• Home
  • Practice Focus
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
    • How I Do It
    • TRIO Best Practices
  • Business of Medicine
    • Health Policy
    • Legal Matters
    • Practice Management
    • Technology
    • AI
  • Literature Reviews
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Career
    • Medical Education
    • Professional Development
    • Resident Focus
  • ENT Perspectives
    • ENT Expressions
    • Everyday Ethics
    • From TRIO
    • The Great Debate
    • Letter From the Editor
    • Rx: Wellness
    • The Voice
    • Viewpoint
    • SUO Corner
  • TRIO Resources
    • Triological Society
    • The Laryngoscope
    • Laryngoscope Investigative Otolaryngology
    • TRIO Combined Sections Meetings
    • COSM
    • Related Otolaryngology Events
  • Home
  • Practice Focus
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
    • How I Do It
    • TRIO Best Practices
  • Business of Medicine
    • Health Policy
    • Legal Matters
    • Practice Management
    • Technology
    • AI
  • Literature Reviews
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Career
    • Medical Education
    • Professional Development
    • Resident Focus
  • ENT Perspectives
    • ENT Expressions
    • Everyday Ethics
    • From TRIO
    • The Great Debate
    • Letter From the Editor
    • Rx: Wellness
    • The Voice
    • Viewpoint
    • SUO Corner
  • TRIO Resources
    • Triological Society
    • The Laryngoscope
    • Laryngoscope Investigative Otolaryngology
    • TRIO Combined Sections Meetings
    • COSM
    • Related Otolaryngology Events
  • Search

How to Avoid a Healthcare Data Breach

by Steven M. Harris, Esq. • June 1, 2014

  • Tweet
  • Email a link to a friend (Opens in new window) Email
Print-Friendly Version

Although the Security Rule does not require encryption, if a breach occurs, failure to encrypt is likely to invite scrutiny from OCR, other regulators, and plaintiffs’ attorneys. Moreover, even if ePHI is lost or stolen, breach-reporting obligations may be excused if encryption is in accordance with National Institute of Standards and Technology (NIST) standards.

You Might Also Like

  • Avoid Data Breaches, HIPAA Violations When Posting Patients’ Health Information Online
  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Preparing for Increased HIPAA Audits Among Smaller Providers
  • HIPAA Expansion: Ensure your practice meets the law’s new provisions
Explore This Issue
June 2014

Risk analysis is a recurring theme in OCR’s resolution agreements and Security Rule guidance. In August 2013, OCR expressed a similar focus on risk analysis when settling with Affinity Health Plan Inc. for returning used photocopy machines without erasing PHI from the copier hard drives. In its press release, OCR stated, “covered entities are required to undertake a careful risk analysis to understand the threats and vulnerabilities to individuals’ data, and have appropriate safeguards in place to protect this information.”

This settlement is a reminder of the importance of taking appropriate steps to protect the privacy and security of PHI. Parties will pay a high price for their failure to take appropriate steps to protect the confidentiality and security of PHI. In addition to the monetary fine, addressing the breach and the resulting investigation will result in other heavy costs. For example, legal and consulting costs can be substantial; attention of staff members and leadership is diverted; and a corrective action plan can be significantly more expensive and time consuming to implement than if effective policies and procedures had been employed. Moreover, it is difficult to quantify the adverse impact of a breach on one’s reputation and relationships. Thus, even when covered entities diligently pursue HIPAA compliance, they should still consider cyber insurance or other means to offset the potential for incurring the immense costs of a breach or investigation.

Action Steps

To avoid potentially significant costs and liabilities for HIPAA noncompliance and to minimize the likelihood and consequences of a data breach, proactive steps should be taken to ensure that systems, policies, and procedures comply with the HIPAA Rules and applicable state law. Accordingly, consider:

  • Reviewing written HIPAA privacy, security, and breach notification policies and procedures, and updating them if necessary;
  • Identifying and reviewing all business associate relationships and business associate agreements;
  • Assessing potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI through the performance of risk analysis;
  • Engaging in risk management to identify and take action on security gaps and promptly correcting identified HIPAA violations;
  • Documenting HIPAA-related determinations and actions;
  • Training workforce members to comply with the HIPAA Rules and promptly identifying, investigating, and responding to possible data breaches;
  • Encrypting ePHI to the extent feasible;
  • Avoiding unnecessary disclosures of PHI; and
  • Obtaining cyber insurance.

HIPAA compliance is imperative, and taking proactive measures can help you avoid a bigger issue down the road.

Pages: 1 2 3 | Single Page

Filed Under: Departments, Legal Matters Tagged With: HIPAA, otolaryngology, patient information, policy, practice management, privacyIssue: June 2014

You Might Also Like:

  • Avoid Data Breaches, HIPAA Violations When Posting Patients’ Health Information Online
  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Preparing for Increased HIPAA Audits Among Smaller Providers
  • HIPAA Expansion: Ensure your practice meets the law’s new provisions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

The Triological SocietyENTtoday is a publication of The Triological Society.

Polls

More and more medical trainees are taking dedicated, prolonged gap years. Did you?

View Results

Loading ... Loading ...
  • Polls Archive

Top Articles for Residents

  • Is the SLOR in Otolaryngology Residency Applications Contributing to Rural Disparities?
  • Applications Open for Resident Members of the ENTtoday Editorial Board
  • A Resident’s View of AI in Otolaryngology
  • Call for Resident Bowl Questions
  • Resident Pearls: Pediatric Otolaryngologists Share Tips for Safer, Smarter Tonsillectomies
  • Popular this Week
  • Most Popular
  • Most Recent
    • Gap Year for Research: Is It Worth It?
    • What Otolaryngologists Can Learn from Athletes
    • Office Laryngoscopy Is Not Aerosol Generating When Evaluated by Optical Particle Sizer
    • Some Laryngopharyngeal Reflux Resists PPI Treatment
    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment
    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment
    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?
    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?
    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment
    • Complications for When Physicians Change a Maiden Name
    • Short-Term Efficacy of Biologics in Recalcitrant AFRS: A Systematic Review and Meta-Analysis
    • The Devaluation of Otolaryngology: An Evaluation of CMS’s Involvement in Physician Reimbursement
    • Embolized Middle Meningeal Artery as a Surgical Landmark in Infratemporal Fossa
    • Lord of the (Magnetic) Rings: Rigid Bronchoscopy for Aspirated Magnetic Foreign Bodies in Tertiary Bronchi
    • What Otolaryngologists Can Learn from Athletes

Follow Us

  • Contact Us
  • About Us
  • Advertise
  • The Triological Society
  • The Laryngoscope
  • Laryngoscope Investigative Otolaryngology
  • Privacy Policy
  • Terms of Use
  • Cookies

Wiley

Copyright © 2026 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1559-4939