HIPAA Risk Analysis Tip – What Captures OCR’s Attention?

here’s pain in the voices of CISOs who haven’t been able to persuade their executive team to invest in an accurate, thorough enterprise-wide HIPAA risk analysis and risk management plan.

CEOs too often are willing to take on risk to increase revenue rather than mitigate existing risk to avoid cost.  The story goes something like: “We’ll never be chosen for an audit, less than 200 organizations have been selected.  Even if we do have a breach, it’s unlikely they’ll ever decide to investigate us.  There’s 1800 organizations listed on OCR’s wall of shame, in an industry that has over 10,000,000 organizations responsible for protecting PHI.  What are the chances?!”

OCR investigations and resulting resolution agreements / corrective action plans have increasingly larger $ settlement amounts, broad exposure, reputational damage and on-going incremental operational costs and distraction.  And those enforcement actions often result from circumstances about which OCR wants to highlight to make a specific point.

OCR has demonstrated that all types of organizations are subject to enforcement actions.  Examples include:

  • State Universities – Idaho State University and the University of Mass-Amherst
  • County government – Skagit County Public Health Department
  • Community Services – Anchorage Community Mental Health Services
  • State Government – Alaska Department for Health and Human Services
  • Private Physician Practices – Cancer Care Group and Phoenix Cardiac Surgery
  • Specialty Services – Massachusetts Eye and Ear Infirmary
  • Research institutions – Feinstein Institute for Medical Research

OCR has demonstrated that all types of regulatory violations are subject to enforcement actions.  Examples include:

  • For a breach under 500 Records – Hospice of North Idaho
  • For not filing a required breach report – 1st one following the HITECH Act -BCBST
  • For not reporting breaches in timely manner – Presence Health
  • For lack of institutional oversight – University of Mississippi Medical Center
  • For failure to erase photocopier hard drive – Affinity Health Plan
  • For failure to cooperate – CIGNET
  • Referral from OIG, for marketing without permission – Management Services Organization

OCR has demonstrated that varying trigger events may result in enforcement actions:

  • Nine (9) of the fifty (50) investigations that led to settlement agreements were initiated by complaints?
  • Another four (4) were initiated following news reported in the media.
  • Five (5) others focused on business associates and business associate agreements.
  • Lately, since OCR has fixed their tracking system (thanks to OIG’s recommendation), the reporting of multiple breach reports has stimulated investigative activities and resulted in settlement agreements with six (6) more organizations.
  • Successful hacks have prompted OCR to look into the policies, procedures and evidence of monitoring access, implementing patches, and social engineering training of five (5) organizations, in addition to another five (5) dinged for not having encrypted laptops, thumb drives or mobile devices.

Good news – all the OCR Resolution Agreements / Corrective Action Plans are available for review and learning.

So the short story is that it doesn’t have to be a big breach, or a complex situation, or even a blatant failure for OCR to decide an enforcement action and ultimately a resolution agreement and corrective action plan is in order.

Once they are in, if the case involves ePHI, you can be 100% certain that they will be looking for that risk analysis that would have identified the vulnerability that was exploited by the threat, because controls and safeguards were insufficient to protect the information.  And when that isn’t done, or it isn’t done right, the fines and disruption will follow.

Newsletter

Sign up for our monthly newsletter discussing hot topics and access to invaluable resources.


Related Blogs

Clinical Research Organizations: M&A Goldmine or Data Liability? Why Cybersecurity Must Be on Every Investor’s Radar

Clinical Research Organizations: M&A Goldmine or Data Liability? Why Cybersecurity Must Be on Every Investor’s Radar

The market for clinical trials is experiencing significant momentum in mergers and acquisitions (M&A). Private equity (PE) investment in Clinical Research Organizations (CROs) and Site Management Organizations (SMOs) is being spurred by site consolidation, expansion of specialized services, and technology innovation. These firms are important players in the pipeline of drug development and the best targets for investors who wish to capitalize on healthcare innovation.
8 Easy Ways to Prepare for an OCR HIPAA Compliance Audit

8 Easy Ways to Prepare for an OCR HIPAA Compliance Audit

The Office for Civil Rights (OCR) has officially launched its third round of HIPAA audits, following previous assessments in 2012 and 2016.  Learn 8 easy ways to prepare for an OCR HIPAA compliance audit and safeguard your health information against rising cyber threats. Past audits revealed widespread compliance gaps, prompting increased oversight.
OCR’s Proposed HIPAA Security Rule Notice of Proposed Rulemaking

OCR’s Proposed HIPAA Security Rule Notice of Proposed Rulemaking

In Part 1 of this blog, I provide an overview of OCR’s proposed changes to the HIPAA Security Rule, some commentary on the background, rationale and the potential impact on healthcare, descriptions of key changes in definitions, and OCR’s broader themes. In Part 2, I will dive into specific proposed new or updated standards and implementation specifications and speculate on what may happen next.

Connect
With Us


Let us know who referred you, if you went to an event, found us in search, or liked one of our LinkedIn posts.