It’s Your Call – November 2024
HIPAA: How does ransomware spread? Ransomware commonly spreads through phishing emails, malicious attachments, or compromised websites. Once a user clicks on a link or downloads infected content, the ransomware installs itself on the device, often spreading across the network to other systems. OSHA: What should an employer do immediately after an employee reports a needlestick […]
OCR’s Expectations for Preventing Ransomware in Healthcare
Key Lessons from the Cascade Eye and Skin Centers Settlement The recent settlement between the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and Cascade Eye and Skin Centers underscores OCR’s expectations for healthcare providers regarding cybersecurity under the HIPAA Security Rule. Following a ransomware attack that compromised nearly 291,000 […]
Reopening After A Hurricane: Steps for Healthcare Facilities to Ensure Safety and Compliance
Following the aftermath of Hurricane Helene, and any other disaster, one of the many challenges that medical and dental facilities will face is reopening. This article’s purpose is to provide some guidance for all facilities to open safely and to ensure a sanitary environment for both employees and patients. There are several concerns that will […]
What to Look for in a Healthcare IT Company
Selecting the right IT company for a healthcare organization is critical to safeguarding data security, regulatory compliance, and optimal operational performance. Healthcare providers need to find a partner that can meet their specific needs while maintaining high standards of compliance, particularly with regulations like HIPAA. Below is a breakdown of key factors to consider when […]
It’s Your Call – September 2024
OSHA: TRUE or FALSE? Federal law requires employers to notify OSHA of a work-related hospitalization, amputation, or loss of an eye within 24 hours of the incident? TRUE: Standard Number 1904.39(a)(3) states you must report inpatient hospitalization, amputation, or loss of an eye within 24 hours using one of the following methods: By telephone or in-person to the OSHA […]
It’s Your Call – August 2024
HIPAA: Why is regular testing of a Disaster Recovery Plan important? Regular testing ensures the plan’s effectiveness, identifies weaknesses, and trains staff in their roles during a disaster. HIPAA mandates at least annual testing, but more frequent tests are advisable for optimal preparedness. OSHA: Does OSHA enforce ergonomics in the workplace? Under OSHA’s General […]
You Have a Disaster Recovery Plan, Now What?
Creating a Disaster Recovery Plan (DRP) is a significant achievement for any organization, especially for those handling sensitive data such as healthcare providers. However, having a plan is only the beginning. Ensuring the plan’s effectiveness and compliance with HIPAA regulations requires ongoing actions and detailed attention. Regular Testing and Updates Scheduled Testing: A DRP must […]
Information Blocking Rule Final Disincentives for Healthcare Providers Released
Health and Human Services (HHS) has finalized disincentives for Information Blocking and healthcare providers. Here is a summary: The HHS rule impacts the Merit-based Incentive Payment System (MIPS) by penalizing clinicians who engage in information blocking. MIPS eligible clinicians found to be information blockers by the HHS Office of Inspector General will receive a zero […]
It’s Your Call – July 2024
HIPAA: Do surveillance cameras breach HIPAA regulations? Since HIPAA mandates the confidentiality of protected health information (PHI), installing video cameras can result in a violation if they are not placed correctly or used appropriately. Infection Control: What is the difference between universal, standard, and transmission-based precautions in preventing the spread of infection? Universal precautions […]
Ensuring HIPAA Compliance with Video Surveillance in Healthcare Settings
Safeguarding PHI is required under both the HIPAA Privacy Rule and Security Rule. The Security Rule specifically pertains to electronic PHI, which includes video surveillance footage. How to ensure your video surveillance system meets these standards: 1. Administrative Safeguards Administrative safeguards involve creating policies and procedures to protect electronic PHI. For video surveillance this includes: […]