Ways to HIPAA Security Incidents 2016

Expiré
Dates : 01 septembre 2016 » 01 septembre 2016

Lieu : Online Event
États-Unis

Book your hotel


Organisateur :

Domaine : Santé et Médecine; Healthcare Training courses
Mathématiques et Statistiques; Economie; Santé et Médecine;
Mots-clé:: Analysis, Business, Human Resources, Health
Description :

Overview: 

 

This webinar will cover everything that you need to know about how to handle HIPAA security incidents, breaches, and complaints and the Department of Health and Human Resources Investigations thereof. Not all security incidents are breaches, but all breaches of confidentiality are within the broad ambit of security incidents. Privacy rule violations, such as failing to give a patient a copy of his or her medical records, may also constitute a breach as the $4.2 million fine assessed against Cignet Healthcare of Prince George's County, Maryland, dramatically proved. Handling an investigation properly is key to determining not only how to handle it to mitigate any harm and to take action to prevent it from happening again but also to determine whether it is reportable to affected individuals and to DHHS.

 

HIPAA requires a complaint procedure (policy). The webinar will suggest what such a document should contain as it also will for the required report procedure (what is reportable, who reports, to whom, and required/suggested contents of the report) and the required response procedure (what do the responsible officials do after receiving the report or the complaint).

 

Investigating a possible security incident is key. The webinar will cover how to conduct a thorough investigation of HIPAA security incidents, breaches, and patient complaints.

 

Finally, the second largest HIPAA civil money penalty or settlement, $4.2 million, was in large part due to the offender's failure to cooperate with the DHHS investigation. The presenter has successfully defended his clients in seven such investigations and knows how to respond to them to avoid or minimize liability. 

 

Think of a gap analysis as an examination of: What you currently have in place for HIPAA compliance. Is that adequate? Can it be done better? Is it enough? And what am I missing? Asking these questions will help establish the direction and next steps to take. It lays the ground work for a good Risk Analysis and the policies and procedures your organization may be lacking in a cost-effective manner so you are not wasting money and other resources in unnecessary security measures. 

 

Why should you attend: 

 

As of the so-called HITECH Act, covered entities and their business associates must report certain breaches of HIPAA to DHHS which can result in seven-figure fines, lawsuits, bad publicity, and other sanctions. Remediation costs may be immense, such as the $17 million incurred by Blue Cross/Blue Shield of Tennessee on top of the $1.5 million civil money penalty for not having sufficient security to prevent a burglar from stealing all their computer equipment and media with millions of individuals' health insurance data. That is not the only method DHHS may learn of a breach, however. Civil money penalties have resulted from complaints by patients, and one even resulted from a newspaper story. Civil money penalties to date range from $50,000 to two in the $4 million range. And a $50,000 or low six-figure fine may doom a small practice. And these fines cannot be discharged in bankruptcy because they are imposed as a punishment rather than compensating the government for that money it had expended. The largest civil money penalty is reserved for breaches that are not handled properly, capped at $1.5 million for identical such breaches in a calendar year. And DHHS considers that, say, if you lose an unencrypted laptop with no other reasonable and appropriate security in its place, it constitutes a separate violation for each patient's data on the lost laptop. In addition, patients and others who complain to DHHS may receive a portion of any fine, thereby providing an incentive to complain. Also, an audit by DHHS may lead to a civil money penalty.

 

Nor are these penalties reserved for large practices. Fines have been assessed against two-physician practices and a small hospice in North Dakota. Being not-for-profit provides no immunity, nor does being a government entity. Alaska Medicaid was fined $1.5 million; and a county government (Skagit County in Washington State), $215,000.

 

Thus, it is crucial to know how to avoid breaches, how to investigate a security incident, how to determine whether it is a breach, when you have to report a security incident to DHHS (and sometimes to state agencies), and how to mitigate (lessen) the harm of a breach. How a so-called covered entity responds to security incidents and breaches receives great scrutiny in DHHS audits and is a factor in determining whether a sanction is warranted and in lessening the fine from what it otherwise might be. 

 

HIPAA requires covered entities to, in addition to its Privacy Officer, have a complaint procedure and a complaint official (who can be the Privacy Officer) in addition to having a report procedure and a response (how do you handle the report) procedure. Failure to have these elements of HIPAA compliance or having inadequate ones constitutes a breach of the HIPAA requirements. 

 

Areas Covered in the Session:

 

What is a security incident?

What is a breach?

What are the penalties for a breach?

What types of breaches are likely to result in sanctions?

What are the HIPAA requirements for handling breaches?

The Report and Response Procedure

Investigating security incidents and patient complaints

Taking action on the breach-immediate and subsequent-including mitigation

What breaches are reportable to DHHS?

How to respond to an investigation by DHHS

Conclusion and questions and answers<

 

Who Will Benefit:

 

HIPAA Compliance Officers

HIPAA Security Officers

HIPAA Privacy Officers

CFOs

CEOs

COOs

CIOs

Human Resources Directors

Business Office Managers

Administrators

Medical Records Personnel

Audiologists

Group Practices

Nurses

Chiropractors

 

Speaker Profile :

 

Jonathan P. Tomes , J.D., is a health care attorney and partner in the law firm of TOMES & DVORAK, CHARTERED. He has written more than 50 books, including The Compliance Guide to HIPAA and the DHHS Regulations, and dozens of articles in the area of HIPAA compliance. 

 

He has been an expert witness in litigation involving health information compliance issues and is the President of EMR Legal, Inc., a national HIPAA consulting firm. His knowledge of the law and of the practical aspects of setting up a security system provides a rare opportunity for compliance officers and medical records veterans and novices alike. Mr. Tomes has presented seminars nationally for 20 years.

 

Price : $139.00 

 

Contact Info:

 

MentorHealth

Phone No: 1-800-385-1607

FaX: 302-288-6884 

support@mentorhealth.com

Event Link: http://bit.ly/HIPAA-Security-Incidents

http://www.mentorhealth.com/

 

LinkedIn  Follow us – https://www.linkedin.com/company/mentorhealth 

Twitter Follow us – https://twitter.com/MentorHealth1 

Facebook Like us– https://www.facebook.com/MentorHealth1


Ways to HIPAA Security Incidents 2016 se tiendra du 01 septembre 2016 au 01 septembre 2016 en Online Event , États-Unis. Il couvre divers domaines de Santé et Médecine, y compris Healthcare Training courses. Pour plus d'informations, visitez le site web de la conférence ou contactez l'organisateur.
Ajouter au calendrier 2016-09-01 2016-09-01 Europe/London Ways to HIPAA Security Incidents 2016 https://www.sciencedz.net/fr/conference/21464-ways-to-hipaa-security-incidents-2016 Online Event - États-Unis

Trouver d'autres conférences connexes

Vous cherchez d'autres conférences scientifiques auxquelles participer ? Explorez un large éventail d'événements à venir dans divers domaines et lieux. Que vous recherchiez des sujets spécialisés, des lieux spécifiques ou des dates, nous avons un large éventail de conférences à vous proposer.
Conférences en Santé et Médecine en États-Unis 2016 : Découvrez les dernières tendances et recherches en Santé et Médecine en participant à des conférences en États-Unis en 2016. Créez des réseaux avec des professionnels, des chercheurs et des leaders de l'industrie pour rester à la pointe des avancées technologiques.
Conférences et séminaires en États-Unis
Conférences et séminaires en États-Unis en 2016
Conférences et séminaires en Santé et Médecine
Conférences et séminaires en Santé et Médecine en 2016
Conférences et séminaires en Santé et Médecine en États-Unis
Conférences et séminaires en Santé et Médecine en États-Unis en 2016
Tous les événements
Evénements par pays

Avertissement: Nous visons à fournir des informations exactes et fiables sur les événements à venir, mais nous ne pouvons pas accepter la responsabilité pour le texte des annonces ou de la bonne foi des organisateurs de l'événement.S'il vous plaît, n'hésitez pas à nous contacter si vous remarquez des informations incorrectes ou trompeuses et nous tenterons d'y remédier.Nous ne sommes impliqués dans l'organisation d'aucun des événements répertoriés et nous ne gérons pas les paiements d'inscription au nom des organisateurs.