{"id":238,"date":"2016-08-08T15:18:21","date_gmt":"2016-08-08T22:18:21","guid":{"rendered":"https:\/\/blog.sprucehealth.com\/?p=238"},"modified":"2023-10-26T06:22:43","modified_gmt":"2023-10-26T13:22:43","slug":"5-hipaa-violations-likely-cost-avoid","status":"publish","type":"post","link":"https:\/\/sprucehealth.com\/blog\/5-hipaa-violations-likely-cost-avoid\/","title":{"rendered":"The 5 HIPAA Violations Most Likely to Cost You (And How to Avoid Them)"},"content":{"rendered":"<p>Everybody knows that HIPAA violations can be costly, with penalties\u00a0that can include seven-digit fines and jail time. Even worse, the combined text of the current HIPAA regulations stretches to <a href=\"http:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/laws-regulations\/combined-regulation-text\/index.html\">115 pages<\/a>\u00a0and more than 60,000 words.\u00a0It&#8217;s little\u00a0wonder, then, that\u00a0most healthcare providers are\u00a0scared they might be missing something that could\u00a0ruin them financially or put their practice in jeopardy.<\/p>\n<p>Luckily, the Office of Civil Rights (OCR), which enforces HIPAA, makes <a href=\"http:\/\/www.hhs.gov\/hipaa\/for-professionals\/compliance-enforcement\/data\/enforcement-results-by-year\/index.html\">data available<\/a> on its\u00a0investigations and enforcement actions. We can see exactly how many complaints they field each year (about 10 to 20 thousand), how many of these result in &#8220;corrective actions&#8221; (about 20 to 30%), and most importantly, what types of HIPAA violations\u00a0most commonly result in corrective actions. &#8220;Corrective action,&#8221; by the way, is the OCR way of saying that you&#8217;re likely settling\u00a0(paying the government) or paying a fine (also paying the government) in addition to agreeing to a plan to rectify and then monitor your areas of violation, which will also cost money and time to carry out.<\/p>\n<h1>HIPAA Violations Most Likely to Get You a Corrective Action<\/h1>\n<p>So which areas of your HIPAA coverage should you focus on most to avoid the dreaded corrective action? Let&#8217;s go\u00a0right to\u00a0the horse&#8217;s mouth and see <a href=\"http:\/\/www.hhs.gov\/hipaa\/for-professionals\/compliance-enforcement\/data\/enforcement-highlights\/index.html\">what OCR says<\/a>:<\/p>\n<h2>1)\u00a0Impermissible Uses and Disclosures<\/h2>\n<p>This has been the undisputed #1 type of violation to net a corrective action\u00a0for <a href=\"http:\/\/www.hhs.gov\/hipaa\/for-professionals\/compliance-enforcement\/data\/top-five-issues-investigated-cases-closed-corrective-action-calendar-year\/index.html\">every year in the last decade<\/a>, which makes sense. HIPAA is very focused on what you&#8217;re doing with the protected health information (PHI) that is under your control, and improper uses and disclosures of that information are obvious areas for enforcement. Additionally, patients are likely to notice and be upset about this type of violation, which could increase the volume of complaints to OCR for this category.<\/p>\n<p>An easy\u00a0two-step process to avoid this violation:<\/p>\n<ol>\n<li><strong>Identify the PHI that you have<\/strong><br \/>\nPHI is &#8220;all individually identifiable health information held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral.&#8221; For more on this, see the Health and Human Services (HHS) <a href=\"http:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/laws-regulations\/index.html\">site<\/a>.<\/li>\n<li><strong>Identify and validate your uses and disclosures of this PHI<\/strong><br \/>\nLoosely, a &#8220;use&#8221; occurs when you&#8217;re doing something\u00a0internal with PHI and a &#8220;disclosure&#8221; occurs when you&#8217;re sharing PHI with an outside person or organization.<br \/>\nHIPAA allows uses and disclosures\u00a0without specific authorization in the following six categories:\u00a0&#8220;(1) To the Individual (unless required for access or accounting of disclosures); (2) Treatment, Payment, and Health Care Operations; (3) Opportunity to Agree or Object; (4) Incident to an otherwise permitted use and disclosure; (5) Public Interest and Benefit Activities; and (6) Limited Data Set for the purposes of research, public health or health care operations.&#8221; Some of these categories\u00a0are opaque, but HHS provides <a href=\"http:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/laws-regulations\/index.html\">guidance<\/a> to clarify them. Other uses and disclosures typically require authorization from the patient.<\/li>\n<\/ol>\n<h2>2) Lack of Safeguards<\/h2>\n<p>HIPAA requires that you maintain\u00a0&#8220;administrative, technical, and physical&#8221; safeguards to prevent impermissible uses or disclosures of protected health information (PHI). These three types of safeguards are very important throughout all of HIPAA, and it&#8217;s worth your time to <a href=\"https:\/\/sprucehealth.com\/blog\/easiest-complete-hipaa-compliance-checklist-youll-ever-see\/\">understand them<\/a>.<\/p>\n<p>What&#8217;s important here is that\u00a0it&#8217;s not just your\u00a0uses and disclosures that can get you penalized; you are also responsible for the systems that you have in place to <em>prevent<\/em> those uses and disclosures. Identify what systems you need (administrative, technical, and physical), implement them, document them, and maintain them.<\/p>\n<h2>3) Lack of Patient Access<\/h2>\n<p>Patients have a right to obtain copies of their\u00a0medical records in almost all cases, and you have a duty under HIPAA to provide complete versions of those records in a timely fashion, at minimal or no cost, and in a reasonable format of the patient&#8217;s choosing. Patients may also request an accounting of disclosures that you have made of their protected health information (PHI). There are some caveats to these rules but not many. The HIPAA &#8220;Privacy Rule&#8221; covers this topic more extensively, if you are curious about the details.<\/p>\n<p>Patients also typically have the right to request that\u00a0information in their records\u00a0be amended\u00a0when that information is inaccurate or incomplete. You should make every effort to comply with such\u00a0requests in a timely fashion, too.<\/p>\n<h2>4) More Than the Minimum Necessary<\/h2>\n<p>The concept of the &#8220;minimum necessary&#8221; amount of information is a guiding principle in HIPAA. In all situations, you should seek to use or disclose the absolute <strong>minimum<\/strong> amount of protected health information (PHI) that is necessary to accomplish the goal of the use or disclosure. For example, if sending a patient&#8217;s name and birthday is all that is needed\u00a0for a certain permissible disclosure, then do not also send their entire problem list or their current medications. Always think, &#8220;What is the least amount of information needed to get this task done?&#8221;<\/p>\n<h2>5) Lack of Administrative Safeguards<\/h2>\n<p>If\u00a0this seems like a partial repeat of the general &#8220;Lack of Safeguards&#8221; category above, then that&#8217;s because it almost is. The difference here is that OCR is highlighting a lack of administrative safeguards on <strong>electronic<\/strong> protected health information (PHI). Remember that PHI refers to health information in any form, electronic or otherwise, and it is covered by the HIPAA Privacy Rule. Electronic PHI, however, gets special, more in-depth regulation, and it is the subject of the entire HIPAA Security Rule. All types of PHI need administrative, technical, and physical safeguards, but HIPAA gives these extra attention\u00a0when the\u00a0PHI is in electronic form.<\/p>\n<p>If you&#8217;re handling electronic PHI, then you need to be familiar with the <a href=\"https:\/\/sprucehealth.com\/blog\/easiest-complete-hipaa-compliance-checklist-youll-ever-see\/\">HIPAA Security Rule<\/a>\u00a0and its extra specifications for administrative, technical, and physical safeguards. It would be a shame to\u00a0do a good job on general PHI safeguards and then get nailed for missing ones that are specific to electronic PHI.<\/p>\n<hr \/>\n<p>That&#8217;s it. Those are the five\u00a0HIPAA violations\u00a0most likely to end with\u00a0penalties for you, and that&#8217;s straight from the government office\u00a0that does\u00a0the enforcing. For more information on getting your HIPAA ducks in a row, check out our <a href=\"https:\/\/sprucehealth.com\/blog\/easiest-complete-hipaa-compliance-checklist-youll-ever-see\/\">easy, complete HIPAA compliance checklist<\/a>\u00a0and also the\u00a0<a href=\"http:\/\/www.hhs.gov\/hipaa\/for-professionals\/index.html\">Department of Health and Human Services<\/a>.<\/p>\n<p><em>This article is part of a series of posts relating to HIPAA law and regulation. The information provided is\u00a0meant as general guidance only and is not intended to be legal advice.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Everybody knows that HIPAA violations can be costly, with penalties\u00a0that can include seven-digit fines and jail time. Even worse, the combined text of the current HIPAA regulations stretches to 115 pages\u00a0and more than 60,000 words.\u00a0It&#8217;s little\u00a0wonder, then, that\u00a0most healthcare providers are\u00a0scared they might be missing something that could\u00a0ruin them financially or put their practice in jeopardy.<\/p>\n","protected":false},"author":1,"featured_media":468,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"slim_seo":{"title":"The 5 HIPAA Violations Most Likely to Cost You (And How to Avoid Them) - Spruce Blog","description":"Everybody knows that HIPAA violations can be costly, with penalties\u00a0that can include seven-digit fines and jail time. Even worse, the combined text of the curre"},"footnotes":""},"categories":[14],"tags":[16,15],"different-template":[],"class_list":["post-238","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hipaa","tag-compliance","tag-hipaa"],"acf":[],"_links":{"self":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts\/238","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/comments?post=238"}],"version-history":[{"count":0,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts\/238\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/media\/468"}],"wp:attachment":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/media?parent=238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/categories?post=238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/tags?post=238"},{"taxonomy":"different-template","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/different-template?post=238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}