Release of Information
HIPAA, Release of Information

Right of Access Compliance

A Contemporary Risk Management and Regulatory Imperative 

Written By Dr. Stacey R. Atkins, PhD, MSW, LSW, CPC, CIGE 

The HIPAA Right of Access (ROA) provision continues to stand as a vital patient-rights protection and a persistent enforcement focus for OCR. Since 2022, the OCR has escalated enforcement activity—issuing multiple monetary settlements ranging from small practices to large organizations, including significant penalties such as $200,000 against Oregon Health & Science University (OHSU) in 2025. This article updates the scholarly discussion with recent data, reviews enforcement activity, and underscores strategic imperatives for compliance through inclusive workforce education, robust policy frameworks, centralized oversight, and ongoing auditing.

Introduction

Since its introduction, HIPAA’s Right of Access—which empowers patients to access their protected health information (PHI)—has been elevated by the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) as a leading enforcement priority. OCR’s Right of Access Initiative, instituted in 2019, has remained dynamically active, with continued resolution of complaints and repeated emphasis across enforcement years 2022 through 2025.

Regulatory Framework of the Right of Access

Under HIPAA, individuals are entitled to access their PHI in “designated record sets” (45 C.F.R. § 164.524). Covered entities must provide this access within 30 days of receiving a request, with a single 30-day extension permitted if documented and communicated to the patient.

Key requirements include:

  • Timeliness: Records must be provided within the prescribed timeframes.
  • Reasonable fees: Covered entities may charge only cost-based fees for labor, supplies, and postage.
  • Format: Information must be provided in the form and format requested, if readily producible.
  • Exceptions: Access may be denied under limited circumstances, such as if disclosure is reasonably likely to endanger life or safety.

Failure to meet these requirements can result in HIPAA violations, OCR investigations, and reputational harm.

Recent Enforcement Activity (2022–2025)

OCR’s enforcement record demonstrates an ongoing pattern of provider noncompliance with the Right of Access. Key examples include:

2022:
- Multiple ROA settlements involving dental practices, including one finalized in December 2022.
- Memorial Hermann Health System settled for $240,000 over delayed access requests.

2023:
- OCR resolved 13 enforcement actions totaling $4.18 million, nearly doubling 2022’s penalties.
- Life Hope Labs was fined $16,500 for delayed records release.

2024:
- OCR imposed $170,000 in penalties against a dental practice and a Los Angeles County mental health program.

2025:
- Oregon Health & Science University (OHSU) was fined $200,000 for failing to provide timely access to a patient’s representative.
- OCR also continued settlements tied to ransomware incidents, such as the Comstar breach affecting over 585,000 individuals.

Enforcement Trend Analysis

Recent enforcement illustrates key trends:

  • Widespread focus: ROA cases involve providers of all sizes and types.
  • Significant financial liability: Penalties range from modest fines to $200,000+.
  • Business associate accountability: Covered entities are liable for their partners’ noncompliance.
  • Cybersecurity overlap: Breaches and ransomware are increasingly tied to ROA violations.

Compliance Challenges in Healthcare Organizations

Despite regulatory clarity, many organizations continue to struggle with operationalizing the Right of Access. Common barriers include:

  • Lack of workforce training: Staff may be unaware of timelines, fee structures, or documentation requirements.
  • Decentralized recordkeeping: PHI may be stored across multiple EHR platforms, making access requests cumbersome.
  • Inconsistent policies: Outdated or incomplete policies may lead to variable practices across departments.
  • Cultural barriers: Some providers remain reluctant to share full records, particularly behavioral health information, despite HIPAA requirements.

These challenges highlight the need for strong compliance frameworks that integrate policy, training, and oversight.

Risk Mitigation Through Compliance Programs

Right of Access compliance should be viewed not only as a legal requirement but as a risk management strategy. By embedding compliance into organizational culture, healthcare leaders can reduce the likelihood of OCR investigations and enhance patient satisfaction.

Effective strategies include:

1.  Policy development  

     Create and regularly update written policies aligned with HIPAA and state privacy rules.

2.  Workforce training  

     Ensure all staff—front desk, nursing, HIM, billing, IT—understand their responsibilities.

3.  Monitoring and auditing  

     Conduct regular internal audits of access requests, timeliness, and fees.

4.  Centralized oversight  

     Designate a privacy officer or compliance team to oversee all Right of Access processes.

5.  Patient engagement  

     Communicate clearly with patients regarding their rights, timelines, and any applicable fees.

6.  Cybersecurity integration  

     Align ROA procedures with breach and ransomware response protocols.

Conclusion

The HIPAA Right of Access reflects a core principle of modern healthcare: empowering patients with information to participate in their care. Recent enforcement actions from 2022–2025 highlight the continued priority OCR places on this right, with penalties applied to providers of all sizes.

Healthcare leaders must proactively address this risk by developing robust policies, ensuring comprehensive workforce training, monitoring compliance, and integrating cybersecurity protections. In doing so, organizations protect themselves from regulatory enforcement while upholding the trust and dignity of the patients they serve.

About the Author

Dr. Stacey R. Atkins, PhD, MSW, LMSW, CPC, CIGE

Dr. Atkins is a Compliance Specialist working as a team member in the Education Department of the American Institute of Healthcare Compliance. Her career spans leadership roles with the Office of the State Inspector General, Department of Behavioral Health and Developmental Services, and HRSA, among others.

References:

Copyright © 2025 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

HITECH Compliance

Checklist for Individual & Small Group Practices

Written by: Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO, CORCM  

This article provides an overview of Health Information Technology for Economic and Clinical Health Act (HITECH) and basic checklist of policies and procedures for compliance of smaller health care organizations. This information is not all-inclusive and is not intended as consulting or legal advice.

HITECH is a critical aspect of the Health Insurance Portability & Accountability Act (HIPAA).  Since 2009, HITECH has given “teeth” to HIPAA law.  What’s the difference between HIPAA and HITECH? HIPAA guarantees patients access to their paper medical records. HITECH extended those rights to electronic medical records, extended privacy rights of patients to access their records, increased penalties for HIPAA violations, extended the HIPAA security and breach notification rules and expands the HIPAA encryption compliance requirement.

HIPAA and HITECH is for all health care organizations falling under the definition as a Covered Entity, from solo practices to larger clinics and hospital medical networks to health plans and clearinghouses. 

As a smaller organization your security measures can be in place whether you have an IT person you have access to as a 1099 employee or a person that is on your own payroll.  But, someone must be providing oversight to ensure compliance to both HITECH and HIPAA security rules, both Federal and any applicable State rules.

Let’s start with what HITECH, the acronym for the “Health Information Technology for Economic and Clinical Health Act.”  This act was signed into law by President Obama back in 2009.  For years we lived with HIPAA and understood we needed to protect patient information. HIPAA standards brought us the Administrative Safeguards, Physical Safeguards along with Technical Safeguards.  While we learned to protect information, everything was on paper.  Yes, we faxed and mailed and then the computer age brought us into sending information, claims, through the internet. Our PHI (Protected Healthcare Information) became EPHI (Electronic Protected Healthcare Information).   So here we are, understanding the rules on what we need to do on our own for our practices. But, is that really true?  As you will find out, we do have a lot of information, so much when you are writing your own HITECH plan you don’t know where to start.

Patient information is everywhere.  We can own a Durable Medical Equipment store, see our own doctor, or go and have a test done at a medical facility.  Each of these can cause exposure on behalf of patient information. 

The focus of this article is to be able to launch a list of questions which can be answered to put in place a basic plan in its simplicity of how to protect your own practice.  This can give you a start and with time being aware of “HITECH” you can add to what you have in place. Links have been provided for additional information which is recommended for review as you go through the process.

So, let’s start! Answer the questions and document.  Focus on the easier ones and go back into the others utilizing the links provided.

[Name of Your Practice]

HITECH Policy and Procedures

Electronic Health Records

When changing over from paper records to Electronic Health Records or E.H.R., electronic systems have the potential to actually reduce errors and often have additional security features, such as audit logs to track access to records and security controls assigned per user. 

  • Is your system a user-friendly tailored software for smaller practices? This will minimize challenges EHR has in setting up your software with your patient database. 
  • Does your system offer Artificial Intelligence (AI) options?
  • If so, is it “secure by design”?

Risk Assessment

  • When going through the list identify any vulnerabilities which can cause risks to Protected Health Information (PHI) or Electronic PHI (ePHI). Know your risks, so they can be mitigated accordingly. What are they? 
  • Who is responsible for conducting security risk assessments?
  • How often are these risk assessments performed?
  • What type of vulnerabilities were revealed and how were they address?

Patient privacy, confidentiality and the breach notification rule

  • The importance of maintaining privacy and confidentiality of patient information should be the top priority for your practice. 
  • How does patient information flow through your office?  Are all communications secure and private?  HIPAA requires Covered Entities to protect the privacy of all health information, including who can access it, and gives patients specific rights over it.
  • Is your organization compliant to a patient’s Right of Access?
  • How are security breaches prevented?
  • What is your procedure to notify patients in the event of a data breach?
  • Does your practice have a procedure for notifying the Health & Human Services (HHS) Secretary when there is a breach of 500 or records?

Preventing fraudsters

Having security measures in place safeguards patient data.  However, patients may not realize that someone has stolen their medical identity. 

  • Do your patients understand why they must show proof of identity when they arrive for care?
  • What are your protocols to verify patient identity?  Yes, there are patients that will use someone else’s medical card for services.
  • Does your organization have materials for patient education and risks of identity theft and medical fraud?
  • Do you encourage patients to review their medical statements for charges that are not known to them need to be reviewed?

Administrative safeguards

HIPAA administrative safeguards are actions, policies, and procedures designed to manage the selection, development, implementation, and maintenance of security measures to protect ePHI. These safeguards guide the conduct of a covered entity's staff concerning ePHI.

  • What security checks are employed to ensure that individuals in key employee positions are screened? This includes background checks and taking oaths of confidentiality, where necessary.
  • Administrative safeguards include four implementation specifications.  Is there documentation to support practice compliance to these requirements?
  1. Risk Analysis
  2. Risk Management
  3. Sanction Policy
  4. Information System Activity Review
  • What security measures are already in place to protect EPHI (i.e., safeguards)?
  • Is executive leadership and/or management involved in risk management and mitigation decisions?
  • Are security processes being communicated throughout the organization?
  • Does the covered entity need to engage other resources to assist in risk management?
  • Does your practice apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity?
  • Are employees required to sign a statement of adherence to security policy and procedures (e.g., as part of the employee handbook or confidentiality statement) as a prerequisite to employment?
  • Are there existing procedures for determining that the appropriate workforce members have access to the necessary information?
  • Are the procedures used consistently within the organization when determining access of related workforce job functions?
  • Does the sanction policy provide examples of potential violations of policy and procedures?
  • Does the sanction policy adjust the disciplinary action based on the severity of the violation?
  • Do the termination policies and procedures assign responsibility for removing information system and/or physical access?
  • Do the policies and procedures include timely communication of termination actions to ensure that the termination procedures are appropriately followed?
  • Are the information systems functions adequately used and monitored to promote continual awareness of information system activity?
  • What logs or reports are generated by the information systems?
  • Would it serve the organization’s needs to designate the same individual as both the Privacy and Security Official (for example, in a small provider office)?
  • Has the organization agreed upon, and clearly identified and documented, the responsibilities of the Security Official?
  • How are the roles and responsibilities of the Security Official crafted to reflect the size, complexity and technical capabilities of the organization?

Technical safeguards

Securing your electronic systems protects ePHI.  This is where it is recommended that you have an “IT person” who is a person who works in the field of information technology (IT) and specializes in computer systems and networks. 

  • Has an IT professional installed and set up your infrastructure in your organization can ensure reliability and security?
  • Encryption is not mandatory to be compliant to the security rule.  However, encryption renders data unusable.  In the event of a data breach, when the data was encrypted, the breach is not required to be reported.  The encryption implementation specification is addressable, which means is should be implemented if, after a risk assessment, your Security Officer has determined that the specification is a reasonable and appropriate safeguard in its risk management of the confidentiality, integrity and availability of e-PHI.  How does your organization protect ePHI that is used in emails and/or texts?

Cybersecurity

With all the cyber threats and vulnerabilities, a structured cybersecurity framework needs to be in place. 

  • What do you have in place to prevent malicious software?  What do you have to protect your network from cyber threats?
  • Are your monitoring systems done routinely?
  • How do you respond in the event to mitigate a cybersecurity incident?   
  • Do you have a contingency plan in the event of a cybersecurity incident?
  • How do you evaluate if the cybersecurity incident is a breach (or not)?
  • Ransomware attacks are also referred to as Cy-X or Cyber extortion. Don’t forget the anti-virus software and the educating of employees on signs of unusual activity.  NIST which stands for National Institute of Standards and Technology is part of the U.S. Department of Commerce.

Data backup and recovery

  • Data should be backed up on a regular basis.  Encrypted storage protects the integrity of the software and database in case of a disaster.  Has this been tested?

Audits and assessments

  • Are you conducting internal audits? Security assessments and compliance review should be in place.  Remember these are areas that can validate the protection of PHI and ePHI.

Education and Training

Training for employees on HITECH should include educating staff members about the basics. Their responsibilities include safeguarding protected health information (PHI), and the requirements of compliance regarding electronic health records (EHRs), and health information technology (HIT). Let’s look at what we can include under the training.

  • Include an overview of the HITECH Act, its purpose and objectives.  By providing comprehensive training on HITECH Act and related HIPAA regulations, employees will understand how to participate in safeguarding patient information. They will be able to actively prevent the risks of breaches, and help maintain compliance with regulatory requirements.
  • Understanding HIPAA is crucial.  Come up with a list of what ways you can prevent breaches.  Is it the computer screen in your office that is viewable from the lobby?  Can they hear you discussing with a patient privacy information? Are patient files sitting out?  Come up with your own list and implement training for prevention. Train your staff on HIPAA regulations and how their responsibility is in protecting patients.
  • Training and awareness educating staff members on the importance of protecting PHI and EPHI should be done on a continual basis.  How often are you training?
  • Are you keeping employees up to date on any changes in regulations? 
  • Are they reporting risks to management? 
  • Can your employees recognize a threat through an email such as Phishing?
  • Are there internal office policies regarding no downloading from unknown web pages? 
  • Are they allowed to attach their own devices to their computers which could cause breach of security controls.

Additional Resources

Review the HIPAA provisions and how the HITECH Act strengthens the HIPAA enforcement. You will see added information requiring privacy, security, and breach notifications.

HHS 405(d) Knowledge on Demand

Knowledge on Demand is the 405(d) Program’s free cybersecurity education platform. It includes multiple levels of delivery methodologies designed to reach the varied size health care facilities across the country. Our platform includes cybersecurity awareness trainings that align with the top 5 cybersecurity threats outlined in the landmark 405(d) Health Industry Cybersecurity Practices publication.

HIPAA Security 101 for Covered Entities

Health IT Privacy and Security Resources for Providers

HHS Smaller providers and businesses

NIST Small business for Cybersecurity Corner

Conclusion

This is just a start!  This is Part 1 in a mini-series on HIPAA and HITECH rules for smaller health care organizations. 

Utilize the steps and keep on adding as you gather your information.  There is a lot of information available.  Be sure to use web sites that give you information that is accurate such as Centers for Medicare and Medicaid Services, Health and Human Services, Office of Civil Rights and U S Government Agencies.

If you are a Practice Manager, Administrator or owner of a small medical organization and responsible for overseeing HITECH and HIPAA compliance, consider online training.  Click Here to learn more.

Learn more about HIPAA HITECH

  • For more information on our HIPAA Privacy and Security Course CLICK HERE!
  • For more information on our HIPAA Privacy Officer Course CLICK HERE!


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
HIPAA Compliance
HIPAA

How to Handle Passwords Like a Boss!

Written by: J. David Sims, CHITSP, CHMSP, Managing Partner at Security First IT, LLC; Board Member with the American Institute of Healthcare Compliance; Podcaster, Speaker, & HIPAA Instructor; Help Me with HIPAA Podcast Contributor and Federal HICP 405(d) Task Group & HIC-TCR Task Group



Cybersecurity starts with the basics, such as appropriately managing passwords within your organization. The Health Insurance Portability & Accountability Act (HIPAA) requires access controls and password management, which requires a top-down approach within your organization. Whether you are a Covered Entity or Business Associate, handle it like a boss!

In a recent article by Joanne Byron, she discussed one of the biggest challenges with proper password management… password sharing! In this article, I’m going to introduce you to some ways that you can overcome this challenge in your organization.

First, let’s start by setting three ground rules that I use for cybersecurity:

Rule #1 – Security is not convenient

Rule #2 – Security is not optional

Rule #3 – Security should not unnecessarily hinder the user

Understand that by design, security is there to hinder or stop an action. Think of your house for a minute. I have a sign in my yard advertising that I have monitored security in my home. I also have an alarm system, a deadbolt, a dog, and a shotgun. All these things represent different levels of security and incident response. They all cost me money and they are all inconvenient in some way. To protect my family, my most precious assets, is not optional. However, I can’t make this level of security so inconvenient that it doesn’t work. Therefore, I’ve ensured that these levels of security do not hinder my family’s ability to quickly enter and exit the home.

Security is there to deter the bad guys and to keep out those who should not be in my home (like the in-laws).

Passwords are just one layer of security for your electronic Protected Health Information and other digital assets. It is also a layer of security that is heavily dependent on the user… the human. The human must follow your password policy so that proper passwords are created and used in the correct manner. However, like a flowing river, humans will often find the path of least resistance (or create one) to get their job done.

Therefore, it is so important to train employees on your password policy, why passwords matter, what can happen when passwords are shared, and so on. Equally important is that the organization should take reasonable measures to make using passwords not a huge hinderance. Let’s take a look at some solutions to help your team be password ninjas!

Password Managers

Password managers are a fantastic tool for… you guessed it… managing passwords! I could not do without a password manager. At last check, I had over 1700 unique passwords stored in my password manager.

Password managers offer an array of other benefits and services but at its core, a password manager allows you to store all your passwords in a single, secure place. Instead of having to remember dozens or hundreds of passwords, the user only has to remember the one password that opens their password manager. Think of it as a vault for your passwords.

Another feature of most password managers that I love is the ability for me to share a password with someone without giving them the password. There are a few ways this can be used. I can set up a user account for someone and program their password into the password manager so that they can login to the application using their own credentials, and they never see the password. This ensures that a user can’t use their credentials outside of the office to access anything business related.

This is also very helpful for those websites that do not allow for multiple user accounts, but you still need multiple users to access it and use it. I see this often in practices where a business website only gives the practice a single account to use. The practice uses the same username and password for every employee that needs access to that website. Even worse, when employees leave the practice the credentials are not changed, which allows the separated employee to assess the site from anywhere.

There are several additional benefits of a good password manager application, so investigate one for your organization. They are well worth the small investment.

Creating Passwords

Whether you use a password manager or not, you still must deal with creating secure, unique passwords. Remember, you do not want to have the same password used more than once. Using the same password for everything is like having one key for your house, your car, your office, as well as all your past houses, cars, and offices. Oh, and the key has your name and address on it. Can you see how important it is to use different passwords everywhere?

Before we continue, it is important for you to understand that the bad guys aren’t trying to login to your online accounts typing in one password at a time hoping to get lucky. The bad guys use software automation and databases of passwords to throw at your accounts. This is called a brute force attack.

They know that most people are lazy and use terrible passwords. The most common password is 123456. You may laugh, but this password has been exposed in breaches more than 23 million times. It seems that no matter how terrible of a password it is, people still use it. For these people convenience is a higher priority than security. I wonder if these same people leave their car and homes unlocked… because, yeah… fumbling for a key is not convenient either.

Just a few months ago, the cybersecurity world learned of a leaked list of passwords called RockYou2021. This massive list of breached passwords and passwords from other sources comprises an impressive list of 8.4 billion unique passwords. 8.4 billion!!! Is there a chance that a password you use will show up on a list that size? Yeah, most likely. Unless you are one of the smart ones that use good password creation practices.

Since I’ve already mentioned password managers, it is worth noting that most password managers come with a password generator built-in that allows you to select a few criteria for your password and presto, it creates a password for you to use. Whether you’re using a password manager or not, here are some criteria to consider for your secure password:

Size Matters

Length is more important than complexity. Forever and a day we’ve heard that password complexity is necessary. Well, after years of research, we’re finding that all that complexity lends itself to creating other problems.

Many users fulfill this complexity requirement the same way by simply capitalizing the first letter of the password and adding a 1 or ! to the end. If I just guessed 25% of your password, you should be relegated to using a manual typewriter for the next month. Your password should be at least 8 characters (I prefer 12 to 16) minimum. The longer the password, the harder it is for software to crack it.

Change Is Good, or Is It?

Consider eliminating or reducing periodic password resets. We are also finding out that having people change their passwords too often means that they can’t remember them. I can often tell how many times someone has changed their password by how many exclamations they have at the end. Every time there was a password change, they simply added an exclamation.

If you are using secure passwords, there is no need to change them unless they become compromised in any way. However, knowing if they are compromised becomes super important and your organization should subscribe to services that monitor your accounts for compromised credentials. This brings us to the next point.

You Made the List! That Sucks.

Every password should be checked against known “blacklists” that include dictionary words, repetitive or sequential strings, passwords taken in prior security breaches, variations on the site name, commonly used passphrases, or other words and patterns that cybercriminals are likely to guess. Using a password that is on a Blacklist makes the password almost useless. Imagine if your home had one of those digital keypads for keyless entry. Now, imagine that there was a list floating around your town that had your home’s key code. How would it make you feel that thousands of strangers can easily walk right into your home if they desire? Using a compromised password is much the same.

Lie… Seriously!

You know those password hints you had to create to set up your bank account? Chances are, those answers are fairly easy to get by just paying attention to your social media accounts and what you share online. Heck, the answers may even be able to be socially engineered out of you.

When presented with these password hints and security questions… lie like crazy! What’s my mother’s maiden name? NunYoBitNess!

Get creative and have fun with it but remember you may need to use these answers at some point to recover or reset your real password, so you need to keep this information. I hate to keep coming back to password managers, but most of them also allow you to keep secure notes in your vault (it’s not just for passwords).

What Do You Have? What Do You Know?

Multi-factor (MFA) or Two-factor (2FA) authentication requires users to authenticate themselves using something they know and something they have.

2FA has been around for a very long time. If you’ve ever used an ATM machine to get cash, you’ve used 2FA. You used your card (something you have) and your PIN (something you know).

Using 2FA will likely require that you use an “Authenticator” app. There are many available but stick with the known companies like Google, Microsoft, Authy, etc.

I highly recommend using 2FA everywhere it is available. Even if someone has your username and password, it will be difficult for them to get past your additional authentication methods.

Wrapping It Up

Now that you know how to create secure passwords, how to store them safely, and how to manage them properly, you are ready to go out into the world and show everyone in your organization how they too can handle passwords like a boss!

Want More Information on HIPAA Compliance?

Help Me With HIPAA is the most popular, longest running podcast of its kind. Patient care starts from the moment a person entrusts you with their personal information. Join Donna and David each week as they deliver HIPAA and humor in a way you've never experienced. Who says learning can't be fun? Not us!

Train Online in HIPAA Privacy & Security Compliance – Click Here for more information.

Only need short refresher courses or targeted training? Check out the AIHC HIPAA short courses.

Read More
HIPAA Compliance
HIPAA

Is Sharing EHR Passwords a Problem?

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS

This article addresses the importance of Electronic Health Record (EHR) security to help health care organizations, health plans, clearinghouses (Covered Entities) and their business associates avoid HIPAA violations under the Security Rule Standard § 164.312(a)(1). To obtain more information about mitigating the risk of a HIPAA violation, please consult with legal counsel or a HIPAA Security Consultant. 

 

What If . . .

 

What would happen if you shared your login and password to your online bank account? How about sharing the password to access your credit cards? How would you feel if you knew your doctor shared his/her password to your personal medical records with an unauthorized user? What if someone in medical billing shared his/her password to your account (containing your medical and financial identity) with someone not authorized to access your information?

What If EHR Passwords Are Shared . . .

Electronic health records (EHRs) incorporate a vast amount of patient information and diagnostic data, most of which is considered protected health information. With the advancement of technology, the emergence of advanced cyber threats has escalated, which hinders the privacy and security of health information systems such as EHRs.

As defined by the Center of Medicare and Medicaid Services (CMS), “An electronic health record (EHR) is an electronic version of a patient’s medical history, that is maintained by the provider over time, and may include all of the key administrative clinical data relevant to that person’s care under a particular provider, including demographics, progress notes, problems, medications, vital signs, past medical history, immunizations, laboratory data and radiology reports.”

Because this protected information and data can easily get into the wrong hands, individuals should not share passwords with anyone.  

Is This Really a Problem? Doesn’t Everyone Share Passwords?

Due to the sensitive nature of the information stored within EHRs, several security safeguards have been introduced through the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.

Prevalence of Sharing Access Credentials in Electronic Medical Records

To summarize an abstract published by PMC (Public Med Central) of the U.S. National Institutes of Health’s National Library of Medicine, it was found that to prevent data leakage, many countries have created regulations regarding medical data accessibility. These regulations require a unique user ID for each medical staff member, and this must be protected by a password, which should be kept undisclosed by all means. A survey was conducted with the following results:

  • A total of 299 surveys were gathered.
  • The responses showed that 220 (73.6%) participants reported that they had obtained the password of another medical staff member.
  • Only 171 (57.2%) estimated how many times it happened, with an average estimation of 4.75 episodes. All the residents that took part in the study (45, 15%) had obtained the password of another medical staff member, while 57.5% (38/66) of nurses reported this.

Their conclusion from this study: the use of passwords is doomed because medical staff members share their passwords with one another. Strict regulations requiring each staff member to have a unique user ID might lead to password sharing and to a decrease in data safety. Click Here to access the full study.


Remember to Comply With the 3 Pillars of Securing ePHI

The three pillars to securing protected health information outlined by HIPAA are administrative safeguards, physical safeguards, and technical safeguards. These three pillars are also known as the three security safeguard themes for healthcare. These themes range from techniques regarding the location of computers to the usage of firewall software to protect health information. A brief list of the HIPAA Security Safeguards:

  • Access control (technical safeguard) is a technique that prevents or limits access to an electronic resource. The intent behind access control techniques is to limit access to only authorized parties. The healthcare facility collects, stores, and secures patients’ data, which is very sensitive. This safeguard can take the form of role-based access control, attribute-based access control, and identity-based access control. Role-based refers to a person’s role in the healthcare facility. For instance, when a provider begins working at a healthcare facility, he/she has access to patient data, but only the patient data for his/her patients. If this provider also serves on a certain committee in the hospital, then another set of privileges is created to enable access to committee resources. When other data is accessed, a log is created that is periodically audited. When a front-desk clerk begins working in a facility, he/she has no reason to access clinical data, but may need access to the administrative data such as address and phone number, depending on the role that the person plays in the organization. Other names for this are media controls, entity authentication, encryption, firewall, audit trails, virus checking, and packet filtering.
  • Physical access control (physical safeguard) is a technique that prevents or limits physical access to resources. The intent of this control is similar to the technical safeguard: It limits access to only authorized parties. A patient in a facility will not have access to any clinic or ward except the one he/she is seen in. A front-desk clerk in the optometry clinic will not typically need access to the emergency room, so his/her access card will not open those doors. A provider in a facility will not typically need access to the server room, so his/her access card will not unlock those doors. Other names for this are physical security, (some) workstation security, assigned security responsibility, media controls (access cards), and physical access control.
  • Administrative safeguards are techniques that are not entirely technical or physical, but may contain a piece of each. These safeguards typically take the form of policies, practices, and procedures in the facility to regularly check for vulnerabilities and continually improve the security posture of the organization. Other names for this control are risk analysis and management, system security evaluation, personnel chosen for certain roles, contingency, business continuity, and disaster recovery planning.

When Someone Shares a Password – It Is a HIPAA Violation Under the HIPAA Security Rule – Technical Safeguard Related to Access Controls. 

 

The Security Rule defines access in § 164.304 as “the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource. (This definition applies to “access” as used in this subpart, not as used in subpart E of this part [the HIPAA Privacy Rule]).” Access controls provide users with rights and/or privileges to access and perform functions using information systems, applications, programs, or files. Access controls should enable authorized users to access the minimum necessary information needed to perform job functions. Rights and/or privileges should be granted to authorized users based on a set of access rules that the covered entity is required to implement as part of § 164.308(a)(4), the Information Access Management standard under the Administrative Safeguards section of the Rule.

Unique User Identification Requirement - § 164.312(a)(2)(i)

 

The Unique User Identification implementation specification states that a covered entity must: “Assign a unique name and/or number for identifying and tracking user identity.”

User identification is a way to identify a specific user of an information system, typically by name and/or number. A unique user identifier allows an entity to track specific user activity when that user is logged into an information system. It enables an entity to hold users accountable for functions performed on information systems with ePHI when logged into those systems using audit trails (addressed toward the end of this article).

Regardless of the technology or information system used, access controls should be appropriate for the role and/or function of the workforce member. For example, even workforce members responsible for monitoring and administering information systems with electronic protected health information or ePHI, such as administrators or super users, must only have access to ePHI as appropriate for their role and/or job function.

Sample questions for covered entities to consider:

  • Does each workforce member have a unique user identifier?
  • What is the current format used for unique user identification?
  • Can the unique user identifier be used to track user activity within information systems that contain ePHI?

So, What Can Happen If We Have Insufficient ePHI Access Controls?

Violating HIPAA law 104-191 can be costly. The HIPAA Security Rule requires covered entities and their business associates to limit access to ePHI to authorized individuals. The failure to implement appropriate ePHI access controls is also one of the most common HIPAA violations and one that has caused financial penalties. 

Financial penalties issued to covered entities for ePHI access control failures include:

Anthem Inc. – $16,000,000 penalty for access control failures and other serious HIPAA violations

OCR Imposes a $2.15 Million Civil Money Penalty against Jackson Health System for HIPAA Violations

OCR Imposes a $1.6 Million Civil Money Penalty against Texas Health and Human Services Commission for HIPAA Violations

University of California Los Angeles Health System – $865,500 penalty for the failure to restrict access to medical records

Colorado Medical Center – $111,400 penalty for the failure to terminate access to ePHI after an employee termination and a lack of a business associate agreement

Controlling Access to ePHI: For Whose Eyes Only?

The government HIPAA privacy/security enforcement agency is the Office for Civil Rights (OCR). OCR published the Summer 2021 Cybersecurity Newsletter on July 14, 2021, which states:

The rise in data breaches due to hacking as well as threats to ePHI by malicious insiders highlight the importance of establishing and implementing appropriate policies and procedures regarding these Security Rule requirements. Ensuring that workforce members are only authorized to access the ePHI necessary and that technical controls are in place to restrict access to ePHI can help limit potential unauthorized access to ePHI for both threats.

A recent report of security incidents and data breaches found that 61% of analyzed data breaches in the healthcare sector were perpetrated by external threat actors and 39% by insiders.

Without appropriate authorization policies and procedures and access controls, hackers, workforce members, or anyone with an Internet connection may have impermissible access to the health data, including protected health information (PHI), that HIPAA regulated entities hold. News stories and OCR investigations abound of hackers infiltrating information systems, workforce members impermissibly accessing patients’ health information, and electronic PHI (ePHI) being left on unsecured servers.

Information Access Management and Access Control are two HIPAA Security Rule standards that govern access to ePHI.

Download this newsletter:

Monitor Audit Trails

Audit trails automatically register and record where, when and who accessed the system. They also record what users do when they access the system. This tracks every change in patients’ information and documents it.

Since all the data is logged in the EHR system, it enables users to review the data at regular intervals and flag activities that seem suspicious. Regular reviews can also help correct mistakes caused by human error that could be flagged as a HIPAA violation. An audit trail answers the following:

  • Which patients’ data was accessed?
  • What time was it accessed?
  • Who retrieved the data?
  • Where was the data accessed from?

EHR software can also be set to send notifications to patients when their information is accessed. This way patients can report breaches as soon as they happen.

Conclusion

Create strong policies and procedures, then communicate these rules to your workforce. Enforce compliance through auditing and monitoring. Explain that when an individual allows another to use his/her password to access ePHI, that individual can alter and perform unauthorized functions and not be held accountable. The audit trail points back to the person who is assigned that password. 

Conduct on-going training of your workforce, which needs to include your C-Suite executives (who are not exempt from the rules). To gain the BEST results, conduct additional quarterly training with your front-line managers and supervisors.  Give them tools to incorporate HIPAA training at EVERY department meeting. If you think annual HIPAA training is sufficient, then you simply are not doing enough to protect your patient’s ePHI.

Additional Resources

Weekly HIPAA Podcasts (free) at:

OCR “The Security Rule” on the HHS website:

Train Online in HIPAA Privacy & Security:

Read More
HIPAA Compliance
HIPAA

Scenarios That Can Lead to HIPAA Violations – Are you doing anything to avoid them?

Written by: Salman Rashid

HIPAA, which stands for the Health Insurance Portability and Accountability Act, is a monumental piece of legislation in the U.S. that was enacted in 1996 in order to reduce healthcare fraud and facilitate the transfer of worker’s coverage when they switch or leave jobs.


Decades later, with several new standards introduced within the law, this Act is now best known for protecting the privacy of patients and health plan members’ medical information and, as well as ensures that health information is kept secure and patients are notified whenever there’s a breach of information.


As beneficial as it may sound, HIPAA can be devastating for those who do not follow the rules. There are two types of entities that must abide by the rules and regulations of HIPAA. One is covered entities and the other is their business associates. A single instance of a HIPAA violation can range from thousands to millions of dollars. HIPAA violations are categorized into four tiers, the more severe and neglected the violations are, the higher the tier.


So today, we’ll discuss a few scenarios that can lead to a HIPAA violation so that you can take appropriate actions to comply with the law.


Common types of HIPAA violations

Shortfall in encryption

The risk of leaving Protected Health Information (PHI) unsecured is straightforward. Encryption adds layer of protection, including cybersecurity and all other best practices. Even if someone is somehow able to get their hands on PHI, whether by stealing or cyber hacking, they won’t be able to access the information if there’s an added layer of protection without the passcode. Even though encryption is not a strict HIPAA requirement, it is highly recommended because encryption can better protect PHI from prying eyes. Many progressive healthcare organizations have also implemented biometric patient identification solutions for enhanced protection.

Shortfall in training

individuals who might come into contact with PHI in the course of their work. However, it’s best to provide training for everyone in the organization so they understand the purpose of HIPAA and learn the best practices to better protect themselves from fines and penalties, as well as patients’ healthcare data. Often employees inadvertently access PHI or violate the law because they do now possess enough knowledge. It is recommended to train all the staff members on the law and the particular policies and procedures set forth by the organization.

Sharing or Gossiping PHI

Gossiping is an innate nature of all human beings. Especially healthcare workers may be tempted to discuss a patients’ medical case with their coworkers or in a place where conversations can be overheard. However, PHI should be off-limit unless the other person is involved in the patients’ health care. Healthcare workers with access to PHI should also be very careful about the information they share with others. Information might be shared out of curiosity, but the consequences are the same regardless of the intent. Sharing patients’ information on social media without the patients’ consent is also prohibited.

Disposing of medical records improperly

This is a very common scenario in many healthcare organizations where they dispose of PHI without shredding them first or in a place where it is visible or can easily be stolen. Either way, if PHI falls into the hands of the wrong person, there could be serious HIPAA consequences. Staff members should understand PHI contains valuable and sensitive information like financial numbers, social security numbers, etc., and should be shredded or destroyed before disposal, or wiped from the hard drive.

Avoiding HIPAA violations

There could be several other ways HIPAA can be violated. Staff members must be provided with up-to-date and frequent training so that they understand the purpose of HIPAA and avoid actions that can lead to a HIPAA violation. Healthcare organizations must also understand that HIPAA is not a one-time implementation. It requires continuous development, monitoring, and application. Part of it also includes conducting risk assessments to identify potential vulnerabilities and gaps within the practice to mitigate problems before a violation occurs. Many healthcare organizations also utilize HIPAA compliance software applications to streamline their efforts, some of which are simple, affordable, and very easy to implement and use.

Author Bio

Salman Rashid is an avid reader, loves writing on healthcare issues, and loves all things related to technology, especially PCs and smartphones. He’s also a Digital Marketing Analyst at RightPatient, a platform that helps enhance patient safety across hospitals. He can be contacted at salman@rightpatient.com.

Read More
HIPAA Compliance
HIPAA

Cybersecurity Is Not an IT Issue

Why it takes more than technology to defend your organization

Written by J. David Sims, HHS 405(d) Task Group Member and AIHC Board Member

Introduction

This article is reproduced with permission from the HHS 405(d) Task Group Newsletter.  In 2021, the 405(d) Program has grown its reach and continues to pursue its mission of Aligning Healthcare Industry Security Approaches. The 405(d) Program is now able to assist in many of your cybersecurity needs. Whether it is instituting cybersecurity practices using the Health Industry Cybersecurity Practices, better known as “HICP,” or educating your staff on cybersecurity, we are here for you! AIHC is so excited that our talented Board Member, David Sims, is serving on this important task force.

“Dr. Cooper, the computers aren’t working right. They all have a message on the screen about paying to have our data and systems unlocked!”

This was the welcome that Dr. Cooper received on Monday morning from his panicked practice manager, Sherry, as he walked into his practice. No, this would not be a good morning, not at all.

“Sherry, get IT on the phone!” shouted Dr. Cooper as he made his way to every computer and was met with the same ransomware message on each screen. Dr. Cooper had invested a modest amount of money each month to outsource his IT support and security to a local IT firm.

“The IT guys said they can’t log in remotely, so they’ll have to send someone out. It will be an hour or so before anyone can get here,” Sherry explained. In the meantime, patients were starting to fill the lobby for their morning appointments. With no plan of how to respond to such an incident, Sherry instructed her staff to start rescheduling patients and prepared to close the office for the rest of the day. A little while later, Scott from their IT firm arrived. He instantly realized he was walking into a mess. As he walked through the parking lot, he could hear agitated patients complaining about having to reschedule.

Upon entry he noticed another patient expressing concern about their medical records as the front desk person explained that they are experiencing a ransomware attack. Scott quickly assessed the situation and realized that there was nothing he can do to resolve this. Scott turned to Dr. Cooper with a look of dread and began rapidly firing questions:

“Do you have a ransomware response plan?”  “Do you have cyber insurance?”  “Who is handling public relations?”  “Have you called your attorney?”

Dr. Cooper threw up his hands and said, “Wait. So, you’re telling me that you can’t fix this?”

Scott replied, “You have an active ransomware attack happening. Likely, this is going to be a data breach. If so, you are going to have to notify all your patients that have been affected. You may also have to notify the State and HHS and follow State and Federal breach laws. You’ll also need to determine if the media will need to be notified.”

“How could this happen?! We pay you for security!” exclaimed Dr. Cooper, who was sitting down with his head in his hands as he pondered what this will mean for his practice and his patients.

We will leave this true story now and look closer at the question Dr. Cooper asked, “How could this happen?” Afterall, they are indeed paying for cybersecurity and the IT firm is providing good security. So, how then, can this happen?

Like many businesses, this practice did not understand that cybersecurity is not just a function of IT. In fact, there are three areas that must be present for an effective privacy and security program to work. Let’s take a closer look at these three areas.

People

Social engineering, or hacking humans as it is sometimes called, is today’s most successful way to attack an organization. The attacker can bypass all the security that keeps them out if they are able to have someone on the inside let them in. Technology has no way of keeping out the bad guys if the good guys are letting them in through the “employee entrance.”

Your people will either be a security asset or a security liability.

Mostly, people want to do what is right. They want to protect the patients and their employers, but they are often not given the proper tools or training to make them effective security assets.

Organizations should dedicate time and resources to effectively train and test their employees on proper cyber hygiene, privacy and security topics, and incident response. Remember, it’s the people, people.

Processes

A process is the guide that explains to employees how your business does certain things. All too often, a business will either not have processes in place, or they do have them, but nobody knows what they are because they are not trained on them.

It is a guarantee that if your organization has never practiced an incident response, even a table-top exercise, your team will do nearly everything wrong when an actual incident occurs.

Not having an effective, planned response will cost you much more when (not if) disaster strikes. “Failing to plan is planning to fail,” as Ben Franklin said.

Technology

This is the final piece of the cybersecurity trifecta, and yet most people think it is the only piece. This is also the most confusing piece due to its complexity and many other factors. Following a framework or guide, like HICP (Health Industry Cybersecurity Practices), will help organizations understand where their focus should be to properly address the most common threats. Ensure you are devoting enough resources to this area, but understand that technology alone will not properly protect you.

Conclusion

People, processes, and technology. Those are the three areas that must thrive for any organization to have an effective privacy and security program. A cyber incident can happen at a moment’s notice. How well you can recover from it will depend on how prepared you are in advance. In a crisis, people do not rise to the occasion; they fall to their level of preparation.

A resource that can definitely get you started and begin to protect your patients from cyber threats are publications located on the 405(d) Task Force Website.

This publication lays out the top five threats facing the healthcare industry and provides the top 10 practices needed to mitigate them. If you do not have your IT department in house but use a third party, this is a document you can provide to your IT contractor and ask- “Are you doing these things? And if not, why?”

Protecting patients is our number one priority and we all now have to realize that this includes cyber, and using the most up to date practices is paramount to achieving this goal.

Read More