For the better part of the last three years, many healthcare providers either voluntarily or by force have put many of the mandated HIPAA self-assessment audit requirements on the back burner. As has been seen most recently, that is all about to change…significantly.
By way of background, the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH) requires the Department of Health and Human Services to periodically audit covered entities and business associates for their compliance with the requirements of HIPAA. During these audits, covered entities are often asked to produce policies and procedures as well as evidence that they have been conducting accurate and thorough assessments of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all electronically-protected health information (PHI) that they create, receive, maintain or transmit.To assist these entities in maintaining compliance, the Office of Civil Rights (OCR) has provided many different self-assessment tools, many of which can be found here.
Since the onset of COVID however, many covered entities have been faced with other significant challenges including strict adherence to vaccine and quarantine requirements as well as significant reductions in workforce and discretionary income often needed to conduct such intensive HIPAA self-assessments. Continue reading ›