Ways to HIPAA Security Incidents 2016

Expired
Dates : 01 setembro 2016 » 01 setembro 2016

Place : Online Event
Estados Unidos

Book your hotel


Organizer :

Topic : Saúde e Medicina; Healthcare Training courses
Matemática e Estatística; Economia; Saúde e Medicina;
Keywords: Analysis, Business, Human Resources, Health
Description :

Overview: 

 

This webinar will cover everything that you need to know about how to handle HIPAA security incidents, breaches, and complaints and the Department of Health and Human Resources Investigations thereof. Not all security incidents are breaches, but all breaches of confidentiality are within the broad ambit of security incidents. Privacy rule violations, such as failing to give a patient a copy of his or her medical records, may also constitute a breach as the $4.2 million fine assessed against Cignet Healthcare of Prince George's County, Maryland, dramatically proved. Handling an investigation properly is key to determining not only how to handle it to mitigate any harm and to take action to prevent it from happening again but also to determine whether it is reportable to affected individuals and to DHHS.

 

HIPAA requires a complaint procedure (policy). The webinar will suggest what such a document should contain as it also will for the required report procedure (what is reportable, who reports, to whom, and required/suggested contents of the report) and the required response procedure (what do the responsible officials do after receiving the report or the complaint).

 

Investigating a possible security incident is key. The webinar will cover how to conduct a thorough investigation of HIPAA security incidents, breaches, and patient complaints.

 

Finally, the second largest HIPAA civil money penalty or settlement, $4.2 million, was in large part due to the offender's failure to cooperate with the DHHS investigation. The presenter has successfully defended his clients in seven such investigations and knows how to respond to them to avoid or minimize liability. 

 

Think of a gap analysis as an examination of: What you currently have in place for HIPAA compliance. Is that adequate? Can it be done better? Is it enough? And what am I missing? Asking these questions will help establish the direction and next steps to take. It lays the ground work for a good Risk Analysis and the policies and procedures your organization may be lacking in a cost-effective manner so you are not wasting money and other resources in unnecessary security measures. 

 

Why should you attend: 

 

As of the so-called HITECH Act, covered entities and their business associates must report certain breaches of HIPAA to DHHS which can result in seven-figure fines, lawsuits, bad publicity, and other sanctions. Remediation costs may be immense, such as the $17 million incurred by Blue Cross/Blue Shield of Tennessee on top of the $1.5 million civil money penalty for not having sufficient security to prevent a burglar from stealing all their computer equipment and media with millions of individuals' health insurance data. That is not the only method DHHS may learn of a breach, however. Civil money penalties have resulted from complaints by patients, and one even resulted from a newspaper story. Civil money penalties to date range from $50,000 to two in the $4 million range. And a $50,000 or low six-figure fine may doom a small practice. And these fines cannot be discharged in bankruptcy because they are imposed as a punishment rather than compensating the government for that money it had expended. The largest civil money penalty is reserved for breaches that are not handled properly, capped at $1.5 million for identical such breaches in a calendar year. And DHHS considers that, say, if you lose an unencrypted laptop with no other reasonable and appropriate security in its place, it constitutes a separate violation for each patient's data on the lost laptop. In addition, patients and others who complain to DHHS may receive a portion of any fine, thereby providing an incentive to complain. Also, an audit by DHHS may lead to a civil money penalty.

 

Nor are these penalties reserved for large practices. Fines have been assessed against two-physician practices and a small hospice in North Dakota. Being not-for-profit provides no immunity, nor does being a government entity. Alaska Medicaid was fined $1.5 million; and a county government (Skagit County in Washington State), $215,000.

 

Thus, it is crucial to know how to avoid breaches, how to investigate a security incident, how to determine whether it is a breach, when you have to report a security incident to DHHS (and sometimes to state agencies), and how to mitigate (lessen) the harm of a breach. How a so-called covered entity responds to security incidents and breaches receives great scrutiny in DHHS audits and is a factor in determining whether a sanction is warranted and in lessening the fine from what it otherwise might be. 

 

HIPAA requires covered entities to, in addition to its Privacy Officer, have a complaint procedure and a complaint official (who can be the Privacy Officer) in addition to having a report procedure and a response (how do you handle the report) procedure. Failure to have these elements of HIPAA compliance or having inadequate ones constitutes a breach of the HIPAA requirements. 

 

Areas Covered in the Session:

 

What is a security incident?

What is a breach?

What are the penalties for a breach?

What types of breaches are likely to result in sanctions?

What are the HIPAA requirements for handling breaches?

The Report and Response Procedure

Investigating security incidents and patient complaints

Taking action on the breach-immediate and subsequent-including mitigation

What breaches are reportable to DHHS?

How to respond to an investigation by DHHS

Conclusion and questions and answers<

 

Who Will Benefit:

 

HIPAA Compliance Officers

HIPAA Security Officers

HIPAA Privacy Officers

CFOs

CEOs

COOs

CIOs

Human Resources Directors

Business Office Managers

Administrators

Medical Records Personnel

Audiologists

Group Practices

Nurses

Chiropractors

 

Speaker Profile :

 

Jonathan P. Tomes , J.D., is a health care attorney and partner in the law firm of TOMES & DVORAK, CHARTERED. He has written more than 50 books, including The Compliance Guide to HIPAA and the DHHS Regulations, and dozens of articles in the area of HIPAA compliance. 

 

He has been an expert witness in litigation involving health information compliance issues and is the President of EMR Legal, Inc., a national HIPAA consulting firm. His knowledge of the law and of the practical aspects of setting up a security system provides a rare opportunity for compliance officers and medical records veterans and novices alike. Mr. Tomes has presented seminars nationally for 20 years.

 

Price : $139.00 

 

Contact Info:

 

MentorHealth

Phone No: 1-800-385-1607

FaX: 302-288-6884 

support@mentorhealth.com

Event Link: http://bit.ly/HIPAA-Security-Incidents

http://www.mentorhealth.com/

 

LinkedIn  Follow us – https://www.linkedin.com/company/mentorhealth 

Twitter Follow us – https://twitter.com/MentorHealth1 

Facebook Like us– https://www.facebook.com/MentorHealth1


Ways to HIPAA Security Incidents 2016 to be held from 01 setembro 2016 to 01 setembro 2016 in Online Event , Estados Unidos. It covers various areas of Saúde e Medicina including Healthcare Training courses. For more information, visit the website of the conference or contact the organizer.
Add to calendar 2016-09-01 2016-09-01 Europe/London Ways to HIPAA Security Incidents 2016 https://www.sciencedz.net/pt/conference/21464-ways-to-hipaa-security-incidents-2016 Online Event - Estados Unidos

Find More Related Conferences

Looking for more scientific conferences to attend? Explore a wide range of upcoming events in various fields and locations. Whether you're looking for specialized topics, specific locations, or dates, we have a wide range of conferences to choose from.
Saúde e Medicina Conferences in Estados Unidos 2016: Discover the latest trends and research in Saúde e Medicina by attending conferences across Estados Unidos in 2016. Network with professionals, researchers, and industry leaders to stay at the forefront of technological advancements.
Conferences and seminars in Estados Unidos
Conferences and seminars in Estados Unidos in 2016
Conferences and seminars in Saúde e Medicina
Conferences and seminars in Saúde e Medicina in 2016
Conferences and seminars in Saúde e Medicina in Estados Unidos
Conferences and seminars in Saúde e Medicina in Estados Unidos in 2016
Todos os eventos
Events by country

Disclaimer : Temos como objectivo proporcionar informações precisas e confiáveis sobre os próximos eventos, mas não podemos aceitar a responsabilidade para o texto de anúncios ou boa-fé dos organizadores do evento. Por favor, não hesite em contactar-nos se você observar informações incorretas ou enganosas e vamos tentar corrigi-lo.We are not involved in the organization of any of the events listed and we do not handle registration payments on behalf of the organizers.