SlideShare ist ein Scribd-Unternehmen logo
1 von 2
6 things to know about an OCR/HIPAA audit



It's one thing to know which hot buttons can trigger a visit from OCR. But according to Mahmood Sher-
Jan, vice president of product management at ID Experts, and Chris Apgar, president and CEO at Apgar &
Associates, organizations should also know what to expect if they're chosen to undergo an audit -- and
know how to prepare for one.

Apgar and Sher-Jan outline six things to know about an OCR/HIPAA audit.

1. If everything is in order, look at an audit or investigation as an opportunity. Apgar, who's recently
been conducting training sessions, said an investigation could be looked upon as an opportunity to gain
feedback on your privacy and security efforts – presuming you have everything in place. "If you're
selected and you've completed your risk analysis, you have policies and procedures implemented, and
you can show you're making a good-faith effort, look at it as an opportunity for someone to come in,
externally, and help your compliance efforts." He said OCR still intends to "live up to the sport of the
enforcement rule," which is informal enforcement, and unless you cross the line into willful neglect,
OCR "still wants to work with organizations," said Apgar.

2. Understand the culture of compliance. "There are some specific areas [where] OCR has been
wandering around the country and preaching the culture of compliance," said Apgar. This has been
happening for the past year and a half and includes policy awareness, training programs, and discussions
around incident response and risk analysis. "Those are the areas they're preaching, and the new head of
the Office of Civil Rights even highlighted risk analysis in his testimony before Congress," he added.

[See also: HIPAA – An opportunity for continuum of care.]

3. Ignorance isn't bliss – it's willful neglect. In training sessions, Apgar said he highlights what exactly
willful neglect entails. It's "knowing you're in violation," or that "you should have known," he said.
"Ignorance is not bliss. I asked the question [in a training session], how many people in the room
conducted a risk analysis in the last year, and less than a third of their hands went up." That number,
Apgar said, was actually more than he's seen in the past, but, essentially, if you haven't conducted a risk
analysis by now, you're in trouble. "[It's] been required since April 2005 and is the first requirement in
the Administrative Safeguard section of the Rule," said Apgar. "You can't beg ignorance because you
should have known, and therefore, you're guilty of willful neglect." Not to mention, he added, if you
haven't conducted a risk analysis, there is a higher likelihood of finding yourself in trouble with OCR and
not getting meaningful use dollars. "It's a two-edge sword type of problem," he said.

4. There's overlap between undergoing an investigation and undergoing an audit. Sher-Jan referenced
an incident at the UCLA Health System and a recent incident at Phoenix Cardiac Surgery to help prove
his point. "One of the big things that got UCLA in trouble is they couldn't provide proof of training
around privacy and security," he said. "Just to point out, there is a lot of overlap whether you're audited
or investigated." Looking at the PCS resolution agreement, he said, the organization was called out on a
number of different things and were "in complete ignorance of the privacy and compliance rules," he
said. "And that's something to point out [about] UCLA as well," he said. "They didn't have a security
official identified, they didn't have a risk analysis, so I'd imagine there were a number of these
safeguards that weren't in place." Whether you're being investigated or audited, he continued, there's
significant overlap in terms of where OCR looks, "and the more they see you're not in compliance, the
more they will dig and the more they will find," he said.

[See also: HIPAA 5010 deadline stays with bit of leniency.]

5. It's all about clean, clear documentation. "One of the things about auditors that makes them happy is
good, complete documentation upfront," said Apgar. Having good documentation, he said, will also
make them less likely to want to "look under the rug … If you don't have that, they'll get suspicious and
turn a little nastier." From a bottom line perspective, said Apgar, organizations should expect a letter
from OCR, requesting information within 10 business days. "And that's 10 days since the letter was sent,
not 10 days since you receive it," he said. "If you're the CEO, it takes a while for the letter to percolate
down, so now you're way behind the 8 ball." Therefore, it's key to have documentation prepared ahead
of time, paying attention to programs, policies, procedures, incident response plans and risk analysis.
"That all needs to be centralized, so you can quickly grab it and make it available to the auditors," said
Apgar.

6. Know auditors can look at anything and everything. The last thing that's important to know, said
Apgar, is whether the auditor can look or review patient information. "And the answer is yes, they can
because they're working on behalf of the OCR and are in contract with them," he said. "Under the HIPAA
regulation, if the secretary, meaning OCR, is investigating or auditing, then they have the right to see
anything and everything." In the end, said Apgar, if you're information is up-to-date and in-line with
HIPAA rules, you're good to go. "It needs to be current, accurate, complete and not only implemented,
but enforceable," he said.




--------
Source: http://www.healthcareitnews.com/news/6-things-know-about-ocrhipaa-audit



This is what we feel:

“More than compliance, look at ‘Audit’ as a self-checking mechanism”, remarks Dr. Charu Chitalia –
Director Operations, Acroseas Global Solutions. One needs to be compliant at all times, due to which
one needs to install an internal control system that institutes efficient check points at different levels
that corrects the inefficiencies from time to time.

Weitere ähnliche Inhalte

Andere mochten auch (12)

武山さんコメント
武山さんコメント武山さんコメント
武山さんコメント
 
Alsace C[1].Bi Bi Diapo..
Alsace C[1].Bi Bi Diapo..Alsace C[1].Bi Bi Diapo..
Alsace C[1].Bi Bi Diapo..
 
Lavradores maus
Lavradores mausLavradores maus
Lavradores maus
 
PHP: Rechnen mit PHP
PHP: Rechnen mit PHPPHP: Rechnen mit PHP
PHP: Rechnen mit PHP
 
Carta de Laura
Carta de LauraCarta de Laura
Carta de Laura
 
Learning style
Learning styleLearning style
Learning style
 
Industrial Hemp for Clean Sustainable Fuel
Industrial Hemp for Clean Sustainable Fuel  Industrial Hemp for Clean Sustainable Fuel
Industrial Hemp for Clean Sustainable Fuel
 
Promociones 2012
Promociones 2012Promociones 2012
Promociones 2012
 
Pollo relleno
Pollo relleno Pollo relleno
Pollo relleno
 
Evaluación parcial
Evaluación parcialEvaluación parcial
Evaluación parcial
 
Limericks
LimericksLimericks
Limericks
 
Relato parte 2
Relato parte 2Relato parte 2
Relato parte 2
 

Mehr von ACROSEAS Global Solutions

Health Information Technology: Paving the Way to Improved Patient Care
Health Information Technology: Paving the Way to Improved Patient CareHealth Information Technology: Paving the Way to Improved Patient Care
Health Information Technology: Paving the Way to Improved Patient Care
ACROSEAS Global Solutions
 
EHR Quality Measurement In Its Infancy, Study Says
EHR Quality Measurement In Its Infancy, Study SaysEHR Quality Measurement In Its Infancy, Study Says
EHR Quality Measurement In Its Infancy, Study Says
ACROSEAS Global Solutions
 
Tips for transitioning to electronic health records
Tips for transitioning to electronic health recordsTips for transitioning to electronic health records
Tips for transitioning to electronic health records
ACROSEAS Global Solutions
 

Mehr von ACROSEAS Global Solutions (8)

4 keys to the cost of Health IT
4 keys to the cost of Health IT4 keys to the cost of Health IT
4 keys to the cost of Health IT
 
Towards a learning health system
Towards a learning health systemTowards a learning health system
Towards a learning health system
 
Govt to 'innovate, leverage technology' to improve healthcare
Govt to 'innovate, leverage technology' to improve healthcareGovt to 'innovate, leverage technology' to improve healthcare
Govt to 'innovate, leverage technology' to improve healthcare
 
Health Information Technology: Paving the Way to Improved Patient Care
Health Information Technology: Paving the Way to Improved Patient CareHealth Information Technology: Paving the Way to Improved Patient Care
Health Information Technology: Paving the Way to Improved Patient Care
 
4 ways social media can improve your medical practice
4 ways social media can improve your medical practice4 ways social media can improve your medical practice
4 ways social media can improve your medical practice
 
EHR Quality Measurement In Its Infancy, Study Says
EHR Quality Measurement In Its Infancy, Study SaysEHR Quality Measurement In Its Infancy, Study Says
EHR Quality Measurement In Its Infancy, Study Says
 
Tips for transitioning to electronic health records
Tips for transitioning to electronic health recordsTips for transitioning to electronic health records
Tips for transitioning to electronic health records
 
HIMSS CPHIMS Certification - What It Can Do For You
HIMSS CPHIMS Certification - What It Can Do For YouHIMSS CPHIMS Certification - What It Can Do For You
HIMSS CPHIMS Certification - What It Can Do For You
 

Kürzlich hochgeladen

Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
mahaiklolahd
 
🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
adilkhan87451
 

Kürzlich hochgeladen (20)

Call Girls Kolkata Kalikapur 💯Call Us 🔝 8005736733 🔝 💃 Top Class Call Girl Se...
Call Girls Kolkata Kalikapur 💯Call Us 🔝 8005736733 🔝 💃 Top Class Call Girl Se...Call Girls Kolkata Kalikapur 💯Call Us 🔝 8005736733 🔝 💃 Top Class Call Girl Se...
Call Girls Kolkata Kalikapur 💯Call Us 🔝 8005736733 🔝 💃 Top Class Call Girl Se...
 
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
 
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
 
9630942363 Genuine Call Girls In Ahmedabad Gujarat Call Girls Service
9630942363 Genuine Call Girls In Ahmedabad Gujarat Call Girls Service9630942363 Genuine Call Girls In Ahmedabad Gujarat Call Girls Service
9630942363 Genuine Call Girls In Ahmedabad Gujarat Call Girls Service
 
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
 
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
 
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
 
Independent Call Girls In Jaipur { 8445551418 } ✔ ANIKA MEHTA ✔ Get High Prof...
Independent Call Girls In Jaipur { 8445551418 } ✔ ANIKA MEHTA ✔ Get High Prof...Independent Call Girls In Jaipur { 8445551418 } ✔ ANIKA MEHTA ✔ Get High Prof...
Independent Call Girls In Jaipur { 8445551418 } ✔ ANIKA MEHTA ✔ Get High Prof...
 
Best Rate (Guwahati ) Call Girls Guwahati ⟟ 8617370543 ⟟ High Class Call Girl...
Best Rate (Guwahati ) Call Girls Guwahati ⟟ 8617370543 ⟟ High Class Call Girl...Best Rate (Guwahati ) Call Girls Guwahati ⟟ 8617370543 ⟟ High Class Call Girl...
Best Rate (Guwahati ) Call Girls Guwahati ⟟ 8617370543 ⟟ High Class Call Girl...
 
Trichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service Available
Trichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service AvailableTrichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service Available
Trichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service Available
 
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
 
Low Rate Call Girls Bangalore {7304373326} ❤️VVIP NISHA Call Girls in Bangalo...
Low Rate Call Girls Bangalore {7304373326} ❤️VVIP NISHA Call Girls in Bangalo...Low Rate Call Girls Bangalore {7304373326} ❤️VVIP NISHA Call Girls in Bangalo...
Low Rate Call Girls Bangalore {7304373326} ❤️VVIP NISHA Call Girls in Bangalo...
 
🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
🌹Attapur⬅️ Vip Call Girls Hyderabad 📱9352852248 Book Well Trand Call Girls In...
 
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
 
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
 
Coimbatore Call Girls in Coimbatore 7427069034 genuine Escort Service Girl 10...
Coimbatore Call Girls in Coimbatore 7427069034 genuine Escort Service Girl 10...Coimbatore Call Girls in Coimbatore 7427069034 genuine Escort Service Girl 10...
Coimbatore Call Girls in Coimbatore 7427069034 genuine Escort Service Girl 10...
 
Coimbatore Call Girls in Thudiyalur : 7427069034 High Profile Model Escorts |...
Coimbatore Call Girls in Thudiyalur : 7427069034 High Profile Model Escorts |...Coimbatore Call Girls in Thudiyalur : 7427069034 High Profile Model Escorts |...
Coimbatore Call Girls in Thudiyalur : 7427069034 High Profile Model Escorts |...
 
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any TimeTop Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
 
Call Girls Madurai Just Call 9630942363 Top Class Call Girl Service Available
Call Girls Madurai Just Call 9630942363 Top Class Call Girl Service AvailableCall Girls Madurai Just Call 9630942363 Top Class Call Girl Service Available
Call Girls Madurai Just Call 9630942363 Top Class Call Girl Service Available
 
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
 

6 things to know about an OCR/HIPAA audit

  • 1. 6 things to know about an OCR/HIPAA audit It's one thing to know which hot buttons can trigger a visit from OCR. But according to Mahmood Sher- Jan, vice president of product management at ID Experts, and Chris Apgar, president and CEO at Apgar & Associates, organizations should also know what to expect if they're chosen to undergo an audit -- and know how to prepare for one. Apgar and Sher-Jan outline six things to know about an OCR/HIPAA audit. 1. If everything is in order, look at an audit or investigation as an opportunity. Apgar, who's recently been conducting training sessions, said an investigation could be looked upon as an opportunity to gain feedback on your privacy and security efforts – presuming you have everything in place. "If you're selected and you've completed your risk analysis, you have policies and procedures implemented, and you can show you're making a good-faith effort, look at it as an opportunity for someone to come in, externally, and help your compliance efforts." He said OCR still intends to "live up to the sport of the enforcement rule," which is informal enforcement, and unless you cross the line into willful neglect, OCR "still wants to work with organizations," said Apgar. 2. Understand the culture of compliance. "There are some specific areas [where] OCR has been wandering around the country and preaching the culture of compliance," said Apgar. This has been happening for the past year and a half and includes policy awareness, training programs, and discussions around incident response and risk analysis. "Those are the areas they're preaching, and the new head of the Office of Civil Rights even highlighted risk analysis in his testimony before Congress," he added. [See also: HIPAA – An opportunity for continuum of care.] 3. Ignorance isn't bliss – it's willful neglect. In training sessions, Apgar said he highlights what exactly willful neglect entails. It's "knowing you're in violation," or that "you should have known," he said. "Ignorance is not bliss. I asked the question [in a training session], how many people in the room conducted a risk analysis in the last year, and less than a third of their hands went up." That number, Apgar said, was actually more than he's seen in the past, but, essentially, if you haven't conducted a risk analysis by now, you're in trouble. "[It's] been required since April 2005 and is the first requirement in the Administrative Safeguard section of the Rule," said Apgar. "You can't beg ignorance because you should have known, and therefore, you're guilty of willful neglect." Not to mention, he added, if you haven't conducted a risk analysis, there is a higher likelihood of finding yourself in trouble with OCR and not getting meaningful use dollars. "It's a two-edge sword type of problem," he said. 4. There's overlap between undergoing an investigation and undergoing an audit. Sher-Jan referenced an incident at the UCLA Health System and a recent incident at Phoenix Cardiac Surgery to help prove his point. "One of the big things that got UCLA in trouble is they couldn't provide proof of training around privacy and security," he said. "Just to point out, there is a lot of overlap whether you're audited or investigated." Looking at the PCS resolution agreement, he said, the organization was called out on a number of different things and were "in complete ignorance of the privacy and compliance rules," he said. "And that's something to point out [about] UCLA as well," he said. "They didn't have a security official identified, they didn't have a risk analysis, so I'd imagine there were a number of these
  • 2. safeguards that weren't in place." Whether you're being investigated or audited, he continued, there's significant overlap in terms of where OCR looks, "and the more they see you're not in compliance, the more they will dig and the more they will find," he said. [See also: HIPAA 5010 deadline stays with bit of leniency.] 5. It's all about clean, clear documentation. "One of the things about auditors that makes them happy is good, complete documentation upfront," said Apgar. Having good documentation, he said, will also make them less likely to want to "look under the rug … If you don't have that, they'll get suspicious and turn a little nastier." From a bottom line perspective, said Apgar, organizations should expect a letter from OCR, requesting information within 10 business days. "And that's 10 days since the letter was sent, not 10 days since you receive it," he said. "If you're the CEO, it takes a while for the letter to percolate down, so now you're way behind the 8 ball." Therefore, it's key to have documentation prepared ahead of time, paying attention to programs, policies, procedures, incident response plans and risk analysis. "That all needs to be centralized, so you can quickly grab it and make it available to the auditors," said Apgar. 6. Know auditors can look at anything and everything. The last thing that's important to know, said Apgar, is whether the auditor can look or review patient information. "And the answer is yes, they can because they're working on behalf of the OCR and are in contract with them," he said. "Under the HIPAA regulation, if the secretary, meaning OCR, is investigating or auditing, then they have the right to see anything and everything." In the end, said Apgar, if you're information is up-to-date and in-line with HIPAA rules, you're good to go. "It needs to be current, accurate, complete and not only implemented, but enforceable," he said. -------- Source: http://www.healthcareitnews.com/news/6-things-know-about-ocrhipaa-audit This is what we feel: “More than compliance, look at ‘Audit’ as a self-checking mechanism”, remarks Dr. Charu Chitalia – Director Operations, Acroseas Global Solutions. One needs to be compliant at all times, due to which one needs to install an internal control system that institutes efficient check points at different levels that corrects the inefficiencies from time to time.