Video: Every Case Tells a Story| Webinar: ACR/CHEST ILD Guidelines in Practice

An official publication of the ACR and the ARP serving rheumatologists and rheumatology professionals

  • Conditions
    • Axial Spondyloarthritis
    • Gout and Crystalline Arthritis
    • Myositis
    • Osteoarthritis and Bone Disorders
    • Pain Syndromes
    • Pediatric Conditions
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Sjögren’s Disease
    • Systemic Lupus Erythematosus
    • Systemic Sclerosis
    • Vasculitis
    • Other Rheumatic Conditions
  • FocusRheum
    • ANCA-Associated Vasculitis
    • Axial Spondyloarthritis
    • Gout
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Systemic Lupus Erythematosus
  • Guidance
    • Clinical Criteria/Guidelines
    • Ethics
    • Legal Updates
    • Legislation & Advocacy
    • Meeting Reports
      • ACR Convergence
      • Other ACR meetings
      • EULAR/Other
    • Research Rheum
  • Drug Updates
    • Analgesics
    • Biologics/DMARDs
  • Practice Support
    • Billing/Coding
    • EMRs
    • Facility
    • Insurance
    • QA/QI
    • Technology
    • Workforce
  • Opinion
    • Patient Perspective
    • Profiles
    • Rheuminations
      • Video
    • Speak Out Rheum
  • Career
    • ACR ExamRheum
    • Awards
    • Career Development
  • ACR
    • ACR Home
    • ACR Convergence
    • ACR Guidelines
    • Journals
      • ACR Open Rheumatology
      • Arthritis & Rheumatology
      • Arthritis Care & Research
    • From the College
    • Events/CME
    • President’s Perspective
  • Search

How to Maintain HIPAA Compliance

Kelly Tyrrell  |  September 1, 2016

In 2010, the federal government published a guide, titled Basic Security for the Small Healthcare Practice, complete with best practices and checklists to help small providers achieve and maintain HIPAA compliance.1

This year, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR)—following a critical report of its HIPAA compliance audit and enforcement practices—is focusing on audits of covered entities (including physicians) of all sizes and their business associates.2

ad goes here:advert-1
ADVERTISEMENT
SCROLL TO CONTINUE

Legal Advice
Rachel Yaffe, a healthcare attorney with McDonald Hopkins LLC, suggests physicians utilize the checklists in the guide to “do an internal check-up, to see whether you’re hitting these big-ticket items and following policies and procedures.”

Consulting a healthcare attorney with HIPAA compliance expertise is one way for physicians to ensure they are ready to undergo an audit, which can carry penalties if the OCR finds violations of the HIPAA Privacy, Security and Breach Notification Rules.

ad goes here:advert-2
ADVERTISEMENT
SCROLL TO CONTINUE

Ms. Yaffe also indicated physicians must have written HIPAA policies and protocols in place and train their employees and staff. They must also have a designated privacy officer. A risk analysis of the practice could help in the event of an audit.

“If you are investigated and you can show you’ve taken internal proactive measures to comply with HIPAA, that will be positively received by the OCR,” Ms. Yaffe says.

Ms. Yaffe adds that the OCR’s expectations are tailored to the nature and size of the particular practice being audited. “The OCR recognizes that the policies, procedures and technologies implemented by a small physician practice are going to be different than those implemented by a large health system.”

One Rheumatologist’s Point of View
Richard Brasington, MD, FACP, professor of medicine and rheumatology fellowship program director at Washington University in St. Louis School of Medicine, has seen his hospital take a number of steps to ensure compliance, which include implementing a HIPAA-secure email system and establishing a patient portal for patient–provider communications.

“I do think it’s good for us to be attentive and always be thinking about how we are protecting patient privacy and confidentiality,” he says of the OCR audits. “But I don’t think anyone finds they never make violations.”

However, he believes most health professionals already strive to protect patient health information. “We can’t be looking over our shoulder constantly,” he says. “We should be using common sense when protecting patient information.”

The Trouble with Texting
Texting, Ms. Yaffe says, is one way physicians leave themselves vulnerable; for example, “the on-call physician texting the treating physician Patient X’s protected health information, albeit in an effort to better Patient X’s care,” she says. “Many are communicating using personal cell phones, which are likely not secure.”

Page: 1 2 | Single Page
Share: 

Filed under:Legal UpdatesPractice SupportProfessional Topics Tagged with:HIPAA auditHIPAA complianceOffice for Civil Rights

Related Articles

    Phase 2 of HIPAA Audit Program Launches

    May 13, 2016

    With many competing priorities facing physician practices, HIPAA compliance and security is not a topic that usually makes it to the top of the list. But this is not the case with the Department of Health and Human Services’ Office for Civil Rights (OCR), because it has initiated a new phase of audits of physician…

    HIPAA Audit Activities Increase in 2016

    August 17, 2016

    In the coming months, rheumatologists may want to pay particular attention to their email inboxes. By the end of the year, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) will complete stage I, phase II of a series of desk and on-site audits designed to assess providers and their business…

    Legal Updates: Healthcare Data Privacy and Security under HIPAA

    May 1, 2014

    Maintaining the privacy of healthcare data Is paramount, and a breach can cost you hundreds of thousands of dollars

    Preparing for Increased HIPAA Audits Among Smaller Rheumatology Providers

    May 13, 2016

    Recent enforcement activities of the Department of Health and Human Services’ Office for Civil Rights (OCR) have shown an increase in fines and penalties assessed against smaller providers for failing to comply with the privacy, security and breach notification requirements of the Health Insurance Portability and Accountability Act (HIPAA). Historically, OCR has focused on larger…

  • About Us
  • Meet the Editors
  • Issue Archives
  • Contribute
  • Advertise
  • Contact Us
  • Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1931-3268 (print). ISSN 1931-3209 (online).
  • DEI Statement
  • Privacy Policy
  • Terms of Use
  • Cookie Preferences