THERE'S A NEW HIPAA SHERIFF IN TOW Arizona

Medicare is apparently now policing HIPAA

Local Companies

Alliance for Affordable Services
(480) 747-1996
7150 E Camelback Rd, Ste. 230
Scottsdale, AZ
Health Insurance Solutions
623-933-8569
9009 N. 103rd Ave #104
Sun City, AZ
Gary Insurance Group
480-443-3249
8501 E. Greenway Pkwy
Scottsdale, AZ
Steinberg Financial Advisers
888-456-5299
15849 N 71st Street
Scottsdale, AZ
Valley Fever
(480) 555-1212
321 Main St
Mesa, AZ
Employee Benefit Exchange, Corp
480-839-6100
1745 S. Alma School Rd. ste 210
Mesa, AZ
United American Insurance Company
520-465-9252
702 S Craycroft Rd.
Tucson, AZ
Arizona Health and Life
602-743-7210
P.O. Box 25035
Scottsdale, AZ
Insure 2 Health
623-229-7326
23033 N. 105th
Peoria, AZ
Find a Doctor
480-668-6647
1530 W. Country Club #7
Mesa, AZ

THERE'S A NEW HIPAA SHERIFF IN TOW

provided by: 

The HIPAA Privacy Rule has been in effect since April 2003; the Security Rule went into effect April 2005. Since its implementation, the Office of Civil Rights (OCR) has been in charge of verifying that covered entities are in compliance with the Privacy Rule. The OCR is also responsible for responding to complaints of HIPAA violations, which is where it spends most of its time. During the past few years, the OCR has received about 24,000 complaints, but its response has usually been to assist the covered entity in fixing the problems that led to the HIPAA violation. Fewer than 400 cases have been referred to the Department of Justice (DoJ) for criminal action, and, of those, fewer than 50 have been accepted by the DoJ. There have been no civil monetary penalties assessed, yet, by the OCR.

However, another group is now apparently stepping in to review healthcare providers' compliance with HIPAA. In March, the Office of Inspector General (OIG) gave notice to Piedmont Hospital in Atlanta that it was being "audited" for HIPAA Security Rule compliance. Of course, being audited for compliance does not mean that the hospital has done anything wrong. What it does mean is that the Medicare police are now apparently becoming the HIPAA police as well. Generally speaking, in the past, the OIG has focused its efforts on fraud and program abuse. This new foray into regulatory compliance is likely due to the limited resources of CMS to police policy issues, other than to use its chief enforcers, the OIG.

This does not appear to be an isolated incident. The OIG seems poised to conduct similar audits with other healthcare providers; however, I doubt we will see a rash of these audits in the EMS industry any time soon. The OIG will likely focus on larger entities, at least at first. On the other hand, if the OIG is becoming familiar with HIPAA compliance, then it may add that to its bag of tricks when it conducts other investigations for issues such as fraud and abuse, which ambulance services are more likely to be involved in. (Remember that last year, the OIG released two reports on the ambulance industry, both finding that we have been on the receiving end of some significant "overpayments.")

Understanding the HIPAA Security Rule

My main concern with this is that the Security Rule is not the Privacy Rule, and I am afraid that too many ambulance services do not appreciate the difference.

The Privacy Rule came first, and many healthcare providers seem to think that if they are in compliance with the Privacy Rule, they are in compliance with HIPAA.

Unfortunately, that is not the case. The Security Rule came along two years later, and it is much more complicated than the Privacy Rule.

The Security Rule is broken into three parts: administrative safeguards, physical safeguards and technical safeguards. A better way to look at it is that there are literal lock-and-key safeguards (physical), electronic access and encryption safeguards (technical), and, for each one of those, there is a written policy on what is to be done and how (administrative safeguards). Then there are 27 sub-parts under the umbrella of the three main sections of the Security Rule. For each of the 27 "specifications," you must either implement a "required" security measure or conduct a risk analysis and determine what type of "addressable" security measure should be implemented, if any. And, of course, you must have written policies for each specification, as well as written documentation concerning your risk analysis for the addressable specifications (even the ones you do implement).

If you understood everything in the preceding paragraph, and if it all sounded not only like something you did several years ago, but also like something you revisit and revise on a regular basis as required by changing circumstances and technological advances, then you are probably in good shape. On the other hand, if this all sounds less than familiar, you probably will not fare well if the OIG comes knocking!

If you want help with HIPAA, look at the Security Rule guidance at www.cms.hhs.gov/SecurityStandard, or post me questions at www.emscltd.com. Questions or comments on this column, as well as ideas for new topics, can be sent to Nancy.Perry@cygnusb2b.com.

G. Christopher Kelly is an attorney Practicing in Atlanta, GA. Chris focuses on federal laws and regulations as they relate to the healthcare industry and specifically to the ambulance industry. He also lectures and advises ambulance company clients across the U.S. Contact him at chris@emscltd.com.

author: By G. Christopher Kelly


Featured Local Company

Insure 2 Health

623-229-7326
23033 N. 105th
Peoria, AZ

Related Articles
- Sleep Deprivation Arizona
According to experts, sleep deprivation can affect you in many negative ways. Learn more in this article about the growing national phenomenon of sleep deprivation and its effects.
- Medicare Watchdogs Arizona
- Billing Basics for EMS Arizona
- EMS Intelligence Sensors Arizona
- DOUBLE TROUBLE Arizona
- How GOOD Is That Data? Arizona
- SIGN ON THE DOTTED LINE Arizona
- BILLING BASICS Arizona
- Something Old, Something New Arizona
- JUST SAY NO TO PERSONAL CELL PHONES ON AMBULANCES Arizona
Regional Articles
- THERE'S A NEW HIPAA SHERIFF IN TOW Apache Junction AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Avondale AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Buckeye AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Bullhead City AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Casa Grande AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Cave Creek AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Chandler AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Cottonwood AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Flagstaff AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Fountain Hills AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Gilbert AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Glendale AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Goodyear AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Green Valley AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Kingman AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Lake Havasu City AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Mesa AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Paradise Valley AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Peoria AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Phoenix AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Prescott AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Prescott Valley AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Safford AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Scottsdale AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Sedona AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Sierra Vista AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Somerton AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Sun City AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Sun City West AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Surprise AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Tempe AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Tucson AZ
- THERE'S A NEW HIPAA SHERIFF IN TOW Yuma AZ
Related Articles
- Sleep Deprivation Arizona
According to experts, sleep deprivation can affect you in many negative ways. Learn more in this article about the growing national phenomenon of sleep deprivation and its effects.
- Medicare Watchdogs Arizona
- Billing Basics for EMS Arizona
- EMS Intelligence Sensors Arizona
- DOUBLE TROUBLE Arizona
- How GOOD Is That Data? Arizona
- SIGN ON THE DOTTED LINE Arizona
- BILLING BASICS Arizona
- Something Old, Something New Arizona
- JUST SAY NO TO PERSONAL CELL PHONES ON AMBULANCES Arizona
Related Local Events
Monthly Mixer - Pinnacle Physical Therapy
Dates: 12/3/2008 - 12/3/2008
Location: Pinnacle Physical Therapy
Maricopa AZ
View Details

Blood Drive
Dates: 12/18/2008 - 12/19/2008
Location: Bullhead City Hall Council Chambers
Bullhead City AZ
View Details

Rock "N" Roll Marathon Health and Fitness Expo
Dates: 1/16/2009 - 1/17/2009
Location: PCC South Building
Phoenix AZ
View Details

Mohave County Veteran's Day Parade
Dates: 11/8/2008 - 11/8/2008
Location: TBA
Kingman AZ
View Details

Monthly Mixer - A1 Health & Wellness
Dates: 11/5/2008 - 11/5/2008
Location: A-1 Health & Wellness
Maricopa AZ
View Details
Rate Article
     
Articles Insider

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Engineering Home Services Retail & Consumer Services
Business Services Entertainment Industrial Goods & Services Software
Career Family Insurance Technology
Cars Financial Services Internet Telecommunications
Computer Hardware Food & Beverage Legal Transportation & Logistics
Construction Health Pets Travel
Education Home Electronics Real Estate Wedding