HIPAA – SECURITY RISK ANALYSIS
What Is HIPAA And EPHI?
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) required the Secretary of the U.S. Department of Health and Human Services (HHS) to develop regulations protecting the privacy and security of certain health information. To fulfill this requirement, HHS published what are commonly known as the HIPAA Privacy Rule and the HIPAA Security Rule. The Privacy Rule, or Standards for Privacy of Individually Identifiable Health Information, establishes national standards for the protection of certain health information. The Security Standards for the Protection of Electronic Protected Health Information (the Security Rule) establish a national set of security standards for protecting certain health information that is held or transferred in electronic form. The Security Rule operationalizes the protections contained in the Privacy Rule by addressing the technical and non-technical safeguards that organizations called “Covered entities” must put in place to secure individuals’ “Electronic Protected Health Information” (e-PHI). Within HHS, the Office for Civil Rights (OCR) has responsibility for enforcing the Privacy and Security Rules with voluntary compliance activities and civil money penalties.
Security Risk Analysis for Protecting Electronic Health Information
To pass an OCR audit, covered entities must have a thorough, documented Security Risk Analysis in place to protect Electronic Patient Health Information. Streamline Billing Group takes on this task with great vigilance and completes a security risk analysis in collaboration with providers within a time period depending on the size of your practice. Some of the services we offer include:
- Appointing a privacy and security officer within the facility
- Developing documented policies and procedures
- Providing HIPAA-compliant employee training as part of the service package
- Thorough module-based Risk Assessment
- Contingency plans for disaster recovery
- Security incident monitoring and guidelines for reporting incidents
Enjoy The Best Experience with Us
We recommend reaching out to a professional if you happen to undergo an audit. While there are numerous online tools that offer convenience, taking risky shortcuts is not advisable. “Having” documentation should not be mistaken for “Good” documentation. Auditors will prioritize quality over quantity, scrutinizing the documentation to ensure it contains the necessary information.
Details
Contact Information
Info@streamlinebillinggroup.com
(859) 618-7862
Lexington, Kentucky, 40504