Articles
17 Red Flags of HIPAA Security in ASCs
| 17 Red Flags of HIPAA Security in ASCs |
|
|
| Written by Marion K. Jenkins, PhD | |
| Friday, 18 July 2008 | |
|
Depending on your point of view, HIPAA is either
a boon or a bane: It?s generated a whole new line
of business for many consultants, but has probably
presented a major pain for providers, or ?covered entities.?
What started in the 1990s as a set of guidelines to
allow patients more control over their healthcare destinies
(the ?P? in HIPAA stands for portability, after all) has
generated hundreds of pages of government regulations,
spawned dozens of books and seminars, and resulted in
the deforestation of countless acres to make the paper
required for all medical practices, hospitals and ASCs to
produce and print HIPAA policy manuals.
HIPAA Privacy versus HIPAA Security This combination of factors probably explains why an estimated 80 percent (according to some national estimates) of covered ambulatory healthcare entities are non-compliant with HIPAA Security. That doesn?t mean ASCs aren?t trying; many simply aren?t equipped for HIPAA Security, which deals exclusively with EPHI, or electronic protected health information. Don?t be lulled into a sense of false security because you have HIPAA Privacy compliance manuals and use software labeled HIPAA-compliant. There are 42 specifications in the HIPAA Security Rule, broken down into three categories: administrative safeguards, physical safeguards and technical safeguards. Each of the specifications is categorized as either required or addressable. The term ?addressable? is a bit of a misnomer, because you are still required to deal with each addressable specification, but you may be able to satisfy the compliance requirements of the addressable specifications simply by stating that it does not apply to your situation ? that is, address the requirement one way or the other. Note that the Security Rule is very generic; it doesn?t require or recommend specific technology solutions. Any software or hardware vendor who claims its product is endorsed or recommended by the HIPAA Security Rule lacks integrity. And there is no single hardware, software or security product or service that addresses all specifications. Further, software that is technically HIPAA-compliant can be implemented and used in a manner that makes it completely non-compliant. Also keep in mind that less than one-third of the specifications are even categorized as technical in nature, as there are also administrative and physical safeguard categories, which have nothing to do with software. And just to avoid confusion and point out a common misconception, even though the name administrative safeguards may imply some simple procedures and manuals, they are very critical and should not be overlooked.
Keys to compliance 1. Workstations running anything other than the most current operating systems. That means Windows Vista Business (Service Pack 1) Windows XP (Service Pack 2) or Windows 2000 (Service Pack 4). (Therefore, Windows 98, Windows Me, Windows NT Workstation, XP Home, Vista Home, etc., are all non-compliant.) 2. Lack of a client/server architecture. If you are using a workgroup, where there is no domain controller to centrally control user security and permissions, you are non-compliant. Client/server architecture can be implemented with as few as five users. 3. ?Weak? or shared logons/passwords (such as ?staff ? or ?billing? or ?front desk?). This also includes usernames/passwords posted on sticky notes on the monitor, keyboard or taped to the desk. If you are doing this to save on software-licensing fees, you face a double whammy: The Business Software Alliance (BSA ? not the Boys Scouts) can hit you with a fine of up to $3,000 per instance for this violation, on top of HIPAA sanctions. 4. No formal employee acceptable use policy (AUP) covering IT systems. 5. No written security incident reporting policy. You must have this ? and about 10 other written policies/practices ? in place to be fully compliant. 6. Lack of good data backup/disaster recovery system( s), including RAID data storage systems and rotation procedures. Taking the backup tapes home isn?t a good idea. The news media is full of stories of loss/theft in this scenario, and we once worked on a medical practice where the practice manager was going through a messy divorce and the soon-to-beex- spouse stole the practice?s backup tapes. 7. EPHI stored on local workstations and/or laptops, or on portable media like floppies, thumb drives or CDs. In fact, you should strongly consider disabling the ability to use those devices on workstations, as it makes it theoretically possible for someone to download all your data to portable media. 8. Any user account that has system administrator rights. We frequently see this situation because of some issue where the IT company is unable to make something work on the network without giving users admin rights. 9. Use of any ?public? email address or domain name (such as AOL, MSN, Comcast). If you are using an email address with Gmail, MSN, Hotmail, Yahoo, etc., then you are non-compliant. This also governs any outside partner entities as well; we have seen practices and surgery centers e-mail dictation files to an outsider who was using an AOL e-mail address. 10. Not having a hardware firewall. Your Internet provider probably put a firewall when they installed your Internet circuit, but that?s to protect them from you, not to protect you from the outside. 11. Lack of updated, business-class anti-virus, AND anti-spyware, AND anti-adware software. It?s worth the cost, and it should be installed on the server and ?pushed? out to all the workstations on the network. 12. Peer-to-peer/file-sharing applications. Allowing use of applications such as Kazaa, Morpheus, Limewire, Bit-Torrent and chat apps is like sharing a soda straw with others at the local bus station. 13. Most ?free-ware.? Do no allow staff to downloaded screensavers, weather apps, horoscopes, Internet search bars, etc., and even some anti-virus and anti-malware software. Only approved software should be used, and installed only by your IT professional. 14. Internet games such as partypoker.com, wildtangent. com, empirepoker.com, etc. Don?t allow your facility?s computers to be used for this purpose, no exceptions. 15. Unsecured WiFi (wireless), or WiFi with WEP security. This isn?t a coffee shop; you need to ensure information is locked down, virtually speaking. 16. Laptops that move in and out of the facility (especially physicians? personal machines). These can too easily compromised by other users, loss or theft. 17. Using ?remote control? software to access your desktop remotely instead of using a hardware/software VPN (virtual private network) solution. We aren?t going to name names here, but there are several commonly used commercial software products in the marketplace that could easily allow your systems to be compromised.
Further resources Dr. Jenkins ( This e-mail address is being protected from spam bots, you need JavaScript enabled to view it ) is the CEO and founder of Englewood, Colo.-based QSE Technologies, a provider of IT consulting and implementation services to ASCs, physician clinics and medical office buildings nationwide. |
- Will the Federal Government Shut Down Surgery Centers and Physician-Owned Hospitals?
- 17 Orthopedic Coding Questions Answered By Stephanie Ellis
- Coder's Guide to ASC and Physician Practice Modifiers
- More Charges, Indictments in $154 Million, Largest-Ever Insurance Fraud Scheme Involving ASC
- 10 Benchmarks for Billing and Collections
- 11 Leaks to Plug in Your Billing Department to Ensure Total Reimbursement
- Preparing for Quality Reporting in 2009
- Senate Supplemental Appropriations Bill Would Ban New Physician-Owned Hospitals
- Non-Compete Agreement Imposed by Doctor Group on Physician's Practice Upheld by Court
- Fee Splitting Arrangement Between Physicians and Medical Biller Invalidated by Court
- 6 Trends in Minimally Invasive Spine Surgery
- 41 Things You Should Know About ASCs
- General Surgery Coding Guidance for 2009 Additions and Revisions
- From the VMG Health Intellimarker: Revenue Per Case by Specialty in ASCs
- What is a good benchmark for total hours worked per case?
Ambulatory Surgery Center
| Surgery Center Education |
| Selling a Surgery Center |
| Business Issues |
| Planning |
| Safe Harbor Surgery Center |
| Legal Issues |
| ASC Review |
Outpatient Surgery
| Business Issues |
| Outpatient Surgery |
Healthcare Business
| Legislation |
| Legal Issues |
| Business Issues |
| Clinical Issues |
| General News |
About Becker's ASC Review
| About Us |
| About Scott Becker |
| Exhibiting |
| Advertising |
| eNewsletter |
| Subscribe |
| Contact Us |
| Previous Issues |










