Home Health & Hospice Week

HIPAA:

Are You Ready For 2016's HIPAA Audits?

Add HIPAA readiness to your to-do list.

As expected, HIPAA audits will continue this year — and they will expand to more entities. If you haven’t already, now is the time to prepare your organization for a visit from the HHS Office for Civil Rights.

Starting early this year, OCR will begin performing random desk and on-site audits of not only covered entities (CEs), but also business associates (BAs), according to a recent alert by attorneys James Bailey and Kelsey Farbotko of the law firm Williams Mullen. “These audits are expected to focus on areas of noncompliance that OCR has witnessed in its previous audits and enforcement actions, such as risk analyses and use of encryption technology.”

Best practices: Before undergoing an OCR audit, make sure that you’re complying with the HIPAA Privacy, Security and Breach Notification rules. At a minimum, ensure that your organization:

  • Has documentation of and compliance with privacy and security policies and procedures;
  • Performs security risk analyses of electronic protected health information (ePHI);
  • Uses Business Associate Agreements (BAAs) appropriately;
  • Disseminates a Notice of Privacy Practices (NPP) as required;
  • Documents any and all breaches in accordance with HIPAA; and
  • Has systems and protocols in place to properly address a breach.

“With HIPAA audits right around the corner, healthcare practitioners, providers and their [BAs] need to place additional focus on carefully evaluating their past and current HIPAA compliance to identify and strengthen any areas of potential noncompliance,” Bailey and Farbotko urged.

Other Articles in this issue of

Home Health & Hospice Week

View All