HIPAA: Address Risk Factors with These 3 Tips

Subscribe or sign in to view the full article.

Note:  The following article synopsis was NOT provided by AAPC. It was created by Find-A-Code/innoviHealth.

Article Overview

This article is aimed at healthcare organizations, compliance staff, and security professionals responsible for HIPAA privacy and security programs. It discusses an OCR enforcement action involving breach reporting and corrective measures, then presents three high-level areas of focus for reducing HIPAA risk: physical protections, oversight of health IT movement and access, and device/data protection practices. The piece is useful for readers evaluating whether their current safeguards and risk analysis processes are aligned with HIPAA expectations.

Why This Topic Matters

It shows how OCR enforcement can follow gaps in risk analysis and safeguards, making it relevant for organizations that manage ePHI and need to understand broad HIPAA security priorities.

Article Sections

  1. Context

    Provides background on the enforcement action and the organizations involved. Summarizes the general compliance areas implicated and why the matter drew attention from OCR.

  2. Quell Violations with This Advice

    Introduces practical compliance focus areas based on the enforcement example. Frames the remainder of the article around broad risk-reduction topics for HIPAA-covered organizations.

  3. 1. Confirm physical safeguards are rock solid

    Covers facility and equipment protection as part of HIPAA security planning. Discusses general oversight of access, inventory, and physical security controls.

  4. 2. Outline the access, movement, and removal of practice HIT

    Addresses management of health information technology and related administrative oversight. Focuses on organizing responsibility, movement of devices or media, and coordination of security roles.

  5. 3. Encrypt ePHI and maintain device control

    Discusses broader device protection and data safeguarding practices. Emphasizes protective measures for portable technology, access control, and data security programs.

What You Will Learn

  • How an OCR enforcement action can highlight general HIPAA compliance risks
  • What broad categories of safeguards are emphasized in the article
  • How organizations can evaluate their physical security, device oversight, and data protection programs at a high level
  • Why risk analysis and corrective action planning matter for HIPAA-covered entities

Who Should Read This

  • Healthcare compliance professionals
  • HIPAA privacy and security officers
  • Health information technology staff
  • Healthcare administrators
  • Practice managers

Subscribe or sign in to view the full article.

Keep pace with evolving Medicare regulations — and onboard your team — with timely analysis of critical updates interpreted in an easy-to-follow, easy-to-apply format. Your subscription to TCI's Medicare Compliance & Reimbursement Alert will equip you to navigate code and guideline changes, CCI edits, and revisions to modifiers, payer policies, the fee schedule, OIG target areas, and more.

  • Current newsletters added each month
  • Fully searchable archives - over 4200 articles
  • ALL years/issues back to 2003 organized by year and issue
  • Codes mentioned in articles are linked to Code Information pages
  • Code Information pages link back to related articles

This feature is currently unavailable for online purchase. For more information, please call 801-770-4203 or Contact Us.

Thank you for choosing Find-A-Code, please Sign In to remove ads.

Aimee- AI -powered coding assistant - Try it now for Free Would you like Aimee - AI
to help you with this?