HIPAA Compliance
HIPAA

HITECH Compliance

Checklist for Individual & Small Group Practices

Written by: Nancie Lee Cummins, CFE, CHA, CIFHA, OHCC, CHCM, CHCO, CORCM  

This article provides an overview of Health Information Technology for Economic and Clinical Health Act (HITECH) and basic checklist of policies and procedures for compliance of smaller health care organizations. This information is not all-inclusive and is not intended as consulting or legal advice.

HITECH is a critical aspect of the Health Insurance Portability & Accountability Act (HIPAA).  Since 2009, HITECH has given “teeth” to HIPAA law.  What’s the difference between HIPAA and HITECH? HIPAA guarantees patients access to their paper medical records. HITECH extended those rights to electronic medical records, extended privacy rights of patients to access their records, increased penalties for HIPAA violations, extended the HIPAA security and breach notification rules and expands the HIPAA encryption compliance requirement.

HIPAA and HITECH is for all health care organizations falling under the definition as a Covered Entity, from solo practices to larger clinics and hospital medical networks to health plans and clearinghouses. 

As a smaller organization your security measures can be in place whether you have an IT person you have access to as a 1099 employee or a person that is on your own payroll.  But, someone must be providing oversight to ensure compliance to both HITECH and HIPAA security rules, both Federal and any applicable State rules.

Let’s start with what HITECH, the acronym for the “Health Information Technology for Economic and Clinical Health Act.”  This act was signed into law by President Obama back in 2009.  For years we lived with HIPAA and understood we needed to protect patient information. HIPAA standards brought us the Administrative Safeguards, Physical Safeguards along with Technical Safeguards.  While we learned to protect information, everything was on paper.  Yes, we faxed and mailed and then the computer age brought us into sending information, claims, through the internet. Our PHI (Protected Healthcare Information) became EPHI (Electronic Protected Healthcare Information).   So here we are, understanding the rules on what we need to do on our own for our practices. But, is that really true?  As you will find out, we do have a lot of information, so much when you are writing your own HITECH plan you don’t know where to start.

Patient information is everywhere.  We can own a Durable Medical Equipment store, see our own doctor, or go and have a test done at a medical facility.  Each of these can cause exposure on behalf of patient information. 

The focus of this article is to be able to launch a list of questions which can be answered to put in place a basic plan in its simplicity of how to protect your own practice.  This can give you a start and with time being aware of “HITECH” you can add to what you have in place. Links have been provided for additional information which is recommended for review as you go through the process.

So, let’s start! Answer the questions and document.  Focus on the easier ones and go back into the others utilizing the links provided.

[Name of Your Practice]

HITECH Policy and Procedures

Electronic Health Records

When changing over from paper records to Electronic Health Records or E.H.R., electronic systems have the potential to actually reduce errors and often have additional security features, such as audit logs to track access to records and security controls assigned per user. 

  • Is your system a user-friendly tailored software for smaller practices? This will minimize challenges EHR has in setting up your software with your patient database. 
  • Does your system offer Artificial Intelligence (AI) options?
  • If so, is it “secure by design”?

Risk Assessment

  • When going through the list identify any vulnerabilities which can cause risks to Protected Health Information (PHI) or Electronic PHI (ePHI). Know your risks, so they can be mitigated accordingly. What are they? 
  • Who is responsible for conducting security risk assessments?
  • How often are these risk assessments performed?
  • What type of vulnerabilities were revealed and how were they address?

Patient privacy, confidentiality and the breach notification rule

  • The importance of maintaining privacy and confidentiality of patient information should be the top priority for your practice. 
  • How does patient information flow through your office?  Are all communications secure and private?  HIPAA requires Covered Entities to protect the privacy of all health information, including who can access it, and gives patients specific rights over it.
  • Is your organization compliant to a patient’s Right of Access?
  • How are security breaches prevented?
  • What is your procedure to notify patients in the event of a data breach?
  • Does your practice have a procedure for notifying the Health & Human Services (HHS) Secretary when there is a breach of 500 or records?

Preventing fraudsters

Having security measures in place safeguards patient data.  However, patients may not realize that someone has stolen their medical identity. 

  • Do your patients understand why they must show proof of identity when they arrive for care?
  • What are your protocols to verify patient identity?  Yes, there are patients that will use someone else’s medical card for services.
  • Does your organization have materials for patient education and risks of identity theft and medical fraud?
  • Do you encourage patients to review their medical statements for charges that are not known to them need to be reviewed?

Administrative safeguards

HIPAA administrative safeguards are actions, policies, and procedures designed to manage the selection, development, implementation, and maintenance of security measures to protect ePHI. These safeguards guide the conduct of a covered entity's staff concerning ePHI.

  • What security checks are employed to ensure that individuals in key employee positions are screened? This includes background checks and taking oaths of confidentiality, where necessary.
  • Administrative safeguards include four implementation specifications.  Is there documentation to support practice compliance to these requirements?
  1. Risk Analysis
  2. Risk Management
  3. Sanction Policy
  4. Information System Activity Review
  • What security measures are already in place to protect EPHI (i.e., safeguards)?
  • Is executive leadership and/or management involved in risk management and mitigation decisions?
  • Are security processes being communicated throughout the organization?
  • Does the covered entity need to engage other resources to assist in risk management?
  • Does your practice apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity?
  • Are employees required to sign a statement of adherence to security policy and procedures (e.g., as part of the employee handbook or confidentiality statement) as a prerequisite to employment?
  • Are there existing procedures for determining that the appropriate workforce members have access to the necessary information?
  • Are the procedures used consistently within the organization when determining access of related workforce job functions?
  • Does the sanction policy provide examples of potential violations of policy and procedures?
  • Does the sanction policy adjust the disciplinary action based on the severity of the violation?
  • Do the termination policies and procedures assign responsibility for removing information system and/or physical access?
  • Do the policies and procedures include timely communication of termination actions to ensure that the termination procedures are appropriately followed?
  • Are the information systems functions adequately used and monitored to promote continual awareness of information system activity?
  • What logs or reports are generated by the information systems?
  • Would it serve the organization’s needs to designate the same individual as both the Privacy and Security Official (for example, in a small provider office)?
  • Has the organization agreed upon, and clearly identified and documented, the responsibilities of the Security Official?
  • How are the roles and responsibilities of the Security Official crafted to reflect the size, complexity and technical capabilities of the organization?

Technical safeguards

Securing your electronic systems protects ePHI.  This is where it is recommended that you have an “IT person” who is a person who works in the field of information technology (IT) and specializes in computer systems and networks. 

  • Has an IT professional installed and set up your infrastructure in your organization can ensure reliability and security?
  • Encryption is not mandatory to be compliant to the security rule.  However, encryption renders data unusable.  In the event of a data breach, when the data was encrypted, the breach is not required to be reported.  The encryption implementation specification is addressable, which means is should be implemented if, after a risk assessment, your Security Officer has determined that the specification is a reasonable and appropriate safeguard in its risk management of the confidentiality, integrity and availability of e-PHI.  How does your organization protect ePHI that is used in emails and/or texts?

Cybersecurity

With all the cyber threats and vulnerabilities, a structured cybersecurity framework needs to be in place. 

  • What do you have in place to prevent malicious software?  What do you have to protect your network from cyber threats?
  • Are your monitoring systems done routinely?
  • How do you respond in the event to mitigate a cybersecurity incident?   
  • Do you have a contingency plan in the event of a cybersecurity incident?
  • How do you evaluate if the cybersecurity incident is a breach (or not)?
  • Ransomware attacks are also referred to as Cy-X or Cyber extortion. Don’t forget the anti-virus software and the educating of employees on signs of unusual activity.  NIST which stands for National Institute of Standards and Technology is part of the U.S. Department of Commerce.

Data backup and recovery

  • Data should be backed up on a regular basis.  Encrypted storage protects the integrity of the software and database in case of a disaster.  Has this been tested?

Audits and assessments

  • Are you conducting internal audits? Security assessments and compliance review should be in place.  Remember these are areas that can validate the protection of PHI and ePHI.

Education and Training

Training for employees on HITECH should include educating staff members about the basics. Their responsibilities include safeguarding protected health information (PHI), and the requirements of compliance regarding electronic health records (EHRs), and health information technology (HIT). Let’s look at what we can include under the training.

  • Include an overview of the HITECH Act, its purpose and objectives.  By providing comprehensive training on HITECH Act and related HIPAA regulations, employees will understand how to participate in safeguarding patient information. They will be able to actively prevent the risks of breaches, and help maintain compliance with regulatory requirements.
  • Understanding HIPAA is crucial.  Come up with a list of what ways you can prevent breaches.  Is it the computer screen in your office that is viewable from the lobby?  Can they hear you discussing with a patient privacy information? Are patient files sitting out?  Come up with your own list and implement training for prevention. Train your staff on HIPAA regulations and how their responsibility is in protecting patients.
  • Training and awareness educating staff members on the importance of protecting PHI and EPHI should be done on a continual basis.  How often are you training?
  • Are you keeping employees up to date on any changes in regulations? 
  • Are they reporting risks to management? 
  • Can your employees recognize a threat through an email such as Phishing?
  • Are there internal office policies regarding no downloading from unknown web pages? 
  • Are they allowed to attach their own devices to their computers which could cause breach of security controls.

Additional Resources

Review the HIPAA provisions and how the HITECH Act strengthens the HIPAA enforcement. You will see added information requiring privacy, security, and breach notifications.

HHS 405(d) Knowledge on Demand

Knowledge on Demand is the 405(d) Program’s free cybersecurity education platform. It includes multiple levels of delivery methodologies designed to reach the varied size health care facilities across the country. Our platform includes cybersecurity awareness trainings that align with the top 5 cybersecurity threats outlined in the landmark 405(d) Health Industry Cybersecurity Practices publication.

HIPAA Security 101 for Covered Entities

Health IT Privacy and Security Resources for Providers

HHS Smaller providers and businesses

NIST Small business for Cybersecurity Corner

Conclusion

This is just a start!  This is Part 1 in a mini-series on HIPAA and HITECH rules for smaller health care organizations. 

Utilize the steps and keep on adding as you gather your information.  There is a lot of information available.  Be sure to use web sites that give you information that is accurate such as Centers for Medicare and Medicaid Services, Health and Human Services, Office of Civil Rights and U S Government Agencies.

If you are a Practice Manager, Administrator or owner of a small medical organization and responsible for overseeing HITECH and HIPAA compliance, consider online training.  Click Here to learn more.

Learn more about HIPAA HITECH

  • For more information on our HIPAA Privacy and Security Course CLICK HERE!
  • For more information on our HIPAA Privacy Officer Course CLICK HERE!


Copyright © 2024 American Institute of Healthcare Compliance All Rights Reserved

Read More
Release of Information
HIPAA, Release of Information

OCR Enforcement of HIPAA Right of Access and Release of Information (ROI)

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The article addresses the HIPAA Privacy Rule for Covered Entities regarding time limitations to respond to an individual’s request for access of protected health information or “PHI.” This article is not all inclusive and should not be used as legal or consulting advice. Scroll down for hyperlinks to free and low-cost training related to Right of Access & ROI.

What Is HIPAA Right of Access?

The HIPAA Privacy Rule generally provides individuals with a legal, enforceable right to see and receive copies, upon request, of the information in their medical and other health records maintained by their health care providers and health plans. This right is known as the HIPAA Right of Access.

HIPAA Right of Access policies have evolved over the years to ensure that patients have equitable access to their medical records. HIPAA requires covered entities to provide patients with access to their medical records. The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted in 2009, helped right of access policies evolve to reflect the growing use of EHR systems.

HIPAA Enforcement

HIPAA compliance it monitored by the Health & Human Services (HHS) enforcement agency, the Office for Civil Rights (OCR). The Office for Civil Rights is responsible for enforcing the Privacy and Security Rules. Enforcement of the Privacy Rule began April 14, 2003, for most HIPAA covered entities. Since 2003, OCR's enforcement activities have obtained significant results that have improved the privacy practices of covered entities. OCR also works in conjunction with the Department of Justice (DOJ) to refer possible criminal violations of HIPAA.

In 2019, the OCR launched the HIPAA Right of Access Initiative to advocate for individuals trying to obtain their health records in a timely manner at a reasonable cost as required by covered entities in the HIPAA Privacy Rule.

Complying With the HIPAA Privacy Right of Access Rule

If your organization is not responding timely to requests for medical records, a complaint to the Office for Civil Rights can trigger an investigation resulting in fines and other consequences, such as being posted on the OCR HIPAA website and a forced Corrective Action Plan.

A dedicated government webpage lists HIPAA News Releases & Bulletins listing OCR cases after investigating organizations which includes Right of Access settlements. Click Here to access this page. https://www.hhs.gov/hipaa/newsroom/index.html

The July 15, 2022, Health & Human Services (HHS) Press Release announces the resolution of eleven investigations and the enforcement actions taken with these eleven organizations related to violations of patient’s rights under HIPAA. In this press release the OCR Director Lisa J. Pino states:

“It should not take a federal investigation before a HIPAA covered entity provides patients, or their personal representatives, with access to their medical records. Health care organizations should take note that there are now 38 enforcement actions in our Right of Access Initiative and understand that OCR is serious about upholding the law and peoples’ fundamental right to timely access to their medical records.”

 

So, how timely must a covered entity be in responding to individuals’ requests for access to their PHI?

This is addressed under 45 CFR 164.524(b)(2) of the HIPAA Privacy Rule regarding access of individuals to protected health information (PHI). Under the HIPAA Privacy Rule, a covered entity must act on an individual’s request for access no later than 30 calendar days after receipt of the request.

If the covered entity is not able to act within this timeframe, the entity may have up to an additional 30 calendar days as long as it provides the individual, within that initial 30-day period, a written statement of the reasons for the delay and date when the entity will complete its action on the request. The 30-day timeline applies regardless of the following circumstances:

  • The PHI that is the subject of the request is maintained by the covered entity or by a business associate on behalf of the covered entity, or the covered entity uses a business associate to fulfill individual requests for access.

o The 30-day clock starts on the date that the covered entity receives a request for access, so any delay in obtaining the necessary information from a business associate or forwarding the request to the business associate for action “uses up” part of the allotted time.

o Alternatively, the 30-day clock starts when, instead of the covered entity, a business associate receives a request directly from an individual because the covered entity instructed the individual through its notice of privacy practices (or otherwise) to submit the access request directly to its business associate for processing. 

  • The covered entity negotiates with the individual on the format of the response. Covered entities that spend significant time before reaching agreement with individuals on format are depleting the 30 days allotted for the response by that amount of time.
  • The PHI that is the subject of the request is old, archived, and/or not otherwise readily accessible.

As noted by OCR, these timelines are outer limits. The government expects that covered entities should be able to respond to requests for access well before these outer limits are reached. However, in cases where a covered entity is aware that an access request may take close to these outer time limits to fulfill, the entity is encouraged to provide the requested information in pieces as it becomes available, if the individual indicates a desire to receive the information in this manner.

Resources to Comply With ROI and Right of Access

Learn more about 45 CFR § 164.524 - Access of individuals to protected health information. Free and reasonably priced training for you and your workforce is listed below:

Right of Access Specialist - Online Course

AIHC HIPAA Compliance Training Videos Free

Legal Information Institute (Cornell Law School) Free

HIPAA Online Privacy Course (Earn 12 AIHC and AHIMA CEUs)

Read More
HIPAA Compliance
HIPAA

Is Sharing EHR Passwords a Problem?

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS

This article addresses the importance of Electronic Health Record (EHR) security to help health care organizations, health plans, clearinghouses (Covered Entities) and their business associates avoid HIPAA violations under the Security Rule Standard § 164.312(a)(1). To obtain more information about mitigating the risk of a HIPAA violation, please consult with legal counsel or a HIPAA Security Consultant. 

 

What If . . .

 

What would happen if you shared your login and password to your online bank account? How about sharing the password to access your credit cards? How would you feel if you knew your doctor shared his/her password to your personal medical records with an unauthorized user? What if someone in medical billing shared his/her password to your account (containing your medical and financial identity) with someone not authorized to access your information?

What If EHR Passwords Are Shared . . .

Electronic health records (EHRs) incorporate a vast amount of patient information and diagnostic data, most of which is considered protected health information. With the advancement of technology, the emergence of advanced cyber threats has escalated, which hinders the privacy and security of health information systems such as EHRs.

As defined by the Center of Medicare and Medicaid Services (CMS), “An electronic health record (EHR) is an electronic version of a patient’s medical history, that is maintained by the provider over time, and may include all of the key administrative clinical data relevant to that person’s care under a particular provider, including demographics, progress notes, problems, medications, vital signs, past medical history, immunizations, laboratory data and radiology reports.”

Because this protected information and data can easily get into the wrong hands, individuals should not share passwords with anyone.  

Is This Really a Problem? Doesn’t Everyone Share Passwords?

Due to the sensitive nature of the information stored within EHRs, several security safeguards have been introduced through the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.

Prevalence of Sharing Access Credentials in Electronic Medical Records

To summarize an abstract published by PMC (Public Med Central) of the U.S. National Institutes of Health’s National Library of Medicine, it was found that to prevent data leakage, many countries have created regulations regarding medical data accessibility. These regulations require a unique user ID for each medical staff member, and this must be protected by a password, which should be kept undisclosed by all means. A survey was conducted with the following results:

  • A total of 299 surveys were gathered.
  • The responses showed that 220 (73.6%) participants reported that they had obtained the password of another medical staff member.
  • Only 171 (57.2%) estimated how many times it happened, with an average estimation of 4.75 episodes. All the residents that took part in the study (45, 15%) had obtained the password of another medical staff member, while 57.5% (38/66) of nurses reported this.

Their conclusion from this study: the use of passwords is doomed because medical staff members share their passwords with one another. Strict regulations requiring each staff member to have a unique user ID might lead to password sharing and to a decrease in data safety. Click Here to access the full study.


Remember to Comply With the 3 Pillars of Securing ePHI

The three pillars to securing protected health information outlined by HIPAA are administrative safeguards, physical safeguards, and technical safeguards. These three pillars are also known as the three security safeguard themes for healthcare. These themes range from techniques regarding the location of computers to the usage of firewall software to protect health information. A brief list of the HIPAA Security Safeguards:

  • Access control (technical safeguard) is a technique that prevents or limits access to an electronic resource. The intent behind access control techniques is to limit access to only authorized parties. The healthcare facility collects, stores, and secures patients’ data, which is very sensitive. This safeguard can take the form of role-based access control, attribute-based access control, and identity-based access control. Role-based refers to a person’s role in the healthcare facility. For instance, when a provider begins working at a healthcare facility, he/she has access to patient data, but only the patient data for his/her patients. If this provider also serves on a certain committee in the hospital, then another set of privileges is created to enable access to committee resources. When other data is accessed, a log is created that is periodically audited. When a front-desk clerk begins working in a facility, he/she has no reason to access clinical data, but may need access to the administrative data such as address and phone number, depending on the role that the person plays in the organization. Other names for this are media controls, entity authentication, encryption, firewall, audit trails, virus checking, and packet filtering.
  • Physical access control (physical safeguard) is a technique that prevents or limits physical access to resources. The intent of this control is similar to the technical safeguard: It limits access to only authorized parties. A patient in a facility will not have access to any clinic or ward except the one he/she is seen in. A front-desk clerk in the optometry clinic will not typically need access to the emergency room, so his/her access card will not open those doors. A provider in a facility will not typically need access to the server room, so his/her access card will not unlock those doors. Other names for this are physical security, (some) workstation security, assigned security responsibility, media controls (access cards), and physical access control.
  • Administrative safeguards are techniques that are not entirely technical or physical, but may contain a piece of each. These safeguards typically take the form of policies, practices, and procedures in the facility to regularly check for vulnerabilities and continually improve the security posture of the organization. Other names for this control are risk analysis and management, system security evaluation, personnel chosen for certain roles, contingency, business continuity, and disaster recovery planning.

When Someone Shares a Password – It Is a HIPAA Violation Under the HIPAA Security Rule – Technical Safeguard Related to Access Controls. 

 

The Security Rule defines access in § 164.304 as “the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource. (This definition applies to “access” as used in this subpart, not as used in subpart E of this part [the HIPAA Privacy Rule]).” Access controls provide users with rights and/or privileges to access and perform functions using information systems, applications, programs, or files. Access controls should enable authorized users to access the minimum necessary information needed to perform job functions. Rights and/or privileges should be granted to authorized users based on a set of access rules that the covered entity is required to implement as part of § 164.308(a)(4), the Information Access Management standard under the Administrative Safeguards section of the Rule.

Unique User Identification Requirement - § 164.312(a)(2)(i)

 

The Unique User Identification implementation specification states that a covered entity must: “Assign a unique name and/or number for identifying and tracking user identity.”

User identification is a way to identify a specific user of an information system, typically by name and/or number. A unique user identifier allows an entity to track specific user activity when that user is logged into an information system. It enables an entity to hold users accountable for functions performed on information systems with ePHI when logged into those systems using audit trails (addressed toward the end of this article).

Regardless of the technology or information system used, access controls should be appropriate for the role and/or function of the workforce member. For example, even workforce members responsible for monitoring and administering information systems with electronic protected health information or ePHI, such as administrators or super users, must only have access to ePHI as appropriate for their role and/or job function.

Sample questions for covered entities to consider:

  • Does each workforce member have a unique user identifier?
  • What is the current format used for unique user identification?
  • Can the unique user identifier be used to track user activity within information systems that contain ePHI?

So, What Can Happen If We Have Insufficient ePHI Access Controls?

Violating HIPAA law 104-191 can be costly. The HIPAA Security Rule requires covered entities and their business associates to limit access to ePHI to authorized individuals. The failure to implement appropriate ePHI access controls is also one of the most common HIPAA violations and one that has caused financial penalties. 

Financial penalties issued to covered entities for ePHI access control failures include:

Anthem Inc. – $16,000,000 penalty for access control failures and other serious HIPAA violations

OCR Imposes a $2.15 Million Civil Money Penalty against Jackson Health System for HIPAA Violations

OCR Imposes a $1.6 Million Civil Money Penalty against Texas Health and Human Services Commission for HIPAA Violations

University of California Los Angeles Health System – $865,500 penalty for the failure to restrict access to medical records

Colorado Medical Center – $111,400 penalty for the failure to terminate access to ePHI after an employee termination and a lack of a business associate agreement

Controlling Access to ePHI: For Whose Eyes Only?

The government HIPAA privacy/security enforcement agency is the Office for Civil Rights (OCR). OCR published the Summer 2021 Cybersecurity Newsletter on July 14, 2021, which states:

The rise in data breaches due to hacking as well as threats to ePHI by malicious insiders highlight the importance of establishing and implementing appropriate policies and procedures regarding these Security Rule requirements. Ensuring that workforce members are only authorized to access the ePHI necessary and that technical controls are in place to restrict access to ePHI can help limit potential unauthorized access to ePHI for both threats.

A recent report of security incidents and data breaches found that 61% of analyzed data breaches in the healthcare sector were perpetrated by external threat actors and 39% by insiders.

Without appropriate authorization policies and procedures and access controls, hackers, workforce members, or anyone with an Internet connection may have impermissible access to the health data, including protected health information (PHI), that HIPAA regulated entities hold. News stories and OCR investigations abound of hackers infiltrating information systems, workforce members impermissibly accessing patients’ health information, and electronic PHI (ePHI) being left on unsecured servers.

Information Access Management and Access Control are two HIPAA Security Rule standards that govern access to ePHI.

Download this newsletter:

Monitor Audit Trails

Audit trails automatically register and record where, when and who accessed the system. They also record what users do when they access the system. This tracks every change in patients’ information and documents it.

Since all the data is logged in the EHR system, it enables users to review the data at regular intervals and flag activities that seem suspicious. Regular reviews can also help correct mistakes caused by human error that could be flagged as a HIPAA violation. An audit trail answers the following:

  • Which patients’ data was accessed?
  • What time was it accessed?
  • Who retrieved the data?
  • Where was the data accessed from?

EHR software can also be set to send notifications to patients when their information is accessed. This way patients can report breaches as soon as they happen.

Conclusion

Create strong policies and procedures, then communicate these rules to your workforce. Enforce compliance through auditing and monitoring. Explain that when an individual allows another to use his/her password to access ePHI, that individual can alter and perform unauthorized functions and not be held accountable. The audit trail points back to the person who is assigned that password. 

Conduct on-going training of your workforce, which needs to include your C-Suite executives (who are not exempt from the rules). To gain the BEST results, conduct additional quarterly training with your front-line managers and supervisors.  Give them tools to incorporate HIPAA training at EVERY department meeting. If you think annual HIPAA training is sufficient, then you simply are not doing enough to protect your patient’s ePHI.

Additional Resources

Weekly HIPAA Podcasts (free) at:

OCR “The Security Rule” on the HHS website:

Train Online in HIPAA Privacy & Security:

Read More
HIPAA Compliance
HIPAA

Healthcare Apps and Data Privacy/Security Risks

Written by Susan Walberg, JD MPA CHC

Healthcare apps have become increasingly prevalent, with people using them for counting steps, monitoring their calories, or linking to various medical devices, to name just a few examples. Since the COVID outbreak, however, and the explosion of telehealth as a healthcare option, these apps have proliferated at an insane rate. As of 2020, there were 325,000 healthcare apps on the market, with more coming all the time.

Whether you are a consumer who uses such apps, or a provider who wants to develop an app for patients to use, it’s important to understand some of the privacy and security risks that may accompany the use of such tools and what to watch out for.

What Are Healthcare Apps?

An ‘app’ is a small program that can be loaded onto a phone or mobile device to perform a specialized function. There are two main types of healthcare apps in terms of privacy and security regulations, and the rules governing them vary accordingly.

The first type are the applications that are used by your healthcare provider. They may be used to store your lab or radiology results or might be integrated with a medical device for tracking/monitoring purposes, such as an electrocardiography device that monitors heart activity. Or they may be used to coordinate your care.

The second type are personal or private healthcare apps, those that an individual can get at an app store to track and manage their diet, exercise, or specific health conditions. There are apps for mental health, diabetes, and, of course, COVID, to name just a few. Many of these apps are free.

Nothing in Life Is Free

First, let’s talk about those ‘free’ apps.

Free apps, how cool is that? Depending on your view, an application that tracks and shares your personal information might not really be ‘free’.

If you go online and look for a free app to help you count calories or manage your diet, for instance, the odds are good that there are advertisements on the app, right? Well, most of those ‘free’ apps, with the ads included, will be sharing your information with the advertisers and perhaps even with other companies, such as the ‘big tech’ companies or other stakeholders or investors.

You may expect this, and you might not care. After all, any online Google search leads to targeted Facebook ads relating to that same subject matter, as many of us have noticed. We may not like it, but we are getting used to the fact that our online activity is not really private.

But when you choose one of those apps, think about what information you are entering, because it is probably not private. How much of your medical information is being collected in order to help you manage your diabetes or exercise program? And do you know where that information might be shared? You may accept the fact that your use of the app is not private, just like your Google searches seem to have a direct pipeline to Facebook. But think about the data collected, because that’s not private either. And that’s not illegal in this situation.

But…But…HIPAA

How can this health information NOT be private? There must be regulations protecting your privacy, especially when it comes to your healthcare information, right? We hear all the time about HIPAA (The Health Insurance Portability and Accountability Act of 1996) and how your health information can’t be shared.

Just to be clear, in a nutshell, HIPAA only applies to those apps that are used and offered by your healthcare provider or insurance company (or some similar organization that is regulated by HIPAA). Those organizations are subject to the HIPAA Privacy and Security regulations (as well as the HITECH and Omnibus laws that followed), so any product they offer in conjunction with their regulated services would typically be subject to the same laws. This does not mean that if your doctor tells you there are apps in the marketplace to monitor your diabetes that they would be subject to HIPAA. But if your insurance company, for instance, offers you a tool as part of your plan that will help you manage a chronic health condition, HIPAA would generally apply. You may not be sure, so it’s important to ask.

If the app is, indeed, regulated under HIPAA, that means that privacy and data security controls must be in place. There should be a privacy/security policy that you can review, and you have specific rights with respect to your information and how it’s used. There are limitations around, for instance, how your data can be used or shared for marketing purposes. It also means that there must be a designated privacy and security ‘official’ who has oversight of compliance with these regulations. A company that provides a healthcare app to physician practices, insurance companies, or similar organizations would be considered a ‘Business Associate’ of that provider or insurance company, which means they are subject to the same requirements. HIPAA does provide a broad range of protections, but they are limited to those specific scenarios.

The reality is that few laws govern the privacy of information you voluntarily share in one of these publicly-available apps, so if you go online and pick an app to track or monitor your own health condition or information…most are not subject to privacy laws.

Apps Provided by Your Physician, Insurance Company, Etc.

The apps used by your doctor’s office or insurance company are subject to much tighter regulation, but also often contain more personal data. Especially with the increased use of telehealth services, provider’s offices are relying on various applications and platforms to facilitate the provision of healthcare services. These apps, and the companies that offer them, are covered under HIPAA as ‘Business Associates’ of the provider or insurance company if the app uses, stores, or transmits patient health information on behalf of the healthcare organization.

Due to COVID, the government has loosened up the privacy regulations in order to allow greater flexibility in providing telehealth services. While this is good news for providers and the patients needing those services, it also means more potential risk to protected health information (PHI). It’s important to keep in mind that, in addition to whatever information you enter online, a telehealth application likely has requested permission to access your calendar, camera, and microphone.

The good news is that, although providers may have been using some of the less secure apps in the beginning of COVID, just out of necessity, those providers who plan to continue providing telehealth services are working to ensure compliance with privacy and security requirements. App developers are busy developing apps to accommodate this changing market, and compliance is a top concern.

Apps as Mobile Devices

There is one type of application which is actually considered by the Food and Drug Administration (FDA) to be a medical device, in addition to being covered under HIPAA (because they are provided in conjunction with healthcare services). Those are the apps that are intended to be used ‘for the diagnosis of disease or other conditions, or the cure, mitigation, treatment, or prevention of disease, or is intended to affect the structure or any function of the body of man’ under section 201(h) of the Food, Drug, and Cosmetic Act. In general, if the purpose or function of the app is to assist in performing a medical device function, it will be treated as a medical device under the FDA. For instance, if the app can be run on a smart phone or other hand-held device and analyzes and interprets EKG waveforms to monitor cardiac irregularities, it would be considered analogous to those software programs that perform the same function and are otherwise regulated as a medical device.

The intent of the FDA is to ensure patient safety related to the use of those devices that could compromise or risk patient health. This oversight is limited to those devices marketed and offered to perform these medical device functions.

Although the FDA purview is not privacy or data security, the FDA jurisdiction is noteworthy in terms of regulatory oversight. For purposes of HIPAA, these devices would typically be subject to the Privacy and Security rules as they are used in conjunction with your provider or insurance company, as discussed above.

How Do You Know if Your Data Is Secure?

Apps in the marketplace that are available to help track health-related information should have a privacy policy, although at the current time it is not required by law for apps that are not considered a medical device or are subject to HIPAA. It is highly recommended that you find those policies and read them, even though some may be lengthy and not written clearly (might be overly technical or legalistic).

Even if the apps have privacy policies, those policies might not be easy to find, and you might discover that the policy does state the ways in which they do share your information. There is no law against the sale or disclosure of data from independent apps to third parties and those apps are being funded somehow (data is valuable). In addition to data sharing, the privacy policy should explain how it safeguards your data. There should be information security measures in place to prevent breaches of your data. And lastly, even if the privacy policy sounds good, the app developer may not necessarily follow their own policies. This is not to say that an app developer is deliberately being deceptive; a developer or their sponsoring company may adopt a policy from another app they are familiar with or may bring in a consultant to write their policy, but the specific terms in the policy aren’t implemented during development. It can happen. And this isn’t limited to app developers; any organization can fall short of following its own policies. Many app developers have a technical or clinical background and may not fully understand the healthcare regulatory framework.

You can also check an app’s automatic settings and look for those that impact privacy, such as location tracking. Beware, though, that in some instances turning those options off will make it more difficult to use the app.

The bottom line here is caveat emptor…buyer beware. Especially if you’re not ‘buying’ and it’s ‘free’.

How Can Data Be Compromised?

Even when providers, insurance companies, and app developers are focused on compliance with the various privacy and security requirements, PHI can still be compromised, but it is less likely. Common mishaps occur in a number of ways:

  • Employee errors. Human errors can occur in any setting. It can be an employee discussing patient information out loud in a non-private setting, clicking on a link that allows a virus or ransomware attack, or accidentally entering an incorrect phone number and sending information to the wrong person. This isn’t limited to technology-related issues but privacy in general.
  • Poor access controls. There needs to be a solid process, that is followed religiously, to ensure that only individuals who need access are given access, and that former employees or business associates are promptly removed when they no longer have a need for access. This also includes business partners who have employees who need access in order to provide services to another company or practice. These employees need their own access, not a universal access that cannot be tracked.
  • Failure to monitor. Any organization that maintains PHI electronically should have a process for routinely reviewing who is accessing sensitive information and following up on any questionable access. Audit trails are part of any good security structure.
  • Failure to securely store data. Not only should data be stored in a secure manner, it should also be consistently destroyed/removed when applicable retention periods have expired.
  • Inadequate encryption.
  • Workstation and device security. Applications should time-out when not in use, rather than rely on users to remember to do so.
  • Failure to conduct a comprehensive risk assessment that includes the various apps and networked devices where PHI is stored or transmitted.
  • Increased remote workers. Employees working from home are more likely to use personal devices that don’t have proper levels of encryption and that are, by definition, less private due to the offsite location. Access is much harder to control and networks may not be secure.

The above issues do not pertain only to apps, but in general to information privacy and security, especially in the new era of increased telehealth services. Those issues are also the types of failures HIPAA was designed to prevent and would likely be considered violations, depending on the specific facts. If you are considering using an app or electronic platform where personal information will be entered, it’s recommended that you ask your provider or insurance company who is offering this tool what their privacy and security policies are. If their organization is using and recommending such a tool, they have almost certainly done the review of privacy and security controls. And if you are a provider considering using an app, or an app developer, the above list is for you. You should have designated ‘privacy and security officials’ who ensure the above risk areas are addressed.

What Are the Risks?

Most people care about the privacy of their health information just because it’s private and not other people’s business. But there are actual risks to consider, which users of these apps should understand:

  • Data is shared with third parties for sales and marketing, increasing the targeting of ads you receive.
  • Even information that is supposedly ‘de-identified’ can include enough information to make users identifiable, and it may be very sensitive information, for instance relating to mental health or substance abuse.
  • Medical identity theft, which can result in someone using your identity to receive free healthcare services or to file fraudulent claims. Healthcare data is valuable for those reasons, which is why it is often targeted by hackers.
  • Additional outside companies, such as Facebook or Google, may acquire the information and build user profiles. Once the information is out there in that environment, there is little control over it and it’s difficult to know who could access it or how it could be used.
  • Your PHI could be acquired by insurance companies or other healthcare companies that could use it against you in underwriting or pricing determinations. Who else would you not want knowing your private information? An employer? The possibilities are frightening, especially considering that once the information is out there, it’s out there. You can’t put the genie back in the bottle.

Conclusion

Telemedicine and the use of online applications has exploded in recent years, particularly in relation to the COVID pandemic and the resulting changes in the delivery of healthcare. The regulatory framework has not necessarily caught up to technology yet, so while HIPAA laws apply to some applications, many that are out there being used by consumers are not regulated in terms of protecting sensitive information. Health information can be bought and sold in the marketplace, it has a value for advertisers, thieves, and others.

For consumers, just be aware of the potential risks before you start using an app; check the app’s privacy and security policies and consider carefully what information you are comfortable exposing. If the app comes from your provider or insurance company, ask about the security controls and how they are protecting your data.

For providers, consider your own liability in terms of recommending an app and make sure your organization has done its due diligence to ensure proper security measures are in place. You should have your own privacy and security experts evaluate the tool before offering it to patients.

For app developers, be aware that technical security isn’t your only concern; you will want to have assistance from someone with healthcare privacy and security regulatory expertise. This will be something that potential clients and investors will be asking about.

Susan Walberg is a healthcare consultant who works with providers and healthcare start-ups. She can be reached at https://www.susanwalberg.com/

Read More