HIPAA: Rein in Your Risks Before a Crisis Hits

Subscribe or sign in to view the full article.

Note:  The following article synopsis was NOT provided by AAPC. It was created by Find-A-Code/innoviHealth.

Article Overview

This article is a compliance-focused overview for healthcare organizations, privacy and security officers, and coding/billing-adjacent administrators who need to understand HIPAA Security Rule risk analysis expectations. It explains why risk analysis remains important during the COVID-19 public health emergency, summarizes guidance from HHS OCR, CMS, and NIST, and describes broad steps for identifying, evaluating, documenting, and prioritizing security risks affecting electronic protected health information.

Why This Topic Matters

Conducting and documenting a risk analysis is central to HIPAA Security Rule compliance, and gaps can lead to enforcement exposure. The article helps readers understand the scope of required planning and the kinds of organizational safeguards that should be reviewed.

Article Sections

  1. Context and compliance emphasis during the public health emergency

    Introduces why HIPAA compliance remains important during the COVID-19 public health emergency and frames the article’s focus on electronic information handling.

  2. Heed This Expert Security Rule Insight

    Summarizes expert commentary on the need for risk analysis and the general approach to identifying organizational risk points and assessing them.

  3. Add These 8 Steps to Your Security Planning

    Outlines a structured, high-level process for examining scope, data flows, threats, existing safeguards, likelihood, impact, risk level, and documentation.

  4. Small practice advice

    Discusses how the compliance approach may differ for smaller organizations and notes the importance of documenting risk analysis activities and related security processes.

  5. Resources

    Points readers to external reference materials from NIST and HHS OCR for further information on Security Rule guidance.

What You Will Learn

  • How HIPAA Security Rule risk analysis is positioned in the article
  • What broad categories of information and systems should be reviewed
  • How organizations can organize a risk assessment process at a high level
  • Why documentation and prioritization of risks matter
  • How the article frames compliance considerations for smaller practices

Who Should Read This

  • Healthcare compliance professionals
  • Privacy and security officers
  • Practice managers
  • Covered entities
  • Business associates
  • Small medical practices

Subscribe or sign in to view the full article.

Keep pace with evolving Medicare regulations — and onboard your team — with timely analysis of critical updates interpreted in an easy-to-follow, easy-to-apply format. Your subscription to TCI's Medicare Compliance & Reimbursement Alert will equip you to navigate code and guideline changes, CCI edits, and revisions to modifiers, payer policies, the fee schedule, OIG target areas, and more.

  • Current newsletters added each month
  • Fully searchable archives - over 4200 articles
  • ALL years/issues back to 2003 organized by year and issue
  • Codes mentioned in articles are linked to Code Information pages
  • Code Information pages link back to related articles

This feature is currently unavailable for online purchase. For more information, please call 801-770-4203 or Contact Us.

Thank you for choosing Find-A-Code, please Sign In to remove ads.

Aimee- AI -powered coding assistant - Try it now for Free Would you like Aimee - AI
to help you with this?