• Skip to main content

DistilGovHealth

DistilNFO GovHealth Advisory

  • Publications
    • Home
    • DistilINFO HealthPlan
    • DistilINFO HospitalIT
    • DistilINFO IT
    • DistilINFO Retail
    • DistilINFO POPHealth
    • DistilINFO Ageing
    • DistilINFO Life Sciences
    • DistilINFO GovHealth
    • DistilINFO EHS
    • DistilINFO HealthIndia
    • Subscribe
    • Submit Article
    • Advertise
    • Newsletters

Health Plans Struggle with HIPAA Compliance, Unprepared for Audit

Share:

January 28, 2020

Many health plan sponsors aren’t fully compliant with HIPAA or struggle to remain compliant with the rule, which means they are not prepared for an OCR HIPAA audit, Buck researchers find.

Many health plan group sponsors are struggling to remain or are not fully compliant with HIPAA rules. Further, those same healthcare organizations are not prepared for a HIPAA audit, according to new research from Buck.

Buck researchers conducted a HIPAA readiness survey of primarily group health plan sponsors to get a sense of the industry’s adherence to and awareness of the HIPAA rule, in response to the increase in HIPAA enforcement actions taken by the Department of Health and Human Services.

“Strong governance is essential to protecting information,” Laurie DuChateau, Buck’s US Compliance Consulting Practice Leader, said in a statement. “It’s risky for group health plan sponsors to be unprepared for a HIPAA audit or investigation as penalties for non-compliance can amount to millions of dollars.”

Want to publish your own articles on DistilINFO Publications?

Send us an email, we will get in touch with you.

Under HIPAA, covered entities are required to implement processes to safeguard protected health information, including privacy and security policies that are periodically reviewed and or updated.

Typically, updates should occur when changes are made in HIPAA security regulations or with new state laws, as well as with technology, environmental, or business process changes. Organizations should also review those policies after a serious security violation or breach.

However, just 39 percent of respondents had conducted a review or update of their HIPAA privacy and security policies within the last year and 13 percent did not know when the policies were last updated. And 48 percent had not conducted a review between one and five years, or more.

What’s more, 42 percent of respondents did not know when their organization last conducted a risk or threat analysis, or last conducted an assessment more than one to five years ago.

“Not only does HIPAA require a risk/threat analysis to be performed, best practice dictates that one be conducted annually – especially with cyberattacks on the rise. Infrequent risk/threat analyses are one of the most common violations cited by OCR in their analysis of HIPAA audits,” researchers wrote.

Risk assessments ensure compliance with HIPAA, and the researchers noted it’s a cost-effective compliance mechanism. Failure to perform an analysis can lead to a breach deemed as “willful neglect,” which carries the highest monetary fines.

The report also found health plan sponsors are also predominantly neglecting workforce HIPAA training, with only 42 percent conducting training in the last year. Thirty-five percent had not provided staff with training in at least one to five years, while 10 percent did not know.

Notably, 13 percent of respondents said they only provided HIPAA training upon onboarding new employees. It’s concerning as reports show that education and training can reduce healthcare cyber risk.

Further, the vast majority of respondents said they either had not conducted an operational review to determine whether employees are following the areas covered in HIPAA training, as well as policies and procedures.

On the positive side, the majority of health plan sponsors (67 percent) maintain an inventory of all their business associates and maintain current business associate agreements. Just 13 percent do not have an inventory and only 3 percent do not have a BAA in place.

“It is important to retain a list of all current BAs and to read and understand the language in your BAAs,” researchers wrote. “The reality is when a breach or any other kind of security incident happens, you are at risk for what was declared in your BAA. In many ways, a BAA is a mechanism for transferring risk (and thus liability) from one entity to another.”

“Over the last few years, the HHS’ Office of Civil Rights has ramped up its investigations, resulting in some of the largest monetary settlements in HIPAA’s history,” DuChateau concluded. “Understanding and complying with the rules is the best way to prevent a breach and the only way to emerge successfully from a HIPAA audit.”

Source: HealthIT Security

Coffee with DistilINFO's Morning Updates...

Sign up for DistilINFO e-Newsletters.

Just a little bit more about you...
PROCEED
Choose Lists
BACK

Related Stories

  • Major Payers Find HHS Finalized Nondiscrimination Rule Too NarrowMajor Payers Find HHS Finalized Nondiscrimination Rule Too Narrow
  • New Clinically Validated Sleepcheck App LaunchesNew Clinically Validated Sleepcheck App Launches
  • Apple Still has a Lot of Room to Grow in the $3.5 Trillion Health Care SectorApple Still has a Lot of Room to Grow in the $3.5 Trillion Health Care Sector
  • Google Moves Further Into Healthcare: a Timeline of the Last YearGoogle Moves Further Into Healthcare: a Timeline of the Last Year
  • Superb Healthcare At Ultra-Low Prices? How Singapore Does ItSuperb Healthcare At Ultra-Low Prices? How Singapore Does It
  • AI, Machine Learning, and Blockchain are Key for Healthcare InnovationAI, Machine Learning, and Blockchain are Key for Healthcare Innovation

Trending This Week

Sorry. No data so far.

About Us

DistilINFO is media company that publishes Industry news, views and Interviews. We distil the information for you – saving time and keeping you up to date on your interest areas.

More About Us

Follow Us


Useful Links

  • Subscribe
  • Contact
  • Advertise
  • Privacy Policy
  • Terms of Service
  • Feedback

All Publications

  • DistilINFO HealthPlan Advisory
  • DistilINFO HospitalIT Advisory
  • DistilINFO IT Advisory
  • DistilINFO Retail Advisory
  • DistilINFO POPHealth Advisory
  • DistilINFO Ageing Advisory
  • DistilINFO Life Sciences Advisory
  • DistilINFO GovHealth Advisory
  • DistilINFO EHS Advisory
  • DistilINFO HealthIndia Advisory

© DistilINFO Publications