This article is about compliancy and the regulations surrounding the protection of Protected Health Information (PHI).
Nearing my 50’s I feel that my generation was perfectly set at the crossroads of yesterday and today, allowing me to witness firsthand how quickly the world changes. Growing up in the 1970’s provided for some interesting perspectives compared to how we understand the laws of today. Smoking was considered cool - at any age. Drinking and driving was basically invented during this time. This was even more special for me as my father owned a plane. Seatbelts? Not in the back compartment of that wood paneled station wagon, facing backwards out the window as we tried to distract the car behind us. I remember being 8 years old and leaving in a boat to go
Don’t get me wrong, laws were in place back then, but my father taught me from a young age that “perception is 9/10th's of the law… and you’re only guilty if you get caught”.
HIPAA compliancy is kind of like a Rubik’s cube (another reference to my generation). It makes sense if you understand all the rules, but unfortunately, only a few nerds had this level of time, resources, and training invested. Most healthcare professionals understand the importance PHI and their intentions would never be to purposely place this information at risk. The challenge is that these professionals earn their living by providing the services that they spent eight years in school for. Their level of success is directly tied to billable hours, or how much time is spent offering healthcare services. School did not prepare them to be IT or legal experts, yet HIPAA regulations pertaining to PHI treat them that way. The fines associated with a data breach carry the power to cripple their business.
The risk doesn’t stop at the practice, HIPAA Compliancy is a requirement for all Covered Entities – including Business Associates. If you are an IT service provider, it doesn’t really matter if you are healthcare specific or not. Having at least one healthcare customer with PHI, and hosting/managing that data, as a Business Associate, it makes you just as “at risk” for non-compliance penalties.
In the ‘70’s, Nerds wrote instruction books to help the average person conquer the Rubik’s cube and lucky for you, my network of PHI protection nerds are providing the following instructions* to help you solve the HIPAA PHI compliancy puzzle:
* These steps alone put you on the correct path for HIPAA compliance, but of course do not guarantee that you are compliant in all areas regarding PHI. These recommendations are not legal advice, and qualified counsel should always be consulted regarding legal issues specific to your practice.
There are several ways that your data can become compromised as disaster presents itself in many forms. It is best to identify these risks before they happen, speculate on what could happen, and build a plan for dealing with them. Being HIPAA compliant is necessary, and while it’s great to avoid audits and penalties, protecting your PHI serves the greatest interest of keeping the doors open. With or without regulations, every business (that wants to stay in business) should invest in putting together a quality data protection plan. Even the loss of every-day business data like accounting information can be devastating. Nobody can afford down time or a bad reputation in the age of instant information.
As much of a puzzle HIPAA compliancy can be, working with experts in this field, I’ve learned that HIPAA regulations can actually be more forgiving than AquanNet was to mullets and big hair. If you can prove intent, you can avoid penalty.
Therefore take the time to document your procedures, then build a PHI/data recovery plan and maintain proof that you frequently test against this plan. Nobody wants to lose or risk the integrity of their PHI and you definitely do not want to be fined up to hundreds of thousands of dollars in penalties.
Flash forward to today. The world is in a different kind of chaos.
"you’re only guilty if you get caught"... without a plan.
A NovaStor webinar on HIPAA Compliance and Backup can be viewed here.