.jpg)
In an age of Internet hacking and identity theft, no entity can be entirely secure or immune from unauthorized access to its protected health information (PHI). The HITECH Act, which amended HIPAA, recognized this and created a tiered penalty structure tied to the violator’s level of culpability. Thus, an entity that can demonstrate it has a robust HIPAA compliance program in place is far more likely to emerge from an HHS Office for Civil Rights (OCR) investigation with a warning than entities whose HIPAA compliance practices are lax. In many cases, the latter have been subject to significant fines and burdensome resolution agreements.
When conducting an investigation of a breach or other possible violation, the OCR will afford the entity an opportunity to explain (in a light favorable to the entity, if possible) the events at issue. It will also look for evidence of the entity’s past and current HIPAA compliance efforts, as well as a description of the entity’s corrective actions. In a recent investigation, for example, OCR requested copies of the entity’s risk analyses and risk management plan addressing the identified risks, documentation of the entity’s procedures for regularly reviewing information system activity and results of those reviews, copies of vendor agreements, and documentation of disciplinary action taken against employees who violated HIPAA’s requirements.
Often times, policies may be out of date, staff training perfunctory and ineffective, monitoring nonexistent and enforcement uneven. It is inefficient and expensive to create a HIPAA compliance program in response to an OCR investigation. And no amount of effort can create satisfactory documentation of past compliance if there has been little. Covered entities and business associates should therefore consider reviewing their current programs to see if they would pass OCR scrutiny and strengthening their practices where indicated.
The elements of an effective HIPAA compliance program are similar to those of a corporate compliance program: adoption of policies, procedures and controls; regular workforce training; on-going monitoring/auditing; consistent enforcement and discipline for violations; and prompt and thorough investigation and remediation of possible violations. In addition, covered entities must (and business associates should) conduct a risk assessment to identify areas where the entity’s PHI could be at risk and to facilitate compliance with HIPAA’s administrative, physical, and technical safeguards.
Resources abound for updating or implementing HIPAA compliance programs. Many are quite cost effective and some are free, like the OCR website, which includes links to HIPAA’s requirements, model notices and agreements, training materials and a risk assessment tool. An entity responding to an OCR investigation will find that the time and effort spent on HIPAA compliance is a sound investment.















