
HIPAA compliance tips for small medical practices
Even small private practice groups are seeing HIPAA violations. Utilize these tips to avoid CMS fines and embarrassment.
You’ve seen the headlines splashed on TV and across the internet: data breaches hit national businesses such as Target, Chipotle, and many
But data breaches don’t just affect large corporate entities, they affect small healthcare organizations as well. Take the case of Holland Eye Laser Surgery in March 2018. Their five-provider group practice saw a data breach which made available the patient records of
In fact, some of the medical records of these patients
Brief primer on HIPAA and data breaches
• The Privacy Rule protects individually identifiable health information held or transmitted by a covered entity or its business associate, in any form, whether electronic, paper, or
• Each entity must analyze the risks to e-PHI in its environment and create solutions appropriate for its own situation.
• The HIPAA Breach Notification Rule requires providers to notify affected individuals, HHS, and in some cases, the media of a breach of unsecured PHI. Most notifications must be provided without delay and no later than 60 days following the
5 tips to help you and your medical staff to avoid data breaches
1. CMS requires organizations to “[i]mplement policies and procedures to prevent, detect, contain, and correct security violations.” (45 C.F.R. § 164.308(a)(1).) Conduct a detailed risk analysis to evaluate the current staff and product deficiencies and create corrective measures.
2. Designate a staff member to train employees on your practice’s HIPAA policies and procedures and spend time going over typical breaches.
3. Hire an outside expert to help your organization with compliance support. Your outside organization should set up monthly meetings with the business owners to evaluate your company compliance program and work with your organization to identify cost-effective resources to keep your company compliant.
4. Customize your internet toolbars with anti-phishing protection. These applications can run website checks and compare them to lists of known phishing sites and alert users.
5. Be suspicious of any email message that asks you to enter or verify personal information through a website or by replying to the message itself. Practice groups and or staff members should never reply to or click the links in such a messages.
Doris Dike, Esq., is the founder and principal the
The information presented reflects general information that is current as of the date it was first published. In light of changes that may occur in the health care regulatory and compliance environments, the author’s presentation of this information might become outdated. Please check with your individual legal and/or compliance advisor(s) or contact the DIKE LAW GROUP prior to taking any significant actions based upon the information and advice presented.
Newsletter
Stay informed and empowered with Medical Economics enewsletter, delivering expert insights, financial strategies, practice management tips and technology trends — tailored for today’s physicians.