Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: HIPAA Violations

A HIPAA violation is defined as the following: the failure to comply with the HIPAA Rules – Privacy, Security and Breach Notification.

The failure to comply with any of the Standards in these Rules is considered a violation under HIPAA. The Standards apply to Covered Entities and Business Associates who electronically transmit PHI in connection with transactions for which HHS has adopted standards. Since the publication of the Final Omnibus Rule in 2013, Business Associates have the same requirements to comply with all HIPAA Rules.

Here are some of the most common violations under HIPAA:

  • Failure to provide patients access to their PHI, either ignoring the requests or not providing the PHI in a timely basis.
  • Unauthorized disclosure of PHI beyond permitted uses and disclosures (minimum necessary).
  • Annual HIPAA Security Risk Analysis is not conducted and completed.
  • Lack of workforce training for HIPAA, Security Awareness and Cybersecurity.
  • Business Associate Agreements were not put in place with third parties accessing a Covered Entities’ patients’ data. A written contract between a Covered Entity and Business Associate is required under HIPAA.
  • Improper disposal of PHI whether in paper form or electronic (computer hard drives, servers).
  • Lack of encryption technology when transmitting ePHI, sharing patient data in unsecured files or channels, or unsecured portable devices that contain ePHI.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


Author:

Dawn Meglino

HIPAA Compliance Specialist, CHPSE, CCSA, CCAP