On January 2, 2013, HHS posted a news release announcing the settlement agreement and $50,000 settlement amount assessed to Hospice of North Idaho. Here’s today’s big tip — learn 7 key lessons from this event (spoiler alert: completing a MANDATORY risk analysis is included in the list). Read more.
HIPAA Risk Analysis Tips – $50K Penalty vs. Does Size Matter?
Yikes! Blogosphere has been lit up by every self-proclaimed (and newly-2013-declared) ‘expert’ about the Hospice of North Idaho-HHS Settlement Agreement Document and Corrective Action Plan (SADCAP, my new acronym!).
Clearwater Compliance has successfully guided dozens of organizations through OCR Audits and Investigations. And this most recent news is a great time to review seven great lessons:
- Size doesn’t matter, nor apparently your mission.
- There is an ROI on trying.
- Trying starts with taking stock of where you currently are.
- Taking stock of where you are includes compliance gap assessments (mock audits) AND, that HIPAA Risk Analysis that has been required since April, 2005… It’s time!
- There’s a much higher ROI for spending $50K on good-faith effort than for paying HHS penalties and CAP for a lost laptop. (FYI: 12K laptops a week in USA go missing!)
- You actually can start with much less than $50K and a closed office and still make a meaningful move closer to full compliance.
- Let’s work together to keep the money aimed at treating needy patients (good grief, especially hospice patients!) and not into government coffers to fund more enforcement.
Learn more About Doing an authentic HIPAA Security Risk Analysis…
The HIPAA Security Rule (at 45 C.F.R. §164.308(a)(1)(ii)(A)) requires an initial security risk analysis according to risk analysis guidance issued by HHS/OCR based on NIST standards. The one-of-a-kind Clearwater HIPAA Risk Analysis is guaranteed to simplify that process, immediately identify threats and vulnerabilities and make risk analysis less overwhelming.
OCR Audit Protocols for Risk Analysis are clear! CMS, as planned, has launched audits of organizations who have attested to Meaningful Use Objectives and Risk Analyses will be audited. Have you completed a bona fide HIPAA Security Risk Analysis?
The subscription fee to the Clearwater HIPAA Risk Analysis™ is based on the size of the organization in an effort to make this powerful tool available to organizations of all sizes.
OR, call 800-704-3394 X3007 Today!
Latest posts by Bob Chaput (see all)
- Making the case for comprehensive cyber-risk strategies: 10 startling facts that will spur C-suite action - August 8, 2016
- Building Capability and Capacity to Take on Healthcare’s Evolving Security Threats - August 5, 2016
- HIPAA Risk Analysis Tip – The Biggest Risk Management Surprises in the 2016 OCR Audit Protocol - April 11, 2016