Outpatient Facility Coding Alert - 2014 Issue 11
Practice Management: Avoid Brutal HIPAA Fines With These 3 Steps
Subscribe or sign in to view the full article.
Article Overview
This article explains how general surgery and other health care practices can use lessons from HITECH-mandated breach and compliance reports to reduce HIPAA risk. It focuses on broad compliance themes such as protecting information stored on devices and older systems, monitoring business associates and subcontractors, and recognizing the significance of repeated smaller breaches in security risk assessments. The piece is aimed at practice managers, compliance staff, and covered entities seeking a high-level understanding of current privacy and security concerns.
Why This Topic Matters
It helps practices understand which operational areas are most associated with breach exposure and why recurring minor incidents can signal broader compliance problems. That makes it relevant for organizations reviewing HIPAA privacy, security, and breach-response readiness.
Article Sections
-
Ratchet Up Your Theft-Prevention Efforts
Discusses breach trends related to theft and the need to strengthen security for information stored on older systems and portable devices. The section also frames the relevance of mobile-device policies and general safeguards for protected health information.
-
Keep a Close Eye on Your BAs
Reviews the role of business associates and subcontractors in breach reporting and emphasizes organizational oversight. The section focuses on vendor-related compliance responsibilities under HIPAA privacy and security requirements.
-
Beware the Cumulative Effects of Small Breaches
Explains why repeated smaller breaches can be a meaningful compliance concern even when no single incident is large. The section highlights risk assessment, identifying gaps, and addressing systemic issues.
What You Will Learn
- How breach-report trends can inform HIPAA compliance priorities
- Why device and storage security is a recurring concern in breach analysis
- Why business associate oversight matters in privacy and security compliance
- How repeated smaller breaches can signal broader organizational risk
- How risk assessments are used to identify and correct compliance gaps
Who Should Read This
- Practice managers
- Compliance officers
- Privacy and security staff
- Covered entities
- Business associate oversight teams
- General surgery practices
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com