SlideShare ist ein Scribd-Unternehmen logo
1 von 2
Downloaden Sie, um offline zu lesen
Why Preparing for an OCR HIPAA Audit May
Lead to a False Sense of Security
Many healthcare organizations breathed a collective sigh of relief when the Office of Civil Rights (OCR) under the
Department of Health and Human Services (HHS) finally made their HIPAA audit protocol publicly available this past
June. It can be accessed here. As a refresher, Section 13411 of the 2009 HITECH Act required that HHS “provide for
periodic audits to ensure that covered entities and business associates that are subject to the requirements of (HITECH
and HIPAA), comply with such requirements.” The protocol was developed under OCR collaboration with “Big 4”
consulting firm KPMG.

Uncertainty persisted since late last year when it was announced that OCR/KPMG had completed work on the audit
protocols. Indeed, even the first 20 audits were conducted before the protocol was made public. Not knowing what they
might be audited for had raised anxiety levels among some covered entities. Many of Redspin’s clients and prospective
clients asked us for guidance during the 7 or 8 months prior to the protocol publication. We advised all who asked that if
they wanted an early look at the HIPAA security audit protocol, they need only refer back to the HIPAA Security Rule
itself. We posted that the federal government, even with KPMG’s potential bias (since they are also conducting the first 115
audits), could not stray very far from a law that had been on the books since 2005.

We were right. Each of the 77 audit areas of performance evaluation that relate to IT security cite Security Rule section
numbers and use the exact Security Rule language to describe “Established Performance Criteria.” Years ago, Redspin
mapped our own HIPAA Risk Analysis and Security Assessment to the Security Rule so we had a good idea of what to look
for in the OCR/KPMG document. (A copy of our crosswalk map is freely downloadable click here to download).

However, there is one very important difference between Redspin’s scope of work and any audit protocol. We’ve always
maintained that the HIPAA Security Rule informs our work but we also consider the Rule and any protocols derived
thereunder a subset of the work we do. What the HIPAA Security Rule and the OCR audit protocols fail to dictate is the
comprehensive security testing that is also required to truly be in compliance.

Redspin’s approach has been instrumental in our success in helping nearly 100 hospitals meet their security requirements
under the Stage 1 EHR “Meaningful Use” Incentive Program. Core Measure 14 of Meaningful Use mandates that
hospitals conduct a security Risk Analysis in accordance with the requirements under 45 CFR 164.308(a)(1), implement
security updates as necessary, and correct security deficiencies identified as part of its risk management process.

Thus, while most people generally associate HIPAA with privacy, the migration to electronic health records has placed the
emphasis squarely on security. As Howard Schultz, former White House Cybersecurity Czar has said, “Without security,
there is no privacy.”

This shift is vitally important to understand. Most hospitals’ IT staff members do not have the expertise or tools needed to
accurately perform a Core Measure 14 Risk Analysis. HIPAA consultants, particularly those who have been in the industry
for many years, invariably understand the privacy regulations far better than IT security. Even the auditors empowered by
OCR are likely to emphasize privacy and notification policy and procedures while missing the larger threat to safeguarding
protected health information (PHI) that may manifest as an erroneous firewall configuration, open port, or default
password on a critical system.
Our point is that comprehensive security testing in healthcare organizations is an absolute must. Today’s hospital IT
infrastructures are an order of magnitude more complex than they were just two years ago. Electronic health records have
raised the stakes for data breach; a simple oversight, an insecure password, a theft of a single portable electronic device –
can now impact thousands if not millions of patients and result in a major financial and reputational hit to a healthcare
provider.

The HIPAA Security Rule and the OCR/KPMG HIPAA audit protocol provide compliance guidance but ultimately they are
just words on paper. Truly safeguarding protected health information means digging in technically with security experts
(internally or with outside consultants such as Redspin). IT security itself is a process, not an audit. It involves testing your
infrastructure, your systems, your applications, your employees, and your business associates. It is about finding
vulnerabilities, implementing remediation plans, validating that the appropriate fixes have been made, and building
periodic, repeat IT security testing into your overall risk management program.




                         WEB                                PHONE                             EMAIL

                 WWW.REDSPIN.COM                        800-721-9177                   INFO@REDSPIN.COM

Weitere ähnliche Inhalte

Mehr von Redspin, Inc.

Mehr von Redspin, Inc. (20)

HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?
 
Healthcare IT Security Who's Responsible, Really?
Healthcare IT Security Who's Responsible, Really?Healthcare IT Security Who's Responsible, Really?
Healthcare IT Security Who's Responsible, Really?
 
Healthcare IT Security - Who's responsible, really?
Healthcare IT Security - Who's responsible, really?Healthcare IT Security - Who's responsible, really?
Healthcare IT Security - Who's responsible, really?
 
Redspin Webinar - Prepare for a HIPAA Security Risk Analysis
Redspin Webinar - Prepare for a HIPAA Security Risk AnalysisRedspin Webinar - Prepare for a HIPAA Security Risk Analysis
Redspin Webinar - Prepare for a HIPAA Security Risk Analysis
 
Redspin Webinar Business Associate Risk
Redspin Webinar Business Associate RiskRedspin Webinar Business Associate Risk
Redspin Webinar Business Associate Risk
 
Redspin HIPAA Security Risk Analysis RFP Template
Redspin HIPAA Security Risk Analysis RFP TemplateRedspin HIPAA Security Risk Analysis RFP Template
Redspin HIPAA Security Risk Analysis RFP Template
 
Mobile Device Security Policy
Mobile Device Security PolicyMobile Device Security Policy
Mobile Device Security Policy
 
Financial institution security top it security risk
Financial institution security top it security riskFinancial institution security top it security risk
Financial institution security top it security risk
 
Managing Windows User Accounts via the Commandline
Managing Windows User Accounts via the CommandlineManaging Windows User Accounts via the Commandline
Managing Windows User Accounts via the Commandline
 
Redspin February 17 2011 Webinar - Meaningful Use
Redspin February 17 2011 Webinar - Meaningful UseRedspin February 17 2011 Webinar - Meaningful Use
Redspin February 17 2011 Webinar - Meaningful Use
 
Redspin Report - Protected Health Information 2010 Breach Report
Redspin Report - Protected Health Information 2010 Breach ReportRedspin Report - Protected Health Information 2010 Breach Report
Redspin Report - Protected Health Information 2010 Breach Report
 
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT SecurityRedspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
 
Email hacking husband faces felony
Email hacking husband faces felonyEmail hacking husband faces felony
Email hacking husband faces felony
 
Meaningful use, risk analysis and protecting electronic health information
Meaningful use, risk analysis and protecting electronic health informationMeaningful use, risk analysis and protecting electronic health information
Meaningful use, risk analysis and protecting electronic health information
 
Understanding the Experian independent third party assessment (EI3PA ) requir...
Understanding the Experian independent third party assessment (EI3PA ) requir...Understanding the Experian independent third party assessment (EI3PA ) requir...
Understanding the Experian independent third party assessment (EI3PA ) requir...
 
Top 10 IT Security Issues 2011
Top 10 IT Security Issues 2011Top 10 IT Security Issues 2011
Top 10 IT Security Issues 2011
 
Beginner's Guide to the nmap Scripting Engine - Redspin Engineer, David Shaw
Beginner's Guide to the nmap Scripting Engine - Redspin Engineer, David ShawBeginner's Guide to the nmap Scripting Engine - Redspin Engineer, David Shaw
Beginner's Guide to the nmap Scripting Engine - Redspin Engineer, David Shaw
 
Ensuring Security and Privacy in the HIE Market - Redspin Information Security
Ensuring Security and Privacy in the HIE Market - Redspin Information SecurityEnsuring Security and Privacy in the HIE Market - Redspin Information Security
Ensuring Security and Privacy in the HIE Market - Redspin Information Security
 
Mapping Application Security to Business Value - Redspin Information Security
Mapping Application Security to Business Value - Redspin Information SecurityMapping Application Security to Business Value - Redspin Information Security
Mapping Application Security to Business Value - Redspin Information Security
 
Step by Step Guide to Healthcare IT Security Risk Management - Redspin Infor...
Step by Step Guide to Healthcare IT Security Risk Management  - Redspin Infor...Step by Step Guide to Healthcare IT Security Risk Management  - Redspin Infor...
Step by Step Guide to Healthcare IT Security Risk Management - Redspin Infor...
 

Kürzlich hochgeladen

💚Call Girls In Amritsar 💯Anvi 📲🔝8725944379🔝Amritsar Call Girl No💰Advance Cash...
💚Call Girls In Amritsar 💯Anvi 📲🔝8725944379🔝Amritsar Call Girl No💰Advance Cash...💚Call Girls In Amritsar 💯Anvi 📲🔝8725944379🔝Amritsar Call Girl No💰Advance Cash...
💚Call Girls In Amritsar 💯Anvi 📲🔝8725944379🔝Amritsar Call Girl No💰Advance Cash...
Sheetaleventcompany
 
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
adilkhan87451
 
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
chetankumar9855
 

Kürzlich hochgeladen (20)

Call Girls Service Jaipur {9521753030 } ❤️VVIP BHAWNA Call Girl in Jaipur Raj...
Call Girls Service Jaipur {9521753030 } ❤️VVIP BHAWNA Call Girl in Jaipur Raj...Call Girls Service Jaipur {9521753030 } ❤️VVIP BHAWNA Call Girl in Jaipur Raj...
Call Girls Service Jaipur {9521753030 } ❤️VVIP BHAWNA Call Girl in Jaipur Raj...
 
Kollam call girls Mallu aunty service 7877702510
Kollam call girls Mallu aunty service 7877702510Kollam call girls Mallu aunty service 7877702510
Kollam call girls Mallu aunty service 7877702510
 
Top Rated Hyderabad Call Girls Chintal ⟟ 9332606886 ⟟ Call Me For Genuine Se...
Top Rated  Hyderabad Call Girls Chintal ⟟ 9332606886 ⟟ Call Me For Genuine Se...Top Rated  Hyderabad Call Girls Chintal ⟟ 9332606886 ⟟ Call Me For Genuine Se...
Top Rated Hyderabad Call Girls Chintal ⟟ 9332606886 ⟟ Call Me For Genuine Se...
 
Top Rated Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...
Top Rated  Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...Top Rated  Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...
Top Rated Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...
 
Call Girls Mumbai Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Mumbai Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Mumbai Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Mumbai Just Call 8250077686 Top Class Call Girl Service Available
 
Call Girls Rishikesh Just Call 9667172968 Top Class Call Girl Service Available
Call Girls Rishikesh Just Call 9667172968 Top Class Call Girl Service AvailableCall Girls Rishikesh Just Call 9667172968 Top Class Call Girl Service Available
Call Girls Rishikesh Just Call 9667172968 Top Class Call Girl Service Available
 
💚Call Girls In Amritsar 💯Anvi 📲🔝8725944379🔝Amritsar Call Girl No💰Advance Cash...
💚Call Girls In Amritsar 💯Anvi 📲🔝8725944379🔝Amritsar Call Girl No💰Advance Cash...💚Call Girls In Amritsar 💯Anvi 📲🔝8725944379🔝Amritsar Call Girl No💰Advance Cash...
💚Call Girls In Amritsar 💯Anvi 📲🔝8725944379🔝Amritsar Call Girl No💰Advance Cash...
 
Call Girls Hyderabad Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 8250077686 Top Class Call Girl Service Available
 
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
Russian Call Girls Lucknow Just Call 👉👉7877925207 Top Class Call Girl Service...
 
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
 
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
 
Call Girls Jaipur Just Call 9521753030 Top Class Call Girl Service Available
Call Girls Jaipur Just Call 9521753030 Top Class Call Girl Service AvailableCall Girls Jaipur Just Call 9521753030 Top Class Call Girl Service Available
Call Girls Jaipur Just Call 9521753030 Top Class Call Girl Service Available
 
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
Call Girl In Pune 👉 Just CALL ME: 9352988975 💋 Call Out Call Both With High p...
 
Call Girls Service Jaipur {9521753030} ❤️VVIP RIDDHI Call Girl in Jaipur Raja...
Call Girls Service Jaipur {9521753030} ❤️VVIP RIDDHI Call Girl in Jaipur Raja...Call Girls Service Jaipur {9521753030} ❤️VVIP RIDDHI Call Girl in Jaipur Raja...
Call Girls Service Jaipur {9521753030} ❤️VVIP RIDDHI Call Girl in Jaipur Raja...
 
Call Girls Amritsar Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Amritsar Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Amritsar Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Amritsar Just Call 8250077686 Top Class Call Girl Service Available
 
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
 
Most Beautiful Call Girl in Bangalore Contact on Whatsapp
Most Beautiful Call Girl in Bangalore Contact on WhatsappMost Beautiful Call Girl in Bangalore Contact on Whatsapp
Most Beautiful Call Girl in Bangalore Contact on Whatsapp
 
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any TimeTop Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
 
Andheri East ) Call Girls in Mumbai Phone No 9004268417 Elite Escort Service ...
Andheri East ) Call Girls in Mumbai Phone No 9004268417 Elite Escort Service ...Andheri East ) Call Girls in Mumbai Phone No 9004268417 Elite Escort Service ...
Andheri East ) Call Girls in Mumbai Phone No 9004268417 Elite Escort Service ...
 
Saket * Call Girls in Delhi - Phone 9711199012 Escorts Service at 6k to 50k a...
Saket * Call Girls in Delhi - Phone 9711199012 Escorts Service at 6k to 50k a...Saket * Call Girls in Delhi - Phone 9711199012 Escorts Service at 6k to 50k a...
Saket * Call Girls in Delhi - Phone 9711199012 Escorts Service at 6k to 50k a...
 

Why Preparing for an OCR HIPAA Audit May Lead to a False Sense of Security

  • 1. Why Preparing for an OCR HIPAA Audit May Lead to a False Sense of Security Many healthcare organizations breathed a collective sigh of relief when the Office of Civil Rights (OCR) under the Department of Health and Human Services (HHS) finally made their HIPAA audit protocol publicly available this past June. It can be accessed here. As a refresher, Section 13411 of the 2009 HITECH Act required that HHS “provide for periodic audits to ensure that covered entities and business associates that are subject to the requirements of (HITECH and HIPAA), comply with such requirements.” The protocol was developed under OCR collaboration with “Big 4” consulting firm KPMG. Uncertainty persisted since late last year when it was announced that OCR/KPMG had completed work on the audit protocols. Indeed, even the first 20 audits were conducted before the protocol was made public. Not knowing what they might be audited for had raised anxiety levels among some covered entities. Many of Redspin’s clients and prospective clients asked us for guidance during the 7 or 8 months prior to the protocol publication. We advised all who asked that if they wanted an early look at the HIPAA security audit protocol, they need only refer back to the HIPAA Security Rule itself. We posted that the federal government, even with KPMG’s potential bias (since they are also conducting the first 115 audits), could not stray very far from a law that had been on the books since 2005. We were right. Each of the 77 audit areas of performance evaluation that relate to IT security cite Security Rule section numbers and use the exact Security Rule language to describe “Established Performance Criteria.” Years ago, Redspin mapped our own HIPAA Risk Analysis and Security Assessment to the Security Rule so we had a good idea of what to look for in the OCR/KPMG document. (A copy of our crosswalk map is freely downloadable click here to download). However, there is one very important difference between Redspin’s scope of work and any audit protocol. We’ve always maintained that the HIPAA Security Rule informs our work but we also consider the Rule and any protocols derived thereunder a subset of the work we do. What the HIPAA Security Rule and the OCR audit protocols fail to dictate is the comprehensive security testing that is also required to truly be in compliance. Redspin’s approach has been instrumental in our success in helping nearly 100 hospitals meet their security requirements under the Stage 1 EHR “Meaningful Use” Incentive Program. Core Measure 14 of Meaningful Use mandates that hospitals conduct a security Risk Analysis in accordance with the requirements under 45 CFR 164.308(a)(1), implement security updates as necessary, and correct security deficiencies identified as part of its risk management process. Thus, while most people generally associate HIPAA with privacy, the migration to electronic health records has placed the emphasis squarely on security. As Howard Schultz, former White House Cybersecurity Czar has said, “Without security, there is no privacy.” This shift is vitally important to understand. Most hospitals’ IT staff members do not have the expertise or tools needed to accurately perform a Core Measure 14 Risk Analysis. HIPAA consultants, particularly those who have been in the industry for many years, invariably understand the privacy regulations far better than IT security. Even the auditors empowered by OCR are likely to emphasize privacy and notification policy and procedures while missing the larger threat to safeguarding protected health information (PHI) that may manifest as an erroneous firewall configuration, open port, or default password on a critical system.
  • 2. Our point is that comprehensive security testing in healthcare organizations is an absolute must. Today’s hospital IT infrastructures are an order of magnitude more complex than they were just two years ago. Electronic health records have raised the stakes for data breach; a simple oversight, an insecure password, a theft of a single portable electronic device – can now impact thousands if not millions of patients and result in a major financial and reputational hit to a healthcare provider. The HIPAA Security Rule and the OCR/KPMG HIPAA audit protocol provide compliance guidance but ultimately they are just words on paper. Truly safeguarding protected health information means digging in technically with security experts (internally or with outside consultants such as Redspin). IT security itself is a process, not an audit. It involves testing your infrastructure, your systems, your applications, your employees, and your business associates. It is about finding vulnerabilities, implementing remediation plans, validating that the appropriate fixes have been made, and building periodic, repeat IT security testing into your overall risk management program. WEB PHONE EMAIL WWW.REDSPIN.COM 800-721-9177 INFO@REDSPIN.COM