Review HIPAA/HITECH Protocols for Your Compliance Health
By Francie Fernald - July 18, 2012
Francie

If you haven’t reviewed them already, take a look at the audit protocols the Office for Civil Rights has posted for HIPAA security and privacy and HITECH breach compliance. According to the website, “OCR established a comprehensive audit protocol that contains the requirements to be assessed through these performance audits. The entire audit protocol is organized around modules, representing separate elements of privacy, security, and breach notification.”

The HIPAA security protocol has 77 entries broken down by regulatory section for each of the administrative, physical, and technical safeguards. The table lists the regulatory sections, the performance criteria, the key activity, and the audit procedure. And the procedures all begin with “Inquire of management…” and then instruct the auditors to review relevant policies and procedures. The privacy and HITECH protocols are structured the same way as the security protocols and review (1) notice of privacy practices for PHI, (2) rights to request privacy protection for PHI, (3) access of individuals to PHI, (4) administrative requirements, (5) uses and disclosures of PHI, (6) amendment of PHI, and (7) accounting of disclosures. The first 10 entries address breach audit procedures; the remaining 78 address the HIPAA privacy requirements.

The posted protocols contain a significant amount of detail as to what auditors will request and review. While they may seem overwhelming, they are well worth review if for no other reason than to give your HIPAA/HITECH compliance program a thorough checkup. You also would be prepared if you are one of the lucky 95 covered entities/business associates OCR will audit this year. To what degree is your organization reviewing the protocols and for what purpose?

It's quick and easy to sign up for FREE access to AISHealth.com!

Why do I need to register?

About the AIS Bloggers
Managing Editor, Health Plan Week, Inside Health Insurance Exchanges and The AIS Report on Blue Cross and Blue Shield Plans*
View Steve's Profile
Managing Editor, AIS’s Health Reform Week and Medicare Advantage News
View James's Profile
Managing Editor, Specialty Pharmacy News, Drug Benefit News and AIS E-Media
View Angela's Profile
Managing Editor, Report on Medicare Compliance
View Nina's Profile
Editor, Health Plan Week
View Patrick's Profile
Editor, Report on Patient Privacy and Report on Research Compliance
View Theresa's Profile
Editor, Drug Benefit News
View Lauren's Profile
Editor, AIS’s Health Reform Week
View Neal's Profile
Manager, Web and e-Newsletter Content, and Associate Editor, Medicare Advantage News and Health Plan Week
View BJ's Profile
President & Publisher
View Rick's Profile