Wednesday, June 5, 2013

EVERYDAY TIPS FOR PASSING A RISK ASSESSMENT

  1. For a start follow the guidelines and rules set by HIPAA.

  1. Keep all paper Medical Records under lock and key and make sure non-authorized personnel have no access to it.

  1. Destroy any paper records which are passed their required storage date or digitized and no longer needed.

  1. Install an antivirus and firewall software on all your PCs and Laptops and also on your internal network. If possible keep only limited internet access on your internal network.

  1. Computers should not be facing the waiting room or any direction where non-authorized people can view it, use password locks when away.

  1. Always log out of the EHR system when leaving the computer.

  1. Do not use social security numbers as a unique patient identifier.

  1. Patients have the right to revoke access to any Health Information Network your practice may be part of. Ensure you have proper written consent/consent forms filled when sharing information with anyone.

  1. Change your passwords as mandated by the Guidelines. Ensure that passwords are not exchanged or written/posted in places where other can see. An employee of the practice making such a mistake can have big repercussions for the whole practice.

  1.  Portable hardware containing data should be kept secure and locked away when not in use.

  1. All hardware should be kept in a clean environment and with minimum or no access possible to non-authorized personnel.

  1.  Train all staff members on data security policies and procedures. Make sure everyone in the practice understands and observes the policies and procedures for protecting patient health information.

  1. Make sure your staffing policies and procedures are up to date. If an employee leaves the practice, change the user’s status to inactive.

  1. Review audit trails periodically. Reviewing audit trails can alert practices to potential system abuse or misuse.

  1. Have a disaster recovery procedure. Accidents happen, stuff breaks, the weather isn't always cooperative. You need to be prepared for everything that happens.

  1.  Make sure your data is backed up every day.

  1. The computer that stores the patient data must be encrypted.

  1. The server should be kept in a locked room with limited access.

  1. Keep a list of third party vendors that interact with your practice. Make sure they sign a NDA or some kind of agreement that states the third party vendor won't disclose any information in your practice.

  1. Designate someone as a "security officer" or someone who is in charge of making sure the practice is HIPAA compliant.

  1. All employees should be wearing badges or something that identifies them as someone that works for the practice.

  1. Train the staff on proper internet use. Going to non-work related sites is incredibly risky.

  1. If a patient's name is stored somewhere that is not in an EHR system, there cannot be anything that identifies that person as a patient.

  1. If flash drives or any external data device is used in the practice, make sure that device stays within the practice and only plugs into computers that are owned by the practice.

  1. In the event that your computer shows signs of being infected, stop what you're doing and tell the security officer right away.


  1. Flash drives or external media that was found on the ground should never be put into your computer. Who knows what is on that media.

2 comments:

Ebio Metronics said...

Following Health Insurance Portability and Accountability Act is must that affect every aspect of healthcare services, even including the medical billing services.

Zach Thalman said...

I like that the first tip is to follow the guidelines and rules set up by HIPAA. If you are going to get passed the risk assessment, you are going to through them. I would rather play by their rules than try to cut corners. Cutting corners are when people get in a lot of trouble. http://www.mindsetconsultinggroup.com/what-we-do/scientific-consultation/risk-assessment-expertise

Post a Comment