Download our ungated guide to high-quality penetration testing.
With data breaches in the healthcare industry increasing exponentially, it's critical for those in leadership positions to get serious about HIPAA security and enforcement. You need to understand not only why HIPAA is important but how the rule enforcement process works and the penalties that can be implemented.
The Health Insurance Portability and Accountability Act (HIPAA) was legislated in 1996 and provides security and data privacy for medical information. The Department of Health and Human Services (HHS) and, in particular, the Office for Civil Rights (OCR) oversee and enforce HIPAA.While the rules regarding HIPAA may seem complicated, they can be summed up in a few simple statements. These include keeping patients' medical records secure and private. The only people who should have access to patients' medical history documents are the healthcare professionals who have authorization and need to know for a patient's care.
Security and privacy aren't just limited to actual paper records. The regulations also extend to electronic documents and medical information that is discussed verbally. Records are expected to be completely accurate and quickly available to those who need to know the information.If you're responsible for the security of medical information in your organization it's imperative that you're serious about correctly implementing and enforcing HIPAA regulations. Fines have been imposed, individuals have lost their jobs and offices have been closed when HIPPA has not been followed according to guidelines.
There are several ways in which the Office for Civil Rights enforces the privacy rules set forth by HIPAA.
There have been thousands of cases regarding privacy practices that have been investigated by the Office for Civil Rights. Corrective measures have been applied in cases when an investigation has shown noncompliance. According to Enforcement Results, reported by Health and Human Services, a dollar amount reaching $72,929,182 has been imposed or settled in 52 cases. These cases have included hospitals, medical centers and pharmacy chains.OCR has become more aggressive during the last few years regarding enforcement of HIPAA regulations. There have been several specific cases that have resulted in steep fines.
These are just a few high-profile cases that have resulted from various HIPAA violations.The Office for Civil Rights is serious about enforcing HIPAA security rules in the workplace. If you're responsible for HIPAA in your company it's imperative that you understand and carry out enforcement within your organization. The potential fines and jail time would not only be devastating on a personal level but could potentially destroy a company or organization.
Security news, tips, webinars, and more straight to your inbox.