff
- Healthcare administrators
- Medical practice managers
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com