
HIPAA violation fines can reach up to $50,000 per occurrence and a maximum annual penalty of $1.5 million per violation. Medical practices need to ensure they are HIPAA compliant at all times. While all possible HIPAA violations must be considered potential threats, some are more common than others. HIPAA regulations are complex. Also, it’s ever-changing, and it’s hard to stay up-to-date on the latest changes and common violations.
When you ensure that the staff from revenue cycle management companies is well-trained on HIPAA compliance and understand which violations occur, the practice can adequately protect against instances of violations.
Here are the common HIPAA violations your practice may take to prevent. Likewise, here’s what you need to avoid:
Unsecured records
When it comes to employee training, all staff members require documents with PHI in a secure location. Physical files with PHI should be locked in a desk, filing cabinet, or office. Now, digital files require secure passwords to access them with proper encryption.
Unencrypted data
PHI data is vulnerable without proper encryption. Meanwhile, healthcare debt collection agencies focus on adding protection with encryption. There’s an additional layer of security when a password-protected device is somehow accessed, including hacking. While this is not a strict HIPAA requirement, revenue cycle management companies highly recommend it.
You should be familiar with State’s HIPAA regulations, as many states have passed laws requiring ePHI and PII to be encrypted.
Hacking
Hacking is a real threat to medical ePHI. Unfortunately, some people want to use this information for malicious purposes, so medical practices must protect this whenever possible.
With an updated software system active on all devices containing ePHI, it’s a great place to start. Using firewalls adds another layer of protection as well. Finally, creating unique and complex passwords and changing them frequently is another crucial measure to prevent hacking.
Device theft
Devices containing ePHI are not stored in a secure location at all times. Moreover, they’re subject to the possibility of loss or theft. When all the information stored on such devices isn’t encrypted or password-protected, the loss or theft of the device becomes a significant long-term issue.
Employee training
When it’s about training employees on HIPAA regulations and compliance, it’s significant that employees who come in contact with PHI are trained. Training on HIPAA compliance is a recommendation for professional revenue cycle management companies. All staff members must be well trained on the law and the particular policies and procedures set forth by individual practices.
Employee dishonesty
When employees try to access the PHI, they’re not authorized to view it; this is a HIPAA violation. Often it’s merely out of curiosity; however, the punishment is the same regardless of the intent. With specific training and procedures, it outlines who can access what, as well as a clear indication of the consequence that will result, it can help prevent the occurrence of particular HIPAA violations.
Record disposal
When it comes to training staff members, the essential procedure is the proper disposal of PHI records. Staff members must understand that all PHI information, including social security numbers, medical procedures, diagnosis, etc., must be destroyed and wiped from the hard drive.
If any of this information is left in a computer file, it could get into the hands of the wrong person. In these circumstances, this would have a severe HIPAA violation. You can prevent this with proper employee training and enforcement by a compliance officer or other staff.
Unauthorized information release
Violations occur when members of the media release PHI records. This may also occur when medical personnel release PHI to unauthorized family members, as only dependents and those with a power of attorney are allowed access to the PHI of a family member.
Disclosure of PHI
PHI must be discussed with the people who need to know, including the patients, the doctors, and the billing person for the procedure, medication, or other related services. If you have access to PHI and discuss it with those who do not have convenient access to this information, this can be a direct violation of HIPAA.
Educating staff members with access to PHI about HIPAA regulations helps eliminate the majority of data breaches caused due to violations.
Conclusion
The medical staff needs to ensure policies and procedures reflect the most current rules associated with the law. For example, we train them to be careful with PHI records and to share only with those authorized.
