• Home
  • Practice Focus
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
    • How I Do It
    • TRIO Best Practices
  • Business of Medicine
    • Health Policy
    • Legal Matters
    • Practice Management
    • Tech Talk
    • AI
  • Literature Reviews
    • Facial Plastic/Reconstructive
    • Head and Neck
    • Laryngology
    • Otology/Neurotology
    • Pediatric
    • Rhinology
    • Sleep Medicine
  • Career
    • Medical Education
    • Professional Development
    • Resident Focus
  • ENT Perspectives
    • ENT Expressions
    • Everyday Ethics
    • From TRIO
    • The Great Debate
    • Letter From the Editor
    • Rx: Wellness
    • The Voice
    • Viewpoint
  • TRIO Resources
    • Triological Society
    • The Laryngoscope
    • Laryngoscope Investigative Otolaryngology
    • TRIO Combined Sections Meetings
    • COSM
    • Related Otolaryngology Events
  • Search

Preparing for Increased HIPAA Audits Among Smaller Providers

by Steven M. Harris, Esq. • May 9, 2016

  • Tweet
  • Click to email a link to a friend (Opens in new window) Email
Print-Friendly Version

The unfortunate truth is that a security incident is more likely to happen than not. Therefore, it is critical that you take the following steps now to ensure you are prepared in the event of an audit or breach:

You Might Also Like

  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Healthcare Providers Must Comply with HIPAA Privacy Practices
  • HIPAA Expansion: Ensure your practice meets the law’s new provisions
  • How to Avoid a Healthcare Data Breach
Explore This Issue
May 2016
  • Conduct a thorough review of your HIPAA policies and procedures. Confirm that those policies and procedures have actually been implemented and are effective.
  • Review applicable state law to ensure that your HIPAA compliance program also complies with state health privacy laws. Many states have adopted privacy regulations that specifically address health information, and understanding these laws is a critical component of compliance.
  • Assemble an incident response team (IRT). Involve legal, IT, and human resources representatives, among others.
  • Draft an incident response plan (IRP). This will be your go-to document in the event of a breach and should identify the IRT and clearly describe the decision-making process when handling security incidents.
  • Test your IRT & IRP. This can be done by educating and then testing your IRT on HIPAA compliance requirements. In addition, pose hypothetical security incidents to the IRT and have them follow the IRP. Once completed, revise the IRP to overcome any shortcomings noted during the hypothetical scenario.
  • Perform a risk assessment. Include penetration testing of your computers, devices, and electronic health record software.

Completing these steps will not only benefit your organization by reducing the likelihood of investigations, complaints, security incidents, and significant time and money spent responding to such issues, it will bring you peace of mind in the knowledge that your organization is well prepared.


Steven M. Harris, EsqSteven M. Harris, Esq., is a nationally recognized healthcare attorney and a member of the law firm McDonald Hopkins LLC. Contact him via email.

Pages: 1 2 | Single Page

Filed Under: Departments, Legal Matters Tagged With: audit, HHS, HIPAA complianceIssue: May 2016

You Might Also Like:

  • Department of Health and Human Services’ Final Rule Expands HIPAA Obligations, Violation Penalties
  • Healthcare Providers Must Comply with HIPAA Privacy Practices
  • HIPAA Expansion: Ensure your practice meets the law’s new provisions
  • How to Avoid a Healthcare Data Breach

The Triological SocietyENTtoday is a publication of The Triological Society.

Polls

Would you choose a concierge physician as your PCP?

View Results

Loading ... Loading ...
  • Polls Archive

Top Articles for Residents

  • Applications Open for Resident Members of ENTtoday Edit Board
  • How To Provide Helpful Feedback To Residents
  • Call for Resident Bowl Questions
  • New Standardized Otolaryngology Curriculum Launching July 1 Should Be Valuable Resource For Physicians Around The World
  • Do Training Programs Give Otolaryngology Residents the Necessary Tools to Do Productive Research?
  • Popular this Week
  • Most Popular
  • Most Recent
    • A Journey Through Pay Inequity: A Physician’s Firsthand Account

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • The Dramatic Rise in Tongue Tie and Lip Tie Treatment

    • Rating Laryngopharyngeal Reflux Severity: How Do Two Common Instruments Compare?

    • Is Middle Ear Pressure Affected by Continuous Positive Airway Pressure Use?

    • Otolaryngologists Are Still Debating the Effectiveness of Tongue Tie Treatment

    • Complications for When Physicians Change a Maiden Name

    • Excitement Around Gene Therapy for Hearing Restoration
    • “Small” Acts of Kindness
    • How To: Endoscopic Total Maxillectomy Without Facial Skin Incision
    • Science Communities Must Speak Out When Policies Threaten Health and Safety
    • Observation Most Cost-Effective in Addressing AECRS in Absence of Bacterial Infection

Follow Us

  • Contact Us
  • About Us
  • Advertise
  • The Triological Society
  • The Laryngoscope
  • Laryngoscope Investigative Otolaryngology
  • Privacy Policy
  • Terms of Use
  • Cookies

Wiley

Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1559-4939