Proudly serving Tampa since 2000
i-Tech Support is your trusted local HIPAA compliance support and HIPAA compliance consulting services company in the Tampa, FL area. Our HIPAA compliance consultants help both solo practitioners and larger healthcare and medical organizations get in HIPAA compliance and stay that way. Contact us today!
The need for HIPAA compliance and the requirements
The Health Insurance Portability and Accountability Act (HIPAA) protects sensitive patient data, also referred to as protected health information (PHI). It requires healthcare entities to create physical, network and process security measures that meet HIPAA compliance standards.
Fines for non-compliance reach as high as $1.5 million for repeat offenders, so it is a must that your institution needs to adhere to its guidelines. Here’s what your organization needs to know about HIPAA requirements.
HIPAA compliance overview
President Bill Clinton signed HIPAA into law in 1996. Under the original law, HIPAA consisted of five titles:
Employees are most familiar with this title because it enshrines into law the right to continue employer-based coverage after termination through COBRA plans. It also restricts coverage denials based on certain conditions and bans lifetime coverage limits.
Title II requires the Department of Health and Human Services (HHS) to create standards for electronic PHI records. With the move to electronic records in healthcare entities, this title has become even more important.
This title contains tax provisions and medical care guidelines.
This provides pre-existing conditions protections and guarantees continued coverage.
Contains provisions for revenue offsets for company-owned life insurance and taxes on former U.S. citizens.
In addition, HIPAA contains the HIPAA Security Rule, which governs data security. In 2013, HHS increased requirements for electronic security through its Omnibus Rule. The increased measures were a response to the 2009 Health Information Technology for Economic and Clinical Health Act.
Data breaches occur frequently. Some breaches are accidental while others result from criminal cyberattacks. Common reasons for data breaches include:
- Misuse of database
In phishing attacks, criminals send emails that appear to come from a trusted sender to trick healthcare employees into revealing login credentials. Pretexting attacks involve criminals impersonating legitimate actors over the phone to gain private information from employees.
The need for HIPAA compliance
HHS takes HIPAA compliance very seriously. It enforces HIPAA requirements aggressively and hands down stiff financial penalties according to a four-tier system.
Accidental, low-impact HIPAA violations are eligible for a $100 fine per violation, with an annual maximum of $25,000.
For higher impact violations, fines increase to $1,000 per violation, with an annual maximum of $100,000.
HHS takes intentional neglect of HIPAA requirements very seriously. If healthcare entities correct first-time HIPAA compliance violation in a timely fashion, the fine stands at $10,000 per violation, with an annual maximum of $250,000.
Entities that willfully violate HIPAA and fail to correct the problem face a fine of $50,000 per violation, with an annual maximum of $1.5 million. Intentional violations of the HIPAA requirements for privacy, such as in a hacking attack or copying and disseminating PHI, carry fines up to $100,000 and up to 10 years in prison.
The requirements for healthcare institutions
To comply with HIPAA, healthcare entities obtain a 10-digit national provider identifier. HHS standardized procedures for the ease of transactions and the administrative costs of HIPAA compliance.
If a PHI data breach occurs, the entity must report it to HHS and to affected individuals. A HIPAA data breach involves information that makes healthcare records individually identifiable. Also, HIPAA-covered entities must perform the following procedures:
- Appoint a privacy officer to oversee HIPAA compliance
- Provide employee training on HIPAA compliance
- Create privacy safeguards: Administrative, technical and physical
- Provide a complaint process for unauthorized PHI disclosure
- Mitigate the impact of any HIPAA violations