MDNews - Central New York

January/February 2013

Issue link: https://viewer.e-digitaledition.com/i/100763

Contents of this Issue

Navigation

Page 22 of 27

create risk management plan; (d) develop a sanction policy; (e) review information system activity; (f) establish workforce authorization, clearance and termination procedures; (g) foster security awareness and conduct training; (h) protect systems from malicious software; and (i) establish a data backup plan, an emergency mode operations plan, a disaster recovery plan complete with testing and revision procedures, applications/data criticality analyzed and security incident response and reporting. organizational Requirements (164.314) Business associate contract compliance with rules about the length of time that documentation is maintained and its availability to staff. technical Safeguards (164.312) (A) Access control; (b) unique user identification; (c) emergency access procedure; (d) automatic logoff; (e) encryption and decryption; (f) audit controls; (g) integrity controls; (h) authentication; and (i) transmission security. Physical Safeguards (164.310) (A) Facility access controls, including contingency operations, a facility security plan, access control and validation procedures, and maintenance records; (b) workstation use and security; and (c) devices and media controls, such as disposal, media reuse, accountability, data backup and storage. To meet meaningful use, the Security Risk Analysis, which is a review of an established security program, must be performed within an EP���s reporting period. Many practices underestimate the scope of this effort and are left scrambling to address requirements before the end of the period in order to secure their incentive payments. The HITECH Act also includes a substantial HIPAA Security enforcement component, which is the responsibility of the Office for Civil Rights (OCR). OCR has engaged the KPMG consulting firm to conduct random audits, which are currently under way. These will be relatively few in number and are intended to focus on education in this early stage of enforcement. However, this should not lead EPs into complacency because the intention is clearly to increase accountability over time. The law entails substantial penalties for noncompliance, which range from $25,000 (maximum) for ���unknowing��� violations to $1.5 million (maximum) for ���uncorrected willful neglect.��� As we enter a new age of electronic health information, we will need to expand the way we think about protecting patient information. In time, the primary enforcer for doing so will not only be the government, but patients, too. John Netti is President of Netti Consulting Ser vices, www.netticonsulting.com, which provides an array of EHR services, as well as President of the Mountain Creek HIPAA Group, www.MCHIPAAGroup.com. He can be contacted at jnetti@netticonsulting.com or (315) 437-4377. ��� New Bachelor of Science Degree Program! IMPROVING MEDICAL SERVICES AND PROFITABILTY THROUGH BETTER EDUCATION. It���s what our new Health Services Administration Bachelor���s Degree Program is all about. Do you want your office to run more effectively and cost-efficiently? Are you looking for a highly capable, knowledgeable and dedicated professional to help take your practice to the next level? Bryant & Stratton College can deliver what you need. We can train your current employees or provide one of our graduates as an intern or permanent staff member. It���s your choice and a great way to enhance your operations. For more information about our graduation rates, the median debt of students who completed the program, and other important information, please visit our website at www.bryantstratton.edu/disclosures. w w w . b r y a n t s t r a t t o n . e d u facebook.com/BSCSyracuse ��� facebook.com/BSCNorth Liverpool Syracuse Veteran Helpful Bryant & Stratton College 1.315.804.4004 Personal Education. Lifetime Success.�� Since 1854 Scan here with your smartphone for more information.

Articles in this issue

Links on this page

Archives of this issue

view archives of MDNews - Central New York - January/February 2013