Showing posts with label OCR. Show all posts
Showing posts with label OCR. Show all posts

Thursday, December 5, 2013

The Office for Civil Rights Did Not Meet All Federal Requirements in Its Oversight and Enforcement of the Health Insurance Portability and Accountability Act Security Rule

11-21-2013

Summary

The Office for Civil Rights (OCR) did not meet certain Federal requirements critical to the oversight and enforcement of the Health Insurance Portability and Accountability Act Security Rule (Security Rule). OCR had not assessed risks, established priorities, or implemented controls for its Federal requirements to provide for periodic audits of covered entities to ensure their compliance with Security Rule requirements. In addition, OCR's Security Rule investigation files did not contain required documentation supporting key decisions made because management had not implemented sufficient controls, including supervisory review and documentation retention, to ensure investigators follow investigation policies and procedures for properly initiating, processing, and closing Security Rule investigations. Further, OCR had not fully complied with Federal cybersecurity requirements for its information systems used to process and store investigation data because it focused on system operability to the detriment of system and data security.
We recommended that OCR (1) assess the risks, establish priorities, and implement controls for its HITECH auditing requirements; (2) provide for periodic audits in accordance with HITECH to ensure Security Rule compliance at covered entities; (3) implement sufficient controls, such as supervisory reviews and documentation retention, to ensure policies and procedures for Security Rule investigations are followed; and (4) implement the National Institute of Standards and Technology Risk Management Framework for systems used to oversee and enforce the Security Rule. In its comments on our draft report, OCR generally concurred with our recommendations and described the actions it has taken to address them. In specific comments on our second recommendation, however, OCR explained that no funds had been appropriated for it to maintain a permanent audit program and that funds used to support audit activities previously conducted were no longer available.
Get the entire report in PDF here

Thursday, September 26, 2013

Fax Sent to Wrong Number Results in HIPAA Violation


Fax Sent to Wrong Number Results in HIPAA Violation
Fax Sent to Wrong Number Results in HIPAA Violation
Dr. G, 58, was a urologist with a solo practice. His business was thriving, and he employed both a nurse and an office manager to help him.
One morning, the office manager got a call from one of the practice's patients, Mr. M, a 52-year-old, HIV-positive man who had been seeing Dr. G for a decade. Although he was happy with the treatment he had been receiving, Mr. M's company was promoting him and he was relocating to another town. He called to ask Dr. G to fax his medical records to his new urologist.
The office manager was juggling numerous tasks, but managed to send the fax out later that day. The office did not have personalized fax cover sheets, just sheets that the office manager printed off once a week which had spaces to fill in the “to” and “from” sections. She hurriedly filled them in and shot off the fax, one of several she had to do before checking in the next patient.
At the end of the day she told Dr. G that it had been done. He thought nothing of it until the following Monday when the office manager came into the back office to speak to him. She was pale and looked shaken, and the physician immediately asked if she was okay.
“It's Mr. M,” the office manager said. “He just called – absolutely furious. He says that we faxed his medical records to his employer rather than his new doctor, and that now his company is aware of his HIV status. He is extremely upset.”
“I'm so sorry,” the office manager said tearfully. “I was the one who sent that fax out. I must have accidentally grabbed the wrong number from his file. What should we do?” She looked at Dr. G for guidance.
Dr. G was holding his forehead, and trying to figure out how to remedy the situation. “The first thing we're going to do is to call Mr. M and apologize. Then we'll take it from there.”
The office manager and Dr. G called Mr. M and apologized profusely for the mix-up. Mr. M understood that it had not been done maliciously, but he was still not satisfied and reported the incident to the U.S. Department of Health and Human Services' (HHS) Office for Civil Rights (OCR). 
An initial investigation indicated that the incident was not criminal and so it was not referred to the Department of Justice. Rather, it was handled by the OCR. OCR officials appeared at Dr. G's office to look into the matter, and after a thorough investigation, the OCR issued a letter of warning to the office manager, referred the office staff for HIPAA privacy training, and had the office revise the fax cover sheets to underscore that they contain a confidential communication for the intended recipient only.

Legal Background


The Health Insurance Portability and Accountability Act, commonly known as HIPAA, protects personally identifiable health information of patients, and specifies to providers how such information may be used. HIPAA has been in effect for about a decade, and in that time, the HHS has received a total of almost 80,000 complaints.
Of those, more than 44,000 were dismissed, 19,000 were investigated and resolved with changes to privacy practice, and 9,000 were investigated but no violations were found. 
According to HHS, private medical practices were the ones most often required to take corrective action as a result of enforcement. The top two compliance issues most frequently investigated are impermissible use and disclosure of protected health information and lack of safeguards for protected health information.
When a HIPAA complaint is filed with the HHS, the first determination made is whether there was a possible privacy violation and whether it was of a criminal nature. If it was determined to be criminal, the case is referred to the Department of Justice for investigation and possible prosecution. If it was determined that it was not a criminal issue (as in this case) the violation is investigated by the OCR. 
If it is determined that a HIPAA violation did, in fact, take place, the OCR can either obtain voluntary compliance, corrective action or some other voluntary agreement with the offender, or the OCR can issue a formal finding of violation and force the offender to change its practices.
In this particular case, the office manager and Dr. G recognized the mistake and immediately tried to take corrective action by apologizing to the patient. Dr. G's office also voluntarily agreed to extra compliance training for the staff and to a change in their faxing procedures to indicate that the faxed materials are confidential.

Protecting Yourself


This particular scenario was the result of a careless error. While a careless error can happen to anyone, one such as this could cause irreparable harm to the patient if his employer now views or treats him differently because of the new knowledge of his HIV-positive status.
Confidential patient records must be treated with the greatest of care as they contain information of an extremely personal nature. Many HIPAA cases have involved the unintentional divulging of the HIV or AIDS status of a patient. 
In a similar case, a dental practice was reported for using red stickers and the word AIDS on the outside of patient folders. And in a case that took place in a hospital, a nurse and orderly lost their jobs for discussing a patient's HIV status within earshot of other patients.
A good rule of thumb is to treat a patient's confidential information as you would want yours to be treated, and then add a little extra security for good measure.


Wednesday, September 18, 2013

OCR, ONC Release Model Notices for HIPAA Compliance


TOPIC ALERT:

Two HHS agencies have released model notices that health care providers can use to comply with new HIPAA privacy and security rules that take effect in less than a week, Health Data Managementreports (Goedert, Health Data Management, 9/16).

Background

The final HIPAA omnibus rule -- which includes four final rules that implement tougher privacy and security provisions -- was called for under the 2009 federal economic stimulus package's HITECH Act and the Genetic Information Nondiscrimination Act. The rules:
  • Clarify when breaches must be reported to HHS' Office for Civil Rights;
  • Establish new standards for the use of patient-identifiable information for fundraising and marketing;
  • Expand liability to "business associates" of hospitals and other "HIPAA-covered entities," such as data miners and health IT service providers; and
  • Raise the maximum penalty for noncompliance to $1.5 million per violation.
The new federal privacy and security regulations will take effect Sept. 23 (iHealthBeat, 9/10).

Details of Models

The examples were developed by HHS' Office for Civil Rights and the Office of the National Coordinator for Health IT.
OCR and ONC released the model notices in three formats:
  • A booklet;
  • A layered notice with a summary of the information on the first page and full content on additional pages; and
  • A notice with the design elements of a booklet, but formatted for full-page presentation.
Covered entities also can download a text-only version (Miliard, Healthcare IT News, 9/17).

Friday, August 23, 2013

HHS settles with health plan in photocopier breach case


Under a settlement with the U.S. Department of Health and Human Services (HHS), Affinity Health Plan, Inc. will settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules for $1,215,780.  Affinity Health Plan is a not-for-profit managed care plan serving the New York metropolitan area.

Affinity filed a breach report with the HHS Office for Civil Rights (OCR) on April 15, 2010, as required by the Health Information Technology for Economic and Clinical Health, or HITECH Act. The HITECH Breach Notification Rule requires HIPAA-covered entities to notify HHS of a breach of unsecured protected health information.  Affinity indicated that it was informed by a representative of CBS Evening News that, as part of an investigatory report, CBS had purchased a photocopier previously leased by Affinity.  CBS informed Affinity that the copier that Affinity had used contained confidential medical information on the hard drive.

Affinity estimated that up to 344,579 individuals may have been affected by this breach. OCR’s investigation indicated that Affinity impermissibly disclosed the protected health information of these affected individuals when it returned multiple photocopiers to leasing agents without erasing the data contained on the copier hard drives.  In addition, the investigation revealed that Affinity failed to incorporate the electronic protected health information (ePHI) stored on photocopier hard drives in its analysis of risks and vulnerabilities as required by the Security Rule, and failed to implement policies and procedures when returning the photocopiers to its leasing agents. 

"This settlement illustrates an important reminder about equipment designed to retain electronic information: Make sure that all personal information is wiped from hardware before it’s recycled, thrown away or sent back to a leasing agent," said OCR Director Leon Rodriguez.  “HIPAA covered entities are required to undertake a careful risk analysis to understand the threats and vulnerabilities to individuals’ data, and have appropriate safeguards in place to protect this information.”

In addition to the $1,215,780 payment, the settlement includes a corrective action plan requiring Affinity to use its best efforts to retrieve all hard drives that were contained on photocopiers previously leased by the plan that remain in the possession of the leasing agent, and to take certain measures to safeguard all ePHI.

For more information on safeguarding sensitive data stored in the hard drives of digital copiers: http://business.ftc.gov/documents/bus43-copier-data-security

The National Institute of Standards and Technology has issued guidance on media sanitation: http://csrc.nist.gov/publications/drafts/800-88-rev1/sp800_88_r1_draft.pdf

OCR offers free training on compliance with the HIPAA Privacy and Security Rules for continuing medical education credit athttp://www.medscape.org/sites/advances/patients-rights.


The HHS Resolution Agreement and CAP can be found on the OCR website athttp://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/affinity-agreement.html

HHS settles with health plan in photocopier breach case

Thursday, July 25, 2013

Providers stumble after recent HIPAA audits | Contemporary OB/GYN




When it comes to securing and protecting patient health information, physician practices with fewer than 50 providers fared the worst in a recent audit by the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR).
In fact, Linda Sanches, MPH, an OCR senior adviser, reports that only two of the 64 healthcare providers in the audit passed without problems.
While OCR’s audit on privacy and security also included health plans and healthcare clearinghouses, the report says that significant compliance issues exist among physician practices.
OCR evaluated practices related to security (administrative, physical and technical safeguards), breach notification, and privacy [access to patient health information (PHI), administrative requirements, uses and disclosures of PHI, etc.]. Security problems accounted for 60% of the findings and observations. Data privacy problems were noted in 30% of the audits, while only 10% were attributed to data breach notifications.
Small practices, OCR notes, “struggled with all three audit areas.”
Nearly 50% of the smaller practices posted negative findings and observations related to compliance of uses and disclosure of PHI, another 30% were dinged for not having acceptable administrative requirements in place, 30% had compliance problems related to patient access, and another 31% had findings and observations related to notice of privacy practices for PHI.
Many of the audit problems, Sanches says, were triggered simply because providers were unaware of the requirements. She urged physicians to evaluate the regulations and conduct a compliance assessment to help protect PHI from breaches.


Providers stumble after recent HIPAA audits | Contemporary OB/GYN