HIPAA Tip: Stop HIPAA Violations From Happening
Practical Steps to Prevent Common Healthcare Compliance Issues
Welcome to this week’s HIPAA Tip Tuesday! HIPAA violations continue to happen daily in healthcare organizations—often for the same preventable reasons. In this guide, Dawn Meglino shares the most common violations she encounters and practical steps to stop them before they occur.
- Eliminate shared login credentials—every user needs unique access
- Configure auto-lock on all computers (5-15 minute timeout)
- Implement email encryption for all ePHI communications
- Conduct security training regularly, not just annually
- Apply HIPAA rules to everyone—owners and physicians included
No one working in the healthcare industry is above HIPAA rules and regulations – no one! And yet every day compliance officers hear: “I can’t do that – we don’t have time to log out and log back in!” “Have someone else log me in; I can’t be bothered to remember a password.” “Those rules don’t apply to me – I’m the owner.” “IT has security on our systems, we don’t have to worry about hackers – that’s not going to happen to us.”
Common Themes (Violations) Continuing to Happen That Must Be Broken:
Shared User Login Credentials
Shared user logins to any systems and applications containing electronic Protected Health Information (ePHI), including Windows Operating Systems (logging into the computers), diagnostic devices, Xray machines. There is no audit trail with shared user accounts and zero accountability of access to ePHI. No minimum necessary rule followed.
Unlocked Computers and Workstations
Computers with no auto-lock or time out after 5-10-15 minutes of inactivity. Staff not adhering to locking computers every time they walk away (ctrl+alt+del / windows key + L key) and leaving a computer screen open with the last patient’s chart open or the EMR or Practice Management schedule available for anyone (including patients and other staff members) to see.
Unencrypted Emails Containing ePHI
Emails sent that include ePHI with no encryption. Why take this chance when encryption is inexpensive and the only secure way to email sensitive data and ePHI?
Inadequate Staff Education and Training
Staff education must be conducted for HIPAA, Cybersecurity and Security Awareness training – regularly, not annually. This includes all management, physicians, owners and staff. To not train or educate is to not know – so whose fault is it then?
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.