Video: Every Case Tells a Story| Webinar: ACR/CHEST ILD Guidelines in Practice

An official publication of the ACR and the ARP serving rheumatologists and rheumatology professionals

  • Conditions
    • Axial Spondyloarthritis
    • Gout and Crystalline Arthritis
    • Myositis
    • Osteoarthritis and Bone Disorders
    • Pain Syndromes
    • Pediatric Conditions
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Sjögren’s Disease
    • Systemic Lupus Erythematosus
    • Systemic Sclerosis
    • Vasculitis
    • Other Rheumatic Conditions
  • FocusRheum
    • ANCA-Associated Vasculitis
    • Axial Spondyloarthritis
    • Gout
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Systemic Lupus Erythematosus
  • Guidance
    • Clinical Criteria/Guidelines
    • Ethics
    • Legal Updates
    • Legislation & Advocacy
    • Meeting Reports
      • ACR Convergence
      • Other ACR meetings
      • EULAR/Other
    • Research Rheum
  • Drug Updates
    • Analgesics
    • Biologics/DMARDs
  • Practice Support
    • Billing/Coding
    • EMRs
    • Facility
    • Insurance
    • QA/QI
    • Technology
    • Workforce
  • Opinion
    • Patient Perspective
    • Profiles
    • Rheuminations
      • Video
    • Speak Out Rheum
  • Career
    • ACR ExamRheum
    • Awards
    • Career Development
  • ACR
    • ACR Home
    • ACR Convergence
    • ACR Guidelines
    • Journals
      • ACR Open Rheumatology
      • Arthritis & Rheumatology
      • Arthritis Care & Research
    • From the College
    • Events/CME
    • President’s Perspective
  • Search

Internal Due Diligence Review Important for Physician Practices

Steven M. Harris, Esq.  |  Issue: June 2015  |  June 15, 2015

Accurate financial reporting is important, and your accounting practice should be consistent. Accounting reports must be prepared in accordance with recognized accounting standards.

Licensure & Human Resource Matters

Ensure that both the practice and each professional (e.g., physician, nurse, nurse practitioner) have maintained all required licenses, accreditations, certifications and other requirements. Review your employee handbook and current employment and independent contractor agreements to ensure they are up to date and that there have not been any changes in law that would affect the validity of any contract provision. For example, if your employment agreement includes a restrictive covenant, such as a noncompetition clause, it’s possible that state law may have changed regarding the enforceability of such a provision since the contract was signed.

ad goes here:advert-1
ADVERTISEMENT
SCROLL TO CONTINUE

Data Privacy & Security

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations are intended to protect the privacy and security of patients’ protected health information. Ensure your practice has implemented (and enforces) internal policies and procedures to comply with the HIPAA Privacy, Security and Breach Notification Rules. The HIPAA Privacy Rule provides limitations and conditions on the use and disclosure of patients’ protected health information. The HIPAA Security Rule requires implementation of administrative, physical and technical safeguards and certain other organizational requirements to protect the confidentiality and security of electronic protected health information. The HIPAA Breach Notification Rule outlines the requirements pertaining to responding to breaches of patient protected health information.

As part of your internal review, you should ensure that your workforce has been properly trained in HIPAA compliance and that such training is documented in writing. A great deal of focus is placed on HIPAA compliance, and it’s important to remain cognizant of state privacy and confidentiality laws, as well as data security laws, that may affect your practice. You need to comply with all relevant state laws, not only for those states in which you have a physical location, but also states where patients may reside, because those state laws may apply as well.

ad goes here:advert-2
ADVERTISEMENT
SCROLL TO CONTINUE

Conclusion

Conducting regular internal compliance checkups could make the difference between a successful government audit, a lucrative business transaction and/or avoiding civil and criminal penalties for violations of law.


Steven M. Harris, Esq.Steven M. Harris, Esq., is a nationally recognized healthcare attorney and a member of the law firm McDonald Hopkins LLC. Contact him via e-mail at [email protected].

Page: 1 2 | Single Page
Share: 

Filed under:Legal UpdatesPractice SupportProfessional Topics

Related Articles

    HIPAA Security Standards: What Rheumatologists Need to Know

    April 1, 2015

    Maintain compliance with updated federal rules governing privacy protection for patient health information

    Phase 2 of HIPAA Audit Program Launches

    May 13, 2016

    With many competing priorities facing physician practices, HIPAA compliance and security is not a topic that usually makes it to the top of the list. But this is not the case with the Department of Health and Human Services’ Office for Civil Rights (OCR), because it has initiated a new phase of audits of physician…

    Healthcare Providers Must Get Compliant with HIPAA Privacy Practices

    August 1, 2013

    Failure to have an updated Notice of Privacy Practices by September 23, 2013 could result in fines and penalties

    LeoWolfert / shutterstock.com

    Legal Updates: Tips for Protecting Your Patients’ Health Information

    December 18, 2019

    In the daily shuffle of evaluating patients and focusing on the delivery of high-quality patient care, the importance of protecting patient information may get overlooked. Human error is just one possible way patient information can be compromised. Cybersecurity attacks are becoming more numerous and sophisticated every day, with the number of patient records compromised increasing….

  • About Us
  • Meet the Editors
  • Issue Archives
  • Contribute
  • Advertise
  • Contact Us
  • Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1931-3268 (print). ISSN 1931-3209 (online).
  • DEI Statement
  • Privacy Policy
  • Terms of Use
  • Cookie Preferences