<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HIPAA Information</title>
	<atom:link href="http://www.hipaastore.com/info/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hipaastore.com/info</link>
	<description>HIPAA Training, Compliance &#38; Awareness</description>
	<lastBuildDate>Tue, 29 Sep 2009 07:52:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>PHI Spells &#8220;CASH&#8221; to Criminals</title>
		<link>http://www.hipaastore.com/info/phi-spells-cash-to-criminals/</link>
		<comments>http://www.hipaastore.com/info/phi-spells-cash-to-criminals/#comments</comments>
		<pubDate>Mon, 28 Sep 2009 23:19:46 +0000</pubDate>
		<dc:creator>Abner</dc:creator>
				<category><![CDATA[Breaches & Losses]]></category>
		<category><![CDATA[HIPAA (General)]]></category>
		<category><![CDATA[Criminals]]></category>
		<category><![CDATA[Economic Value]]></category>
		<category><![CDATA[Monetary Value]]></category>
		<category><![CDATA[PHI]]></category>

		<guid isPermaLink="false">http://www.hipaastore.com/info/?p=122</guid>
		<description><![CDATA[We Still Aren&#8217;t &#8220;Getting It&#8221;!
Here we are, more than six years after the Privacy Rule deadline in 2003, and I am still trying to teach Covered Entities (CEs) and Business Associates (BAs) that Protected Health Information (PHI) is a valuable commodity to criminals. The crooks know that PHI has real, monetary value, but CEs and [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<h4>We Still Aren&#8217;t &#8220;Getting It&#8221;!</h4>
<p>Here we are, more than six years after the Privacy Rule deadline in 2003, and I am still trying to teach Covered Entities (CEs) and Business Associates (BAs) that Protected Health Information (PHI) is a valuable commodity to criminals. The crooks know that PHI has real, monetary value, but CEs and BAs are still learning this most important HIPAA lesson.</p>
<p>Until HIPAA-regulated entities really start to &#8220;get it&#8221; about the dollar value of stolen PHI, criminals will continue to have the advantage. That&#8217;s not a good situation.</p>
<p>It&#8217;s critical to understand that PHI (medical charts, billing files, etc.) has economic value to criminals. PHI is worth money on the international black market and is bought and sold 24 hours a day over illegal channels. More and more criminals know this and are exploiting it. Even Los Angeles&#8217; notorious street gangs, once known for their lock on drugs, prostitution and gambling, are moving into identity fraud &#8211; the LA Times reported in 2008.</p>
<p>It&#8217;s easy to see bundles of records as so much paper, even when we understand intellectually that personal medical information is highly sensitive and confidential.</p>
<h4>Try This with Real Dollars</h4>
<p>Try this metaphor on for size: Imagine that a real US $20 bill is stapled to the inside front cover of every single file or record in <em>your </em>facility. Now imagine leaving piles of such &#8220;monetized&#8221; medical records simply laying around with no armed guard or other security. We wouldn&#8217;t do it. Instinctively, we know that bundles of cash deserve special protection. Unfortunately, most workers in healthcare jobs don&#8217;t automatically think that way about PHI. But PHI is equivalent to currency in the criminal mind.</p>
<h4>In Value to Criminals: Medical Record = Wallet</h4>
<p>In fact, much of the actual data in a person&#8217;s wallet is identical to the data in their medical records, with less clinical information of course. Name, home address, SSN, birth date, phone numbers, family contacts and pictures, banking and credit card data, allergy notices and other &#8220;first responder&#8221; medical data, etc. All these items reside in both wallets and medical records. And we know how devastating it would be if our own wallet fell into criminal hands.</p>
<h4>Teach Your Workforce that PHI Has Value to Criminals</h4>
<p>Some entities fear teaching this concept to their workforce because, they say: &#8220;we don&#8217;t want to give them any ideas!&#8221; They&#8217;re afraid that telling employees that PHI is worth money to criminals will tempt employees to go out and find crooks to sell PHI to. I believe that&#8217;s a mistaken view. Banks are filled with workers who all know their product is &#8216;valuable&#8217;, and banks take security appropriate steps to manage that risk &#8211; at least, most of the time!</p>
<h4>Use Human Nature to Help Protect PHI</h4>
<p>If I accidentally left my own wallet in your HIPAA-regulated facility, any <em>honest</em> employee that found it would know automatically &#8211; instinctively &#8211; to do two things right away:</p>
<ol>
<li><em>Notify </em>Mr. Weintraub that his wallet was obviously misplaced and has now been found.</li>
<li><em>Lock up</em> the wallet and keep it safe while in posession of it.</li>
</ol>
<p>If you see parallels here between 1.) Breach Notification; and 2.) Securing and Protecting PHI, then you deserve kudos. Because that&#8217;s exactly what&#8217;s what this is all about.</p>
<p>If your workforce <em>knew </em>that PHI is worth money to criminals, they would instinctively protect it, much as bank employees <em>instinctively </em>protect the cash they work with. To a healthcare workforce that&#8217;s ignorant of this, PHI may be sensitive, personal, and confidential &#8211; but it&#8217;s still only so much data, so much paper.</p>
<p>But to criminals, PHI spells &#8220;CASH!&#8221;</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.hipaastore.com/info/phi-spells-cash-to-criminals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA at Yosemite National Park!</title>
		<link>http://www.hipaastore.com/info/hipaa-yosemite-national-park/</link>
		<comments>http://www.hipaastore.com/info/hipaa-yosemite-national-park/#comments</comments>
		<pubDate>Sun, 13 Sep 2009 19:31:07 +0000</pubDate>
		<dc:creator>Abner</dc:creator>
				<category><![CDATA[ARRA & HITECH Act]]></category>
		<category><![CDATA[HIPAA (General)]]></category>
		<category><![CDATA[American Recovery and Reinvestment Act]]></category>
		<category><![CDATA[ARRA]]></category>
		<category><![CDATA[Yosemite]]></category>

		<guid isPermaLink="false">http://www.hipaastore.com/info/?p=104</guid>
		<description><![CDATA[There, in the wilds of Yosemite, was the ARRA, funding road and infrastructure improvements to one our greatest national parks! So the next time somebody asks you what the ARRA has achieved, point to HIPAA expansion, breach notifications, tougher sanctions... and yes, Yosemite!


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p><strong>Okay, it&#8217;s almost true&#8230; damn close anyway!</strong></p>
<p>Yours truly took a long needed mini-vacation last weekend to <a title="Yosemite National Park official website" href="http://www.nps.gov/Yose/index.htm" target="_blank">Yosemite National Park</a> &#8211; my first-ever visit to spectacular Yosemite. My 55th birthday was last weekend, and the idea was to get away from the pressures, the meetings, the calls &#8212; away from HIPAA &#8212; for a few days to clear my head.</p>
<p>So there I was, driving into Yosemite valley in the rental car, awestruck at the raw beauty, the magnificence, the splendor&#8230; <a title="The official ARRA website" href="http://www.recovery.gov/" target="_blank"><strong>the ARRA (American Recovery and Reinvestment Act)?</strong></a></p>
<p>Yes readers, in the midst of the Yosemite wilderness, imagine my surprise when I rounded a curve in the steep road and saw this&#8230;</p>
<div id="attachment_109" class="wp-caption aligncenter" style="width: 410px"><img class="size-full wp-image-109" title="ARRA &amp; Yosemite 03" src="http://www.hipaastore.com/info/wp-content/uploads/2009/09/ARRA-Yosemite-03.jpg" alt="ARRA &amp; Yosemite 03" width="400" height="300" /><p class="wp-caption-text">ARRA at Work in Yosemite</p></div>
<p>I was dramatically reminded, as people in the HIPAA world easily forget, that the ARRA is accomplishing much more than expanding HIPAA. There, in the wilds of Yosemite, was the <strong>ARRA, funding road and infrastructure improvements to one our greatest national parks</strong>!</p>
<p>So the next time somebody asks you what the ARRA has achieved, point to HIPAA expansion, breach notifications, tougher sanctions&#8230; and yes, Yosemite!</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.hipaastore.com/info/hipaa-yosemite-national-park/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Leaky&#8217; Online Networks &#8211; Where&#8217;s Your PHI?</title>
		<link>http://www.hipaastore.com/info/online-networks-phi/</link>
		<comments>http://www.hipaastore.com/info/online-networks-phi/#comments</comments>
		<pubDate>Sun, 06 Sep 2009 19:20:25 +0000</pubDate>
		<dc:creator>Abner</dc:creator>
				<category><![CDATA[ARRA & HITECH Act]]></category>
		<category><![CDATA[Breaches & Losses]]></category>
		<category><![CDATA[HIPAA (General)]]></category>
		<category><![CDATA[Breaches]]></category>
		<category><![CDATA[PHI]]></category>
		<category><![CDATA[social networks]]></category>
		<category><![CDATA[threats]]></category>

		<guid isPermaLink="false">http://www.hipaastore.com/info/?p=91</guid>
		<description><![CDATA[While the health care community has been busy caring for patients and trying to protect PHI (Protected Health Information), crooks have been busy finding new ways to get their hands on it.  And as usual, technology has opened helpful new channels faster than HIPAA entities can cope.


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>While the health care community has been busy caring for patients and trying to protect <strong>PHI (Protected Health Information)</strong>, crooks have been busy finding new ways to get their hands on it.  And as usual, technology has opened helpful new channels faster than HIPAA entities can cope.</p>
<p>Various types of online social networks are apparently the &#8220;next big thing&#8221; in relationships, and they are changing the nature of human interactions. But social networks also pose a major threat to the PHI<strong> </strong>Covered Entities (CEs) and Business Associates (BAs) are entrusted with.</p>
<h2>Peer-to-Peer Networks Expose PHI</h2>
<p>Researchers at Dartmouth College <a title="Dartmouth Researchers Probe P2P Networks" href="http://www.scmagazineus.com/Medical-data-leakage-rampant-on-P2P-networks/article/127216/" target="_blank">probed peer-to-peer (P2P) networks</a> recently to try and determine the extent to which private medical data is exposed on these networks. Over a two-week period, what they found was shocking&#8230;</p>
<ul>
<li>A spreadsheet from an AIDS clinic with 232 client names,including Social Security numbers, addresses and birth dates.</li>
<li>Databases for a hospital system that contained detailed information on more than 20,000 patients, including Social Security numbers, contact details, and insurance records, along with diagnosis information.</li>
<li>A 1,718-page document from a medical testing laboratory containing patient Social Security numbers, insurance information, and treatment codes for thousands of patients.</li>
<li>More than 350 megabytes of sensitive patient reports from a group of anesthesiologists.</li>
</ul>
<p><strong>According to the article above&#8230;</strong></p>
<blockquote><p>In all, researchers found hundreds of documents revealing sensitive information on tens of thousands of patients.</p></blockquote>
<p><a title="Dartmouth PHI Report Download" href="http://www.google.com/url?sa=t&amp;source=web&amp;ct=res&amp;cd=1&amp;url=http%3A%2F%2Ffc09.ifca.ai%2Fpapers%2F54_Data_Hemorrhages.pdf&amp;ei=dsmWSpiTJpCINsyLoPkN&amp;rct=j&amp;q=%E2%80%9CData+Hemorrhages+in+the+Health+Care+Sector%E2%80%9D&amp;usg=AFQjCNHtK73LtQM0K860p-q0CHcaUk2hUg" target="_blank">The full Dartmouth report</a> is also available as a PDF download (858 Kb).</p>
<h3>Personal Social Networks Are Another PHI Threat</h3>
<p>P2P networks are different creatures than what are sometimes called &#8220;personal social networks&#8221; (PSNs). Personal social networks include sites like MySpace and Facebook, where people go (usually) to meet and fraternize with other like-minded people.</p>
<p>Exposure of PHI on personal social networks has already been identified as a growing problem. Increasingly, people are use their MySpace, Facebook, and other social network pages to vent their gripes about their doctors and their medical care.</p>
<p><strong>So here are some critical questions you should consider&#8230;</strong></p>
<ul>
<li>Do you know if you or your practice has been mentioned (positively or negatively) in any of your patients&#8217; social network pages?</li>
<li>What would you do if you found your patients&#8217; PHI exposed on such sites? What could you do?</li>
<li>How extensively are your employees using social networks? Are patients being discussed? Is any PHI being disclosed?</li>
<li>Do you have a written policy regarding personal social networks, P2P networks, and similar online social channels?</li>
</ul>
<p>It&#8217;s later than you think on this front. Your patients, vendors, and the crooks out there are likely farther along than you are in dealing with these issues. The HIPAA implications are enormous, especially with the <a title="ARRA's new Breach Notification Rule" href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/breachnotificationifr.html" target="_blank">ARRA&#8217;s new Breach Notification rule</a> kicking in shortly.</p>
<p><strong>Overall, the most important question you need to answer is:</strong></p>
<h3 style="padding-left: 30px;"><span style="color: #0000ff;">Where&#8217;s <span style="text-decoration: underline;">your</span> PHI?</span></h3>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.hipaastore.com/info/online-networks-phi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Workforce Clearance&#8221;&#8230; Ignore It at Your Own Peril!</title>
		<link>http://www.hipaastore.com/info/workforce-clearance/</link>
		<comments>http://www.hipaastore.com/info/workforce-clearance/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 23:40:02 +0000</pubDate>
		<dc:creator>Abner</dc:creator>
				<category><![CDATA[Employers & HIPAA]]></category>
		<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[Covered Entities]]></category>
		<category><![CDATA[Employers]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[Safeguards]]></category>

		<guid isPermaLink="false">http://www.hipaastore.com/info/?p=20</guid>
		<description><![CDATA[One of the least understood and most ignored requirements in HIPAA is called "Workforce Clearance" (WC). This "addressable" requirement is part of the Security Rule's Administrative Safeguards, and appears at 164.308(a)(3).


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>One of the least understood and most ignored requirements in HIPAA is called &#8220;Workforce Clearance&#8221; (WC). This &#8220;addressable&#8221; requirement is part of the Security Rule&#8217;s Administrative Safeguards, and appears at <a title="Security Rule's Administrative Safeguard" href="http://www.bricker.com/legalservices/practice/hcare/hipaa/164.308.asp" target="_blank">164.308(a)(3)</a>.</p>
<blockquote><p><em>&#8220;Workforce clearance procedure (Addressable). Implement procedures to determine that the access of a workforce member to electronic protected health information is appropriate.&#8221;</em></p></blockquote>
<h3></h3>
<h3>A Danger and an Opportunity</h3>
<p>Hidden in these few words is one of the greatest dangers &#8211; and opportunities &#8211; for both Covered Entities and Business Associates. The danger and the opportunity both derive from the fact that many data breaches and thefts of PHI are perpetrated by <em>insiders</em>.</p>
<ul>
<li>Insiders at Tenet were recently charged with <a title="Insiders at Tenet charged with theft and HIPAA violations" href="http://www.healthleadersmedia.com/content/233655/topic/WS_HLM2_LED/Tenet-Employee-Charged-with-Theft-HIPAA-Violations.html" target="_blank">theft and HIPAA violations</a>.</li>
<li>A Johns Hopkins employee who worked in the hospital&#8217;s patient registration area was recently <a title="charged with fraud after stealing patient files" href="http://www.computerworld.com/s/article/9132860/Johns_Hopkins_tells_patients_Employee_stole_data_for_fraud" target="_blank">charged with fraud after stealing patient files</a>.</li>
<li>Kaiser Permanente&#8217;s Bellflower Hospital was recently <a title="Kaiser Permanente Fined 250K" href="http://latimesblogs.latimes.com/lanow/2009/05/nadya-suleman.html" target="_blank">fined $250,000</a> because employees were snooping into an octuplet mom&#8217;s (&#8220;Octomom&#8221;) medical records.</li>
</ul>
<p>The danger to CEs is that some trusted insider will be tempted to steal, sell, or hold Protected Health Information (PHI) hostage for personal gain. The opportunity is the chance to avoid HIPAA violations and bad publicity by making sure the people inside your entity are trustworthy and responsible.</p>
<h3>&#8220;Workforce Clearance&#8221; Really Means &#8220;Background Checks&#8221;</h3>
<p>In truth, many of these incidents might have been prevented if the entities involved had followed HIPAA&#8217;s &#8220;Workforce Clearance&#8221; requirement more strictly. The essence of Workforce Clearance is really background screening of employees, often referred to as &#8220;background checks.&#8221;</p>
<p>While many entities do perform some background screening for new hires, many entities do only a cursory check, and often with the lowest bidder. Unfortunately, this is a recipe for disaster.</p>
<h4>People with Problems are More Prone to Crime</h4>
<p>The simple fact is, people with criminal backgrounds and those with huge amounts of debt are more often involved in PHI thefts and breaches than those without such problems. And well-done background checks frequently identify high-risk individuals.</p>
<h4>Background Screening &#8211; Rule of Thumb</h4>
<p>A general rule of thumb is that the positions that carry the greatest responsibility should have the most intensive background checks. Positions such as IT Director, Senior Admin, Security Director, Medical Records Director and Manager should all have thorough background screening performed for applicants before they are hired. Some HIPAA entities are also re-screening workers in key positions periodically, to discover potential people problems in advance.</p>
<p><strong>Background screenings for critical positions should include:</strong></p>
<ul>
<li>Confirmation of previous employment history.</li>
<li>Multi-state, or nationwide criminal background checks.</li>
<li>Credit history reports.</li>
<li>Driving history and violation reports.</li>
</ul>
<h4>Don&#8217;t Cut Costs on Workforce Clearance</h4>
<p>While many CEs and BAs try to rein in costs by cutting back on background screening, the smartest entities are stepping up their use of background checks. They are moving to comply with HIPAA&#8217;s addressable &#8220;Workforce Clearance&#8221; requirement. They are also being smart, by reducing the risk from another &#8220;reasonably anticipated&#8221; threat to the PHI they are entrusted with.</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.hipaastore.com/info/workforce-clearance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HIPAA Enforcement Is Heating Up!</title>
		<link>http://www.hipaastore.com/info/hipaa-enforcement/</link>
		<comments>http://www.hipaastore.com/info/hipaa-enforcement/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 23:01:16 +0000</pubDate>
		<dc:creator>Abner</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[HIPAA Enforcement]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[enforcement]]></category>
		<category><![CDATA[HHS]]></category>
		<category><![CDATA[OCR]]></category>

		<guid isPermaLink="false">http://www.hipaastore.com/info/?p=18</guid>
		<description><![CDATA[CEa and BAa simply must get  their HIPAA "ducks in a row" as we approach 2010. The major provisions of the ARRA and the HITECH Act kick in on February 18th 2010, and HIPAA enforcement will continue to heat up. Be ready and be careful!


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>After years of easy-going (some would say non-existent) enforcement, HIPAA enforcement finally appears to be heating up. Consider the following&#8230;</p>
<ul>
<li>HHS conducted it&#8217;s first-ever, on-site inspection for HIPAA compliance in March 2007 at Piedmont Hospital in Atlanta, Georgia.</li>
<li>In 2007 HHS granted new and expanded subpoena authority to the Office for Civil Rights to use in HIPAA violation investigations.</li>
<li>As of 2009, over 400 cases have now been referred to the US Department of Justice over possible criminal violations of HIPAA.</li>
<li>The 2009 HITECH Act, part of the ARRA, expanded HIPAA investigations and enforcement, to include, for the first time, mandatory investigations and penalties for cases involving &#8220;willful neglect&#8221;.</li>
<li><a title="HHS re-delegated HIPAA Security enforcement" href="http://www.hhs.gov/ocr/privacy/hipaa/administrative/srdelegationofauthoritytoocr.html" target="_blank">HHS re-delegated HIPAA Security enforcement</a> in August 2009, moving it from the CMS to the OCR. The OCR now handles investigations and enforcement for <em>both </em>the Privacy and Security Rules.</li>
<li>Announced August 2009, <a title="HHS is hiring more investigators" href="http://www.healthleadersmedia.com/content/237367/topic/WS_HLM2_PHY/Office-for-Civil-Rights-to-Hire-HIPAA-Privacy-Enforcers.html" target="_blank">HHS is hiring more investigators</a> to accommodate the growing number of <a title="HHS Complaints" href="http://www.cms.hhs.gov/Enforcement/11_HIPAAEnforcementStatistics.asp" target="_blank">complaints</a> and it&#8217;s new, combined Privacy and Security enforcement duties.</li>
</ul>
<p>Combine these with the ever-growing number of breaches, and the ARRA changes to HIPAA enforcement, and you have an blossoming enforcement situation every Covered Entity (CE) and Business Associate (BA) should be concerned about.</p>
<p>CEa and BAa simply must get  their HIPAA &#8220;ducks in a row&#8221; as we approach 2010. The major provisions of the ARRA and the HITECH Act kick in on February 18th 2010, and HIPAA enforcement will continue to heat up. Be ready and be careful!</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.hipaastore.com/info/hipaa-enforcement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Digital Devices Create Privacy Challenges</title>
		<link>http://www.hipaastore.com/info/digital-devices-privacy/</link>
		<comments>http://www.hipaastore.com/info/digital-devices-privacy/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 22:31:38 +0000</pubDate>
		<dc:creator>Abner</dc:creator>
				<category><![CDATA[HIPAA Compliance]]></category>
		<category><![CDATA[HIPAA Security]]></category>
		<category><![CDATA[Patients & Consumers]]></category>
		<category><![CDATA[Digital Devices]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[Safeguards]]></category>
		<category><![CDATA[Security Rule]]></category>

		<guid isPermaLink="false">http://www.hipaastore.com/info/?p=15</guid>
		<description><![CDATA[It seems like every new cellphone model these days comes with a camera. And many, like the Apple iPhone, also contain audio recorders. In fact, it's getting hard to find digital devices that don't record images, video, or audio. But for Covered Entities (CEs) and Business Associates (BAs) trying to protect PHI, these devices create serious privacy and security challenges.


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>It seems like every new cellphone model these days comes with a camera. And many, like the Apple iPhone, also contain audio recorders. In fact, it&#8217;s getting hard to find digital devices that <em>don&#8217;t</em> record images, video, or audio. But for Covered Entities (CEs) and Business Associates (BAs) trying to protect PHI, these <a title="devices create serious privacy and security challenges" href="http://news.nurse.com/apps/pbcs.dll/article?AID=2008801280301" target="_blank">devices create serious privacy and security challenges</a>.</p>
<h2>&#8220;Reasonably Anticipated&#8221; Threats</h2>
<p><a title="HIPAA requires CEs and BAs to protect PHI against all " href="http://www.bricker.com/legalservices/practice/hcare/hipaa/164.306.asp" target="_blank">HIPAA requires CEs and BAs to protect PHI against all &#8220;reasonably anticipated&#8221; threats</a>. The problem is, many CEs and BAs <em>don&#8217;t know</em> how serious the &#8220;digital device&#8221; threat is to their PHI. On the other hand, HIPAA entities can&#8217;t claim that these threats couldn&#8217;t be &#8220;reasonably anticipated&#8221;, because this  issue is being covered in the general, technical and medical media increasingly often.</p>
<p>So what&#8217;s a concerned CE or BA to do?</p>
<h3>What Can Be Done?</h3>
<p><strong>The first step is to research the potential for abuse in your organization. You should be able to answer the following questions:</strong></p>
<ol>
<li>How and where are digital devices and recordings being used in your facility now?</li>
<li>How will you deal with employees and physicians&#8217; use of digital devices for recording images, video, and audio?</li>
<li>How will you deal with patients and visitors using these devices?</li>
<li>What are the legitimate recording uses, if any, for such devices in your facility?</li>
</ol>
<p>Based on the answers to these questions, you should create clear policies and guidance for the workforce, patients and visitors. Policies should be circulated to everyone and employee &#8220;sign-offs&#8221; should be obtained to establish workforce &#8220;agreement&#8221; to abide by the policies. Consider having patients sign a form laying out the rules and restrictions on recording with digital devices. And consider posting signs in patient and visitor areas that say &#8220;No Photography Allowed&#8221;,  &#8220;Recordings Prohibited&#8221;, or something similar.</p>
<h3>A Variety of Approaches</h3>
<p>CEs and BAs today are taking a variety of approaches to digital devices and the recordings they can produce, including:</p>
<ul>
<li>Banning all cameras, camera-phones, and audio recording devices from the premises. (Very hard to enforce.)</li>
<li>Banning digital devices from patient-care areas. (Easier to enforce, but still problematic.)</li>
<li>Establishing clear policies and restrictions on usage, but not banning the <em>physical presence</em> of relevant digital devices. (More realistic, but still difficult to enforce, as many devices are small and can be used surreptitiously.)</li>
<li>Ignoring the problem or deferring the issue till &#8220;later.&#8221; (The riskiest approach of all.)</li>
</ul>
<h3>No &#8220;Magic Bullet&#8221;</h3>
<p>There is no &#8220;magic bullet&#8221; solution for the privacy and security challenges posed by digital recording devices. Nevertheless, CEs and BAs <em>must attempt </em>to address these challenges somehow, even if only to demonstrate to a judge or jury &#8212; after a breach &#8212; that they were not guilty of &#8220;willful neglect&#8221;. Remember, <a title="HIPAA violations that involve " href="http://www.hospitalreviewmagazine.com/news-and-analysis/legal-and-regulatory/what-hospitals-need-to-know-about-the-arra-and-the-hipaa-updates.html" target="_blank">HIPAA violations that involve &#8220;willful neglect&#8221; carry new investigative and penalty requirements</a> under the recent ARRA expansion to HIPAA. Be careful!</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.hipaastore.com/info/digital-devices-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>An Epidemic of Medical Records Breaches</title>
		<link>http://www.hipaastore.com/info/medical-records-breaches/</link>
		<comments>http://www.hipaastore.com/info/medical-records-breaches/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 21:57:58 +0000</pubDate>
		<dc:creator>Abner</dc:creator>
				<category><![CDATA[Breaches & Losses]]></category>
		<category><![CDATA[HIPAA Security]]></category>
		<category><![CDATA[Breaches]]></category>
		<category><![CDATA[enforcement]]></category>
		<category><![CDATA[Legal Issues]]></category>

		<guid isPermaLink="false">http://www.hipaastore.com/info/?p=12</guid>
		<description><![CDATA[Whether it's from stolen laptops, rogue wi-fi hotspots, employee snooping, or determined hackers, data breaches and losses are skyrocketing. The problem is so acute, that even organizations that track data breaches are amazed at the scope of the data breach problem.


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Where will it end? It seems that incidents of medical records breaches are still on the rise, with no end in sight.</p>
<p>Whether it&#8217;s from <a title="stolen laptops" href="http://www.msnbc.msn.com/id/32304147/ns/technology_and_science-secu" target="_blank">stolen laptops</a>, <a title="wi-fi hotspots" href="http://www.cnn.com/2009/TECH/science/08/11/wifi.security.hackers/index.html?iref=newssearch" target="_blank">rogue wi-fi hotspots</a>, <a title="employee snooping" href="http://www.healthleadersmedia.com/content/236077/topic/WS_HLM2_TEC/Hospital-Slapped-with-Second-SixFigure-Fine-for-Records-Breach-in-Two-Months.html" target="_blank">employee snooping</a>, or determined <a title="hackers" href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2009/05/09/BAPA17H89B.DTL" target="_blank">hackers</a>, data breaches and losses are skyrocketing. The problem is so acute, that even <a title="organizations that track data breaches" href="http://datalossdb.org/" target="_blank">organizations that track data breaches</a> are amazed at the <a title="scope of the data breach problem" href="http://www.techweb.com/article/printArticle?articleID=212700890&amp;prin" target="_blank">scope of the data breach problem</a>.</p>
<h2>Medical Records Have Financial Value to Criminals</h2>
<p>Why is this happening in such a big way? The answer is <em>money</em>. Medical records, and other comprehensive personal records like mortgage applications, have <em>financial value</em> to criminals. Criminals buy and sell people&#8217;s personal records on underground websites and channels because those records are used to create false identities and commit fraud.</p>
<p>The attractiveness of medical records to criminals is one of the main reasons why the HIPAA regulations require such strong protections for PHI. Covered Entities think their records are just paper. But to criminals, medical records are <em>gold</em>.</p>
<p><a title="Foreign crime syndicates" href="http://www.nextgov.com/nextgov/ng_20080516_2203.php?oref=search" target="_blank">Foreign crime syndicates</a> see the potential payoff from I.D. theft. And even common street gangs are, in some cases, turning away from drugs and prostitution and moving into <a title="Identity Theft" href="http://articles.latimes.com/2008/aug/12/business/fi-idtheft12" target="_blank">I.D. theft</a>.</p>
<h3>HIPAA Requirements are Only a Starting Point</h3>
<p>Remember, <a title="HIPAA's Privacy and Security Rule requirements" href="http://www.hhs.gov/ocr/privacy/hipaa/understanding/coveredentities/privacyguidance.html" target="_blank">HIPAA&#8217;s Privacy and Security Rule requirements</a> are only a <em>minimum</em> &#8220;floor&#8221; of protection that every entity should have in place no matter what. It also takes effective training, awareness of how criminals work, and due diligence to prevent data breaches. And you can be sure of one thing: prevention is easier and much, much cheaper than dealing with a data breach. Be careful!</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.hipaastore.com/info/medical-records-breaches/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Abandoned Medical Records Becoming Commonplace</title>
		<link>http://www.hipaastore.com/info/abandoned-medical-records/</link>
		<comments>http://www.hipaastore.com/info/abandoned-medical-records/#comments</comments>
		<pubDate>Sun, 23 Aug 2009 21:10:07 +0000</pubDate>
		<dc:creator>Abner</dc:creator>
				<category><![CDATA[Breaches & Losses]]></category>
		<category><![CDATA[HIPAA Privacy]]></category>
		<category><![CDATA[Breaches]]></category>
		<category><![CDATA[Destruction]]></category>
		<category><![CDATA[Disposal]]></category>
		<category><![CDATA[Losses]]></category>

		<guid isPermaLink="false">http://www.hipaastore.com/info/?p=9</guid>
		<description><![CDATA[Well, it's happened yet again. Another case of un-shredded medical records abandoned or disposed-of in the regular trash stream. This time its in Massachusetts, as the Boston Globe reported here in April 2009.


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Well, it&#8217;s happened yet again. Another case of un-shredded medical records abandoned or disposed-of in the regular trash stream. This time its in Massachusetts, as the <a title="Boston Globe reported here" href="http://www.boston.com/news/local/massachusetts/articles/2009/04/02/patients_files_poised_at_trash_bin/" target="_blank">Boston Globe reported here</a> in April 2009.</p>
<p>It seems an Acton, Mass., family doctor closed his practice suddenly and had hundreds of patient files in storage.  The doctor was apparently evicted from his office as he was being pursued by state regulators for practicing without a license! As a result, the records in storage were in limbo, and were nearly auctioned off to the highest bidder, along with equipment and miscellaneous items belonging to the &#8220;doctor.&#8221;</p>
<p>This incident has a happy ending, as a <a title="Local Hospital Rescues Medical records" href="http://www.boston.com/news/local/massachusetts/articles/2009/04/03/hospital_steps_in_to_rescue_abandoned_medical_records/" target="_blank">local hospital has stepped up and offered</a> to &#8220;rescue&#8221; the records. But not every case like this ends on an upbeat note. This kind of situation is created more often by careless Covered Entities who simply toss un-shredded records in the trash.</p>
<h2>HIPAA Requires Destruction Before Disposal</h2>
<p>Let&#8217;s be crystal clear here folks: <a title="HIPAA regulations require" href="http://www.bricker.com/legalservices/practice/hcare/hipaa/164.310.asp" target="_blank">HIPAA regulations require</a> PHI to be destroyed before it is disposed of; and its is a HIPAA violation to dispose of PHI that has not been destroyed or rendered indecipherable. And <a title="HHS released new guidelines" href="http://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/disposalfaqs.pdf" target="_blank">HHS released new guidelines</a> (PDF download) in 2009 on PHI destruction.</p>
<p>Don&#8217;t fall into such an obvious trap! Make sure your entity has a clear policy and procedures on PHI disposal and destruction. Train staff on the policy and procedures, and be certain your policy is followed consistently every time. This is a <em>preventable </em>HIPAA violation &#8211; be careful!</p>


<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.hipaastore.com/info/abandoned-medical-records/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
