SlideShare une entreprise Scribd logo
1  sur  14
Presented in Partnership with




HIPAA Mandates a PLAN!
  (beyond hardware and software)




            © HIPAA Continuity Planners   1
                      2012
Compliance	
  Simplified	
  –	
  Achieve	
  ,	
  Illustrate,	
  Maintain	
  

Industry	
  leading	
  Education	
  
                                                                      Todays	
  Webinar	
  
                                                           	
  

                                                           •  Please	
  ask	
  questions	
  via	
  
                                                                questions	
  or	
  chat	
  
                                                           	
  
                                                           •  Todays	
  slides	
  are	
  avialable	
  	
  
Certified	
  Partner	
  Program	
                           http://compliancy-­‐group.com/
                                                           slides023/	
  
                	
  
                                                           	
  
                                                           •  Past	
  webinars	
  and	
  recordings	
  
                                                           http://compliancy-­‐group.com/
                                                           webinar/#	
  




                                                           	
                                     855.85HIPAA	
  
                                                                                            www.compliancygroup.com	
  
HIPAA Mandates:

 •    Risk Analysis
 •    Continuity Plan
 •    Security Procedures
 •    An Incident Response Plan
 •    Contact Procedures
 •    Documentation
 •    Employee Training


              © HIPAA Continuity Planners   3
                        2012
Processes and Procedures
       Risk Analysis
Process of identifying possible external
  and internal conditions, events or
  situations, determination of causal
    relationships between probable
happenings, their magnitude with likely
  outcomes, as they might effect the
  continuing operation of the office.




             © HIPAA Continuity Planners   4
                       2012
Processes and Procedures
                          Continuity Plan
Set of documents, instructions, and procedures which enable
  a business to respond to accidents, disasters,
  emergencies, and threats without any stoppage or
  hindrance in its key operations.

Business resumption plan, disaster recovery plan,
  or resilience plan*
* From BusinessDictionary.com




                                © HIPAA Continuity Planners   5
                                          2012
Processes and Procedures
                 Security
HIPAA mandates security procedures for:
•  Premises Access
•  Computer Access authorization
•  Server Access
•  Log-in Monitoring
•  Password management
•  Health information sharing
•  Termination procedures
•  Compliance Tracking Software with logs
•  Business Associates
                  © HIPAA Continuity Planners   6
                            2012
Processes and Procedures for
     Incident Response Plan

Some steps of the IRP may include the following:

•    Define the incident – what happened? When did it
     happen? Who was involved? When was it discovered?
•    Stop the incident – if a smartphone is lost take the
     steps to disable the access, if a breach is found take
     the steps to prevent further access, etc.
•    Document the incident – fill in all the details of what
     occurred from step 1 (define the incident) and step 2
     (steps taken to stop the incident). Clearly document all
     aspects of the incident.

                      © HIPAA Continuity Planners           7
                                2012
Processes and Procedures for
     Incident Response Plan
•    Notify appropriate individuals / agencies –the
     amount of patient records affected will determine what
     notification steps are needed. Individual patients and
     Health and Human Services (HHS) will need to be
     notified. In addition, local media may need to be
     notified as well.
•    Provide guidance to prevent the incident from
     occurring again – an important aspect of an incident
     response is to ensure that the same incident does not
     happen in the future. Recommendations to increase
     security and reduce the risk of an incident are
     essential.


                     © HIPAA Continuity Planners              8
                               2012
Processes and Procedures
             Contact Plan
Establish:
•  Procedures to contact employees via
   telephone, text and/or email in case of
   office closing.
•  A copy of employee emergency notification
   outside of the office
•  A copy of patient contacts for daily
   appointments be available outside the
   office for notification of an office closing.

                 © HIPAA Continuity Planners   9
                           2012
Documentation
HIPAA required documentation:

•  Risk Analysis
•  Written Continuity Plan
•  Security Procedures
•  Emergency operation mode plan
•  Periodic Evaluations
•  Compliance Tracking Software with
   logs
                © HIPAA Continuity Planners   10
                          2012
Training
•    Security Awareness Training
•    Computer Security
•    Incident Command
•    Evacuation Procedures and Responsibility
•    Basic HIPAA Requirements
•    Employee buy-in through understanding


                  © HIPAA Continuity Planners   11
                            2012
HIPAA/HITECH Penalties

•  Tier A is for violations in which the offender didn’t realize he or she
   violated the Act and would have handled the matter differently if he or
   she had. This results in a $100 fine for each violation, and the total
   imposed for such violations cannot exceed $25,000 for the calendar
   year.
•  Tier B is for violations due to reasonable cause, but not “willful
   neglect.” The result is a $1,000 fine for each violation, and the fines
   cannot exceed $100,000 for the calendar year.
•  Tier C is for violations due to willful neglect that the organization
   ultimately corrected , and the fines cannot exceed. The result is a
   $10,000 fine for each violation $250,000 for the calendar year.
•  Tier D is for violations of willful neglect that the organization did not
   correct. The result is a $50,000 fine for each violation, and the fines
   cannot exceed $1,500,000 for the calendar year.
•  The HITECH Act allows states! attorneys general to levy fines and
   seek attorneys fees from covered entities on behalf of victims. Courts
   now have the ability to award costs, which they were previously
   unable to do.
                            © HIPAA Continuity Planners                   12
                                      2012
Compliance	
  Simplified	
  –	
  Achieve	
  ,	
  Illustrate,	
  Maintain	
  



                        Compliance	
  Simplified!	
  

                                          HIPAA	
  Compliance	
  
                 Achieve	
  
                                          HITECH	
  Attestation	
  
                                          Meaningful	
  Use	
  core	
  measure	
  15	
  
Illustrate	
  
                                                Free	
  Demo	
  and	
  15	
  Day	
  Evaluation	
  
                                                           855.85HIPAA	
  	
  
                      Maintain	
  
                                               http://www.compliancygroup.com	
  
                                                                       	
  
                                                        New	
  &	
  Past	
  	
  Webinars	
  
                                            http://compliancy-­‐group.com/webinar/#	
  
                                                                       	
  
                                                                       	
  


                                                                                                     855.85HIPAA	
  
                                                                                               www.compliancygroup.com	
  
Questions?
A.J. (Andy) Weitzberg
       President
   aj@hipaacp.com
  www.hipaacp.com
  631.865.0707 Ofc
  516.641.4001 Cell


  © HIPAA Continuity Planners   14
            2012

Contenu connexe

Plus de Compliancy Group

HIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to knowHIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to knowCompliancy Group
 
HIPAA Compliance and Non-Business Associate Vendors - Strategies and Best Pra...
HIPAA Compliance and Non-Business Associate Vendors - Strategies and Best Pra...HIPAA Compliance and Non-Business Associate Vendors - Strategies and Best Pra...
HIPAA Compliance and Non-Business Associate Vendors - Strategies and Best Pra...Compliancy Group
 
How to prepare for OCR's upcoming phase 2 audits
How to prepare for OCR's upcoming phase 2 auditsHow to prepare for OCR's upcoming phase 2 audits
How to prepare for OCR's upcoming phase 2 auditsCompliancy Group
 
Preparing for the unexpected in your medical practice
Preparing for the unexpected in your medical practicePreparing for the unexpected in your medical practice
Preparing for the unexpected in your medical practiceCompliancy Group
 
HIPAA Compliance and Electronic Protected Health Information: Ignorance is no...
HIPAA Compliance and Electronic Protected Health Information: Ignorance is no...HIPAA Compliance and Electronic Protected Health Information: Ignorance is no...
HIPAA Compliance and Electronic Protected Health Information: Ignorance is no...Compliancy Group
 
How to Survive a HIPAA Audit
How to Survive a HIPAA AuditHow to Survive a HIPAA Audit
How to Survive a HIPAA AuditCompliancy Group
 
How to Effectively Negotiate a Business Associate Agreement: What’s Importan...
How to Effectively Negotiate a Business Associate Agreement:  What’s Importan...How to Effectively Negotiate a Business Associate Agreement:  What’s Importan...
How to Effectively Negotiate a Business Associate Agreement: What’s Importan...Compliancy Group
 
How to Increase Your Profits Using Patient Payments on File, Recurring and On...
How to Increase Your Profits Using Patient Payments on File, Recurring and On...How to Increase Your Profits Using Patient Payments on File, Recurring and On...
How to Increase Your Profits Using Patient Payments on File, Recurring and On...Compliancy Group
 
Why a Risk Assessment is NOT Enough for HIPAA Compliance
Why a Risk Assessment is NOT Enough for HIPAA ComplianceWhy a Risk Assessment is NOT Enough for HIPAA Compliance
Why a Risk Assessment is NOT Enough for HIPAA ComplianceCompliancy Group
 
The must have tools to address your HIPAA compliance challenge
The must have tools to address your HIPAA compliance challengeThe must have tools to address your HIPAA compliance challenge
The must have tools to address your HIPAA compliance challengeCompliancy Group
 
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINEDHIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINEDCompliancy Group
 
What you need to know about Meaningful Use 2 & interoperability
What you need to know about Meaningful Use 2 & interoperabilityWhat you need to know about Meaningful Use 2 & interoperability
What you need to know about Meaningful Use 2 & interoperabilityCompliancy Group
 
Just the Facts- Meaningful Use Stage 2 & ICD 10
Just the Facts- Meaningful Use Stage 2 & ICD 10Just the Facts- Meaningful Use Stage 2 & ICD 10
Just the Facts- Meaningful Use Stage 2 & ICD 10Compliancy Group
 
Is Your EHR Safe? New Technologies for Auditing
Is Your EHR Safe? New Technologies for AuditingIs Your EHR Safe? New Technologies for Auditing
Is Your EHR Safe? New Technologies for AuditingCompliancy Group
 
Business Associate and HIPAA Comliance Infographic
Business Associate and HIPAA Comliance InfographicBusiness Associate and HIPAA Comliance Infographic
Business Associate and HIPAA Comliance InfographicCompliancy Group
 
Surving a HIPAA Audit Infographic
Surving a HIPAA Audit InfographicSurving a HIPAA Audit Infographic
Surving a HIPAA Audit InfographicCompliancy Group
 
Cyber & Privacy Risk Infographic
Cyber & Privacy Risk InfographicCyber & Privacy Risk Infographic
Cyber & Privacy Risk InfographicCompliancy Group
 
Surviving a HIPAA Audit: Five Crucial Steps
Surviving a HIPAA Audit: Five Crucial Steps Surviving a HIPAA Audit: Five Crucial Steps
Surviving a HIPAA Audit: Five Crucial Steps Compliancy Group
 
Where security and privacy meet partnering tips for CSOs and privacy/complian...
Where security and privacy meet partnering tips for CSOs and privacy/complian...Where security and privacy meet partnering tips for CSOs and privacy/complian...
Where security and privacy meet partnering tips for CSOs and privacy/complian...Compliancy Group
 

Plus de Compliancy Group (20)

HIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to knowHIPAA 101- What all Doctors NEED to know
HIPAA 101- What all Doctors NEED to know
 
HIPAA Compliance and Non-Business Associate Vendors - Strategies and Best Pra...
HIPAA Compliance and Non-Business Associate Vendors - Strategies and Best Pra...HIPAA Compliance and Non-Business Associate Vendors - Strategies and Best Pra...
HIPAA Compliance and Non-Business Associate Vendors - Strategies and Best Pra...
 
How to prepare for OCR's upcoming phase 2 audits
How to prepare for OCR's upcoming phase 2 auditsHow to prepare for OCR's upcoming phase 2 audits
How to prepare for OCR's upcoming phase 2 audits
 
Preparing for the unexpected in your medical practice
Preparing for the unexpected in your medical practicePreparing for the unexpected in your medical practice
Preparing for the unexpected in your medical practice
 
HIPAA Compliance and Electronic Protected Health Information: Ignorance is no...
HIPAA Compliance and Electronic Protected Health Information: Ignorance is no...HIPAA Compliance and Electronic Protected Health Information: Ignorance is no...
HIPAA Compliance and Electronic Protected Health Information: Ignorance is no...
 
How to Survive a HIPAA Audit
How to Survive a HIPAA AuditHow to Survive a HIPAA Audit
How to Survive a HIPAA Audit
 
How to Effectively Negotiate a Business Associate Agreement: What’s Importan...
How to Effectively Negotiate a Business Associate Agreement:  What’s Importan...How to Effectively Negotiate a Business Associate Agreement:  What’s Importan...
How to Effectively Negotiate a Business Associate Agreement: What’s Importan...
 
Meaningful Use vs HIPAA
Meaningful Use vs HIPAAMeaningful Use vs HIPAA
Meaningful Use vs HIPAA
 
How to Increase Your Profits Using Patient Payments on File, Recurring and On...
How to Increase Your Profits Using Patient Payments on File, Recurring and On...How to Increase Your Profits Using Patient Payments on File, Recurring and On...
How to Increase Your Profits Using Patient Payments on File, Recurring and On...
 
Why a Risk Assessment is NOT Enough for HIPAA Compliance
Why a Risk Assessment is NOT Enough for HIPAA ComplianceWhy a Risk Assessment is NOT Enough for HIPAA Compliance
Why a Risk Assessment is NOT Enough for HIPAA Compliance
 
The must have tools to address your HIPAA compliance challenge
The must have tools to address your HIPAA compliance challengeThe must have tools to address your HIPAA compliance challenge
The must have tools to address your HIPAA compliance challenge
 
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINEDHIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
 
What you need to know about Meaningful Use 2 & interoperability
What you need to know about Meaningful Use 2 & interoperabilityWhat you need to know about Meaningful Use 2 & interoperability
What you need to know about Meaningful Use 2 & interoperability
 
Just the Facts- Meaningful Use Stage 2 & ICD 10
Just the Facts- Meaningful Use Stage 2 & ICD 10Just the Facts- Meaningful Use Stage 2 & ICD 10
Just the Facts- Meaningful Use Stage 2 & ICD 10
 
Is Your EHR Safe? New Technologies for Auditing
Is Your EHR Safe? New Technologies for AuditingIs Your EHR Safe? New Technologies for Auditing
Is Your EHR Safe? New Technologies for Auditing
 
Business Associate and HIPAA Comliance Infographic
Business Associate and HIPAA Comliance InfographicBusiness Associate and HIPAA Comliance Infographic
Business Associate and HIPAA Comliance Infographic
 
Surving a HIPAA Audit Infographic
Surving a HIPAA Audit InfographicSurving a HIPAA Audit Infographic
Surving a HIPAA Audit Infographic
 
Cyber & Privacy Risk Infographic
Cyber & Privacy Risk InfographicCyber & Privacy Risk Infographic
Cyber & Privacy Risk Infographic
 
Surviving a HIPAA Audit: Five Crucial Steps
Surviving a HIPAA Audit: Five Crucial Steps Surviving a HIPAA Audit: Five Crucial Steps
Surviving a HIPAA Audit: Five Crucial Steps
 
Where security and privacy meet partnering tips for CSOs and privacy/complian...
Where security and privacy meet partnering tips for CSOs and privacy/complian...Where security and privacy meet partnering tips for CSOs and privacy/complian...
Where security and privacy meet partnering tips for CSOs and privacy/complian...
 

Dernier

Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfVirtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfErwinPantujan2
 
Karra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxKarra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxAshokKarra1
 
Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)cama23
 
How to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPHow to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPCeline George
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17Celine George
 
ROLES IN A STAGE PRODUCTION in arts.pptx
ROLES IN A STAGE PRODUCTION in arts.pptxROLES IN A STAGE PRODUCTION in arts.pptx
ROLES IN A STAGE PRODUCTION in arts.pptxVanesaIglesias10
 
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptx
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptxMusic 9 - 4th quarter - Vocal Music of the Romantic Period.pptx
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptxleah joy valeriano
 
Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Celine George
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONHumphrey A Beña
 
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...JojoEDelaCruz
 
Food processing presentation for bsc agriculture hons
Food processing presentation for bsc agriculture honsFood processing presentation for bsc agriculture hons
Food processing presentation for bsc agriculture honsManeerUddin
 
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfInclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfTechSoup
 
Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Mark Reed
 
Integumentary System SMP B. Pharm Sem I.ppt
Integumentary System SMP B. Pharm Sem I.pptIntegumentary System SMP B. Pharm Sem I.ppt
Integumentary System SMP B. Pharm Sem I.pptshraddhaparab530
 
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...Postal Advocate Inc.
 
Full Stack Web Development Course for Beginners
Full Stack Web Development Course  for BeginnersFull Stack Web Development Course  for Beginners
Full Stack Web Development Course for BeginnersSabitha Banu
 
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYKayeClaireEstoconing
 
Earth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatEarth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatYousafMalik24
 
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSGRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSJoshuaGantuangco2
 
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxiammrhaywood
 

Dernier (20)

Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdfVirtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
Virtual-Orientation-on-the-Administration-of-NATG12-NATG6-and-ELLNA.pdf
 
Karra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxKarra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptx
 
Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)
 
How to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERPHow to do quick user assign in kanban in Odoo 17 ERP
How to do quick user assign in kanban in Odoo 17 ERP
 
How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17How to Add Barcode on PDF Report in Odoo 17
How to Add Barcode on PDF Report in Odoo 17
 
ROLES IN A STAGE PRODUCTION in arts.pptx
ROLES IN A STAGE PRODUCTION in arts.pptxROLES IN A STAGE PRODUCTION in arts.pptx
ROLES IN A STAGE PRODUCTION in arts.pptx
 
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptx
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptxMusic 9 - 4th quarter - Vocal Music of the Romantic Period.pptx
Music 9 - 4th quarter - Vocal Music of the Romantic Period.pptx
 
Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17Difference Between Search & Browse Methods in Odoo 17
Difference Between Search & Browse Methods in Odoo 17
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
 
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
ENG 5 Q4 WEEk 1 DAY 1 Restate sentences heard in one’s own words. Use appropr...
 
Food processing presentation for bsc agriculture hons
Food processing presentation for bsc agriculture honsFood processing presentation for bsc agriculture hons
Food processing presentation for bsc agriculture hons
 
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdfInclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
Inclusivity Essentials_ Creating Accessible Websites for Nonprofits .pdf
 
Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)Influencing policy (training slides from Fast Track Impact)
Influencing policy (training slides from Fast Track Impact)
 
Integumentary System SMP B. Pharm Sem I.ppt
Integumentary System SMP B. Pharm Sem I.pptIntegumentary System SMP B. Pharm Sem I.ppt
Integumentary System SMP B. Pharm Sem I.ppt
 
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
USPS® Forced Meter Migration - How to Know if Your Postage Meter Will Soon be...
 
Full Stack Web Development Course for Beginners
Full Stack Web Development Course  for BeginnersFull Stack Web Development Course  for Beginners
Full Stack Web Development Course for Beginners
 
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
 
Earth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatEarth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice great
 
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSGRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
 
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptxECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
ECONOMIC CONTEXT - PAPER 1 Q3: NEWSPAPERS.pptx
 

HIPAA Business Continuity Planning

  • 1. Presented in Partnership with HIPAA Mandates a PLAN! (beyond hardware and software) © HIPAA Continuity Planners 1 2012
  • 2. Compliance  Simplified  –  Achieve  ,  Illustrate,  Maintain   Industry  leading  Education   Todays  Webinar     •  Please  ask  questions  via   questions  or  chat     •  Todays  slides  are  avialable     Certified  Partner  Program   http://compliancy-­‐group.com/ slides023/       •  Past  webinars  and  recordings   http://compliancy-­‐group.com/ webinar/#     855.85HIPAA   www.compliancygroup.com  
  • 3. HIPAA Mandates: •  Risk Analysis •  Continuity Plan •  Security Procedures •  An Incident Response Plan •  Contact Procedures •  Documentation •  Employee Training © HIPAA Continuity Planners 3 2012
  • 4. Processes and Procedures Risk Analysis Process of identifying possible external and internal conditions, events or situations, determination of causal relationships between probable happenings, their magnitude with likely outcomes, as they might effect the continuing operation of the office. © HIPAA Continuity Planners 4 2012
  • 5. Processes and Procedures Continuity Plan Set of documents, instructions, and procedures which enable a business to respond to accidents, disasters, emergencies, and threats without any stoppage or hindrance in its key operations. Business resumption plan, disaster recovery plan, or resilience plan* * From BusinessDictionary.com © HIPAA Continuity Planners 5 2012
  • 6. Processes and Procedures Security HIPAA mandates security procedures for: •  Premises Access •  Computer Access authorization •  Server Access •  Log-in Monitoring •  Password management •  Health information sharing •  Termination procedures •  Compliance Tracking Software with logs •  Business Associates © HIPAA Continuity Planners 6 2012
  • 7. Processes and Procedures for Incident Response Plan Some steps of the IRP may include the following: •  Define the incident – what happened? When did it happen? Who was involved? When was it discovered? •  Stop the incident – if a smartphone is lost take the steps to disable the access, if a breach is found take the steps to prevent further access, etc. •  Document the incident – fill in all the details of what occurred from step 1 (define the incident) and step 2 (steps taken to stop the incident). Clearly document all aspects of the incident. © HIPAA Continuity Planners 7 2012
  • 8. Processes and Procedures for Incident Response Plan •  Notify appropriate individuals / agencies –the amount of patient records affected will determine what notification steps are needed. Individual patients and Health and Human Services (HHS) will need to be notified. In addition, local media may need to be notified as well. •  Provide guidance to prevent the incident from occurring again – an important aspect of an incident response is to ensure that the same incident does not happen in the future. Recommendations to increase security and reduce the risk of an incident are essential. © HIPAA Continuity Planners 8 2012
  • 9. Processes and Procedures Contact Plan Establish: •  Procedures to contact employees via telephone, text and/or email in case of office closing. •  A copy of employee emergency notification outside of the office •  A copy of patient contacts for daily appointments be available outside the office for notification of an office closing. © HIPAA Continuity Planners 9 2012
  • 10. Documentation HIPAA required documentation: •  Risk Analysis •  Written Continuity Plan •  Security Procedures •  Emergency operation mode plan •  Periodic Evaluations •  Compliance Tracking Software with logs © HIPAA Continuity Planners 10 2012
  • 11. Training •  Security Awareness Training •  Computer Security •  Incident Command •  Evacuation Procedures and Responsibility •  Basic HIPAA Requirements •  Employee buy-in through understanding © HIPAA Continuity Planners 11 2012
  • 12. HIPAA/HITECH Penalties •  Tier A is for violations in which the offender didn’t realize he or she violated the Act and would have handled the matter differently if he or she had. This results in a $100 fine for each violation, and the total imposed for such violations cannot exceed $25,000 for the calendar year. •  Tier B is for violations due to reasonable cause, but not “willful neglect.” The result is a $1,000 fine for each violation, and the fines cannot exceed $100,000 for the calendar year. •  Tier C is for violations due to willful neglect that the organization ultimately corrected , and the fines cannot exceed. The result is a $10,000 fine for each violation $250,000 for the calendar year. •  Tier D is for violations of willful neglect that the organization did not correct. The result is a $50,000 fine for each violation, and the fines cannot exceed $1,500,000 for the calendar year. •  The HITECH Act allows states! attorneys general to levy fines and seek attorneys fees from covered entities on behalf of victims. Courts now have the ability to award costs, which they were previously unable to do. © HIPAA Continuity Planners 12 2012
  • 13. Compliance  Simplified  –  Achieve  ,  Illustrate,  Maintain   Compliance  Simplified!     HIPAA  Compliance   Achieve     HITECH  Attestation     Meaningful  Use  core  measure  15   Illustrate   Free  Demo  and  15  Day  Evaluation   855.85HIPAA     Maintain   http://www.compliancygroup.com     New  &  Past    Webinars   http://compliancy-­‐group.com/webinar/#       855.85HIPAA   www.compliancygroup.com  
  • 14. Questions? A.J. (Andy) Weitzberg President aj@hipaacp.com www.hipaacp.com 631.865.0707 Ofc 516.641.4001 Cell © HIPAA Continuity Planners 14 2012