SlideShare a Scribd company logo
1 of 6
Download to read offline
Can Your

Health IT
Service Provider
Ensure Security
For ePHI?

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809
Outsourcing your healthcare documentation, medical
coding and billing, and other back office tasks can help
save time and money and improve your productivity and
efficiency. However, as a physician, there’s one question
that you should ask yourself – is my health IT service
provider conscious about the safety of my data? Poor IT
security policies can land you in troublesome and costly
penalties for HIPAA (Health Insurance Portability and
Accountability

Act)

violations.

Even

a

well

known

institution like the Idaho State University was recently
penalized for a health information security breach. So
before

you

outsource

your

back

office

tasks,

it’s

important to ensure that your health IT service provider
has the following policies in place to ensure security of
electronic protected health information:

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809
Check whether the IT provider offers encryption for both active (in
use) and inactive (not in use) ePHI. Otherwise, the ePHIs are at risk

Encryption for ePHI

of security breaches and HIPAA violations. Suppose that your

medical billing

service

provider

accesses

your

ePHI

via

an

unencrypted network. There is a chance that someone can intrude
the network and access the information when it is being transferred.
The same applies to the ePHI stored in a computer, laptop or USB
drive. If the device is stolen, misplaced or lost, ePHI confidentiality
is at stake. In 2012, BlueCross BlueShield of Tennessee, a leading
Health Benefit Plan company in Tennessee paid around $1.5 million
to the Department of Health and Human Services (HHS) when 57
unencrypted computer hard drives containing the protected health
information of more than 1 million people was stolen.

Business Continuity &
Disaster Recovery Plans

The service provider that you select should have business
continuity and disaster recovery plans. Even though most service
providers plan how to handle an immediate service interruption,
testing usually doesn’t take place until an emergency occurs! This
is a bad practice. So ensure that your service provider has a
tested and proven disaster recovery plan system in place. This will
reduce wait time for updates – for you as well as your patients.

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809
Data breaches may occur if the patients’ health information is not

Proper Shredding of

disposed off safely and securely. For data stored electronically, the

ePHI

potential for unauthorized access, erasing, altering, or losing, is high.
Even if documents are deleted from the recycle bin, they are prone to
unauthorized access via hard disk recovery. When disposing of data
stored on computer disks, the disks need to be erased several times
and it should be ascertained that the data cannot be recovered from
them. The service provider should be able to recognize when, how and
in what circumstances the ePHIs were destroyed.

Identify Data Breaches
Most data breaches are difficult to detect. As per the Verizon
Data Breach Investigations Report 2013, around 66 percent of
data breaches would take even months or years to discover.
So you should ensure that your service provider has an
efficient system (anti-virus software, malware detection tools,
advanced analytic tools) to identify different types of data
breaches.

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809
Regular Risk

Make sure that your service provider performs risk assessments

Assessment

regularly to address changing threats and policies so that effective and
stringent security measures can be implemented. For example, the
HIPAA Omnibus Final Rule effective from March, 2013 considers even
the risk of data breach as a violation. Changes in technology can bring
about new risks. It’s important that your service provider stays up-todate with such changes and conducts regular risk adjustments to
detect and deal with security violation threats.

HIPAA Business Associate
Agreement

If your service provider is willing to sign a HIPAA business
associate agreement (BBA) with you, this is an indication of their
commitment to security for your ePHI. The contract ensures safety
for

personal

health

information

in

accordance

with

HIPAA

guidelines. The agreement should clearly show how your health IT
service provider will report and respond to any kind of data
breach. Also, make sure that the provider can produce evidence
for routine audits such as SSAE 16 reports or PCI certification.

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809
The bottom line: when you outsource your
documentation or medical coding or billing
tasks, look for a medical transcription company
or medical billing company that is HIPAA
complaint.

Outsource Strategies International
www.outsourcestrategies.com

Headquarters:
8596 E. 101st Street, Suite H
Tulsa, OK 74133
Call: 1-800-670-2809

More Related Content

More from Outsource Strategies International

ed Understanding the Challenges in Physical Therapy Medical Billing
ed Understanding the Challenges in Physical Therapy Medical Billinged Understanding the Challenges in Physical Therapy Medical Billing
ed Understanding the Challenges in Physical Therapy Medical BillingOutsource Strategies International
 
How Medical Billing Services Can Maximize Reimbursement and Minimize Denials
How Medical Billing Services Can Maximize Reimbursement and Minimize DenialsHow Medical Billing Services Can Maximize Reimbursement and Minimize Denials
How Medical Billing Services Can Maximize Reimbursement and Minimize DenialsOutsource Strategies International
 
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....Understanding the Significance of Outsourcing Medical Billing and Coding (3)....
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....Outsource Strategies International
 
Optimizing Medical Billing: Strategies to Prevent Claim Denials
Optimizing Medical Billing: Strategies to Prevent Claim DenialsOptimizing Medical Billing: Strategies to Prevent Claim Denials
Optimizing Medical Billing: Strategies to Prevent Claim DenialsOutsource Strategies International
 
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdf
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdfMedical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdf
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdfOutsource Strategies International
 
Medical Codes to Report Cystitis – A Common Bladder Infection
Medical Codes to Report Cystitis – A Common Bladder InfectionMedical Codes to Report Cystitis – A Common Bladder Infection
Medical Codes to Report Cystitis – A Common Bladder InfectionOutsource Strategies International
 

More from Outsource Strategies International (20)

Tips to Handle Prior Authorizations Effectively
Tips to Handle Prior Authorizations EffectivelyTips to Handle Prior Authorizations Effectively
Tips to Handle Prior Authorizations Effectively
 
Minimize Denials with Accurate & Compliant Coding
Minimize Denials with Accurate & Compliant CodingMinimize Denials with Accurate & Compliant Coding
Minimize Denials with Accurate & Compliant Coding
 
ed Understanding the Challenges in Physical Therapy Medical Billing
ed Understanding the Challenges in Physical Therapy Medical Billinged Understanding the Challenges in Physical Therapy Medical Billing
ed Understanding the Challenges in Physical Therapy Medical Billing
 
Tips to Ensure Accurate Health Insurance Verification
Tips to Ensure Accurate Health Insurance VerificationTips to Ensure Accurate Health Insurance Verification
Tips to Ensure Accurate Health Insurance Verification
 
How Medical Billing Services Can Maximize Reimbursement and Minimize Denials
How Medical Billing Services Can Maximize Reimbursement and Minimize DenialsHow Medical Billing Services Can Maximize Reimbursement and Minimize Denials
How Medical Billing Services Can Maximize Reimbursement and Minimize Denials
 
Best Practices for Medical Billing Documentation
Best Practices for Medical Billing DocumentationBest Practices for Medical Billing Documentation
Best Practices for Medical Billing Documentation
 
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....Understanding the Significance of Outsourcing Medical Billing and Coding (3)....
Understanding the Significance of Outsourcing Medical Billing and Coding (3)....
 
Optimizing Medical Billing: Strategies to Prevent Claim Denials
Optimizing Medical Billing: Strategies to Prevent Claim DenialsOptimizing Medical Billing: Strategies to Prevent Claim Denials
Optimizing Medical Billing: Strategies to Prevent Claim Denials
 
Gastroparesis – Causes, Symptoms and ICD-10 Coding.pdf
Gastroparesis – Causes, Symptoms and ICD-10 Coding.pdfGastroparesis – Causes, Symptoms and ICD-10 Coding.pdf
Gastroparesis – Causes, Symptoms and ICD-10 Coding.pdf
 
Medical Codes to Report Epilepsy
Medical Codes to Report Epilepsy Medical Codes to Report Epilepsy
Medical Codes to Report Epilepsy
 
Common Medical Billing Mistakes and How to Avoid Them.pptx
Common Medical Billing Mistakes and How to Avoid Them.pptxCommon Medical Billing Mistakes and How to Avoid Them.pptx
Common Medical Billing Mistakes and How to Avoid Them.pptx
 
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdf
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdfMedical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdf
Medical Codes to Report IBS – A Common Gastrointestinal Disorder ed.pdf
 
What are the ICD-10 Codes for Osteomalacia ed.pdf
What are the ICD-10 Codes for Osteomalacia ed.pdfWhat are the ICD-10 Codes for Osteomalacia ed.pdf
What are the ICD-10 Codes for Osteomalacia ed.pdf
 
ICD-10 Codes to Report Meningitis.pptx
ICD-10 Codes to Report Meningitis.pptxICD-10 Codes to Report Meningitis.pptx
ICD-10 Codes to Report Meningitis.pptx
 
Medical Codes to Report Cystitis – A Common Bladder Infection
Medical Codes to Report Cystitis – A Common Bladder InfectionMedical Codes to Report Cystitis – A Common Bladder Infection
Medical Codes to Report Cystitis – A Common Bladder Infection
 
ICD-10 Codes for Multiple sclerosis (MS)
ICD-10 Codes for Multiple sclerosis (MS)ICD-10 Codes for Multiple sclerosis (MS)
ICD-10 Codes for Multiple sclerosis (MS)
 
CDT Codes to Report Dental Bridges.pdf
CDT Codes to Report Dental Bridges.pdfCDT Codes to Report Dental Bridges.pdf
CDT Codes to Report Dental Bridges.pdf
 
Coding Pregnancy Related Rheumatic Conditions
Coding Pregnancy Related Rheumatic ConditionsCoding Pregnancy Related Rheumatic Conditions
Coding Pregnancy Related Rheumatic Conditions
 
Patient Eligibility Verification
Patient Eligibility VerificationPatient Eligibility Verification
Patient Eligibility Verification
 
A Review of Top 10 OSI Blog Posts of 2022.pptx
A Review of Top 10 OSI Blog Posts of 2022.pptxA Review of Top 10 OSI Blog Posts of 2022.pptx
A Review of Top 10 OSI Blog Posts of 2022.pptx
 

Recently uploaded

Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptxnandhinijagan9867
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon investment
 
Mckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingMckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingNauman Safdar
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with CultureSeta Wicaksana
 
BeMetals Investor Presentation_May 3, 2024.pdf
BeMetals Investor Presentation_May 3, 2024.pdfBeMetals Investor Presentation_May 3, 2024.pdf
BeMetals Investor Presentation_May 3, 2024.pdfDerekIwanaka1
 
TVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdf
TVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdfTVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdf
TVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdfbelieveminhh
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting
 
Structuring and Writing DRL Mckinsey (1).pdf
Structuring and Writing DRL Mckinsey (1).pdfStructuring and Writing DRL Mckinsey (1).pdf
Structuring and Writing DRL Mckinsey (1).pdflaloo_007
 
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All TimeCall 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Timegargpaaro
 
Power point presentation on enterprise performance management
Power point presentation on enterprise performance managementPower point presentation on enterprise performance management
Power point presentation on enterprise performance managementVaishnaviGunji
 
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow ChallengesFalcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow Challengeshemanthkumar470700
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwaitdaisycvs
 
Arti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfArti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfwill854175
 
New 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck TemplateNew 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck TemplateCannaBusinessPlans
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 MonthsIndeedSEO
 
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGParadip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGpr788182
 

Recently uploaded (20)

unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pillsMifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
Mifty kit IN Salmiya (+918133066128) Abortion pills IN Salmiyah Cytotec pills
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
Mckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for ViewingMckinsey foundation level Handbook for Viewing
Mckinsey foundation level Handbook for Viewing
 
Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
BeMetals Investor Presentation_May 3, 2024.pdf
BeMetals Investor Presentation_May 3, 2024.pdfBeMetals Investor Presentation_May 3, 2024.pdf
BeMetals Investor Presentation_May 3, 2024.pdf
 
TVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdf
TVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdfTVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdf
TVB_The Vietnam Believer Newsletter_May 6th, 2024_ENVol. 006.pdf
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
Structuring and Writing DRL Mckinsey (1).pdf
Structuring and Writing DRL Mckinsey (1).pdfStructuring and Writing DRL Mckinsey (1).pdf
Structuring and Writing DRL Mckinsey (1).pdf
 
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All TimeCall 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
Call 7737669865 Vadodara Call Girls Service at your Door Step Available All Time
 
Power point presentation on enterprise performance management
Power point presentation on enterprise performance managementPower point presentation on enterprise performance management
Power point presentation on enterprise performance management
 
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow ChallengesFalcon Invoice Discounting: Aviate Your Cash Flow Challenges
Falcon Invoice Discounting: Aviate Your Cash Flow Challenges
 
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai KuwaitThe Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
The Abortion pills for sale in Qatar@Doha [+27737758557] []Deira Dubai Kuwait
 
Arti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfArti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdf
 
New 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck TemplateNew 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck Template
 
Buy gmail accounts.pdf buy Old Gmail Accounts
Buy gmail accounts.pdf buy Old Gmail AccountsBuy gmail accounts.pdf buy Old Gmail Accounts
Buy gmail accounts.pdf buy Old Gmail Accounts
 
!~+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUD...
!~+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUD...!~+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUD...
!~+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUD...
 
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 MonthsSEO Case Study: How I Increased SEO Traffic & Ranking by 50-60%  in 6 Months
SEO Case Study: How I Increased SEO Traffic & Ranking by 50-60% in 6 Months
 
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGParadip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
 

Can Your Health IT Service Provider Ensure Security for ePHI?

  • 1. Can Your Health IT Service Provider Ensure Security For ePHI? Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809
  • 2. Outsourcing your healthcare documentation, medical coding and billing, and other back office tasks can help save time and money and improve your productivity and efficiency. However, as a physician, there’s one question that you should ask yourself – is my health IT service provider conscious about the safety of my data? Poor IT security policies can land you in troublesome and costly penalties for HIPAA (Health Insurance Portability and Accountability Act) violations. Even a well known institution like the Idaho State University was recently penalized for a health information security breach. So before you outsource your back office tasks, it’s important to ensure that your health IT service provider has the following policies in place to ensure security of electronic protected health information: Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809
  • 3. Check whether the IT provider offers encryption for both active (in use) and inactive (not in use) ePHI. Otherwise, the ePHIs are at risk Encryption for ePHI of security breaches and HIPAA violations. Suppose that your medical billing service provider accesses your ePHI via an unencrypted network. There is a chance that someone can intrude the network and access the information when it is being transferred. The same applies to the ePHI stored in a computer, laptop or USB drive. If the device is stolen, misplaced or lost, ePHI confidentiality is at stake. In 2012, BlueCross BlueShield of Tennessee, a leading Health Benefit Plan company in Tennessee paid around $1.5 million to the Department of Health and Human Services (HHS) when 57 unencrypted computer hard drives containing the protected health information of more than 1 million people was stolen. Business Continuity & Disaster Recovery Plans The service provider that you select should have business continuity and disaster recovery plans. Even though most service providers plan how to handle an immediate service interruption, testing usually doesn’t take place until an emergency occurs! This is a bad practice. So ensure that your service provider has a tested and proven disaster recovery plan system in place. This will reduce wait time for updates – for you as well as your patients. Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809
  • 4. Data breaches may occur if the patients’ health information is not Proper Shredding of disposed off safely and securely. For data stored electronically, the ePHI potential for unauthorized access, erasing, altering, or losing, is high. Even if documents are deleted from the recycle bin, they are prone to unauthorized access via hard disk recovery. When disposing of data stored on computer disks, the disks need to be erased several times and it should be ascertained that the data cannot be recovered from them. The service provider should be able to recognize when, how and in what circumstances the ePHIs were destroyed. Identify Data Breaches Most data breaches are difficult to detect. As per the Verizon Data Breach Investigations Report 2013, around 66 percent of data breaches would take even months or years to discover. So you should ensure that your service provider has an efficient system (anti-virus software, malware detection tools, advanced analytic tools) to identify different types of data breaches. Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809
  • 5. Regular Risk Make sure that your service provider performs risk assessments Assessment regularly to address changing threats and policies so that effective and stringent security measures can be implemented. For example, the HIPAA Omnibus Final Rule effective from March, 2013 considers even the risk of data breach as a violation. Changes in technology can bring about new risks. It’s important that your service provider stays up-todate with such changes and conducts regular risk adjustments to detect and deal with security violation threats. HIPAA Business Associate Agreement If your service provider is willing to sign a HIPAA business associate agreement (BBA) with you, this is an indication of their commitment to security for your ePHI. The contract ensures safety for personal health information in accordance with HIPAA guidelines. The agreement should clearly show how your health IT service provider will report and respond to any kind of data breach. Also, make sure that the provider can produce evidence for routine audits such as SSAE 16 reports or PCI certification. Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809
  • 6. The bottom line: when you outsource your documentation or medical coding or billing tasks, look for a medical transcription company or medical billing company that is HIPAA complaint. Outsource Strategies International www.outsourcestrategies.com Headquarters: 8596 E. 101st Street, Suite H Tulsa, OK 74133 Call: 1-800-670-2809