tci Medicare Compliance & Reimbursement - 2018 Issue 5
HIPAA: Address Risk Factors with These 3 Tips
Subscribe or sign in to view the full article.
Article Overview
This article is aimed at healthcare organizations, compliance staff, and security professionals responsible for HIPAA privacy and security programs. It discusses an OCR enforcement action involving breach reporting and corrective measures, then presents three high-level areas of focus for reducing HIPAA risk: physical protections, oversight of health IT movement and access, and device/data protection practices. The piece is useful for readers evaluating whether their current safeguards and risk analysis processes are aligned with HIPAA expectations.
Why This Topic Matters
It shows how OCR enforcement can follow gaps in risk analysis and safeguards, making it relevant for organizations that manage ePHI and need to understand broad HIPAA security priorities.
Article Sections
-
Context
Provides background on the enforcement action and the organizations involved. Summarizes the general compliance areas implicated and why the matter drew attention from OCR.
-
Quell Violations with This Advice
Introduces practical compliance focus areas based on the enforcement example. Frames the remainder of the article around broad risk-reduction topics for HIPAA-covered organizations.
-
1. Confirm physical safeguards are rock solid
Covers facility and equipment protection as part of HIPAA security planning. Discusses general oversight of access, inventory, and physical security controls.
-
2. Outline the access, movement, and removal of practice HIT
Addresses management of health information technology and related administrative oversight. Focuses on organizing responsibility, movement of devices or media, and coordination of security roles.
-
3. Encrypt ePHI and maintain device control
Discusses broader device protection and data safeguarding practices. Emphasizes protective measures for portable technology, access control, and data security programs.
What You Will Learn
- How an OCR enforcement action can highlight general HIPAA compliance risks
- What broad categories of safeguards are emphasized in the article
- How organizations can evaluate their physical security, device oversight, and data protection programs at a high level
- Why risk analysis and corrective action planning matter for HIPAA-covered entities
Who Should Read This
- Healthcare compliance professionals
- HIPAA privacy and security officers
- Health information technology staff
- Healthcare administrators
- Practice managers
Subscribe or sign in to view the full article.
Thank you for choosing Find-A-Code, please Sign In to remove ads.


Quick, Current, Complete - www.findacode.com