Skip to main content

HIPAA Compliance with the New Omnibus Rule: How to Pass an Audit to Avoid Penalties and Criminal Convictions

                                            Jonathan P. Tomes
Jonathan P. Tomes , J.D., is Keynote Speaker at Compliance key Inc. He is a health care attorney practicing in the greater Kansas City. He is a nationally recognized authority and expert witness on the legal requirements for health information. Jon has written more than 60 books.

 Webinar Id:  HIPHJPT001
 12:30 PM PT | 03:30 PM ET 
 01/18/2018
 Duration: 60 mins 


Overview
Before the HITECH Act, DHHS could audit covered entities for HIPAA compliance, but did not have to. With that Act, now the must audit those entities and business associates as well. In the first audits, the Phase I audits, DHHS came on site. The subsequent Phase II audits, however, were paper audits in which those audited had to provide documentation of their compliance. As yet, we do not know what form Phase III will take, but the necessary actions to prepare will be largely the same whether the audit is purely a paper one or includes an on-site component.
Why should you attend this webinar?
If you are audited and found to be non-compliant, you could face civil money penalties, supervised Corrective Action Plans, bad publicity with concomitant loss of patients, and significant remediation costs.
Civil money penalties to date range from $50,000 to two in the $4 million range. Some of these penalties resulted from improper access by a workforce member, improper use, or improper disclosure. Such improper actions can also result in criminal liability. A physician went to federal prison for improper chart access. A nurse was convicted of improperly using PHI to threaten a lawsuit.
Nor are these penalties reserved for large practices. Fines have been assessed against two-physician practices and a small hospice in North Dakota. Being not-for-profit provides no immunity, nor does being a government entity. Alaska Medicaid was fined $1.5 million; and a county government (Skagit County in Washington State), $215,000.
Areas Covered in the Session:
  • Overview of HIPAA and the Security and Privacy Rules.
  • The Requirement for DHHS to Audit.
  • Audits to Date.
    • Who audits?
    • Phase I audits.
    • Phase II audits.
    • Audit Findings.
    • Possible penalties for failing audits.
    • Benefits of preparing for audits.
    • Will you be audited?
  • Preparing for audits.
    • Audit protocol.
    • Gap analysis.
    • Risk Analysis.
    • Prioritizing remediation.
    • Key areas DHHS focuses on.
    • Documentation.
  • Conclusion and Question and Answer.
Who can Benefit:
Health Professionals and their staffs, Privacy and Security Officers, Medical Records Professionals, IT Professionals, Office Managers, Risk Managers, Business Associates of Covered Entities (those that provide a service for the Covered Entity involving the use of individually identifiable health information (transcription services, billing services, cloud storage companies, and the like), Healthcare Attorneys, Compliance Officers, HIPAA consultants

Comments

Popular posts from this blog

HIPAA changes 2018 and How to comply?

Compliance Key INC  -  HIPAA W ebinar                                                   Brian L Tuttle Brian Tuttle is Keynote Speaker at Compliance key Inc . He is Certified Professional in Health IT (CPHIT), Certified HIPAA Professional (CHP), Certified Business Resilience Auditor (CBRA) with over 17 years experience in Health IT and Compliance Consulting.     Webinar Id:   HIPHBLT001 10:00 AM PT | 01:00 PM ET  01/23/2018 Duration: 90 mins  Overview This lesson will be addressing how practice/business managers (or compliance offers) need to get their HIPAA house in order as HIPAA is now fully enforced and the government is not using kid gloves any more. It will also address major changes under the Omnibus Rule, Trump administration, and any other applicable updates for 2018 and beyon...

Form I-9 Compliance For Small Business

Compliance Key INC  -  Compliance Online Training                                  Matthew W. Burr Matthew Burr has over ten years of experience working in the human resources field, starting his career as an Industrial Relations Intern at Kennedy Valve Manufacturing to most recently founding and managing a human resource consulting company; Burr Consulting, LLC. He specializes in labor and employment law, conflict resolution, performance management, employee relations and work with labor unions.   Webinar Id:  CICMF001  12:30 PM PT | 03:30 PM ET  11/28/2017  Duration 60 mins  Overview This training will focus on the importance of I-9 compliance for small businesses. The training will introduce the I-9 forms, importance of filling out the forms correctly, retention process and proactive I-9 audits. We will also ...

SOX Compliance: Accounts Receivable Risks and Controls

Overview The accounts receivable process includes the sub-cycles of acquiring and accepting customer orders; writing sales contracts; granting customer credit; shipping or otherwise delivering products or services; billing and recording sales and lease transactions; maintaining and monitoring accounts receivable; instituting effective collection procedures; recording and controlling cash receipts; establishing pricing and promotional activities; and properly valuing receivable balances. In management's selection of procedures and techniques of control, the degree of control implemented is a matter of reasonable business judgment. The common guideline used in determining the degree of internal controls implementation is that the cost of a control should not exceed the benefit derived. The Order to Cash Process (O2C) Process is comprised of several sub-processes that must have a foundation of internal controls for SOX 404 certification process. This webinar wil...