General Surgery Coding Alert - 2017 Issue 6
Clip And Save: Keep Your Practice Compliant with This Top 5 List of HIPAA Fails
Subscribe or sign in to view the full article.
Article Overview
This article reviews common HIPAA compliance and security problem areas seen in healthcare settings, with emphasis on practice vulnerabilities, internal assessment, system configuration, monitoring, business associate oversight, and written policies and procedures. It is geared toward healthcare compliance, privacy, and security professionals who want a broad view of where breaches and regulatory problems often arise and what categories of safeguards are discussed.
Why This Topic Matters
HIPAA compliance failures can lead to breaches, investigations, and significant penalties. Understanding the major operational and documentation areas discussed in the article can help practices assess risk and identify where their security program may need attention.
Article Sections
-
Introduction: HIPAA breach risk and internal assessment
The article opens with a discussion of increasing breach activity and the importance of reviewing internal vulnerabilities. It frames the rest of the piece around common areas where healthcare practices lose ground on compliance and security.
-
Human Error
This section focuses on staff-related mistakes and the role of education in reducing security risk. It addresses how people-related weaknesses can affect HIPAA compliance efforts.
-
Configurations
This section discusses system setup and the importance of proper configuration in a healthcare environment. It emphasizes the relationship between technical defaults, access control, and security posture.
-
Logging and Monitoring
This section covers oversight of systems and alerts as part of HIPAA security practices. It highlights why monitoring activity and maintaining visibility are important to detecting problems.
-
Business
This section addresses vendors, business associates, and other third parties that interact with practice data or systems. It focuses on the broader business environment surrounding protected health information and electronic protected health information.
-
Policies and Procedures
This section discusses written documentation and formal security-related procedures. It covers the role of policies in demonstrating compliance and organizing security activities within a practice.
-
Closing note on enforcement and penalties
The article closes with a reminder about enforcement trends and the potential consequences of failing to implement safeguards. It reinforces the compliance and risk-management context of the earlier sections.
What You Will Learn
- The major HIPAA security and compliance areas commonly associated with practice vulnerability
- How internal assessment fits into a broader compliance review
- Why staff education, system setup, and monitoring are recurring security concerns
- How vendor relationships and documentation support compliance efforts
- What kinds of governance and recordkeeping topics are discussed in HIPAA security planning
Who Should Read This
- Healthcare compliance officers
- Privacy and security officers
- Practice administrators
- Medical office managers
- Health IT and information security staff
- Healthcare attorneys
- Revenue cycle and vendor oversight teams
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com