The HHS’ 5 best practices for HIPAA compliance
During the recent Safeguarding Health Information: Building Assurance through HIPAA Security conference, the Department of Health and Human Services...
2 min read
Lusanda Molefe Dec 18, 2024 7:02:20 AM
The Office for Civil Rights (OCR) enforces the Privacy and Security Rules in several ways:
According to Holland & Hart LLP, being well-prepared and transparent in your response to a HIPAA breach can greatly influence the outcome of an HHS investigation. Demonstrating that your organization had taken reasonable steps to prevent breaches and responded appropriately when one occurred can lead to reduced fines and sanctions.
After a breach is reported, the OCR gets involved in the following ways:
Gather a team of specialists to manage a thorough breach response. Based on your company's size and specifics, this team might include experts from forensics, legal, information security, IT, operations, HR, communications, investor relations, and management.
Identify a data forensics team and consider hiring independent forensic investigators to determine the breach's source and scope. These investigators will capture forensic images of affected systems, collect and analyze evidence, and outline remediation steps. Consult with legal counsel to ensure compliance with federal and state laws. You may also consider hiring outside legal counsel with expertise in privacy and data security to provide further guidance.
You must keep written records to show that the following actions have been completed:
Conducting an internal investigation allows the covered entity to determine the scope of the breach in terms of:
Determining this information will also provide guidance on how the organization should provide notice of the breach and to whom.
Conduct a post-incident review to identify lessons learned and improve your organization's privacy and security practices. Use this information to enhance your breach response plan and prevent future incidents.
Notify affected individuals and the HHS Secretary as required by HIPAA regulations. If the breach affects 500 or more individuals, immediate notification is required, along with media notification if it affects more than 500 residents of a state or jurisdiction.
Related: What are the notification requirements if more than 500 individuals are affected
Training programs should be conducted regularly and include updates on new regulations, best practices for data security, and incident response procedures.
Provide comprehensive documentation of your security measures, breach response actions, compliance policies, training programs, and any corrective actions taken.
During the recent Safeguarding Health Information: Building Assurance through HIPAA Security conference, the Department of Health and Human Services...
In March 30, 2020, the OCR released a notification which stated: ‘During the COVID-19 national emergency, which also constitutes a nationwide public...
Anyone who suspects a HIPAA violation by a healthcare provider, an insurance company, or another covered entity, must report the violation to the...