Video: Every Case Tells a Story| Webinar: ACR/CHEST ILD Guidelines in Practice

An official publication of the ACR and the ARP serving rheumatologists and rheumatology professionals

  • Conditions
    • Axial Spondyloarthritis
    • Gout and Crystalline Arthritis
    • Myositis
    • Osteoarthritis and Bone Disorders
    • Pain Syndromes
    • Pediatric Conditions
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Sjögren’s Disease
    • Systemic Lupus Erythematosus
    • Systemic Sclerosis
    • Vasculitis
    • Other Rheumatic Conditions
  • FocusRheum
    • ANCA-Associated Vasculitis
    • Axial Spondyloarthritis
    • Gout
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Systemic Lupus Erythematosus
  • Guidance
    • Clinical Criteria/Guidelines
    • Ethics
    • Legal Updates
    • Legislation & Advocacy
    • Meeting Reports
      • ACR Convergence
      • Other ACR meetings
      • EULAR/Other
    • Research Rheum
  • Drug Updates
    • Analgesics
    • Biologics/DMARDs
  • Practice Support
    • Billing/Coding
    • EMRs
    • Facility
    • Insurance
    • QA/QI
    • Technology
    • Workforce
  • Opinion
    • Patient Perspective
    • Profiles
    • Rheuminations
      • Video
    • Speak Out Rheum
  • Career
    • ACR ExamRheum
    • Awards
    • Career Development
  • ACR
    • ACR Home
    • ACR Convergence
    • ACR Guidelines
    • Journals
      • ACR Open Rheumatology
      • Arthritis & Rheumatology
      • Arthritis Care & Research
    • From the College
    • Events/CME
    • President’s Perspective
  • Search

Preparing for Increased HIPAA Audits Among Smaller Rheumatology Providers

Steven M. Harris, Esq.  |  Issue: May 2016  |  May 13, 2016

The unfortunate truth is that a security incident is more likely to happen than not. Therefore, it is critical that you take the following steps now to ensure you are prepared in the event of an audit or breach:

  • Conduct a thorough review of your HIPAA policies and procedures. Confirm that those policies and procedures have actually been implemented and are effective.
  • Review applicable state law to ensure that your HIPAA compliance program also complies with state health privacy laws. Many states have adopted privacy regulations that specifically address health information, and understanding these laws is a critical component of compliance.
  • Assemble an incident response team (IRT). Involve legal, IT and human resources representatives, among others.
  • Draft an incident response plan (IRP). This will be your go-to document in the event of a breach and should identify the IRT and clearly describe the decision-making process when handling security incidents.
  • Test your IRT & IRP. This can be done by educating and then testing your IRT on HIPAA compliance requirements. In addition, pose hypothetical security incidents to the IRT and have them follow the IRP. Once completed, revise the IRP to overcome any shortcomings noted during the hypothetical scenario.
  • Perform a risk assessment. Include penetration testing of your computers, devices and electronic health record software.

Completing these steps will not only benefit your organization by reducing the likelihood of investigations, complaints, security incidents, and significant time and money spent responding to such issues, it will bring you peace of mind in the knowledge that your organization is well prepared.

ad goes here:advert-1
ADVERTISEMENT
SCROLL TO CONTINUE

Steven M. Harris, Esq.Steven M. Harris, Esq., is a nationally recognized healthcare attorney and a member of the law firm McDonald Hopkins LLC. Contact him via email at [email protected].

Page: 1 2 | Single Page
Share: 

Filed under:Billing/CodingLegal UpdatesPractice Support Tagged with:AuditsHHSHIPAA complianceLegalnoncompliancephysician practicePractice Managementrheumatologist

Related Articles

    Phase 2 of HIPAA Audit Program Launches

    May 13, 2016

    With many competing priorities facing physician practices, HIPAA compliance and security is not a topic that usually makes it to the top of the list. But this is not the case with the Department of Health and Human Services’ Office for Civil Rights (OCR), because it has initiated a new phase of audits of physician…

    Legal Updates: Healthcare Data Privacy and Security under HIPAA

    May 1, 2014

    Maintaining the privacy of healthcare data Is paramount, and a breach can cost you hundreds of thousands of dollars

    HIPAA Audit Activities Increase in 2016

    August 17, 2016

    In the coming months, rheumatologists may want to pay particular attention to their email inboxes. By the end of the year, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) will complete stage I, phase II of a series of desk and on-site audits designed to assess providers and their business…

    LeoWolfert / shutterstock.com

    Legal Updates: Tips for Protecting Your Patients’ Health Information

    December 18, 2019

    In the daily shuffle of evaluating patients and focusing on the delivery of high-quality patient care, the importance of protecting patient information may get overlooked. Human error is just one possible way patient information can be compromised. Cybersecurity attacks are becoming more numerous and sophisticated every day, with the number of patient records compromised increasing….

  • About Us
  • Meet the Editors
  • Issue Archives
  • Contribute
  • Advertise
  • Contact Us
  • Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1931-3268 (print). ISSN 1931-3209 (online).
  • DEI Statement
  • Privacy Policy
  • Terms of Use
  • Cookie Preferences