Events

Webinar: Lessons and Examples from 2019’s HIPAA Breaches and Fines

2019 was another record-breaking year for healthcare industry data breaches. A new record was set in 2018 with 371 healthcare data breaches of 500 or more records reported to the Department of Health and Human Services’ Office for Civil Rights. That record was truly smashed in 2019 with an astonishing 492 breaches of 500 or more records reported.

2019 was a busy year for the HHS’ Office for Civil Rights. In 2019, OCR levied more than $15 million in fines to resolve violations of the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule.

The fines were issued for a variety of compliance failures, including the failure to conduct a comprehensive, organization-wide risk analysis, failures to enter into business associate agreements with vendors, access control failures, disclosure of PHI on social media, breach notification delays and the failure to comply with the HIPAA Right of Access.

The reasons for the financial penalties may have been varied, but there was one common denominator. The financial penalties could have easily been avoided. It may not be possible to prevent all data breaches, but it is possible to avoid OCR financial penalties.

On February 19, 2020, HIPAA Journal sponsor, Compliancy Group, will be reviewing the 2019 healthcare data breaches and the financial penalties that OCR imposed on healthcare organizations and business associates of HIPAA-covered entities.

In the webinar, Compliancy Group will explain how financial penalties and the associated negative publicity can easily be avoided by implementing a simple compliance plan.

Don’t miss out on this opportunity as Compliancy Group’s HIPAA compliance experts will be giving actionable tips that you can apply to start protecting your business immediately!

Webinar Details:

Date: February 19, 2020

Time: 2PM ET / 11AM PT

Click here to register for the webinar

 

The post Webinar: Lessons and Examples from 2019’s HIPAA Breaches and Fines appeared first on HIPAA Journal.

Lessons and Examples from 2019 HIPAA Breaches and Fines

It has been another busy year of HIPAA enforcement for the Department of Health and Human Services’ (HHS) Office for Civil Rights.

So far in 2019 there have been 9 financial penalties imposed on HIPAA covered entities and business associates to resolve compliance failures. In total, $12,209,000 has been paid as a result of HIPAA violations and more financial penalties could be announced before the year is out.

2019 has seen OCR continue to impose penalties for compliance failures related to risk analyses, risk management, business associate agreements, access controls, breach notifications, and impermissible disclosures of protected health information, as has been the case over the past few years.

2019 also saw OCR launch a new HIPAA compliance enforcement initiative. Under the HIPAA Right of Access initiative, OCR has issued two $85,000 financial penalties for failures to provide patients with copies of their medical records in a reasonable time frame without being overcharged.

OCR is not penalizing healthcare organizations and business associates for data breaches, as breaches can occur even when an organization is fully compliant. The penalties are issued because of the lack of an effective HIPAA compliance program. If those 9 entities had an effective compliance plan in place, a sizable financial penalty and all the negative publicity would have been avoided.

On January 22, HIPAA Journal sponsor, Compliancy Group, will be hosting a webinar in which OCR’s HIPAA compliance enforcement actions in 2019 will be reviewed and the changing enforcement priorities of OCR will be discussed.

Compliancy Group will also explain how straightforward it is to implement and maintain an effective HIPAA compliance plan and its compliance coaches will be providing actionable tips to help you immediately start protecting your business.

Webinar: Lessons and Examples from 2019’s HIPAA Breaches and Fines

Date: January 22nd, 2020 @ 2:00 pm ET / 11 am PT

Register Here

The post Lessons and Examples from 2019 HIPAA Breaches and Fines appeared first on HIPAA Journal.

Webinar Today: Solving the HIPAA Problem: Demonstration of Compliancy Group’s Simplified HIPAA Compliance Process

Meeting all requirements of the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, Omnibus, and Breach Notification Rules can be a major challenge.

Many healthcare organizations have established a compliance program and believed they were compliant, only to discover during a HIPAA audit or compliance review that they have failed to comply with one or more HIPAA provisions. Those mistakes can prove to be very costly.

Compliance failures can easily lead to a data breach or could result in a complaint being filed with the Department of Health and Human Services’ Office for Civil Rights (OCR), the primary enforcer of HIPAA compliance.

OCR investigates complaints and data breaches to determine whether HIPAA Rules have been violated and conducts compliance audits to assess whether HIPAA covered entities and business associates of covered entities are complying with all aspects of HIPAA Rules.

Enforcement of compliance has stepped up in recent years. In 2018, OCR imposed $28,683,400 in financial penalties on covered entities and business associates in 11 enforcement actions and 10 compliance investigations resulted in financial penalties in 2019.

Solving HIPAA Compliance Issues

Compliancy Group understands the importance of HIPAA compliance and the difficulties HIPAA-covered entities and their business associates encounter when trying to implement and maintain an effective compliance program.

To simplify the process of HIPAA compliance, Compliancy Group has developed a software solution that guides entities through the compliance process. The software solution, The Guard, simplifies everything your organization needs to achieve HIPAA compliance, mitigate risk, and avoid fines.

On March 25, 2020, Compliancy Group will be running a group demonstration of The Guard and its simplified HIPAA compliance process.

Join Compliancy Group for the demonstration and find out how their compliance coaches help covered entities and business associates achieve compliance and satisfy all federal regulations.

Solving the HIPAA Problem: Group Demonstration of Compliancy Group’s Simplified Process

Date: March 25th @ 2:00 pm ET / 11 am PT

Register Here

The post Webinar Today: Solving the HIPAA Problem: Demonstration of Compliancy Group’s Simplified HIPAA Compliance Process appeared first on HIPAA Journal.

Solving the Communication Problems in Healthcare

52% of healthcare organizations experience communications disconnects that negatively impact patients daily or multiple times a week, according to a recent study by TigerConnect.

These communication problems are more than a cause of frustration for healthcare employees. They make care coordination difficult and lead to lapses in care. In fact, the impact of poor communication is far reaching and affects the entire organization.

At best, communication inefficiency causes delays that increase the cost of healthcare provision. At worst, poor communication contributes to preventable medical errors, physician burnout and, in the most extreme cases, it can lead to death.

Many healthcare facilities are still heavily reliant on outdated communication technology such as pagers and fax machines. Groups of healthcare employees use different tools to communicate and, even with a growing mobile workforce, landlines are relied upon far too frequently.

TigerConnect research has shown that communication channels in hospitals are badly fragmented. 89% of hospitals are still using fax machines and 39% are still heavily reliant on pagers for communicating with certain departments, roles or, in the worst cases, organization-wide.

Even when modern communications technology is adopted, it is often implemented in silos. Physicians and nurses may be moved onto modern communications systems, but others are not. Consequently, the full benefits are not realized.

These communication problems are not only a source of frustration for healthcare employees, patients are also noticing. A Harris poll of patients conducted in August 2019 showed patients are frustrated by inefficient communication in healthcare during hospital stays, visits, and by the methods providers are using to communicate with them.

Fixing Broken Communication in Healthcare

TigerConnect will be hosting a webinar in which the extent of the communication problems in the U.S. healthcare industry will be discussed along with the problems that communication disconnects are causing.

Dr. Will O’Connor, CMIO, TigerConnect  and Jorge Jeffery, Data Scientist & Researcher, will talk about these issues and will suggest a solution that will improve communication in healthcare, increase workflow efficiency, reduce common bottlenecks that are slowing patient throughput, and how improvements in communication can ensure more patients are seen in less time and the cost of healthcare provision can be reduced.

Webinar Details:

Topic:    Fixing Broken Communications in Healthcare

Date:     Thursday December 12, 2019

Time:    1.00 PM Eastern Time / 12:00 PM Central Time / 11:00 AM Mountain Time / 10.00 AM Pacific Time

Hosts:   Dr. Will O’Connor, CMIO, TigerConnect / Jorge Jeffery, Data Scientist & Researcher

The Webinar will be followed by a Q&A session

You can sign up for the webinar here.

The post Solving the Communication Problems in Healthcare appeared first on HIPAA Journal.

Webinar: 12/17/19: How to Become HIPAA Compliant in 2020

As 2019 draws to a close, companies that are looking to start providing products and services to the healthcare industry will be considering how they can become HIPAA-compliant in 2020. Forward-thinking business associates already serving the healthcare sector are thinking about how they can maintain compliance in 2020, build their portfolio of healthcare clients, and grow their businesses.

Resources have been made available to help prospective HIPAA business associates achieve HIPAA compliant status and establish and maintain an effective HIPAA compliance program. One of the best resources was published by the Department of Health and Human Services’ (HHS) Office of Inspector General (OIG). The document – The Seven Fundamental Elements of an Effective Compliance Program – is a powerful tool that serves as a guide for healthcare organizations and business associates to help them develop an effective compliance program, meet all HIPAA requirements, and avoid financial penalties from the HHS’ Office for Civil Rights and state attorneys general.

The document outlines the infrastructure, policies, and procedures that are required and serves as a good base on which to build. Once the fundamentals are established, covered entities and business associates can work through each of the implementation standards of HIPAA to ensure they are fully compliant.

HIPAA compliance is mandatory for all healthcare organizations that conduct healthcare transactions electronically, and also for any vendor that provides products or services to HIPAA-covered entities that requires them to come into contact with protected health information.

Becoming HIPAA compliant also has other important benefits, such as improving security to prevent costly data breaches and protecting an organization’s reputation. Achieving HIPAA-compliant status also helps businesses differentiate their services from the competition and attract new clients from all industry sectors. It shows that you have policies and procedures in place to ensure the confidentiality, integrity, and availability of any data provided to your company and that you are fully committed to privacy and security.

On Thursday December 12, 2019, HIPAA Journal sponsor, Compliancy Group, will be hosting a webinar to explain the importance of HIPAA compliance, how to ensure that all requirements of HIPAA are met and survive a HIPAA audit, and how to start leveraging the true benefits of HIPAA in 2020 and start using HIPAA compliance to help you grow your business.

Webinar Details:

Date:     December 17, 2019

Time:    2:00 PM ET

Click Here to Register for the Webinar

The post Webinar: 12/17/19: How to Become HIPAA Compliant in 2020 appeared first on HIPAA Journal.

Web Event: Solving the HIPAA Problem with Compliancy Group: Demonstration of The Guard HIPAA Compliance Software

HIPAA Journal Sponsor, Compliancy Group, will be hosting a group demonstration of its HIPAA compliance software solution, The Guard, on Wednesday, November 20, 2019 at 14:00 ET.

The event will give you the opportunity to find out more about how The Guard simplifies HIPAA compliance and how it can help your organization meet all requirements of the HIPAA Privacy, Security, Breach Notification, and Omnibus Rules.

The Guard is a proprietary software solution that simplifies compliance with HPAA Rules and covers all aspects of the Health Insurance Portability and Accountability Act. The software is based on Compliancy Group’s “Achieve, Illustrate, and Maintain” methodology, and will not only help covered entities and business associates develop a compliance program, it will help them ensure that compliance is maintained. By simplifying the compliance process, covered entities and business associates can focus on running their businesses and practices.

The Guard includes intuitive training and assistance from Compliancy Group’s compliance coaches along with HIPAA assessments covering privacy, security, device audits, and administrative, physical, and technical safeguards. After successfully completing the 6-step risk analysis and risk remediation process, clients will be awarded Compliancy Group’s HIPAA Seal of Compliance. The solution also includes incident management and breach notification assistance, business associate management and tracking of all vendors, and data breach and HIPAA audit support.

The Guard can be used by vendors who are looking to start providing products and services to healthcare clients but must first ensure they are fully compliant with HIPAA Rules. The software solution will also help established business associates and covered entities ensure that they are fully compliant and will be able to pass an Office for Civil Rights’ compliance audit.

The Group Demonstration will give you the opportunity to find out more about Compliancy Group and The Guard HIPAA compliance solution.

You can register for the event using the link below:

Solving the HIPAA Problem: Group Demonstration of The Guard HIPAA Compliance Solution

The post Web Event: Solving the HIPAA Problem with Compliancy Group: Demonstration of The Guard HIPAA Compliance Software appeared first on HIPAA Journal.

Webinar: Your 2019 MIPS Security Risk Analysis: 6 Steps to Compliance (11/14/19)

Healthcare organizations often struggle with risk analyses, as OCR’s HIPAA enforcement actions clearly show. The risk analysis is the most common HIPAA violation cited in OCR’s enforcement actions.

The risk analysis is essential as it allows healthcare organizations to identify all risks to the confidentiality, integrity, and availability of ePHI. Those risks can then be reduced to a reasonable and acceptable level. A risk assessment should be completed regularly, with the frequency determined by the circumstances of their environment. For many healthcare organizations, this will be annually.

An annual security risk analysis (SRA) is a requirement of the 2019 MIPS Performance Year to comply with Promoting Interoperability. The SRA makes up 25% of the performance score so it is essential that this critical process is completed. The deadline for completing the SRA is December 31, 2019.

If you have yet to conduct your SRA for 2019 and are not yet ready to attest to meeting this objective, help is at hand. HIPAA Journal sponsor, Compliancy Group, is hosting a webinar in conjunction with Compulink Healthcare Solutions which covers this important aspect of compliance.

At the webinar, Compliancy Group and Compulink Healthcare Solutions’ Director of Professional Relations and Government Programs, Dr. Karen Perry, will be discussing the security risk analysis and how you can implement appropriate safeguards to satisfy the MIPS SRA requirement.

At the end of the event you will have access to the tools you need to confidently achieve your mission-critical priorities, ensure compliance, and help your organization thrive in a fast-evolving digital landscape.

Webinar Details:

Your 2019 MIPS Security Risk Analysis: 6 Steps to Compliance

Date: Thursday, November 14, 2019

Time: 14:00 ET

Registration Link

The post Webinar: Your 2019 MIPS Security Risk Analysis: 6 Steps to Compliance (11/14/19) appeared first on HIPAA Journal.

Webinar: Atlantic.Net and Compliancy Group Offer Help on Cybersecurity and HIPAA Compliance

The HIPAA-compliant hosting company, Atlantic.net, is teaming up with HIPAA-compliance specialists Compliancy Group for a webinar to explain some easy-to-implement steps healthcare organizations can take to quickly improve their security posture, become more resilient to cyberattacks, and ensure they continue to stay compliant with HIPAA regulations.

Healthcare organizations are being targeted by cybercriminals for the data they hold. Patient data can be sold for big bucks on the black market, there a growing trade in stolen healthcare login credentials, and ransomware is being used to extort money from hospitals and medical practices. For the past two months, healthcare data breaches have been reported at a rate of more than 1.5 per day, which is twice the rate of 2018. Cybersecurity has never been more important.

Many practices lack the internal resources to devote to cybersecurity and budgets are stretched. Finding the funds to devote to improving cybersecurity protections can be a major challenge, so it is important to ensure any additional funding is well spent.

In the webinar, Altantic.Net’s experts will be speaking about HIPAA-compliant cloud services and cybersecurity and Compliancy Group’s compliance specialists will walk attendees through some of the complexities of HIPAA to help attendees develop a plan to improve cybersecurity, ensure compliance, and avoid regulatory fines.

Join Atlantic.Net and Compliance Group for the webinar on Wednesday October 24th to find out more

Webinar:

HIPAA Compliance & Cybersecurity: 5 Things You Can Do at Your Practice Tomorrow

Date:     Thursday October 24, 2019

Time:    3PM ET / 12PM

Register Here

The post Webinar: Atlantic.Net and Compliancy Group Offer Help on Cybersecurity and HIPAA Compliance appeared first on HIPAA Journal.

Webinar: Ransomware, Malware, Phishing, and HIPAA Compliance

Compliancy Group is offering healthcare professionals an opportunity to take part in a webinar covering the main threats facing the healthcare industry.

Threats such as ransomware, malware, and phishing will be discussed by compliance experts in relation to HIPAA and the privacy and security of patient data.

Cybersecurity has become more important than ever in healthcare. The industry is seen as a weak target by hackers, large volumes of data are stored, and patient information carries a high value on the black market.

April 2019 saw the highest number of healthcare data breaches in a single month and more healthcare data breaches were reported in 2018 than in any other year to date. The increased frequency of attacks on organizations of all sizes highlights just how important cybersecurity has become.

Cyberattacks are not only negatively affecting businesses in the healthcare sector, but also place the privacy of patient’s health information at risk. While it was once sufficient to implement standard security tools, the sophisticated nature of attacks today mean new solutions are required to protect against cyberattacks.

Protecting against cyberattacks while ensuring compliance with HIPAA can be a challenge and oversights could easily lead to a costly breach or regulatory fine.

In the latest Compliancy Group webinar, compliancy experts will walk you through the inns and outs of the regulations and you can find out more about cybersecurity with respect to the requirements of HIPAA and HITECH.

Webinar:

Ransomware, Malware, Phishing, Oh My!

Wednesday, July 10th

2:00 ET/11:00 PT

Advance Registration

The post Webinar: Ransomware, Malware, Phishing, and HIPAA Compliance appeared first on HIPAA Journal.