23
The Cost for Non-Compliance © 2015 eFolder, Inc. All Rights Reserved. 1 Massachusetts provider settles HIPAA case - lost laptop $1.5M Alaska DHSS settles HIPAA security case - lost hard drive $1.7M $150K Resolution Agreement with Adult & Pediatric Dermatology, P.C. of Massachusetts - lost flash drive HHS.gov/ocr/privacy/hipaa/enforcement/ examples/index.html

eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

  • Upload
    efolder

  • View
    228

  • Download
    0

Embed Size (px)

Citation preview

Page 1: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.1

The Cost for Non-Compliance

Massachusetts provider settles HIPAA case - lost laptop$1.5M

Alaska DHSS settles HIPAA security case - lost hard drive $1.7M

$150KResolution Agreement with Adult & Pediatric Dermatology, P.C. of Massachusetts - lost flash drive

HHS.gov/ocr/privacy/hipaa/enforcement/examples/index.html

Page 2: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

HIPAA Policies and Best Practicesfrom a Partner

Carmen YuMarketing Coordinator, [email protected]

Page 3: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.3

Agenda

• Partner Introduction• What is HIPAA?• Why Must MSPs Comply?• Administrative, Physical, and Technical

Safeguards• Business Associates Agreement (BAA)• How to Work Towards Compliance• Questions and Discussion

Page 4: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.4

Partner Introduction

Page 5: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

dmi Networking

© 2015 eFolder, Inc. All Rights Reserved.5

Clients in San Francisco Bay Area and Southern California

Founded in 2010

120 dental managed service clients that must comply with HIPAA

8 employees

Provides risk assessment and HIPAA consultation services

Page 6: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.6

What is HIPAA?

• Health Insurance Portability and Accountability Act (1996)

• Reduces health care fraud and abuse

• Mandates industry-wide standards for health care, especially patient information

• Requires the protection and confidential handling of protected health information

COMPLY & SURVIVE

Page 7: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.7

What is HIPAA?

• Privacy Rule: – Mandates in which situations and with whom

protected health information (PHI) can be shared.

• Security Rule:– Defines standards for protecting the

confidentiality, integrity, and availability of electronic PHI (ePHI)

Page 8: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

8 © 2015 eFolder, Inc. All Rights Reserved.

The Cost for Non-Compliance

$50K

$1.5mMaximum penalty per

violationMaximum penalty per

year

Page 9: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.9

The Cost for Non-Compliance

Massachusetts provider settles HIPAA case - lost laptop$1.5M

Alaska DHSS settles HIPAA security case - lost hard drive $1.7M

$150KResolution Agreement with Adult & Pediatric Dermatology, P.C. of Massachusetts - lost flash drive

HHS.gov/ocr/privacy/hipaa/enforcement/examples/index.html

Page 10: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.10

Why Must MSPs Comply?

• September 2013: HIPAA Omnibus Rule– Expanded HIPAA so that business associates

(BA) of covered entities are required to comply

• Business Associate:– Business associates are entities who support

covered entities by performing duties that involve the usage, storage, or transmission of protected health information (PHI)

Page 11: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.11

Questions for Dan

• When did you decide to become HIPAA compliant?

• How far do you go to help your clients become HIPAA compliant?

• Have you ever sought outside help to become HIPAA compliant?

Page 12: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

Partner Chat: How to Comply with HIPAA

Page 13: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.13

Administrative Safeguards

• Policies and procedures created in the business of an MSP that define how the business will comply with the act

Partner Discussion:What administrative safeguards has dmi Networking implemented?

Page 14: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.14

Physical Safeguards

• Standards to control physical access to protected health information (PHI)

Partner Discussion:What physical safeguards has dmi Networking implemented?

Page 15: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.15

Technical Safeguards

• Standards to control access to computer systems in order to maintain the security of ePHI

• Documented risk analysis

Partner Discussion:What technical safeguards has dmi Networking implemented?

Page 16: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.16

Business Associates Agreement (BAA)

• A contract stating that a business associate will appropriately safeguard PHI

Page 17: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.17

BAA – Partner Discussion

• Do you sign BAAs with all your clients?

• Who originates the contract?

• Do you have a general template?

• What terms are addressed in the BAA?

Page 18: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.18

More Questions for Dan

• How do you make sure that employees are trained on HIPAA?

• How do you detect non-compliance in your business?

• Are there any compliance best practices that you didn’t previously consider but learned over time?

Page 19: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.19

Your Clients’ Compliance

MSPs can still do business with a client even if they are non-compliant

Partner Discussion:• What are common non-compliant solutions that

you see clients using?

• How do you deal with client resistance when trying to move them to a HIPAA-compliant solution?

Page 20: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

© 2015 eFolder, Inc. All Rights Reserved.20

Working Towards Compliance

1. Get a consultation from an expert

2. Identify risks

3. Come up with a roadmap for adjustments

4.Perform a yearly risk assessment!

Page 21: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

21 © 2015 eFolder, Inc. All Rights Reserved.

• eFolder will sign Business Associate Agreements

• eFolder has completed a proper HIPAA Risk Analysis conducted by experienced professionals

• eFolder has written HIPAA-specific policies and procedures

• eFolder has trained its workforce to comply with HIPAA

• eFolder has retained HIPAA professionals to maintain compliance over time

• eFolder will provide you with a letter attesting to our HIPAA compliance to take to your clients

eFolder and HIPAA

Page 22: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

Questions and Discussion

Page 23: eFolder Partner Chat Webinar — HIPAA Policies and Best Practices from a Partner

Thank you!

Carmen YuMarketing Coordinator, [email protected]