Skip to main content

What Does the Term "Reasonable and Appropriate" Mean under HIPAA? And How Do You Achieve It?

Compliance Key INC - HIPAA webinar
Jonathan P. Tomes , J.D., is Keynote Speaker at Compliance key Inc. He is a health care attorney practicing in the greater Kansas City. He is a nationally recognized authority and expert witness on the legal requirements for health information. 

 Webinar Id:  HIPJPTW006 
 12:30 PM PT | 3:30 PM ET 
 03/20/2018
 Duration: 60 mins 

Overview
The HIPAA Security Rule requires covered entities and business associates to implement "reasonable and appropriate" security measures to protect against improper access, use, or disclosure of Protected Health Information ("PHI"). The Rule, however, gives very little guidance as to what constitutes reasonable and appropriate security measures. This is probably a good thing because what is reasonable and appropriate for a small town dental practice will likely be wildly different from a celebrity mental health facility in Beverly Hills. The lack of guidance, however, makes compliance difficult because how does one know whether DHHS will agree that their security measure is reasonable and appropriate if you are audited or investigated. And if you are sued, will the plaintiff 's expert be able to testify that your security measures did not meet that standard and, hence, you were negligent and are liable for the potentially huge damages of a major breach.
Why should you attend this webinar?
If you are audited, investigated, or sued and found not to have reasonable and appropriate security measures, you could face civil money penalties, supervised Corrective Action Plans, bad publicity with concomitant loss of patients, lawsuit damage awards, and significant remediation costs.

Civil money penalties to date range from $50,000 to two in the $4 million range. A number of these have resulted from deficient security measures, such as a missing firewall, lack of adequate security to prevent unauthorized access, and the like.

Nor are these penalties reserved for large practices. Fines have been assessed against two-physician practices and a small hospice in North Dakota. Being not-for-profit provides no immunity, nor does being a government entity. Alaska Medicaid was fined $1.5 million;and a county government (Skagit County in Washington State), $215,000.
Areas Covered in the Session:
  • Overview of HIPAA and the Security Rule.
  • The Requirement for Reasonable and Appropriate Security Measures.
  • DHHS Guidance on What is Reasonable and Appropriate.
  • Other Guidance on What is Reasonable and Appropriate.
    • California Attorney General Guidance.
    • NIST Guidance.
    • Other Guidance?
  • How to Determine Whether Your Security Measures are Reasonable and Appropriate.
    • Risk Analysis.
    • Required and Addressable Security Measures.
    • Penetration Testing.
    • Requirement for Evaluation-Follow-up Testing.
    • Key Security Measures DHHS Focuses On.
    • Documentation.
  • Conclusion and Question and Answer.
Who can Benefit:
Health Professionals and their staffs, Privacy and Security Officers, Medical Records Professionals, IT Professionals, Office Managers, Risk Managers, Business Associates of Covered Entities (those that provide a service for the Covered Entity involving the use of individually identifiable health information (transcription services, billing services, cloud storage companies, and the like), Healthcare Attorneys, Compliance Officers, HIPAA consultants.

Compliance Key INC
717-208-8666
https://www.compliancekey.us/life-science-and-healthcare

Comments

Popular posts from this blog

The 5 most Dangerous Risks Under New HIPAA Laws

Compliance Key  -   Online hipaa training for employees in US Overview This 90-minute webinar will be addressing how practice/business managers (or compliance offers) need to get their HIPAA house in order before the imminent audits occur. It will also address major changes under the Omnibus Rule and any other applicable updates for 2018. We will go into detail about the 5 biggest "gotcha's" related to compliance with this enigmatic law. I will also speak of multiple litigated cases I have been involved with involving HIPAA compliance (or lack there of areas also covered will be texting, email, encryption, medical messaging, voice data and risk factors as they relate to IT.  The primary goal is to ensure everyone is well educated on what is myth and what is reality with this law, there is so much misleading information regarding the do's and don'ts with HIPAA - I want to add clarity for compliance officers and what you guys need to do and how to best im...

Risk and Controls Matrix for SOX, Assurance and Internal Audit

Compliance Key INC  -  SOX Training Online Overview This webinar is created to equip young risk and compliance professionals with the skills necessary to prepare a Risk and Controls Matrix, including the following: Discover the objectives, components and requirements of effective internal controls Leveraging internal control frameworks to create a risk and controls matrix Developing risk identification and management strategies to implement now Learning how to design internal controls Learning how to evaluate the design and operating effectiveness of internal controls Why should you attend this webinar? Whether you are planning a SOX engagement, or an internal audit, regulatory compliance requirements, or other separate evaluations, just where do you start with planning for the engagement? How do you complete the necessary risk and control documentation that you will need to successfully complete the engagement? Attend this webinar to learn more. Areas...

Essentials of Affirmative Action and OFCCP Compliance

Compliance Key INC  -  Human Resource Training Online                                                                  Janette Levey Frisch Janette Levey Frisch is Keynote Speaker at Compliance key Inc. She is founder of  The EmpLAWyerologist Firm, has over 20 years of legal experience, more than 10 of which she has spent in Employment Law. It was during her tenure as sole in-house counsel for a mid-size staffing company headquartered in Central New Jersey, with operations all over the continental US, that she truly developed her passion for Employment Law.   Webinar Id:   CICJE001  10.00 AM PT | 01.00 PM ET   01/09/2018  Duration: 90 mins  Overview If you are a federal contractor, having a firm grasp on the essentials ...