Is it time review your Policies and Procedures?


By Aris Medical Solutions


As you know you HIPAA Compliance is not a once and done process. It continually changes and evolves as your organization grows and your technology changes. This is a reminder to review what you have in place to ensure it still adequately safeguards your data.

Here are some quick helpful tips:

  1. Review your Notice of Privacy Practices. Have you implemented any new technology or added any new services that needs to posted? If you have a website make sure you update your NPP there as well.
  2. If you have a “Contact us” or an “Appointment Scheduler” form on your website and your website is not HTTPS, we recommend placing a disclaimer advising patients not to send personal information via the form. If you do have an HTTPS site, make sure your hosting vendor understands HIPAA and review where the data is sent and stored.
  3. Review your Technology Equipment. Have you added any new software or hardware? Do you regularly check your firewall settings? Are you reviewing your website security to ensure it is up to date? Are you documenting your IT efforts or reviewing your monthly IT vendor reports?
  4. Have you reviewed your list of Business Associates to ensure you have BA agreement in place with ALL of your Associates?
  5. Review your Inventory list. Have you added any new equipment or have you disposed of any?
  6. Have you conducted your annual HIPAA training for everyone? Is it documented?
  7. Have you tested your Contingency Plan?

Of course we could go on and on, but hopefully this will jumpstart your thinking process! Remember, your Risk Management Plan is a living document that needs to be updated on a continual basis. As you review your compliance efforts be sure to document this in your Plan.

For more information on how Aris Medical Solutions can help your organization with HIPAA Compliance and Protecting your Data call 877.659.2467 or click here to contact us.

“Protecting Organizations through Partnership, Education, and Support”

About Suze Shaffer

Suze Shaffer is the owner and president of Aris Medical Solutions. She specializes in HIPAA compliance, risk management, and cyber security. She believes that by educating her clients in understanding why and what needs to be done to protect their practice they have a better outcome.

Suze has been instrumental in helping clients nationwide with risk management, implementing privacy and security rule policies and procedures, and ultimately protecting patient data. She includes state and federal regulatory requirements to ensure clients are protected in all areas.

She has spoken at numerous conferences and functions. She continues to educate organizations how to minimize the risks of data breaches. HIPAA compliance is not an option, it is mandatory for every organization that comes in contact with protected health information to have reasonable and appropriate security measures in place. Unfortunately, most organizations don’t realize they are not compliant until they suffer a data breach or they are faced with an audit or investigation.

Did you know that the Office for Civil Rights (OCR) is the agency that investigates data breaches? Have you seen the heavy fines that have been imposed for non-compliance?

All 50 states now have their own set of privacy laws and the State's Attorney General may also investigate privacy violations!

Share This HIPAA Blog

Patient Data is a Hot Commodity

May 1, 2017

Phishing Scams are hitting everyone!

June 1, 2017
©2022 Aris Medical Solutions – HIPAA Risk Management | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC