HIPAA Tip: What are Cyber Insurance Companies Requiring of Healthcare Organizations?
If you haven’t looked into Cyber Insurance you may be surprised (or shocked!) at what Cyber Insurance companies are requiring to cover your organization.
The responsibility of compliance falls on Covered Entities and Business Associates to prove they are taking the necessary measures to safeguard Protected Health Information (PHI) and prevent risk.
In the event of a cyberattack, insurance companies will only help an organization if they can provide proof the organization and its employees complied with their cyber policy. There needs to be a cybersecurity framework in place before a data breach and that the policies and framework to mitigate risks was in fact followed; this is sometimes referred to as the Book of Evidence.
What you will need to do:
- Annual HIPAA Risk Analysis. It’s no surprise the first key piece of compliance “evidence” would be the annual Risk Analysis for the organization. Without completing there is no way of knowing the vulnerabilities and risks to PHI, ePHI and sensitive data.
- Regular staff training. This does not mean a once-a-year HIPAA training powerpoint that staff watch annually. Continuous security and cybersecurity awareness training including ALL staff, owners and C-Suite needs to be ongoing with commitment from all involved in the organization.
- Year-round compliance and remediation improvements. Conducting an annual HIPAA Risk Analysis is step one; however, if your organization files the report away and does not address threats and vulnerabilities to the environment or network, these become bigger and offer threat actors more opportunities to attack. Mitigate risks and review regularly where stronger security measures can be put in place.
HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.
Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP