HIPAA Tip: HIPAA Denial
Confronting Dangerous Misconceptions About HIPAA Compliance
Welcome to this week’s HIPAA Tip Tuesday! HIPAA denial takes many forms—from believing breaches won’t happen to you, to thinking your practice is too small to be targeted. Dawn Meglino confronts six dangerous myths that put healthcare organizations at serious risk and explains the real consequences of non-compliance.
- Myth: “It won’t happen to me” – Reality: It’s not IF but WHEN
- Myth: “Too small to target” – Reality: Small practices are easier targets
- Myth: “Doesn’t apply to us” – Reality: All Covered Entities must comply
- Myth: “Under 500? No notification needed” – Reality: Must report within 60 days of year-end
- Myth: “Staff don’t need training” – Reality: Human error causes most breaches
- Penalties: $100 to $1.5M civil; up to $50K + 1 year imprisonment criminal
Six Dangerous HIPAA Myths
Myth 1: It Will Never Happen to Me
It will never happen to me. As we say in the HIPAA world, it’s not “if” you will have an attack or breach, it’s “when”. Be as prepared and proactive as possible when addressing the HIPAA Privacy, Security and Breach Notification Rules. The day will come when you need to be ready.
Myth 2: My Practice is Too Small to Target
My practice is too small – the threat actors will ignore me. Hackers and Ransomware attackers work in groups where certain divisions specialize in areas to maximize on skills. Lower hanging fruit such as smaller organizations are easy targets with quick return on a short-term investment, requiring fewer threat actor team members.
Myth 3: HIPAA Doesn’t Apply to My Organization
That doesn’t apply to my organization. If you are considered a Covered Entity or Business Associate under HHS OCR guidelines you are required to comply with the HIPAA Rules, to protect the privacy and security of health information and provide individuals with certain rights with respect to their health information.
Myth 4: Breaches Under 500 Don’t Need Reporting
I don’t need to file a breach notification if the breach involved fewer than 500 individuals. Covered Entities must notify OCR of breaches involving fewer than 500 individuals no later than 60 days after the end of the calendar year in which the breaches are discovered.
Myth 5: Staff Don’t Need Cybersecurity Training
My staff can read – they don’t need me to train them on cyber security and security awareness training, especially with computers – they have their own at home! Human error and unintentional security incidents are major factors in many breaches, especially in phishing attacks or misused/shared credentials. HIPAA, Security and Cybersecurity Awareness training for all staff is a necessity and a requirement.
Myth 6: It Wasn’t Really a Breach or Our Fault
There was a breach! Or was there? I don’t think it was an actual breach and it wasn’t my business’s fault. Accidental or intentional security incidents and/or breaches must be addressed to find out the extent of the violation to the organization’s PHI/ePHI. Once this is determined, patients need to be notified right away or no later than 60 days after the discovery of the incident/breach.
The Reality of HIPAA Requirements
It’s understandable how some Covered Entities and their Business Associates might feel burdened by HIPAA requirements. The fact remains that HIPAA compliance is a legal obligation and can lead to severe consequences when ignored.
Consequences of Non-Compliance
Failure to comply with HIPAA can lead to:
Civil Penalties
Civil penalties: Violations are determined by OCR and can range from $100 to $1.5 million per violation depending on the severity and nature of the breach. Violations are categorized into four tiers based on the level of negligence, with higher tiers resulting in more significant penalties.
Criminal Penalties
Criminal penalties: According to HHS OCR: A person who knowingly obtains or discloses individually identifiable health information in violation of the HIPAA Privacy Rule may face a criminal penalty of up to $50,000 and up to one year imprisonment.
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.