Friday, February 11, 2011

Importance of HITECH Compliance


HIPAA has been enforced to safeguard the confidential personal health information of medical patients. It has strict guidelines making regular security monitoring and assessment mandatory and recommends encryption as an essential security parameter.

With a rising number of security breaches there is a lot at stake for both patients as well as healthcare organizations. The HITECH (Health Information Technology for Economic and Clinical Health) Act came about as an extension of HIPAA extending itself to business associates such as those offering legal, IT or accounting services, those providing financial support or those involved in marketing etc.

The new rule also requires healthcare entities to give specific notification to patients about data breaches. Business Associates and healthcare providers have to undergo audits from time to time to ensure overall HITECH compliance. Non-compliance can result in heavy penalty up to $250,000 while for repetitive and non-rectified violations the penalty can go up to a maximum of $1.5 million. Therefore in order to ensure that all their security parameters are in tandem with HITECH requirements, healthcare organizations need to take care of certain vital elements:

1. Assessment of Risks – The healthcare providers need to conduct an extensive analysis on existing practices that are related to personal health information to assess risks in data breaches. Maintaining a PHI inventory with accurate information can help in identifying risks in policies and procedures as well as in IT systems. Identifying business associates with accessibility to PHI is also vital.
2. Secured Metrics- Healthcare organizations need to ensure that risk assessment information is secure by following the HITECH guidelines. The amount of personal data revealed should be only as per the requirement of any business process. Encryption of information systems is the ideal approach to reduce risks of data breaches and to tackle data breach notification requirements.
3. Contract Scrutiny– As per HITECH law all business associates have to clearly state the utilization of personal information that they have been allowed to access. An assessment of procedures provides an insight on which associates pose the highest threat. As a result healthcare organizations can make changes in the contract and initiate processes for negating high risk contracts.
4. Breach Detection Plan – According to HITECH Act a notification must be provided within 60 days in the event of any data breach. This includes minor losses or revelation of either single records or any amount of personal information. If an organization is reported to be incapable of detecting a breach it would mean fines up to $1.5 million.
5. Breach Response Plan – Notification of the smallest data breach is mandatory according to the HITECH Act. A record of every breach has to be submitted to the Department of Health and Human Services.

Healthcare organizations have to shoulder immense responsibilities in providing security to their patients’ data. Hence it is important for them to invest in competent and aggressive HITECH compliance management software that can detect breach early and maintain IT audits to check for irregularities in patient records.

Top HIPAA Compliance Tips for Small Practitioners


The Health Information Technology for Economic and Clinical Health (HITECH) Act has brought about significant changes in the healthcare industry’s approach to data protection. According to the Ponemon Institute’s benchmark study on Patient Privacy and Data Security, of Nov 2010, “data breaches were responsible for huge costs for healthcare organizations that amounted to an average of close to $1million annually.” However, the HITECH Act is expected to change this scenario soon. 

Now referred to as HIPAA-2, the HITECH Act has stringent requirements for compliance, penalties and incentives for the adoption of Electronic Medical Record keeping (EMR). The new and stronger Act is designed to ensure that data breaches are reduced drastically. Since the HITECH Act makes it mandatory for healthcare organizations to reveal patient privacy breaches to their patients, these organizations including small medical practices are looking for a cost-effective HIPAA/HITECH compliance solution. Here are a few tips to help small medical practitioners pick the right solution to meet HIPAA/HITECH compliance requirements and benefit the small medical practitioners:

  • Choose a compliance solution that can cover both privacy and security standards
  • Opt for a solution that can provide documented proof/evidence of compliance, which they can produce to auditors and other authorities if needed
  • The solution must provide menu-driven assessment to assist in comprehending and controlling HIPAA/HITECH requirements
  • The solution must offer a comprehensive policy framework and customized templates for easily attaching evidence
  • The HITECH compliance management solution should offer medical practitioners a central repository for all HIPAA compliance related documentation
  • Offer automatic updates on new or revised policies, procedures, and forms that reflect changes in standards or changes in regulatory requirements
  • Send out periodic reminders for assessment for monitoring compliance.
  • Provide appropriate tools for tracking and managing business associates with a simple plug-in option for all PCI-DSS compliance requirements.

Introduced in conjunction with the American Recovery and Reinvestment Act of 2009, the HITECH Act makes it mandatory for healthcare entities to follow Electronic Medical Recordkeeping (EMR) methods. To ensure that healthcare companies comply with these requirements, several attractive incentives are being offered. However non-compliance attracts very heavy penalties and fines that could amount to $1.5 million per year, or criminal prosecution. Healthcare practitioners should therefore keep these tips in mind while choosing a compliance solution- because, it’s better to be safe than sorry!

Also read articles on:  IT Compliance  

Monday, February 7, 2011

Understanding HIPAA and HITECH Compliance

The healthcare industry is now governed by stringent regulations that will change the way the healthcare organizations have been operating. Here is an overview of the Laws that govern the healthcare industry today.

The American Recovery and Reinvestment Act (ARRA) is an economic stimulus bill enacted on the 17 February 2009 to help the United States economy recover from recession. Apart from health care, the other sectors where ARRA has its bearing are education, infrastructure, energy, and social welfare.

ARRA and the Health Care Industry

The American Recovery and Reinvestment Act of 2009 not only modifies an already existing federal law but also introduces a new one with the aim to improve economic efficiency in the healthcare industry by encouraging increased use of technology in the sector. Through the HIPAA compliance and HITECH Acts, ARRA makes it mandatory for all doctors, dentists, chiropractors, psychologists, nursing care, or anyone who handles Patient Health Information (PHI) to be compliant with the regulations laid down in both these Acts. Not only lone medical practitioners but also small medical groups are bound to comply with these Acts.  Under the Health Information Technology for Economic and Clinical Health (HITECH) Act, health care data breaches will attract significantly stiffer penalties than they used to with the Department of Health & Human Services (HHS) seriously committed to enforce those penalties and publicize all major data breaches. The HITECH Act also broadens the definition of a covered entity under the Health Insurance Portability and Accountability Act; many organizations that had not been required to comply with HIPAA privacy and security rules must now do so.

HIPAA and the HITECH Acts

HIPAA or the Health Insurance Portability and Accountability Act was enacted in 1996 to enhance the efficiency of the healthcare system by ensuring insurance coverage for employees and workers, forbidding discrimination based on health status, protecting the privacy of patients’ health records and  promoting the use of technology. The data privacy and security requirements of HIPAA came into effect in 2003. As per the amendment, all businesses in the medical and healthcare sector are not only required to protect the medical information of patients, but also to make their systems compliant with the standards set forth in HIPAA.

The HITECH or the Health Information Technology for Economic and Clinical Health Act, on the other hand, was enacted in 2009 as part of ARRA. As per this act, from 2011, financial support will be provided to all those who take steps to embrace technology in the healthcare space by maintaining electronic health records (EHR). However, from 2015 onwards those who fail to comply with the HITECH Act have to face heavy penalties. The Electronic Health Record Incentive program offers cash incentives to hospitals and other eligible professions (EPs) who can successfully demonstrate the meaningful use of EHR technology.

HIPAA/ HITECH Compliance

The need to comply with HIPAA and HITECH Act has placed increased pressure on medical groups and practitioners who not only have to ensure but also prove that their systems and practices are competent enough to protect patient health information. Since lack of a comprehensive security framework can cause irreparable damages, healthcare organizations need a solution that can handle healthcare regulatory compliance effectively. Such a solution would come as a relief for all healthcare providers and practitioners by making healthcare compliance simple and hassle-free.

Friday, February 4, 2011

Top 3 Healthcare IT Challenges


IT is a good investment- especially for healthcare organizations. A study conducted in 2007 by the Florida State University revealed that patients treated in hospitals which employed IT systems had better health outcomes. While the benefits offered by IT systems are quite apparent, managing an increasing number of computers and other devices and the information they hold, poses significant challenges mainly concerning information security. Here are the top three challenges that healthcare organizations should be prepared to tackle:

·         Challenge 1 – Securing the Growing Volumes of Electronically Stored Medical Records: With PCs and mobile devices quickly replacing traditional patient charts, the number of electronic medical records (EMRs) has skyrocketed. And with multiple systems and networked devices, security becomes a huge concern. Determining access rights, implementing effective controls, and managing change can be immensely challenging. Moreover, many healthcare organizations extend beyond a single physical location for off-site services, home-health services etc. In such cases, EMRs are constantly on the move and security of databases and network systems is a major challenge.   
·         Challenge 2 - Issues Concerning Data Storage: With EMRs multiplying every day, data storage is a growing concern. Hence online, and offline data storage, and storage virtualization are adopted to tackle the problem of data storage. However, these solutions may further add to the security concern if carefully defined data storage policies are not in place. And to manage and improve the storage environment, which stores the enormous amount of medical data generated every day, healthcare organizations have to adopt a centralized and standardized storage management solution.  And identifying such a solution by itself is a challenge.
·         Challenge 3 - Compliance with Multiple Changing Regulations: Storage of large volumes of medical records brings with it several risks, and consequently a number of compliance issues. Governing access to sensitive data, keeping track of who has access, when and how, and who can retrieve and process confidential records are all concerns surrounding security and compliance. With more and more stringent regulations laid down by the government in the form of HITECH, HIPAA compliance etc, healthcare compliance is now a major concern.

Irrespective of these challenges, healthcare entities cannot neglect the role of technology in providing superior services in patient care. While on the one hand the healthcare industry has to adopt technological solutions to provide better medical services, on the other they have to abide by HIPAA HITECH compliance. By employing a comprehensive, automated compliance solution, healthcare entities can enjoy the benefits offered by technology while also mitigating the risks that it may pose.

Thursday, February 3, 2011

EHR Incentives: A Catalyst for IT Security


In 2005, when HIPAA came into effect, healthcare organizations were required to mitigate risks by conducting periodic risk assessment. But until recently a significant number of healthcare entities did not put this into practice. According to a recent survey 14 percent of hospitals and 33 percent of clinics were yet to conduct their first risk assessment. However, the EHR program funded by the federal economic stimulus package has been a catalyst for information protection.

The billions of dollars worth of incentives set aside for hospitals and physicians for implementing secure Electronic Medical Recordkeeping (EMR) have spurred security initiatives in the healthcare industry. Many healthcare entities are now ramping up their security measures in risk assessment, encryption and email security, data loss prevention, and providing formal security training to employees.

To qualify for these incentives however, healthcare organizations must use an EMR system that has been certified to include specific functions comprising a strong set of security features. Hence, issues including threat mitigation, risk analysis, and compliance with HIPAA and HITECH Acts have now come to the forefront. However, a significant challenge stems from the fact that most medical practitioners are unfamiliar with encryption and user authentication technology, and the idea of conducting a risk assessment is foreign to them.

Sole practitioners and small healthcare entities especially face issues in achieving and maintaining compliance with HIPAA and HITECH Acts. With HITECH redefining the responsibilities of Business Associates, creating stricter notification standards, tightening enforcement, and raising penalties for non-compliance, small healthcare entities are in need of a solution that can manage these elements efficiently and in a cost-effective manner.

Moreover, with the HITECH Act promoting and offering incentives for the adoption of secure EMR, small medical practitioners face a growing dilemma since adopting an EMR system not only means government incentives, but also greater security risks and bigger penalties for non-compliance.  This is where eGestalt’s SecureGRC SB comes in handy.

SecureGRC SB: Simplified HIPAA/HITECH Compliance Solution for Small Medical Practices

A unified security monitoring and compliance management solution delivered on the cloud, SecureGRC SB is the first of its kind. It offers an inexpensive, easy-to-use, automated system of compliance, specially designed for small medical practices, and their Business Associates to identify, remediate and maintain their HIPAA and HITECH compliance.

With built-in HIPAA/HITECH support, SecureGRC SB efficiently addresses all HIPAA/HITECH requirements, and also helps manage Business Associates with a simple wizard-driven automation tool. SecureGRC SB can be easily extended and automatically kept up-to-date with latest versions and revisions of these Acts

Wednesday, February 2, 2011

Addressing Healthcare Compliance: The HITECH Act


With a dramatic increase in the number of security breaches and Patient Health Record (PHR) thefts, there is mounting pressure on healthcare organizations to implement a thorough access governance framework to protect electronically stored PHR. This called for the extension of The Health Insurance Portability & Accountability Act (HIPAA) to accommodate a more preventive rather than reactive approach to security; the end result being The Health Information Technology for Economic and Clinical Health (HITECH) Act, which imposes much more stringent requirements in addition to the privacy and security norms of HIPAA.

The HITECH Act takes a broader and more preventive approach by enforcing specific control requirements for the protection of PHR. Additionally, HITECH compliance not only requires a system of recording evidence of compliance, but also an audit trail of who has access to Electronic Health Records (EHR), and how and when these records were accessed. With all these regulatory standards to be addressed, healthcare organizations need a comprehensive security monitoring and compliance management solution that can effectively deal with access control and other requirements. Here are some features to look for:

Automated Access Controls: Healthcare organizations need a solution that can implement automated controls to ensure authorized access, and address change management with regard to users’ roles within, and relationships with the organization. It should facilitate maintenance of policies in a consistent fashion to avoid access-related risks.

Preventive, rather than Detective Approach: Applying access-control policies in an environment that is subject to constant change is a formidable challenge. And hence effective change management becomes a growing challenge. Hence the security solution adopted by healthcare organizations should be able to simplify the change management process by assigning pre-determined compliant roles, and by ensuring a closed-loop validation process which can make sure that access rights not required for a certain role are remediated. This helps in taking a preventive approach and helps mitigate risks.

Complete Compliance Support: Complying with multiple regulations is always a challenge for organizations of all sizes. And only more so for healthcare organizations which process electronically stored patient records. While on the one hand they need to ensure overall information security, on the other they have to abide by the stringent requirements of HIPAA Compliance and HITECH Acts. And to ensure healthcare compliance organizations have to adopt a solution that can offer complete support with simple, easy-to-use tools, offering scalability and easy plug-in capabilities to accommodate new regulations.

Some compliance solutions also enable automatic updates on new policies and procedures, and on modified regulations and requirements. They also keep track of the compliance status and send out periodic reminders for compliance maintenance. With such an integrated compliance solution and a strategic policy framework in place, healthcare organizations can gain complete visibility and control over information access, and effectively mitigate risk of unauthorized access to sensitive PHR.   

Top Tips to Avoid Healthcare Compliance Risks in 2011

In 2010, the Obama Administration specially focused on regulatory measures in the healthcare sector, and 2011 is perhaps slated to be the breakthrough year for healthcare compliance. So the healthcare industry should prepare itself to face numerous challenges lurking in the compliance scene. Doctors, dentists, chiropractors, psychologists, and other medical practitioners have to abide by the regulations set forth in the HIPAA and HITECH Acts. With new reforms in place healthcare entities need to be proactive in abiding by compliance standards and changing regulations. Here are some tips that can help healthcare organizations avoid compliance risks:

·         Establish an appropriate policy and procedure framework. An unclear set of policies or compliance framework could go against the organization. Hence it is essential that medical practitioners and healthcare organizations dedicate efforts towards being HIPAA and HITECH compliant. They should ensure that the right policy framework and guidelines are in place to help the implementation of systems and practices that can keep patient’s health records safe.

·         Select a compliance solution that offers centralized up-to-date services. They should ensure that the compliance solution adopted is future proof: A healthcare compliance management system is most effective if it can work anytime, anywhere. Therefore it is important to opt for a solution delivered on the cloud. This also means that the solution is capable of sending timely alerts and updates regarding new versions of security monitoring/compliance management software and techniques. More importantly, it should provide complete in-built HIPAA & HITECH support which can be easily extended if the need arises. Also, the healthcare compliance solution chosen should be easy to deploy and manage.

·         Select a compliance solution that automates audit processes. Healthcare regulatory compliance is essential even if medical practitioners and organizations are not using technology in their medical practice. Small medical practitioners should proactively deploy a healthcare compliance solution that can automate audit processes and provide tangible evidence of compliance. Therefore, they should opt for a solution that has the ability to build a repository of all HIPAA Compliance related documentation and provide automatic updates on revised policies and procedures.

It is well known that ever since HITECH was enacted as part of the American recovery and Reinvestment Act of 2009, organizations abiding by the Act were offered incentives for Electronic Medical Recordkeeping (EMR). However from 2015, non-compliance with these standards would attract criminal penalties. So medical practitioners and healthcare entities which abide by HITECH and HIPAA are likely to face fines that can amount to a formidable sum of $1.5 million per year or more along with criminal prosecution. So being healthcare compliant is certainly a safer bet!