Ways to HIPAA Security Incidents 2016

Expired
Dates : 01 September 2016 » 01 September 2016

Place : Online Event
United States

Book your hotel


Organizer :

Topic : Health and Medicine; Healthcare Training courses
Mathematics and Statistics; Economics; Health and Medicine;
Keywords: Analysis, Business, Human Resources, Health
Description :

Overview: 

 

This webinar will cover everything that you need to know about how to handle HIPAA security incidents, breaches, and complaints and the Department of Health and Human Resources Investigations thereof. Not all security incidents are breaches, but all breaches of confidentiality are within the broad ambit of security incidents. Privacy rule violations, such as failing to give a patient a copy of his or her medical records, may also constitute a breach as the $4.2 million fine assessed against Cignet Healthcare of Prince George's County, Maryland, dramatically proved. Handling an investigation properly is key to determining not only how to handle it to mitigate any harm and to take action to prevent it from happening again but also to determine whether it is reportable to affected individuals and to DHHS.

 

HIPAA requires a complaint procedure (policy). The webinar will suggest what such a document should contain as it also will for the required report procedure (what is reportable, who reports, to whom, and required/suggested contents of the report) and the required response procedure (what do the responsible officials do after receiving the report or the complaint).

 

Investigating a possible security incident is key. The webinar will cover how to conduct a thorough investigation of HIPAA security incidents, breaches, and patient complaints.

 

Finally, the second largest HIPAA civil money penalty or settlement, $4.2 million, was in large part due to the offender's failure to cooperate with the DHHS investigation. The presenter has successfully defended his clients in seven such investigations and knows how to respond to them to avoid or minimize liability. 

 

Think of a gap analysis as an examination of: What you currently have in place for HIPAA compliance. Is that adequate? Can it be done better? Is it enough? And what am I missing? Asking these questions will help establish the direction and next steps to take. It lays the ground work for a good Risk Analysis and the policies and procedures your organization may be lacking in a cost-effective manner so you are not wasting money and other resources in unnecessary security measures. 

 

Why should you attend: 

 

As of the so-called HITECH Act, covered entities and their business associates must report certain breaches of HIPAA to DHHS which can result in seven-figure fines, lawsuits, bad publicity, and other sanctions. Remediation costs may be immense, such as the $17 million incurred by Blue Cross/Blue Shield of Tennessee on top of the $1.5 million civil money penalty for not having sufficient security to prevent a burglar from stealing all their computer equipment and media with millions of individuals' health insurance data. That is not the only method DHHS may learn of a breach, however. Civil money penalties have resulted from complaints by patients, and one even resulted from a newspaper story. Civil money penalties to date range from $50,000 to two in the $4 million range. And a $50,000 or low six-figure fine may doom a small practice. And these fines cannot be discharged in bankruptcy because they are imposed as a punishment rather than compensating the government for that money it had expended. The largest civil money penalty is reserved for breaches that are not handled properly, capped at $1.5 million for identical such breaches in a calendar year. And DHHS considers that, say, if you lose an unencrypted laptop with no other reasonable and appropriate security in its place, it constitutes a separate violation for each patient's data on the lost laptop. In addition, patients and others who complain to DHHS may receive a portion of any fine, thereby providing an incentive to complain. Also, an audit by DHHS may lead to a civil money penalty.

 

Nor are these penalties reserved for large practices. Fines have been assessed against two-physician practices and a small hospice in North Dakota. Being not-for-profit provides no immunity, nor does being a government entity. Alaska Medicaid was fined $1.5 million; and a county government (Skagit County in Washington State), $215,000.

 

Thus, it is crucial to know how to avoid breaches, how to investigate a security incident, how to determine whether it is a breach, when you have to report a security incident to DHHS (and sometimes to state agencies), and how to mitigate (lessen) the harm of a breach. How a so-called covered entity responds to security incidents and breaches receives great scrutiny in DHHS audits and is a factor in determining whether a sanction is warranted and in lessening the fine from what it otherwise might be. 

 

HIPAA requires covered entities to, in addition to its Privacy Officer, have a complaint procedure and a complaint official (who can be the Privacy Officer) in addition to having a report procedure and a response (how do you handle the report) procedure. Failure to have these elements of HIPAA compliance or having inadequate ones constitutes a breach of the HIPAA requirements. 

 

Areas Covered in the Session:

 

What is a security incident?

What is a breach?

What are the penalties for a breach?

What types of breaches are likely to result in sanctions?

What are the HIPAA requirements for handling breaches?

The Report and Response Procedure

Investigating security incidents and patient complaints

Taking action on the breach-immediate and subsequent-including mitigation

What breaches are reportable to DHHS?

How to respond to an investigation by DHHS

Conclusion and questions and answers<

 

Who Will Benefit:

 

HIPAA Compliance Officers

HIPAA Security Officers

HIPAA Privacy Officers

CFOs

CEOs

COOs

CIOs

Human Resources Directors

Business Office Managers

Administrators

Medical Records Personnel

Audiologists

Group Practices

Nurses

Chiropractors

 

Speaker Profile :

 

Jonathan P. Tomes , J.D., is a health care attorney and partner in the law firm of TOMES & DVORAK, CHARTERED. He has written more than 50 books, including The Compliance Guide to HIPAA and the DHHS Regulations, and dozens of articles in the area of HIPAA compliance. 

 

He has been an expert witness in litigation involving health information compliance issues and is the President of EMR Legal, Inc., a national HIPAA consulting firm. His knowledge of the law and of the practical aspects of setting up a security system provides a rare opportunity for compliance officers and medical records veterans and novices alike. Mr. Tomes has presented seminars nationally for 20 years.

 

Price : $139.00 

 

Contact Info:

 

MentorHealth

Phone No: 1-800-385-1607

FaX: 302-288-6884 

support@mentorhealth.com

Event Link: http://bit.ly/HIPAA-Security-Incidents

http://www.mentorhealth.com/

 

LinkedIn  Follow us – https://www.linkedin.com/company/mentorhealth 

Twitter Follow us – https://twitter.com/MentorHealth1 

Facebook Like us– https://www.facebook.com/MentorHealth1


Ways to HIPAA Security Incidents 2016 to be held in Online Event , United States between 01 September 2016 and 01 September 2016. It covers specific areas of Health and Medicine such as Healthcare Training courses. Visit the website of the conference for more detailed information or contact the organizer for specific questions.
Add to calendar 2016-09-01 2016-09-01 Europe/London Ways to HIPAA Security Incidents 2016 https://www.sciencedz.net/en/conference/21464-ways-to-hipaa-security-incidents-2016 Online Event - United States

Find More Related Conferences

Looking for more scientific conferences to attend? Explore a wide range of upcoming events in various fields and locations. Whether you're looking for specialized topics, specific locations, or dates, we have a wide range of conferences to choose from.
Health and Medicine Conferences in United States 2016: Discover the latest trends and research in Health and Medicine by attending conferences across United States in 2016. Network with professionals, researchers, and industry leaders to stay at the forefront of technological advancements.
Conferences and seminars in United States
Conferences and seminars in United States in 2016
Conferences and seminars in Health and Medicine
Conferences and seminars in Health and Medicine in 2016
Conferences and seminars in Health and Medicine in United States
Conferences and seminars in Health and Medicine in United States in 2016
All events
Events by country

Disclaimer : We aim to provide correct and reliable information about upcoming events, but cannot accept responsibility for the text of announcements or for the bona fides of event organizers. Please feel free to contact us if you notice incorrect or misleading information and we will attempt to correct it.We are not involved in the organization of any of the events listed and we do not handle registration payments on behalf of the organizers.