Skip to main content

How to Manage OCR, HHS HIPAA and HITECH Audit


Overview
Among other things, the HITECH Act significantly strengthened HIPAA enforcement activities. In addition to increasing penalties, allowing enforcement by state attorneys general, requiring notices of breaches, and making business associates directly subject to penalties, the HITECH Act mandated that Office for Civil Rights of HHS conduct HIPAA audits. This one-hour webinar will focus on preparation required by healthcare organizations to successfully manage an OCR/HHS audit by regulators.
Why should you attend this webinar?
Section 13411 of the Health Information Technology for Economic and Clinical Health (HITECH) Act, requires Health and Human Services (HHS) to conduct periodic audits of providers and business associates to ensure their compliance with the HIPAA Security and Privacy Rule, and breach notification standards. To implement this mandate, the Office of Civil Rights (OCR) has conducted HIPAA/HITECH audit program with KPMG of 115 health care organizations to assess privacy and security compliance. This webinar will focus on the implementation and tracking of HIPAA audit best practices in a healthcare setup in order to prepare for the federal audit using published OCR audit protocols.
Every audit begins with interviews, a questionnaire, and a thorough policy and procedures review. Presenter, with his decades of knowledge in the compliance, legal, auditing and security areas, will walk the attendees through the audit process, documentation requirements, and implementation specifications of the HIPAA privacy, security and breach rules. This presentation not only provides opportunity for the participants to prepare for the federal HIPAA audit but also to improve the security posture of their organizations by adopting to changing technology (mobile, social media, Health Information Exchange(HIE), cloud services, etc.) and threat landscape perspective as well. This presentation will uncover reasons why many health information breaches are occurring and help organizations better secure and comply with electronic protected health information by meeting the required and addressable HIPAA/HITECH security rules.

The presenter will also share the best practices used for HIPAA security implementation and continuous risk assessment which is considered as "due diligence" by auditors for the HIPAA security compliance program.
Areas Covered in the Session:
  • Healthcare Technology Adoption/Trends
  • Healthcare Regulatory (HIPAA/HITECH) and OCR/HHS Audit Overview
  • Differences between HIPAA and HITECH Regulations
  • Confidentiality, Integrity and Availability (CIA) & ePHI Data Elements
  • HIPAA/HITECH Security, Privacy and Breach Requirements
  • OCR Audit Protocol
  • Patient Data Privacy, Security and Breach Procedures
  • Step-by-step guide preparation techniques
  • Sample policies
  • Risk Assessment questionnaire for protecting electronic health information
  • Checklist
Who can Benefit:
  • Compliance Director
  • CEO
  • CFO
  • Privacy Officer
  • Security Officer
  • Information Systems Manager
  • HIPAA Officer
  • Chief Information Officer

Comments

Popular posts from this blog

Risk and Controls Matrix for SOX, Assurance and Internal Audit

Compliance Key INC  -  SOX Training Online Overview This webinar is created to equip young risk and compliance professionals with the skills necessary to prepare a Risk and Controls Matrix, including the following: Discover the objectives, components and requirements of effective internal controls Leveraging internal control frameworks to create a risk and controls matrix Developing risk identification and management strategies to implement now Learning how to design internal controls Learning how to evaluate the design and operating effectiveness of internal controls Why should you attend this webinar? Whether you are planning a SOX engagement, or an internal audit, regulatory compliance requirements, or other separate evaluations, just where do you start with planning for the engagement? How do you complete the necessary risk and control documentation that you will need to successfully complete the engagement? Attend this webinar to learn more. Areas...

Essentials of Affirmative Action and OFCCP Compliance

Compliance Key INC  -  Human Resource Training Online                                                                  Janette Levey Frisch Janette Levey Frisch is Keynote Speaker at Compliance key Inc. She is founder of  The EmpLAWyerologist Firm, has over 20 years of legal experience, more than 10 of which she has spent in Employment Law. It was during her tenure as sole in-house counsel for a mid-size staffing company headquartered in Central New Jersey, with operations all over the continental US, that she truly developed her passion for Employment Law.   Webinar Id:   CICJE001  10.00 AM PT | 01.00 PM ET   01/09/2018  Duration: 90 mins  Overview If you are a federal contractor, having a firm grasp on the essentials ...

The 5 most Dangerous Risks Under New HIPAA Laws

Compliance Key  -   Online hipaa training for employees in US Overview This 90-minute webinar will be addressing how practice/business managers (or compliance offers) need to get their HIPAA house in order before the imminent audits occur. It will also address major changes under the Omnibus Rule and any other applicable updates for 2018. We will go into detail about the 5 biggest "gotcha's" related to compliance with this enigmatic law. I will also speak of multiple litigated cases I have been involved with involving HIPAA compliance (or lack there of areas also covered will be texting, email, encryption, medical messaging, voice data and risk factors as they relate to IT.  The primary goal is to ensure everyone is well educated on what is myth and what is reality with this law, there is so much misleading information regarding the do's and don'ts with HIPAA - I want to add clarity for compliance officers and what you guys need to do and how to best im...