Showing posts with label HIPPA Compliance. Show all posts
Showing posts with label HIPPA Compliance. Show all posts

Wednesday, October 23, 2013

Navigating The Compliance Maze of Secure Text Messaging in Healthcare

Understanding the impact of secure text messaging in healthcare and the potential risks of privacy that come into play when a doctor texts a patient. 
Everyone is texting — even your doctor. And that means a world of possibility when it comes to making appointments, finding out about new treatment options or simply asking a question about medical issues. But it also opens up potential privacy issues that can mean troubled times for physicians who are trying to stay HIPAA-compliant.
Texting and healthcare privacy laws
Navigating The Compliance Maze of Secure Text Messaging in HealthcareSending a text has become a quick, easy way to communicate, and people of all ages are embracing it. Those under the age of 30 are more likely to engage in online interaction with doctors, according to the National Community Health Survey by The Atlantic and GlaxoSmithKline. Older adults are taking advantage of the Internet and cell phones as well; in 2012, over 69 percent of all adults over the age of 65 had a cell phone, according to the Pew Internet and American Life Project. A separate Pew Internet study showed that texting is here to stay, as 73 percent of all cell phone users reported sending texts at least occasionally.
Many physicians and other healthcare professionals are taking advantage of the opportunity to reach their patients via cell phone. A 2012 New York Times article profiled physicians who are using cell phones as a way to reach and teach their teenage patients, while a 2012 article from Social Work Today pointed out ways that older Americans can make use of healthcare texting, including medication reminders and compliance alerts.
When a doctor texts a patient, questions of privacy come into play. Texting is generally not considered a secure way of relaying information, as cell phones can and do get lost or other people might read the texts meant for a particular person, among other potential problems. But when healthcare professionals text each other, the issues of privacy become even trickier.
HIPAA-compliant apps to the rescue
Navigating The Compliance Maze of Secure Text Messaging in HealthcareBusy physicians might find voice messages or paging to be a cumbersome way of communicating, especially when they have a lightning-fast smartphone in their pocket. In a world where time is of the essence, cutting out the long delays for physicians to give orders, talk to patients or follow up on test results could make a significant difference in the lives of patients. AsBecker’s Hospital Review points out, nurses spend a hour each day tracking down physicians, and that’s just the tip of the inefficient healthcare communication iceberg.
However, the problems with texting are clear: Text messages can sometimes get sent to the wrong person, and even if it gets to the correct number, the text could be read by someone other than the recipient. The information can be forwarded to anyone, and could remain on phones for indefinite amounts of time. In addition, if a phone gets lost — as they often do — a plethora of patient information could be compromised.
Doctors and patients have already embraced the idea of mobile apps for healthcare, so it’s no surprise that secure healthcare texting may depend on mobile apps as well. Healthcare texting applications allow physicians, nurses, and other healthcare professionals to communicate quickly and clearly, without worry about violations of the Health Insurance Portability and Accountability Act (HIPAA). In order to ensure patient confidentiality, the Joint Commission created Administrative Simplification Provisions (AS) designed to protect information sent via text message. The four rules for compliance include secure data centers, encryption of messages, recipient authorization and audit controls, according to the American Association of Orthopaedic Surgeons.
One of the first entries into the world of HIPAA-compliant texting applications is Doc Halo, a text system that has become the professional standard. The early success of the program has spurred other applications, such asTigerText or Sprint Enterprise Messenger — Secure, both from Sprint, andCortext, from IT security company Imprivata. The success of these apps mean that an avalanche of mobile applications are coming soon, and healthcare professionals will have plenty of options.
Navigating the world of healthcare texting
Though these applications can make texting secure between healthcare professionals, texts sent to patients can still create privacy concerns. As such, healthcare professionals should always use their best judgment in deciding how far to take text communications. Some physicians might be comfortable with appointment reminders or alerts to test results received, while others might be willing to answer general health questions.
Yet to be determined are the ways texting will change a medical practice or patient-doctor relationship. For instance, will texting with doctors be a billable service? How many texts are appropriate? What hours are appropriate? And how will doctors handle those patients who are happy to text for all their needs, but balk at the idea of coming into the office for a face-to-face consultation or physical exam?
Just as text messaging between physicians and other healthcare providers is changing, expect to see changing dynamics of texting and other social media pursuits between doctors and patients — and more mobile apps that make healthcare texting much more secure than it is today.
About the Author:
Shannon Dauphin Lee has been writing professionally for two decades on a wide variety of topics, including medical and health issues, education, home repair and relationships. She is a contributor to several websites, includingAlliedHealthWorld.com.

Thursday, October 3, 2013

Google agrees to sign BAA as means to HIPAA compliance

Google removes a barrier to Google Apps adoption by offering to sign BAA for organizations that need to comply with HIPAA. 
HIPAA.gif
In September 2013, Google offered for the first time to sign a HIPAA Business Associate Agreement (BAA) available for Google Apps. That's good news for organizations unwilling to deploy Google Apps without such an agreement. It is also a smart competitive move, as it matches Microsoft, which offers to sign a BAA for Office365.

HIPAA: The basics

For those who may be unfamiliar, HIPAA (Health Insurance Portability and Accountability Act), refers to a set of laws passed in the United States in 1996. The laws seek to limit access to individually identifiable healthcare information to those that "need to know". HIPAA holds healthcare industry professionals accountable for the privacy of patient information.
Effective HIPAA compliance implementations resemble effective security systems: they're designed with the aim of protecting individually identifiable health information (IIHI). Such information is broadly referred to as "protected health information", or PHI. This information includes an individual's name, address, and any information related to the individual's health or payment records. A Business Associate Agreement (BAA) provides written assurances that an organization's partners will also seek to secure an individual's PHI.

Google Apps BAA

Google's BAA agreement covers three Google Apps services (Gmail, Calendar, and Drive), along with the Google Apps Vault service, which archives user data from the other three services. To sign up, an Administrator for the Google Apps domain must answer three questions online. From the website:
  1. Are you a Covered Entity (or Business Associate of a Covered Entity) under HIPAA?
  2. Will you be using Google Apps in connection with Protect Health Information?
  3. Are you authorized to request and agree to a Business Associate Agreement with Google for your Google Apps domain?
After responding, the Administrator will be taken to the BAA document for signature. As of September 27, 2013, Google is using Adobe's Echosign to obtain digital signatures.

Read before signing

The BAA terms state "...other Google services or third party Marketplace Apps should not be used in connections with PHI. This agreement requires that you disable all Additional services in the Admin console." (Emphasis is mine.)
An organization signing the BAA would not be able to use the domain covered by this agreement for additional useful Google services, such as Google+, Google Groups, or Google Sites. As the terms state, you must disable all Additional services: you may use Gmail, Calendar, Drive and Google Vault. The terms also appear to prohibit the use of Marketplace Apps in conjunction with PHI. (It is unclear whether the terms also prohibit the use of apps intended to secure and protect PHI, such as zSentry. zSentry offers to sign a BAA, and is a third-party app, which may be connected through the Marketplace.)

Implement thoughtfully

If your organization needs HIPAA compliant email, calendars and document storage, then sign the BAA and move forward with the migration. Your organization can adopt Gmail, Calendar, and Drive, confident that IIHI and PHI in those apps will be protected by the BAA.
If your organization is already using Google Apps, review your usage carefully before signing the BAA. If you've already implemented measures to ensure HIPAA compliance, the availability of a BAA may not change anything for your organization. For example, you might already prohibit the use of PHI in Gmail, Calendar and Drive. You might already use tools to audit and verify compliance, such as CloudLock.

Documents don't ensure security

Google-Apps-logo.png
Google's willingness to sign a BAA for organizations that need to comply with HIPAA is helpful and certainly welcomed. It may remove a barrier to adoption for some organizations. But healthcare professionals need to remember that HIPAA compliance, like all IT security, involves complex systems comprised of people, policies, and practices. (For example, you still need effective password policies, security measures such as 2-step authentication, and appropriate user permission settings.)
Signing a BAA doesn't ensure your entire organization is HIPAA compliant: the BAA is just one piece of a complex system needed to protect IIHI and PHI.


Sunday, June 23, 2013

ATTENTION GROUP HEALTH PLAN SPONSORS: ACTION REQUIRED TO COMPLY WITH FINAL HIPAA REGULATIONS

Group health plan sponsors have been focusing to a great extent upon the various
significant requirements imposed by the Patient Protection and Affordable Care Act,
most notably the “play or pay” provisions which become effective in 2014. However,
such sponsors with self-insured plans (including FSAs and HRAs) also need to focus
upon changes to the Health Insurance Portability and Accountability Act (HIPAA)
privacy and security rules which become effective later this year.
Earlier this year, the Department of Health and Human Services (HHS) published
a final rule modifying HIPAA, as amended by the Health Information Technology
for Economic and Clinical Health Act (HITECH) and the Genetic Information
Nondiscrimination Act (GINA). Group health plans, as well as their business
associates, are subject to various changes and generally must comply by September
23, 2013. Accordingly, prompt action is recommended.

The rules are of less concern to fully insured plans, since in those cases plan
sponsors rarely receive protected health information (PHI) other than enrollment and
summary information. Under those circumstances, most HIPAA privacy and security
compliance responsibility rests with the insurer. However, it is of significant relevance
to self-insured health plans maintained by an employer, since the employer then
has access (either directly or through a third party administrator) to the medical
information of its employees and is responsible for complying with HIPAA’s privacy
and security rules.
This Bulletin is not intended to provide an exhaustive summary of the changes
Rather, it is intended to highlight the most significant changes and to suggest action
steps.

Business Associates
The final regulations change the rules for the business associates of group health
plans. Third-party administrators and other consultants or health plan service
providers that have access to PHI in performing services are now directly liable for
the civil and criminal penalties for certain violations of HIPAA. Previously, compliance
had been a contractual obligation pursuant to the written agreement with the covered
entity relative to HIPAA compliance. Therefore, business associates must establish
and maintain policies and procedures to implement required safeguards. Business
associates must enter into written agreements with group health plans and with their
own subcontractors to ensure compliance with HIPAA. Business associates will also
often have a major role in breach notification compliance for group health plans.

The final rule allows for a transition period to renegotiate and revise existing
agreements. Generally, agreements in place as of January 25, 2013 that are not
renewed or modified before September 23, 2013 are considered to be compliant
until they are renewed or modified, or September 22, 2014 if earlier. Agreements
renewed or modified before September 23, 2013 must comply by September 23,
2013. The HHS website contains a revised model business associate agreement.

GINA Compliance
The final regulations implement rules under GINA as it applies to the use and
disclosure of PHI by group health plans and business associates. PHI that is genetic
information may not be used or disclosed for underwriting purposes.

Privacy Policies and Procedures
Self-funded health plans are required to have policies and procedures in place
to protect PHI from unauthorized use and disclosure. Some of those policies and
procedures will need to be revised to reflect the new requirements.

Notice of Privacy Practices
Notices of Privacy Practices will need to be updated to include the following:
• Individuals will be notified upon a breach of PHI.
• The use or disclosure of genetic information for underwriting purposes is
prohibited.
• Written authorization is required for disclosures for marketing purposes and for
the sale of PHI.
The notices will need to be revised and posted on the employer’s website, and copies
of its revised notice should be provided to participants and beneficiaries.

Breach Notification
The final regulations modify the factors that plans and business associates are to
take into account in conducting a “risk assessment” to determine whether a breach
requiring notice to affected individuals, the Department of Health and Human
Services, and in some cases the media, has occurred. A breach requiring notice will
be presumed to have occurred whenever PHI maintained by the plan or business
associate is acquired, accessed, used or disclosed in a manner that violates the
privacy rule. This presumption may be rebutted if the plan or business associate can
demonstrate, pursuant to factors provided under the regulations, that there is a “low
probability” that PHI has been compromised. The previous standard, which required
the violation to pose a “significant risk” of financial, reputational or other harm to the
individual, was eliminated.

Enforcement
The regulations include the civil and criminal penalties that apply to HIPAA violations
by group health plans and their business associates. Monetary penalties vary
according to the number of violations, the cause of such violations, and whether the
group health plan or business associate takes timely action to correct the violation.
Civil penalties can be up to $1.5 million per year for each violation of a standard or
requirement. HHS will continue to conduct random audits and investigate complaints,
and increasingly aggressive enforcement is expected.

Action Items for Group Health Plans
The regulations require immediate action by employers sponsoring self-insured
group health plans and their business associates. Plans need to:
• Update their HIPAA Policies and Procedures, and related administrative forms,
to reflect the final rules.
• For breach notification, replace the “significant risk” standard with the “low
probability” standard in conducting a risk assessment.
• Confirm that genetic information is not used for underwriting purposes.
• Update Notices of Privacy Practices.
• Train personnel who have access to PHI.
• Review business associate agreements and incorporate the final rule’s new requirements. Keep in mind the one year transition rule described above.
Business associates will need to come into compliance with the new rules as well,
including establishing policies and procedures of their own. Business associates will
also need to enter into business associate agreements with their subcontractors. In
that connection, business associates should identify which of their subcontractors
will access, use or disclose PHI in performing their services. Business associates
should also consider whether their existing liability insurance provides coverage for
HIPAA violations and whether new or additional coverage is needed.
Please contact any member of the Health Care Group if you need assistance in
complying with the new HIPAA requirements applicable to self-insured group health
plans.

http://www.murthalaw.com/files/hc__action_required_to_comply_with_final_hipaa_regs_6_2013_copy1.pdf


Wednesday, May 29, 2013

Idaho University Patient Records Breach Leads to $400,000 Levy, Corrective Plan

By Eric Topor

The Department of Health and Human Services May 21 announced a resolution agreement with Idaho State University (ISU) outpatient clinics--over a breach of approximately 17,500 patient records--under which the health care provider will pay $400,000 and implement a corrective action plan (CAP).
ISU notified the HHS Office for Civil Rights (OCR) of the data breach in August 2011.
OCR's November 2011 investigation report revealed Health Insurance Portability and Accountability Act Security Rule violations between 2007 and 2012 involving ISU's failure to conduct a risk analysis of the confidentiality of its electronic patient records; inadequate implementation of security measures to reduce patient record breaches; and inadequate review of information system activity to determine whether patient records were inappropriately disclosed.
The investigation determined that ISU patient records were unsecured for at least 10 months after firewall protections on ISU servers were disabled.
“Risk analysis, ongoing risk management, and routine information system reviews are the cornerstones of an effective HIPAA security compliance program,” OCR Director Leon Rodriguez said in a statement.
School Clinic Comments
“We want to reiterate that as far as we are concerned, and as far as our due diligence demonstrates, as well as the third party that we hired to come in and do an audit, that no patient records were accessed, and data was not compromised,” Greg Ehardt, HIPAA/assistant university compliance officer at Idaho State University, told BNA May 22.
“As we recognized that the firewall had been disabled for maintenance purposes, unfortunately that was not restored properly.” As ISU did its “due diligence and our external audit, we determined that as far as we were concerned, no patient records had been accessed. But we felt it appropriate, given the incident, that we need to report this to the Office for Civil Rights for their determination as well.”
He added that his hiring by the university was one of several steps ISU has taken to “fortify the security measures here.” Ehardt added that the university has implemented “an event logging system that will more closely track these types of events.”
The university also brought in and centralized the IT of the clinics, whereas before it was somewhat decentralized,” he said.
“We feel that with the number of changes that we've made, and the remediation that we've taken upon ourselves, that we're a much stronger, more fortified program and system at this time.”
Corrective Action Plan
The CAP, which began May 13 and will extend for two years, designates ISU as a “hybrid entity” and requires ISU to identify all covered health care components in its clinic system. The plan requires ISU to submit its current risk management plan, a report of its information system activity across all clinics, and a compliance gap analysis report, and to implement any changes to the plans and procedures suggested by HHS after review.
ISU is required to notify HHS if any ISU employee fails to comply with privacy and security procedures under the CAP, following an internal review by ISU. The CAP requires any notification to include the name of the employee involved, which security policies or procedures were implicated, the steps ISU has taken to mitigate any privacy or security breach, and what steps will be taken to prevent future similar occurrences.
The CAP also requires ISU to submit annual reports detailing security and privacy measures implemented, system activity review measures, an update of compliance gap analysis activity, any reportable events, and a signed attestation by an ISU officer that he or she has reviewed the report and believes it to be accurate.
ISU is required to retain all documents and records relating to the CAP for at least six years.
In January, another entity in Idaho, a small nonprofit hospice, agreed to pay $50,000 to HHS to settle allegations of federal data security rule violations over the loss of a laptop containing the personal health information of 441 patients. That settlement was the first involving a breach of protected health information affecting fewer than 500 individuals under the HIPAA Security Rule, HHS said (12 PVLR 41, 1/7/13).

Thursday, May 2, 2013

Why Healthcare Must Embrace Cloud Computing


Why Healthcare Must Embrace Cloud Computing

Tuesday, April 30, 2013

A Documentation Improvement Success Story

A Documentation Improvement Success Story
By Judy Sturgeon, CCS
For The Record
Vol. 23 No. 8 P. 8
Is your documentation everything it should be? Are your physicians providing all the information your coders need for accurate coding and reimbursement? Will the information be good enough when ICD-10 is implemented? Has your budget prevented you from enlisting help from a top-shelf consultant’s clinical documentation improvement (CDI) program?
There is a viable solution. Just ask the HIM department at Monroe Clinic, part of an integrated clinic-hospital organization licensed as a 100-bed hospital with an 80-provider multispecialty clinic in Monroe, Wis., and 11 community clinics in southwest Wisconsin and northwest Illinois.
Regardless of a facility’s size, several issues are crucial for all HIM departments. Monroe’s HIM department has the same needs and concerns as the largest university or national medical conglomerates: good documentation, ongoing communication with physicians, improved coding, and a positive response to a staggering number of industry changes.
Laurie Schimek, RHIT, Monroe’s HIM manager and privacy officer, says it was a whirlwind experience as the clinic attempted to take better control of its documentation practices. By addressing its needs one step at a time, Monroe has been able to keep on top of healthcare’s shifting landscape. In 2009, after converting its coding from paper documentation to a new EMR, Monroe began discussing ways to improve physician documentation in the new system.
Rather than enlist help from a vendor, Monroe felt it was imperative to create its own documentation improvement project. The reason? “We had a need to communicate. We already have the knowledge, and we know where the needs are,” Schimek says. “We identified what we did know and built on that. Then one of the inpatient coders volunteered to go talk to the hospitalists to help clear up some of the documentation questions.”
For the project to have any chance at succeeding, Schimek says gaining support throughout the clinic was critical. “We’ve been extremely fortunate in having leadership who consistently provide excellent support and have confidence in our knowledge and ability,” she says. “We quickly received buy-in from the director of information services to whom we report and from both the chief financial officer and the chief medical officer. Our initial outreach coder did her homework, too, by researching the basic concepts and needs involved in order to create an effective and compliant clinical documentation improvement program.”
The project may have seemed overwhelming, but the extensive requirements for the final product did not discourage Schimek, who recalls telling the novice CDI coder, “Let’s just look at this as an experiment. Introduce yourself; ask if there’s anything you can do to help them [physicians].”
By keeping the immediate task at hand manageable, Monroe forged ahead toward its ultimate goal.
“We don’t have any extreme extroverts here,” Schimek says. “Our first few meetings included some white-knuckle moments for our coder, but she began her first encounter by explaining the need to understand why physicians documented as they did. The coder included clinical examples of how their documentation affected the physicians’ level-of-service coding. Then she asked if they had any questions for her and once the dialogue began, there was no stopping it.”
Schimek says the idea was to create a peer relationship with the physician staff. It turned out to be beneficial for both sides, a positive experience that offered assistance to physicians as well as to the coding department. Schimek says several strategies were employed to create this cooperative effort.
“We went in to understand, not to tell them what to do,” she says. “We stopped using punitive and threatening words like ‘audit’ and ‘benchmark’ and ‘review.’ We wanted to develop an interactive relationship, so we created in their place interactive coding sessions and encouraged a peer role relationship. We made certain that our clinical examples were not identified by physician, only by the documentation issue that was of concern. We maintained an attitude of respect and we receive respect in return.”
In addition to these behavior changes, Monroe’s CDI coders created personal business cards and bumped their dress code up a notch to reflect their competence as clinical professionals. “You can’t let clothing cause you to be prejudged,” Schimek notes.
Rather than try to tackle everything at once, the CDI program focused on each department’s top five issues and required that a coder was available for 15 minutes at regular department meetings. As documentation needed clarification, coders jotted down the basic issues daily. At each meeting, the top five reoccurring items were brought to the attention of physicians and staff. As the physicians became more attentive to the most pressing problems, new ones were introduced.
Arrangements were made for a coder to participate in daily rounds, and the medical staff’s demand for her input quickly increased as more departments opted into the program. One skilled coder representative soon became several with a little time and training. Eventually, the program expanded to address outpatient clinic needs as well as inpatient concerns.
One step on a tentative path, created by need and fueled by a coder champion with little nerve and built on a foundation of good planning and cooperation, has brought significantly more to the clinic than some basic documentation improvement.
Letters of commendation from the hospitalists to the chief medical officer further validated the project’s value and gained esteem for the coders and the department as a whole. Meanwhile, case mix has improved noticeably. Trepidation surrounding recovery audit contractor audits has subsided thanks to the improvement in specific and detailed documentation. The thought of a new ICD-10 coding system and its expectations for greater documentation detail is less intimidating.
In addition to those benefits, the program has enhanced employee satisfaction, an important accomplishment in an environment where there is increased demand for competent coders. In fact, the project’s original coder champion has been promoted to coding supervisor.
“Our confidence levels have improved noticeably all around. As awareness of the knowledge and capability of the coding staff spreads even wider, their self-esteem and respectability continue to increase along with their reputation,” Schimek says.
Monroe Clinic has succeeded in turning reaction into action, initiating change rather than waiting around to find out how badly change will affect them. Their world is no longer a static environment. It’s an exciting place to work and an example to other facilities that a generous portion of ‘will do’ can become a successful story of ‘can do.’
If you’d like to learn more about the Monroe Clinic CDI program, visit www.monroeclinic.org or contact Laurie Schimek at laurie.schimek@monroeclinic.org or 608-324-2192.

 

Please contact ERM for more information about on-site and remote training. Education is the only solution. 772-210-2823 or kgifford@ermconsultinginc.com

Monday, April 29, 2013

HIPAA Compliance: What Providers Should Know About HITECH Act Mandatory Audits

HIPAA Compliance: What Providers Should Know About HITECH Act Mandatory Audits
1. HHS mandated audits
Investigations by the Office for Civil Rights related to compliance with the Health Insurance Portability and Accountability Act will no longer be initiated by only complaints and self-reported breaches. Section 13411 of the HITECH Act requires HHS to provide for periodic audits of covered entities' and business associates' compliance with the HIPAA Privacy Rule, Security Rule and Breach Notification standards. While the audits are not intended to be investigations, an audit could reveal a serious compliance issue that could lead to a separate enforcement investigation by OCR. These mandatory audits are further evidence of the increased enforcement efforts of HHS. 

2. What we learned from the pilot audit program
KPMG, on behalf of HHS, conducted a yearlong pilot audit program from November 2011 through December 2012 that included 115 audits of covered entities. The audits focused on key compliance requirements under HIPAA, including (a) various requirements of the Privacy Rule, such as notice of privacy practices and uses and disclosures of protected health information, (b) Security Rule requirements for administrative, physical and technical safeguards, and (c) requirements for the Breach Notification Rule.

The large majority of entities that were audited were providers, rather than health plans or clearinghouses (all of which are covered entities under HIPAA). The preliminary results from the pilot audit program revealed that 65 percent of the compliance issues were related to the Security Rule, while only 26 percent and 9 percent of the compliance issues were related to the Privacy Rule and Breach Notification Rule, respectively. Generally, smaller covered entities, such as physician practices and smaller providers, had more compliance issues than larger covered entities. In the future, both covered entities and business associates will be subject to audits. 

OCR is currently evaluating the pilot program to assess whether changes should be made before routine audits commence. The evaluation will focus on the pilot audit program's effectiveness, analyze the program's strengths and weaknesses and give recommendations for future audits. The evaluation process is scheduled to conclude in September 2013. We anticipate that routine audits will commence after this time. 

3. Audit process
An OCR audit begins the audit process by sending document request to the audit target, which includes an introduction to the audit contractor and a request for required HIPAA documents, including copies of privacy policies and procedures, workforce training documentation, incident response plans, risk analyses and risk mitigation plans. This documentation will generally be due to OCR within 10 business days of the request for information. Following review of the documentation, the auditor will conduct a site visit.
During the site visit, OCR will interview key personnel. Covered entities and business associates should ensure that all members of management and higher-level staff members are familiar with the entity's privacy and security policies, procedures and compliance efforts — the entity's privacy officer will not be the only workforce member interviewed by OCR.

After the site visit is completed, the auditor will provide the covered entity with a draft final report. The entity will then have 10 business days to review and provide written comments back to the auditor. The auditor will complete a final audit report within 30 business days after the entity’s response and submit it to OCR. The reports will be used by OCR to determine what types of technical assistance should be developed and whether a compliance review is necessary to address any serious issues detected during the audit.

4. How to prepare for an audit
The audit protocol can be found on the OCR website and is a great resource for entities looking to perform self-evaluations of their HIPAA compliance. As part of these self-evaluations, the audit protocol can be used by covered entities and business associates to conduct a self-audit. This process will help identify compliance gaps and prepare for an OCR audit. 

Covered entities and business associates should ensure, at a minimum, that the following HIPAA compliance measures are being taken:

a. In the case of a covered entity, provide the entity's form of Notice of Privacy Practices to every patient and update such NPP to reflect the changes under the Omnibus Final Rule (required by September 23, 2013).
b. Have written and signed business associate agreements with all entities considered a business associate.
c. Conduct an accurate and thorough assessment of the risk to electronic protected health information.
d. Implement required physical, technical and administrative safeguards to protect ePHI.
e. Have formal policies and procedures for the privacy and security of protected health information and ensure these are updated to reflect the changes under the Omnibus Final Rule (required by September 23, 2013).
f. Train all employees on privacy and security policies and procedures. Those employees who job duties are affected by the changes resulting from the Omnibus Final Rule will need to receive additional training on such changes.
g. Maintain all documentation required under HIPAA, including documentation of all employee training, disclosure logs, documentation of all breach analyses and documentation of sanctions taken against employees for violations of privacy and security policies.

Covered entities and business associates should start to prepare now rather than after receiving notice from OCR of its intent to audit. Preparing for a potential audit may also help protect covered entities and business associates from complaints to OCR related to HIPAA violations.