Would your company pass a HIPAA compliance audit?
Is your business compliant with HIPAA? Would it pass a compliance audit with flying colors – or face hefty penalties?
A scary percentage of group health plan sponsors aren’t complying with the Health Insurance Portability and Accountability Act (HIPAA). According to Buck’s HIPAA Readiness Survey of 31 companies, only 39% of respondents had updated their privacy and security policies and procedures in the last year.
In terms of HIPAA training, only 42% of respondents had provided training to their workforce in the last year. Conversely, 35% stated the last HIPAA training was between one and five years ago, while 13% only provide training during onboarding. The remaining 10% didn’t even know when their last HIPAA training took place. Those are some concerning responses. Although the sample size is somewhat small, it doesn’t seem farfetched to assume we’d see similar results across a bigger pool. It’s a dangerous trend that needs to be reversed.
Unprepared companies aren’t just risking hefty penalties – they’re also risking possible data misuse and breaches if IT infrastructures aren’t up to snuff. That, my friends, can be costly. HIPAA violations can range anywhere from $100 to $50,000 per violation.
Related: Three Most Common Ways to Violate HIPAA
High-Profile (and High-Cost) HIPAA Violations
The financial damage of each violation depends on severity and frequency, but it can be expensive. Here are a few recent examples from the last couple of years:
Touchstone Medical Imaging: fined $3 million after exposing PHI of over 300,000 patients.
University of Rochester Medical Center: fined $3 million after failing to encrypt mobile devices
Anthem: fined $16 million after failing to take “substantial corrective action” following the largest healthcare data breach in U.S. history, which exposed PHI of approximately 79 million people.
Prudent healthcare companies will want to comply. But how?
HIPAA Compliance: Understanding the Basics
I can’t copy and paste all the HIPAA text here but that being said, here are three areas to focus on:
Privacy Rule – addresses standards around protected health information (PHI).
Security Rule – specifies preventative actions that covered entities and their business associated must take to protect electronic PHI.
Breach Notification Rule – provides procedures for handling data breaches.
Per the Compliancy Group, there are six processes that can help companies reach HIPAA compliance.
Self-audits
Remediation plans
Ongoing training
Documentation
Business associate management
Incident management
Data security isn’t an option, it’s mandatory. In the digital age, companies have mountains of sensitive data about their operations, their clients, their suppliers, their employees, and so on. If you’re not convinced, check out our post on the importance of data protection and possible safeguards.
Personalized, Efficient, and HIPAA Compliant: Direct Mail by Sepire
Is your company implementing the necessary countermeasures to prevent data breaches? Are your partners doing the same?
Sepire’s security protocols, proprietary technology workflow and WBENC certification provide a true differentiator in the marketplace – and they provide you with a vendor that place your and your customers’ best interests as a top priority. As an expert in the healthcare direct mail space, Sepire carries all the required certifications you need from your vendors—and a few others that set us apart.
Contact us to learn how our proprietary technology workflow safeguards your customers’ data.