Home > Security Tips > Compliance Counselor > HIPAA - Points to consider
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

HIPAA - Points to consider


James Michael Stewart
03.25.2003
Rating: -4.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


The Health Insurance Portability and Accountability Act of 1996 (HIPAA) was designed to improve "the efficiency and effectiveness of the health care system by encouraging the development of a health information system through the establishment of standards and requirements for the electronic transmission of certain health information" (Public Law 104-191).

The requirements of HIPAA are fairly complex and affect nearly every aspect of the health care system. It is important to take a detailed and methodical look at HIPAA to ensure that you are fully compliant with every aspect of this legislation. To that end, here are several important points to consider while developing your HIPAA plan of action:

  1. Make sure you, as a provider or health plan, are ready.
    1. Don't rely on your payers, or software vendors to make you compliant. HIPAA is much too complex for a 'HIPAA-in-a-can' solution offered by many vendors.
  2. Contract with uninterested parties (i.e. organizations without a conflict of interest) that are HIPAA-aware to help you through the process.
    1. There are many steps and many areas that need to be addressed. It is always better to have several, specialized people than one who thinks he is the 'HIPAA Kahuna'
  3. Be as prepared as possible for each regulation release by examining the context of the regulations to be released.
    1. Privacy was released first, so go through the steps that ensure you meet the requirements for privacy under HIPAA. Once that is done, start preparing for the security regulations. After all, having a secured network now will reduce the work required to meet the security regulations once they are distributed.
  4. Be realistic about what you are capable of accomplishing.
    1. HIPAA regulations are full of statements like 'reasonable effort' and 'as permitted'. This means depending on who you are, how big you are, and how much money your company has, determines your level of reasonable effort.
  5. HIPAA is about protecting PHI (protected health information, also confidential or sensitive health information), this is a given, what is taken for granted, is the number of possible conduits that PHI is capable of leaving your custody to an unauthorized entity.
    1. Be diligent about covering all the bases. Everything from fax machine location to who is asking for the PHI has to be accounted for.
    2. There also has to be a paper trail or 'chain of custody' for the information.
    3. As long as you know where the information is, who has access to it and you can prove it, who HAS accessed it, and who gave permission for what to be disclosed, the privacy regulations are pretty logical.
  6. If you use software for billing, you NEED to be in conversation with the vendor.
    1. You MUST allow enough time for testing the new billing forms and for any corrective actions that might need to happen.
    2. There are state-governed requirements for submitting billing.
    3. It is well worth the effort to use the services of a third party testing facility to verify your 835/837 forms are formatted correctly. www.claredi.com is a common validation site.
  7. Need to know dates
    1. April 14, 2003: Privacy regulations go into effect except for small health plans
    2. April 16, 2003: EDI transactions and code sets; must start testing
    3. October 16, 2003: EDI transactions and code sets; go into effect for all those covered entities that filed for an extension and small health plans
    4. April 14, 2004: Privacy regulations in effect for small health plans
    5. July 30, 2004: Employer Identifier Standards into effect, except small health plans
    6. August 1, 2005: Employer Identifier Standards into effect for small health plans
  8. Useful resources:
    1. http://aspe.hhs.gov/admnsimp/
    2. http://www.cms.hhs.gov/hipaa/
    3. http://www.claredi.com
    4. http://www.wedi.org/snip/
    5. http://www.hipaagives.org/

There is no way that all the points of HIPAA can be put into a small outline. HIPAA is a complex, sensitive beast, however, it CAN be tamed. It takes time, perseverance and an overall understanding that once these regulations are in place and working properly, it is very possible, if not likely, that these standards will start to expand to cover other entities that deal with sensitive information. Entities like child protection services and foster care agencies are likely candidates. Although HIPAA regulations are lengthy and sometimes confusing the way they override some state laws and yield to others, it is in the best interest of everyone to give HIPAA the proper respect it deserves. After all, what if the information that was accidentally given to the wrong people was yours?

The content for this security policy tip on HIPAA was compiled by Lewis C. Fry.


About the author
James Michael Stewart is a partner and researcher for ITinfopros, a technology-focused writing and training organization.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Law, Public Policy and Standards
National cybersecurity alert system launched
Expert sheds light on Wi-Fi liability issues
Study: Sarbanes Oxley 'catalyst' for process management
Taking a holistic approach to compliance
Spam, virus writing may come under mafia control
November 2003: The best of SearchSecurity.com
The FDA's regulation for the use of electronic records and signatures
Alert: New RPC vulnerabilities
Regulation, bad software, new threats fodder for Congress
Blaster infection may require customer notification

Compliance Counselor
Security certifications: Are they worth the trouble?
How to look past information security vendor rhetoric
Compliance recycling: Combining compliance efforts to manage PCI DSS
Web 2.0 and e-discovery: Risks and countermeasures
Learn from NIST: Best practices in security program management
Best practices for application-level firewall selection and deployment
The 'security standards dilemma': Network segmentation and PCI Compliance
Penetration testing: Helping your compliance efforts
Worst practices: Recognizing the biggest compliance mistakes
E-discovery management: How IT should interact with the legal team

HIPAA
Organization develops health care security framework
Walter Reed admits breach of patient information
Companies still monitoring email manually, survey finds
The road to compliance
Hannaford breach illustrates dangerous compliance mentality
Is it against HIPAA regulations to permanently store sensitive information?
Is it against HIPAA regulations to print a patient's Social Security number (SSN) on an insurance card?
How to conduct an efficient and thorough employee access review.
Is it against HIPAA regulations to display client names?
Will an off-site employee exit procedure violate HIPAA regulations?
HIPAA Research

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts