Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Summer is the Perfect Time to…

Essential HIPAA Tasks for Your Slower Summer Months

Welcome to this week’s HIPAA Tip Tuesday! Summer offers healthcare organizations a strategic opportunity to tackle HIPAA compliance tasks that often get pushed aside during busier times. Dawn Meglino provides a practical 5-step checklist to help you get your compliance house in order before year-end pressures arrive.

TL;DR – Summer HIPAA Compliance Checklist:

  • Complete or update your HIPAA Security Risk Analysis (SRA)
  • Audit active users and disable departed employees across all systems
  • Review and update all required HIPAA policies and procedures
  • Patch systems, update software, remove end-of-life devices
  • Test your Disaster Recovery Plan to ensure it works

Why Summer is the Perfect Time

Get your HIPAA Compliance House in order! Why? Because the organization is not preparing the year-end financials, meeting with management or board members, prepping for a visit from the State or an Accreditation Company, or setting up and completing employee evaluations – so much to do at the end of the year. Business may be a little lighter in the Summer and offer opportunities to address HIPAA requirements that may have been put on the back burner but absolutely need to be completed and put into place.

Start With Self-Assessment

On a scale from 1 to 10 where is your HIPAA compliance level for the organization? Beginning with this very simple question compile a list of what needs to be addressed/completed to assist the business in reaching HIPAA compliance, and ultimately, protecting the privacy and security of patient data – Protected Health Information.

Five Essential Summer HIPAA Tasks

1. Complete or Update Your HIPAA Security Risk Analysis

Use your most recent HIPAA Security Risk Analysis (SRA) to put together a list of the risks and vulnerabilities identified as outstanding to the organization. Prioritize from most critical to least critical areas that need addressing. *NOTE: if you have not had a HIPAA SRA completed within the last year, how do you know the risks and vulnerabilities to the business? Complete the HIPAA SRA right away. NOW IS THE TIME!

2. Conduct User Access Audits

Conduct reviews of active users in all systems and applications containing ePHI to ensure workforce members no longer with the organization have been disabled: Windows, emails, EMR, PM/scheduling, dictation, billing software, diagnostic devices and machines, to name a few. During review check privileges for users – remember minimum necessary rule / least privileged access.

3. Review Policies and Procedures

Ensure policies and procedures required under the HIPAA Security Rule are completed, reviewed, revised if necessary, and sent to all staff for acknowledgment and sign-off (if applicable).

4. Patch Systems and Remove End-of-Life Software

Confirm all business devices are patched and updated with the latest fixes and performance improvements. Replace any end-of-life software systems or, at minimum, remove from the network environment.

5. Test Your Disaster Recovery Plan

Disaster Recovery Plan (DRP) must be in place; list all critical software systems that need to be accessible in the event of a disaster/emergency, who would have remote access to the systems if necessary, and steps to follow with limited access to systems and applications containing ePHI. If the DRP has not been tested this year, take the time now to work through the plan to ensure this can be successfully carried out.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.