Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: HIPAA 26.2

As promised, let’s delve into how to successfully get to HIPAA 26.2!

There will never be a “finish line” when it comes to HIPAA privacy, security and now, cybersecurity awareness and education; however, proactively moving forward and addressing areas that need attention and completion (on many levels) will take your organization to higher HIPAA compliancy.

  1. Research your “course”. What are the required HIPAA Privacy and Security Rule safeguards? Has my organization addressed all of the Implementation Specifications of the HIPAA Security Rule? Are all policies and procedures reviewed and updated annually or when changes occur to the environment?
  2. Read reviews and reports from those who have explored solutions to issues that your organization may still have pending. There are numerous business leaders working for the healthcare industry every day to bring compliancy and safeguards to the forefront of patient data security. Utilize their expertise and knowledge (NIST, CISA, HealthIT.gov, HHS 405(d)).
  3. Pace yourself with training. No, this does NOT mean staff training annually for HIPAA, Security and Cybersecurity Awareness. Consistent updated training is key. The evolution of cyber attacks grows and becomes stronger every single day. Presenting the same HIPAA video year after year, or outdated information for security awareness and cybersecurity, is putting your team and business in the dark ages.
  4. Don’t compare your organization to others. A smaller organization may not have a 160-page compliance manual along with a security and compliance team of 15+ members.

Be certain in these cyber attack times we are in that critical (and required) policies and procedures are in place, communicated to ALL staff and reviewed regularly for any changes. Even in smaller organizations enlist staff members to contribute and assist with the HIPAA privacy, security and cybersecurity awareness and compliance.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


Author:

Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP