• No results found

HIPAA Self-Audit: Locating Threats, Correcting Vulnerabilities, and Protecting Patient Information

N/A
N/A
Protected

Academic year: 2021

Share "HIPAA Self-Audit: Locating Threats, Correcting Vulnerabilities, and Protecting Patient Information"

Copied!
15
0
0

Loading.... (view fulltext now)

Full text

(1)

HIPAA Self-Audit: Locating

Threats, Correcting

Vulnerabilities, and Protecting

Patient Information

Margret Amatayakul, MBA, RHIA, CHPS, CPEHR, CPHIE, CPHIT, FHIMSS 847-895-3386 [email protected]

(2)

Speaker Info

Margret Amatayakul, MBA, RHIA, CHPS, CPEHR, CPHIE, CPHIT, FHIMSS

Margret Amatayakul is a health information management professional with over 25 years of experience in the healthcare industry, including providing medical record department services, health informatics education, association

management and advocacy, and information systems consulting. During her extensive career, Margret has been actively engaged in many of the major health informatics standards development organizations, has led industry organizations and consortia in contributing to the government regulatory process relative to HIPAA, and has extensive experience in implementing and monitoring regulatory, accrediting, and industry practice compliance.

Margret founded and served as the Executive Director of the Computer-based Patient Record Institute from 1992 through 1997. She has also held the position of Associate Executive Director of the AHIMA, was an Associate Professor of Health Information Management at the University of Illinois, and was the Director of Medical Record Services at the Illinois Eye and Ear Infirmary. She is a clinical associate professor at the University of Illinois, is a visiting professor at Kuwait University, and adjunct faculty at the College of St. Scholastica.

Widely quoted and sought after as a speaker on computer-based patient record (CPR) systems, Margret has published extensively, serves on several editorial review boards, and is the recipient of the Professional Achievement Award from the American Health Information Management Association, the Professional Achievement, Literary, and Distinguished Service awards from the Illinois Health Information Management Association, the Information Systems Award from the Healthcare Information and Management Systems Society, and the Excalibur Award for Teaching Excellence from the Student Council of the University of Illinois at Chicago.

(3)

**Certificates of attendance and CEUs, when available, must be requested through the online evaluation.**

Evaluation for Live Event:

We’d like to hear what you thought about the audio conference. Please take a moment to

fill in the survey located here:

http://www.c4cm.com/handouts/051415.htm

Requests for continuing education credits and certificates of attendance must be submitted within 10 days of the live event.

Evaluation for CD Recording:

Please use the following link to submit your evaluation of the recorded event:

http://www.c4cm.com/handouts/CDEval.htm Please note: All links are case sensitive

(4)

1

© 2015 Margret\A Consulting, LLC

HIPAA Self-Audit:

Locating Threats, Correcting Vulnerabilities, and Protecting Patient Information

Margret Amatayakul,

MBA, RHIA,

CHPS, CPHIT, CPEHR, CPHIE, CPORA, FHIMSS President, Margret\A Consulting, LLC An independent consulting firm focusing on preparing

for and optimizing EHR and health IT provisions of HIPAA, HITECH, and ACA.

2

\A Consulting, LLC

Agenda

 Implementing an internal HIPAA auditing program  Processes to conduct a risk analysis to identify gaps,

update documents, and retrain staff on latest policies and procedures

 Establishing a baseline for progress monitoring  What to include in a prioritized remediation plan

 Best practices for documenting compliance policies and

procedures

 Why organizations should go beyond OCR’s online audit

protocol when conducting an internal HIPAA audit

Reduce risk; be ready

(5)

2

3

© 2015 Margret\A Consulting, LLC

What is internal compliance auditing?

 Ongoing process for compliance assurance

o Assists in identifying weaknesses to enable establishment of

internal controls

o Helps demonstrate commitment to responsible corporate conduct

o Provides accurate view of behavior relative to specific compliance

requirements

o Creates a centralized source for managing compliance

 Most hospitals and large clinics have an internal

compliance program to monitor for coding/billing fraud and abuse –but few have such a program for privacy, security,

and breach notification

4

© 2015 Margret\A Consulting, LLC

What comprises an internal compliance

auditing program?

 Central source for distributing information about

compliance

 Process to determine baseline compliance

 Methodology that encourages workforce members to

report potential problems

 Procedures that allow for prompt and thorough

investigation of a problem

 Initiation of immediate and appropriate corrective action  Minimizes loss through early detection and reporting  Reduces exposure to (external audits) and penalties

(6)

5

© 2015 Margret\A Consulting, LLC

Where does it say to audit for compliance?

 Compliance means ongoing conformance to laws and regulations

 Specifically, HIPAA requires:

o Uses and disclosures to be consistent with notice of privacy practices [Privacy Rule at 45 CFR 164.502(i)]

o Security measures to be reviewed and modified as needed to continue provision of reasonable and appropriate protection [Security standards: General rules at 45 CFR 164.306(e)]

o Periodic technical and nontechnical evaluation in response to environmental changes affecting security of ePHI that establishes the extent to which an entity’s security policies and procedures meet the requirements [Security Rule: Evaluation at 45 CFR 164.308(a)(8)]

 EHR Meaningful Use Incentive Program [42 CFR 495.6] measures

require:

o Conduct or review a security risk analysis in accordance with requirements under 45 CFR 164.308(a)(1)

 OCR “encourages consistent attention to compliance activities”

(Linda Sanches, OCR Senior Advisor)

6

\A Consulting, LLC

Business case for internal auditing for

HIPAA privacy, security, and breach

 OCR (HIPAA) and CMS (EHR Meaningful Use) audits reveal serious

weaknesses (see next slide)

 Ever-increasing number of privacy complaints to OCR

 Increasing number and amount of settlements for privacy and security

issues; expected increase in number of criminal cases

 Major HIPAA breaches have reached 1,000 milestone, with 1 in every

10 people in U.S. impacted

 Cost of a breach estimated at $188 per record. Average # of records

in a breach = 23,647; or $4.4M per breach

 Identity theft may be most frequent, costly, and pervasive crime in

U.S., with increasing sophistication

43% of identity thefts have a medical component, including potential for treatment and payment errors

(7)

4

7

© 2015 Margret\A Consulting, LLC

OCR Audit Results

8

© 2015 Margret\A Consulting, LLC

Level setting on terminology

Action: The performance of a process that is regulatedComplaint: Statement that a situation is unsatisfactory or

unacceptable

Event: An action that may contribute to noncompliance

Incident: An event that is noncompliant, or series of events that puts

the organization at high risk for noncompliance

(HIPAA) breach: Acquisition, access, use, or disclosure of PHI in a

manner not permitted by the Privacy Rule that compromises the security and privacy of the PHI

HIPAA safe harbor: Guidelines specifying that encryption or

destruction render PHI unusable, unreadable, or indecipherable for purposes of breach notification

(General) data breach: An incident in which sensitive, protected, or

confidential data have potentially been viewed, stolen, or used by an individual unauthorized to do so

(8)

9

© 2015 Margret\A Consulting, LLC

Implementing internal auditing

 IPO, ISO, compliance officer(s), risk manager, legal

counsel, develop coordinated program

 Determine focus of auditing; use sources such as:

o Establish baseline for progress monitoring o Frequent privacy complaints

o Known security threats

o Most common causes of breaches o Findings from federal audits

o Random spot checks for new vulnerabilities

 Creates culture of:

o Transparency o Hold harmless o Data stewardship

o Commitment to risk mitigation

10

\A Consulting, LLC

Internal compliance audit cycle

(9)

6

11

© 2015 Margret\A Consulting, LLC

Compliance assurance plan template

12

© 2015 Margret\A Consulting, LLC

Example compliance assurance plan:

(10)

13

© 2015 Margret\A Consulting, LLC

14

\A Consulting, LLC

Conducting a (privacy & security) risk analysis:

A special case of internal auditing

C

I

A

(11)

8

15

© 2015 Margret\A Consulting, LLC

Breach notification preparation

 Create and regularly drill a SWAT team to address a breach

 Train members of workforce and ensure business associates know how

to identify and report a potential breach in a timely manner

 Have prepared decision tree to assess whether potential breach meets:

o HIPAA definition and/or

o State data breach definition (Note: not all state breaches are HIPAA breaches)

 Have prepared a checklist of tasks, including:

o Notification to executive management; legal counsel; board of directors o Documentation of all steps taken, by whom, and when

o Preservation of evidence

o Management of business associate relationships as applicable

 Have prepared public notification process and materials, including

public announcement script

 Conduct required notification, reporting, and mitigation

 Assess and take action on lessons learned

16

© 2015 Margret\A Consulting, LLC

External audit preparedness

 Ten-fold increase in audits anticipated. Still no word on whether these

will be desktop or onsite; whether they will be risk-based or comprehensive standards based. Do not assume same protocol

 Have ready all documentation not only P&P but documentary

evidence, ideally with index arranged in order of regulatory standards

(12)

17

© 2015 Margret\A Consulting, LLC

External audit preparedness (cont.)

 Decide how sensitive documentation will be identified and

supplied

 Consider legal counsel review of documentation prior to

submission

 Provide copy with any patient or health professional

identification masked but which contains name of organization on every page and running page numbers

18 \A Consulting, LLC

Documentation

45 CFR 164.530 (j) [Privacy Rule] Documentation oMaintain

• Policies and procedures • Communications required to be

in writing

• Records of actions, activities, or

designations required to be writing

• Documentation sufficient to meet

burden of proof oRetain

•For 6 years from date of creation

or date when last in effect, whichever is later

Lack of, or poor, documentation is one of major findings in (HIPAA and Meaningful Use) audits and findings in OCR settlement cases

45 CFR 164.316 [Security Rule]

o(a) Policies and procedures, taking into consideration flexibility of approach o(b)(1) Documentation of

• Policies and procedures

• Record of action, activity, or assessment as

required o(b)(2)

• Time limit: Retain for 6 years …

• Availability: Make available to persons

responsible for implementing procedures to which documentation pertains

• Updates: Review documentation periodically

and update as needed in response to environmental or operational changes affecting the security of ePHI

(13)

10

19

© 2015 Margret\A Consulting, LLC

Policies and Procedures

20

© 2015 Margret\A Consulting, LLC

Many sources of policies and procedures

 Many policies exist already

o Management o Human resources o Public relations o Procurement

o Institutional review board

o Medical staff bylaws, rules, and regulations o Others

 Ensure HIPAA is explicitly identified, or catalogue generic policies and

procedures (e.g., sanction policy) under a HIPAA umbrella

 Ensure HIPAA procedures are not copies of the regulation, but specific

step-by-step descriptions written in plain language that guide work

 Recognize the sensitivity of certain procedures and documentation; handle

appropriately (e.g., penetration test procedure including identification of all IP addresses)

(14)

21

© 2015 Margret\A Consulting, LLC

Documenting (privacy and security) risk

analysis and remediation priorities/plan

Extend spread-sheet for project plan 22 \A Consulting, LLC

Documentation pitfalls

 Maintaining action logs in help desk ticketing system or IT staff member’s

email is generally not conducive to:

o Producing documentary evidence for an audit o Conducting pattern analysis to identify issues o Retention assurance

o Accessibility to authorized individuals

 Buying policies and procedures and not changing them to fit your environment

All policies and procedures carrying the same effective date, and with no version history Logs maintained without case files

 Documentation without analysis (e.g., records of breaches without risk

assessment documented)

 Risk analysis without remediation plan/evidence of completion

 Integrating federal and state breach files; all forms of compliance (e.g., coding

(15)

12

23

© 2015 Margret\A Consulting, LLC

Training

 Most providers include HIPAA privacy and security training during

orientation; thereafter in an annual compliance training requirement

o Ensure content is updated annually

o Ensure content reflects current trends in industry; issues in environment

 Annual training is not enough. Privacy, security, and breach

awareness need to be part of organizational culture

o Managerial staff need to walk the talk and be held accountable o Use “teachable moments”

o Discuss noteworthy complaints/incidents in newsletters, meetings, etc. o Patients also need “training;” waiting room CCTV, newsletters; website

information; “non-negative” clinician reinforcement

 Don’t put fear into HIPAA

o Many organizations have paralyzed staff into inaction that potentially is

harmful to the organization and the clinical care delivered to its patients

o Find ways to protect privacy and address the CIAof security in positive

ways; ensure transparency and stewardship

24

© 2015 Margret\A Consulting, LLC

Q & A

References

Related documents

fold corners, aligning edge with crease.. fold down and in from

Table 6.9: Significant t-test results for percentage of 3 years or younger products in total sales trend in last 3 years and financial performance………....153 Table 6.10: Significant

 

In formulating investment advice as an independent consultant, InvesTrust Consulting’s methods of analysis include conductive asset allocation studies; if the Client does not have

If you observe or suspect that the confidentiality or security of a patient’s health information has been violated, you must report it to your supervisor, or the SUNY Upstate

The accompanying areas of audit emphasis (HIPAA technical safeguards security standards) presents fairly, in all material respects, the aspects of Vigilant Medical’s

There is no suggestion that the liability is being held for trading purposes nor that the option to have it classified as FVTPL has been made, so, as is perfectly normal,

of the All-India Forward Bloc, the acting chairman of the Communist Party of Germany, the chairman of the Socialist Party of Romania, the general secretary of the