CancerNetwork Members: Login | Register
CancerNetwork SearchMedica Medline Drugs

Powered by SearchMedica

 
PUBLICATIONS
NEWS
PODCASTS
TOPICS
BLOGS
NURSES
PATIENTS
JOBS
CONFERENCES
CME
SUPPLEMENTS
 

Home » EHR

 

OCR's HIPAA Audits: Get Organized and Be Prepared

By Ericka L. Adler | March 21, 2012

In prior blogs I have touched upon HIPAA, the need for confidentiality, and the importance of proper recordkeeping in your practice. The time has now come to find out whether your practice is HIPAA-compliant, as the Office of Civil Rights (OCR) will be conducting random “HIPAA Compliance Audits” of Covered Entities (e.g., your practice) and its Business Associates in 2012. Providers lucky enough to be selected for an audit will be required to submit all written HIPAA compliance materials for review and participate in a three-day to 10-day on-site audit to observe those HIPAA compliance policies in action. Although these audits are not “formal” investigations, discrepancies may trigger a formal OCR investigation, which any practice wants to avoid.

Although HIPAA was all the rage back in the early 2000s when most practices purchased HIPAA manuals and obtained staff training, HIPAA has been neglected by many since then. To be fully HIPAA-compliant, your practice must keep its policies and training updated and stay abreast of new legal interpretations, opinions, and case law. I am routinely asked to provide guidance regarding HIPAA and am consistently surprised by how many providers: (a) base their HIPAA compliance policies on outdated or incomplete information; or (b) believe the generic form they printed off the internet in 2005 is all the HIPAA compliance needed. Nothing could be further from the truth!

(MORE: Closing Your Medical Practice: Steps to a Smooth Retirement (Part I))

Before you are caught with your HIPAA pants down, I recommend you practice take the following steps to plan for a smooth audit:

1. Gather all of your HIPAA documents. The bulk of your HIPAA policies minimally should include: office policies and procedures; a Notice of Privacy Practices; medical record request forms; documented staff training and education material with signed acknowledgments; security rule risk analysis; breach protocols; Business Associate Agreements form; required disclosure log; and documented HIPAA incidents and corrective actions.

2. Review HIPAA policies and procedures and update as necessary. Be certain that you have updated, signed Business Associate Agreements with all Business Associates. The 2009 “Health Information Technology for Economic and Clinical Health” (HITECH) law necessitated updates to Business Associate Agreements and, in addition to other provisions, conferred directly liability on Business Associates. Contact health law counsel or a HIPAA consultant to see if your forms need to be modified or replaced.

3. Conduct a risk assessment of your practice by observing office protocol over a period of time and reporting any potential compliance issues. Follow up with staff training. Remember that no policy is effective if it is neither known nor understood by your practice staff.

4. Consider how the use of technology and social media may have changed since you first developed your HIPAA compliance materials. Determine what guidelines may be needed to protect electronic data and to train staff regarding privacy of patient information in the age of social media (see my blog on social media).

5. If you find risk-areas during your assessment, actively address them through your written HIPAA compliance plan. Do not wait for the auditor to note these deficiencies.

6. Prepare your staff for an audit. Explain what to expect and have a plan in place for who will take the lead with the auditors during a visit (which could extend over many days). Make sure staff understands all HIPAA policies and procedures and can comfortably discuss the same with an auditor.

If you are selected for an audit, stay calm and contact your legal counsel. It’s important to provide all requested documentation within the allotted time frame (but remember you do not have to provide any information that is not specifically requested). During the on-site visit, make the auditors comfortable and cooperate as necessary. If you have any questions regarding whether the auditor should have access to specific information, privately consult your legal counsel.

These OCR audits are just a pilot phase and the beginning of HIPAA compliance efforts nationally. To avoid the penalties associated with HIPAA non-compliance, every practice should dust off their HIPAA manuals, update the practice’s policies and retrain staff on the requirements of the law. Like with any government audit, a little advance preparation can save you a lot of trouble!

Find out more about Ericka L. Adler and our other Practice Notes bloggers.

 

Join the Conversation

Want to join the conversation? If you're a healthcare professional, we'd like to hear your comments. Just sign in or register today to become part of our growing, online community.

Read more about HIPAA related issues

Cardiac Practice’s $100,000 HIPAA-Violation Fee Proves HHS Takes Privacy Seriously

HIPAA Compliance: Access to Practice Staff Medical Records

OCR's HIPAA Audits: Get Organized and Be Prepared

HIPAA 5010 Enforcement Delay Good for Practices

Physicians Get Grace Period from CMS on HIPAA 5010 Enforcement

MGMA’s Tennant Offers Practices Prep Tips for ICD-10, HIPAA 5010

Oops, You’re Violating HIPAA and Didn’t Even Know It

More from Ericka L. Adler:

Negotiating the Sale of Your Medical Practice

Preparing Your Practice for a Possible E&M RAC Audit

Addressing Compensation for Disabled Physicians at Your Practice

Home Health Agency Referrals: A Guide for Physicians

Medical Loss Ratio Rebates: Distributing Them Properly

Abusive Patient Behavior: Physicians Have 'Rights' Too

Don't Waste Patient, Physician Time with Unproductive Visits

Implementing Complementary and Alternative Medicine at Your Practice

Qui Tam Lawsuits: A Threat That Should Concern Physicians

The National Practitioners Data Bank: What Physicians Should Know

Medicare's 2013 Proposed Fee Schedule: The Physician Impact

Physician Recruitment Agreements: Concerns and Considerations

Understanding Physician Recruitment Agreements

Point-of-care Dispensing: Profit, Penalties, and Your Practice

Physicians: Be Cautious When Taking on a Medical Director Role

Understand the Legal Limits of Physician Advertising

Hospital-driven EHR Mandates: Boosting Physician Use, But at What Cost?

Text Messaging and Patients: Benefits and Considerations

Closing Your Medical Practice: Steps to a Smooth Retirement (Part II)

Mentoring Young Physicians: Feedback Is Important to Future Success

Employees vs. Contractors in Medical Practice: What's in a Name?

When the Difficult Physician Is You: Let Your Lawyer Do Her Job

Online Defamation Can Hurt Your Medical Practice Reputation: Be Prepared

OCR's HIPAA Audits: Get Organized and Be Prepared

Creating a Social Media Policy for Your Medical Practice Staff

Addressing Sexual Harassment at Your Medical Practice

Distribution of DHS Income for Physicians: Avoid ‘Stark’ Consequences

Physicians Selling Products: Legal and Ethical Considerations

Balancing Patient Interaction, EHR Use at Your Medical Practice

High-Deductible Health Plans and Your Medical Practice: Be Prepared

How Should Your Medical Practice Handle an Impaired Physician?

Addressing Patient Financial Hardship at Your Medical Practice

Physicians and Self-Prescribing: Just Say ‘No’

Crafting Non-solicitation Provisions in Physician Employment Contracts

Poor Recordkeeping by Physician Employees: Grounds for Termination?

Concierge Medicine: Doing It Right Can Boost Practice Income

Practicing Medicine in New States Can Come with New Issues

Holiday Gifts from Patients: Four Considerations for Every Practice

Navigating Restrictive Covenants in Physician Employment Agreements

Audits: Why They Happen and What Your Medical Practice Should Do

Ancillary Services Can Add Practice Revenue, But Follow the Law

Groupon: Great for Prada Shoes, But Not Physician Services

Discharging Patients with Unpaid Balances

Seven Possible Legal Pitfalls at Your Medical Practice

Clarify Future Equity for New Physicians at Your Medical Practice

Terminating Physicians Paid on Productivity: Contract Issues

Avoid Self-disclosure to CMS: Plan an Annual Legal Audit at Your Practice

Closing Your Medical Practice: Steps to a Smooth Retirement (Part I)





CancerNetwork on Facebook


 
TOPIC INDEX

Cancer Types

 
  • Breast
  • Breast (HER2+)
  • Breast (Triple-Negative)
  • CML
  • Colorectal
  • Gastrointestinal
  • GIST
  • Genitourinary
  • Gynecologic
  • Head & Neck
  • Hematology
  • Kidney (Renal Cell)
  • Leukemia
  • Lung
  • Lymphoma
  • Melanoma
  • Multiple Myeloma
  • Ovarian
  • Prostate
  • Sarcoma

Supportive Care

More Topics

  • Bone Metastases
  • End-of-Life Care
  • Palliative Care
  • Ethics in Oncology
  • Practice Management
  • Practice & Policy


All Topics 


 
   SEARCH MEDICA RX
   Browse drugs by name:
A B C D E F G H I J
K L M N O P Q R S T
U V W X Y Z All      
   Search for drugs:
Search

 

 
FROM PHYSICIANS PRACTICE
Primary Care Can't Thrive Without Nurse Practitioners
Courtney H. Lyder, ND,  May 17, 2013
With a projected shortfall of primary-care physicians, it's time for alternate solutions to patient care. Nurse practitioners are one logical remedy.
VWhat Physicians Can Learn from the Allscripts EHR Lawsuit
Marisa Torrieri,  May 16, 2013
Lawsuit prompts question: What should physicians do to ensure they end up with a great EHR instead of buyer’s remorse?
Eight Ways ICD-9 Will Still Matter to Medical Practices
Brenda Edwards, CPC,  May 15, 2013
What should your medical practice do with your ICD-9-CM book after October 1, 2014? Keep it.
Seven Ways Technology Can Speed Up Patient Collections
Cheyenne Brinson,  May 15, 2013
Failing to adopt widely available billing and collections technology can cost medical practices big. Here's how to do it right.
Four Reasons Private Medical Practice is Becoming Extinct
Carol Stryker,  May 15, 2013
It’s becoming increasingly difficult for private medical practices to thrive. Here’s what’s driving the trend toward consolidation.
 

 

 
MOST POPULAR
  • Most Popular
  • Most Emailed
  • Most Recent
  • Colorectal Lesions
  • Dermatologic Adverse Events Associated With Targeted Therapies
  • “This Is My Last Day on Earth”
  • Slide Show: Squamous Cell Carcinoma of the Head and Neck
  • The ABCDEs of Moles and Melanomas
  • “This Is My Last Day on Earth”
  • Recurrent Epithelial Ovarian Cancer: An Update on Treatment
  • Dermatologic Adverse Events Associated With Targeted Therapies
  • Colorectal Lesions
  • ONS: Understanding Spirituality and How It Can Be Used to Help Patients
  • Bone Metastases
  • Palliative Radiotherapy in Elderly Patients With Bone Metastases Improves Quality of Life
  • Staying Fit Could Ward Off Lung and Colorectal Cancer for Middle-Age Men
  • Obesity Impairs Efficacy of L-Asparaginase in Leukemia Treatment
  • New AUA Guidelines for Prostate Cancer Screening
Click here to subscribe to our newsletter
 
COMMENTS
  • Most Commented
  • Most Recent
  • “This Is My Last Day on Earth”
  • Financial Toxicity, Part II: How Can We Help With the Burden of Treatment-Related Costs?
  • Patient Quality of Life Endpoints in Oncology Trials, Part II
  • Who's Coding Whom?
  • “How Do I Say This Nicely? Your Oncologist Wasn't Following Guidelines”
  • Preventing Exposure to Hazardous Drugs
  • Cancer Metabolism as a Therapeutic Target
  • Study: Cholesterol Drugs Reduced Risk of Prostate Cancer Death
  • “This Is My Last Day on Earth”
  • ONS: Safe Handling of Chemotherapy
Click here to subscribe to our newsletter


 
SearchMedica Search Result

Find peer-reviewed literature and websites for practicing medical professionals

CME on EHR
Evidence on EHR
Guidelines on EHR
Patient Education on EHR
Clinical Trials on EHR
Practical Articles on EHR
Research and Reviews on EHR
All "EHR" results


CancerNetwork | ConsultantLive | Diagnostic Imaging | Musculoskeletal Network | OBGYN.net | PediatricsConsultantLive |
Physicians Practice | Psychiatric Times | SearchMedica | Medical Resources

© 1996 - 2013 UBM Medica LLC, a UBM company
Privacy Statement - Terms of Service - Advertising Information - Editorial Policy Statement - UBM Medica Network Privacy Policy