Compliance in Healthcare
Corporate Compliance

Vendor Compliance – Old Problem, New Risks

Written by Susan Lee Walberg, JD MPA CHC 

Compliance Officers are always stretched thin with many responsibilities, and those duties seem to constantly grow with each year and every new law or regulation. One of the more challenging areas to monitor is the compliance of our vendors and Business Associates.

I believe this is now more important than ever. Why? Because cybercrime, hacking, phishing, and impersonation schemes are rampant, and the cyber-crooks are now using AI to circumvent our (and our vendor’s) security measures.

How many times have we heard about a major breach, and the root cause was a failure to conduct a Security Risk Assessment or apply patches or software updates timely? A failure of routine training is also often to blame. Over 60% of breaches are caused by Business Associates, so this is an area of risk that I believe needs more attention.

Over the years, I have found that prevention is the best cure. There are several steps we can take on the front end to reduce the risk of non-compliance during the term of the Agreement.

1.  Compliance needs to be at the table BEFORE arrangements are entered into. It’s not unheard of, in a large health system, for the compliance officer to not even know about every joint venture or acquisition, but, when there’s a compliance problem at that entity, they are on the hook. It’s critical to build trust with leadership, and educate them as to why Compliance needs to be at the table. We need to understand what the arrangement is about, why we are doing it, and who is paying what to who. If Compliance isn’t informed and engaged, some of these other steps likely won’t happen.

2.  Due diligence is critical for new business partners. While the finance team reviews the balance sheet, Compliance needs to be reviewing the organization’s compliance program, culture and reputation. There should be a document list the Compliance reviews for acquisitions and partnerships, but even for contracted services, we want to take a peek and do some basic reviews.

  • Review their Compliance Plan (and how often it’s been reviewed and updated)
  • Have a conversation with their compliance, privacy, and/or security officer to get a better sense of how they operate
  • Find out if they’ve been subject to any investigations
  • Run a List of Excluded Individuals and Entities (LEIE) OIG check
  • Ask to see their most recent Security Risk Assessment, if ePHI is going to be involved

Pay careful attention to any referrals that are considered as part of the contract. These are not only for physicians, but they can also be an IT vendor or other provider of goods or services-there have been plenty of cases where companies, such as Electronic Medical Record (EMR) companies have been found in violation of the Anti-Kickback statute. Have an attorney review it if this isn’t your area of expertise. The bottom line is to ask yourself if the arrangement itself is appropriate.

Those are just some suggestions, but at least these activities would give you a sense of how much they tend to compliance. Also, it never hurts to do a basic Google search. If they aren’t a new organization, and if they have any ethical or legal issues, you will likely find reviews on the Better Business Bureau site and/or sites where employees and customers can give a rating/review. That activity alone can speak volumes if the organization has a culture problem.

3. Contract provisions need to include compliance. Although bad actors sign contracts all the time, it still helps protect       your organization and does show that you take compliance and ethics seriously. Some suggested provisions:

  • The vendor agrees to comply with all applicable laws, rules, and regulations, including False Claims Act, Stark, HIPAA, and any other that are key for your business and the type of services.
  • The vendor agrees that you are allowed to audit their processes and records that pertain to the services under the contract
  • The vendor agrees that all their employees are checked for disbarment and that none of their employees or contractors are disqualified to participate in government health care programs; and to notify you immediately if that changes.
  • The vendor agrees and attests that they have a compliance, privacy, and security program that meets or exceeds industry and regulatory standards, and that they maintain stringent security standards to protect the integrity of ePHI.
  • Breach notification and remediation procedures need to be detailed. How long after a breach is identified must you be notified? Who notifies clients? Review the breach response requirements under HIPAA and make sure you address those.
  • Data use is an important provision. Review your contract or Business Associate Agreement, keeping in mind that data is now as valuable as gold. Can your business partners sell your data? What if it’s de-identified? Are you comfortable with them doing so, and does your agreed-upon rate take that into account? The advent of AI makes data much more valuable.
  • Adherence and compliance to all Medicare regulations, especially if this is a contract for any business office, documentation, coding, or record review service.

4. Training requirements are not optional. Privacy, Security, and Compliance training should be provided to the vendor’s   employees, or they can take training you provide, if you have that option. If they have their own program, it’s totally acceptable to ask to see it. Ongoing data security training, in particular, is important due to the constantly evolving phishing and other schemes.

5. Make sure you have tight controls on granting access to your information. Your business partner can’t just get one log-in that everyone uses. That should be a core requirement for data access-unique user IDs and passwords.

Those are some key front-end steps. Once the agreement is in place, if the previous activities are completed there shouldn’t really be a heavy load of monitoring, absent some incident or breach. Here are a few things to consider:

  • Stay in contact with the process/contract owner and ask how things are going. If there are problems, that person is likely the first to know. Make sure they know to call you if something starts to go sideways.
  • Conduct any audits or monitoring you included in the contract, if you’re able to (it’s a resource issue, for sure)
  • Send occasional surveys to your vendors inquiring about their compliance, privacy, or security measures. This at least lets them know you are paying attention.
  • Touch base with their compliance, privacy, or security officers
  • Monitor training logs, if they receive training from you (or ask them to provide that information)
  • Look them up online now and then to see if there are any new complaints out there.
  • Get an audit of what information their employees are viewing-make sure it’s appropriate.

Monitoring your vendors can seem like just one too many things to do, and most of the time you will find that there are no red flags. Most businesses try to do the right thing. But it’s important to keep in mind how much of a risk they could pose to your organization, especially if they are handling patient information and/or billing functions. You don’t want to be looking back and wishing you had done it and having to explain that to your leadership!

About the Author Susan Lee Walberg, JD MPA CHC

Ms. Walberg is an author, attorney and healthcare compliance consultant. She is available to help anyone work through these processes and provides a full range of compliance-related services and books, including serving as a fractional Compliance or Privacy Officer, or in an interim role. She can be contacted by email at swalberg@compliancealacarte.com, or find more about services and books on her website at susanwalberg.com or on LinkedIn!

Copyright © 2026 American Institute of Healthcare Compliance All Rights Reserved

Read More
Auditing, Managing Denials Is Important to Good A/R Hygiene
Auditing

You Play a Vital Role in Protecting the Integrity of the U.S. Healthcare System

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




The U.S. health care system relies heavily on third-party payers to pay the majority of medical bills on behalf of patients. Health care insurance fraud is a pressing problem, causing substantial and increasing costs in medical insurance programs. To combat fraud and abuse, all levels within a medical practice, hospital or health care organization must know how to protect the organization from engaging in abusive practices and violations of civil or criminal laws.


If you are a health care provider, remember that payers trust you to provide medically necessary, cost-effective, quality care. You exert significant influence over what services your patients get. You control the documentation describing services they receive, and your documentation serves as the basis for claims you submit. Generally, the health care system pays claims based solely on your representations in the claims documents.


When the federal government covers items or services rendered to Medicare and Medicaid beneficiaries, the federal fraud and abuse laws apply. Many similar state fraud and abuse laws apply to your provision of care under state-financed programs and to private-pay patients. The most important federal fraud and abuse laws that apply to healthcare are the:

  1. False Claims Act (FCA);
  2. Anti-Kickback Statute (AKS);
  3. Physician Self-Referral Law (Stark Law);
  4. United States Criminal Code
  5. Exclusion Authorities; and
  6. Civil Monetary Penalties Law (CMPL).

Implementing a successful compliance program not only assists in protecting your organization but individuals within the organization. It is crucial for providers, coders and billers to understand these laws not only because following them is the right thing to do but also because violating them could result in criminal penalties, civil fines, exclusion from the federal health care programs or loss of your medical license from your state medical board.


Government programs, such as the Centers for Medicare & Medicaid Services (CMS), find the investment in their audit and monitoring programs are effective. CMS announced in the fall of 2021 that their aggressive corrective actions led to an estimated $20.72 billion reduction of Medicare Fee-for-Service (FFS) improper payments over seven years.


When you submit a claim for services provided to a Medicare beneficiary, you are filing a bill with the federal government and certifying you earned the payment requested and complied with the billing requirements. If you knew or should have known the submitted claim was false, then the attempt to collect payment is illegal.


When an organization fails to provide training and education to deter and detect fraud and/or abuse, it is likely to be detected by an outside investigative source via action such as:

  • Focused audit by the payer due to detection of suspect billing patterns when compared to your peers;
  • Routine audits conducted by the payer, such as Medicare’s Comprehensive Error Rate Testing (CERT); and
  • Internal whistleblower or qui tam action.

Internal auditing and monitoring programs are essential to keeping medical records and billing accurate. However, a routine internal billing and documentation review could turn into a more focused internal investigation. During that investigation, is it possible that an aberrant pattern of inappropriate billing is revealed? Do you know how to proceed if this happens?


First, remember that anyone can commit health care fraud. Fraud schemes range from solo ventures to widespread activities by an institution or group. Your organization should have a designated Compliance Officer. Audit professionals should have the authority to report potential fraud and abuse situations directly to the Compliance Officer for further investigation and resolution.


Problem areas brought to the attention of the Compliance Officer should also be included in corrective action training programs to avoid the continuation of the situation. One of the most important aspects of a compliance program is training and education at all levels of the organization.


Now, let’s talk more about qui tam action. There are five potential areas in which qui tam cases arise related to Medicare or Medicaid claims and the False Claims Act (“FCA”). Qui tam claims involving Medicaid/Medicare healthcare vary, depending on the level of care needed and provided. Categories often involve allegations of total neglect or no services, worthless services, inadequate and inferior services and products, and aggressive patient treatment. Other areas of fraud involve misrepresentation of credentials, upcoding of services, unbundling of services, and misrepresentation of patient data or populations.


Words of Advice


Maintain accurate and complete medical records and documentation of the services you provide.

  • Ensure your documentation supports the claims you submit for payment. Good documentation practices help to ensure your patients get appropriate care and allow other providers to rely on your records for patients’ medical histories.

Anytime a health care business offers you something for free or below fair market value, ask yourself, “Why?”

  • Remember, when a vendor or consultant provides coding and billing advice, the provider filing the claim is responsible for the accuracy of that claim. Be suspicious when you are told that a huge enhancement of revenue will be realized if you bill like this . . .

Get expert advice from a qualified source before investing or getting into a joint venture.

  • Some physicians who invest in health care business ventures with outside parties, such as imaging centers, laboratories, equipment vendors, or physical therapy clinics, may refer more patients for the services provided by those parties than physicians who do not invest. These business relationships may improperly influence or distort physician decision-making and result in the improper steering of patients to a therapy or service where a physician has a financial interest. Arrangements could be viewed as illegal.

Avoid illegal incentives to join a hospital’s community.

  • A hospital may pay you a fair market-value salary as an employee or pay you fair market value for specific services you render to the hospital as an independent contractor. However, the hospital may not offer you money, provide you free or below-market rent for your medical office, or engage in similar activities designed to influence your referral decisions.
  • Admit your patients to the hospital best suited to care for their medical conditions or to the hospital your patients select based on their preference or insurance coverage.

Don’t sell free product samples.

  • Many drug/biologic companies provide free product samples to physicians. It is legal to give these samples to your patients free of charge, but it is illegal to sell the samples.
  • The federal government has prosecuted physicians for billing Medicare for free samples.
  • If you choose to accept free samples, you need reliable systems in place to safely store the samples and ensure samples remain separate from your commercial stock.

Relationships with the pharmaceutical and medical device companies

  • As a practicing physician, you may have opportunities to work as a consultant or promotional speaker for the drug or device industry. For every financial relationship offered to you, evaluate the link between the services you can provide and the compensation you will get. Test the appropriateness of any proposed relationship by asking yourself the following questions and when in doubt, get legal advice: o Does the company really need your specific expertise or input? o Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services? o Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?

o  Does the company really need your specific expertise or input?

o  Does the company’s monetary compensation to you represent a fair, appropriate, and commercially reasonable exchange for your services?

o  Is it possible the company is paying for your loyalty so you prescribe its drugs or use its devices?


Educate C-Suite and Compliance Officials in Your Company


An executive, top-down approach is required for a successful compliance program. The following seven components provide a solid basis for a compliance program:


1. Conduct internal monitoring and auditing

2. Implement compliance and practice standards

3. Designate a compliance officer or contact

4. Conduct appropriate training and education

5. Respond appropriately to detected offenses and develop corrective action

6. Develop open lines of communication with employees

7. Enforce disciplinary standards through well-publicized guidelines


Establishing and following a compliance program helps health care providers avoid fraudulent activities and submit accurate claims. However, implementing mechanisms to develop a culture of compliance requires educating high-level influencers within your organization. 


Suggest C-Suite executives take online training in healthcare Corporate Compliance.

Require your Compliance Officer, Chief Executive Officer and Chief Financial Officer to become certified not only in Compliance, but in Auditing for Compliance and Conducting Internal Investigations.


Joanne Byron is the Board Chair and Chief Executive Officer of the American Institute of Healthcare Compliance (AIHC) with more than 35 years of health care coding, documentation, billing and compliance experience as a consultant, health care executive and corporate trainer. Learn more about AIHC, a 501(c)(3) non-profit training organization, today.  

Read More
Telehealth
HIPAA, Telehealth

Audio-Video Telehealth, Mobile Device Management & You

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS


This article addresses how to track telehealth policies while addressing HIPAA compliance and mobile device management as the United States enters into a post-pandemic era. The information is an overview and should not be used as legal or consulting advice. Health care providers need to look toward long-term telehealth policies, ensure compliance and realize there is remaining work to be done. 


Scroll to the end of this article for “Basic Telehealth Terminology” if you are new to telehealth or if you are a mobile device app developer!


Most Providers Utilize Audio-Only Telehealth


More than two-thirds of providers utilizing telehealth use audio-only, according to a recent Telehealth Survey conducted November 2021 through December 2021 by the American Medical Association (AMA). According to this survey, 85% of physician respondents indicate they currently use telehealth. Those reporting a decrease in use since first offering it, now indicate doing a mix of in-person and virtual care. Of physician’s using telehealth, the trend indicates 93% are conducting live, interactive video visits with patients and 69% are doing audio-only visits.  


Considering this survey and other reports on audio-video services, concerns seem to focus on potential overutilization, equity and quality of care. 


A concern expressed to AIHC, by our Compliance and HIPAA Officer members, surrounds mobile devices used by providers and practice managers and the organization’s responsibility to comply with applicable rules, regulations and mobile device policies.


So, how do policies apply? 

 

If your providers use a mobile device to access an organization’s internal network or system, the owner of that network or system’s policies and procedures apply to your use of the mobile device to gain such access. It is your organization’s responsibility to understand and follow the organization’s policies and procedures.


If an organization allows providers and professionals to use mobile devices for work, the organization should have reasonable and appropriate mobile device policies and procedures. The policies and procedures should describe any configuration requirements for mobile devices used by providers and professionals for work. It is your responsibility to understand and follow your organization’s mobile device policies and procedures. But, what about using personally owned mobile devices for work?

  • "Bring Your Own Device" or BYOD refers to using a personally owned mobile device for work. Providers should be reminded to let their organization know when they want to use a personally owned mobile device. Many organizations have centralized security management to make sure mobile devices accessing their internal networks or resources are compliant with their security policies. Centralized security management includes:

o Configuration requirements, such as installing remote disabling on all mobile devices; and


o Management practices, such as setting policy for individual users or a class of users on specific mobile devices.


It is the provider’s responsibility to understand and follow the organization’s mobile device policies and procedures. Registering the provider’s mobile device with the organization allows the organization to control who has access to its network or system and will keep unauthorized persons from accessing its network or systems.

  • Registering these mobile devices with your organization may also help the organization or law enforcement find your mobile device if it is lost or stolen. Providers should be directed to contact their organization’s Privacy Officer or Security Officer to register their mobile device.

Utilizing Step 4 from ONC’s 5-Step Process to Manage Mobile Devices Used by Health Care Providers & Professionals, the list of questions below is a way to take inventory of potential safeguards needed to address risk areas.


Mobile Device Management


 If your organization allows the use of mobile devices, what should the organization do about managing the use of mobile devices?


   o Has the organization identified all the mobile devices that are being used in the organization? How is the organization keeping track of them?


   o Has the organization assigned responsibility to check all mobile devices used for remote access, to find out if selected security/configuration settings are enabled?


   o Should there be a regular review and audit of the mobile devices? 


Misuse of Mobile Devices


 Does the organization have written procedures for addressing misuse of mobile devices?


   o If so, what are the consequences when a mobile device is misused and the incident poses risk of a data breach?


Should the Organization Allow BYOD?


 Is this a policy already in place, where providers are using their own devices?


   o Should the organization let providers and professionals use their personally owned mobile devices within the organization?


 Should providers and professionals be able to connect to the organization’s internal network or system with their personally owned mobile devices, either remotely or on site?


Restrictions on Mobile Device Use


 Does the organization restrict how providers and professionals can use mobile devices?


   o Can providers and professionals use mobile devices to access internal networks or systems, such as an EHR?


   o Are providers and professionals restricted from using mobile devices when they are away from the organization?


   o Can providers and professionals take their mobile devices home?


   o Should the organization allow texting or emailing of health information?


      Is there encryption allowing compliant texting and emailing from the mobile device?


Security/Configuration Settings for Mobile Devices


 Will the organization institute standard configuration and technical controls on all mobile devices used to access internal networks or systems, such as an EHR?


   o If so, is the organization's current mobile device configuration document, including connections to other systems/applications, inside and outside of the firewall.


Information Storage on Mobile Devices


 Are there restrictions on the type of information providers and professionals can store on mobile devices?


   o If so, where and for how long should the data be stored?


 Are providers and professionals allowed to download mobile applications to mobile devices? If so, what type(s) of applications are approved?


Recovery/Deactivation of Mobile Devices


 Does the organization have procedures to wipe or disable a mobile device that is lost or stolen?


 Does the organization have standard procedures to recover mobile devices from providers and professionals when their employment or association with the organization ends?


Mobile Device Training


Training is always a challenge, but if your organization cannot achieve effective training and compliance, you may need to reconsider how telehealth is delivered to your patient population.


 How is the organization training its workforce (management, doctors, nurses, and staff) on policies and procedures?


 How does the organization hold its workforce (management, doctors, nurses, and staff) accountable for non-compliance? 


What Additional Information Should I Know for Compliance?


Covered entities must comply with HIPAA Privacy and Security Rules to protect and secure health information, even when using mobile devices as described above. Taking it a step further, health care leaders are responsible to ensure that mobile device procedures and policies have been developed and properly implemented to protect the health information patients entrust to you.


Make Tracking Audio-Only Policy Easy


A great resource is utilizing the National Telehealth Policy Resource Center called “CCHP,” short for Center for Connected Health Policy. CCHP has been tracking audio-only policies across the country and offers access to state audio-only policies via CCHP’s Policy Finder Tool.


As AIHC advises, another resource is legal advice through your malpractice insurance company. At no additional charge, a risk attorney can be made available to help review which policies impact your type of practice and organization.


Free HIPAA Compliance Resources


Another reliable resource is found at HealthIT.gov, the official website of the Office of the National Coordinator for Health Information Technology, otherwise known as “ONC.” ONC offers basic guidance in these five steps 1) Decide; 2) Assess; 3) Identify; 4) Develop, Document and Implement; and 5) Train entitled “five steps organizations can take to manage mobile devices used by health care providers and professionals.”


Does Your Organization Have a Trained (Certified) HIPAA Privacy/Security Officer?


Your HIPAA Compliance Officer can serve as the best resource to help your organization navigate the telehealth and mobile device compliance issues facing your providers today. AIHC offers an online course covering both privacy and security with the option of certification (proctored and administered online).  The cost of certification is covered in the tuition price. Learn more.


It is highly recommended that mobile health app developers and Managed Service Providers (MSPs) have an in-house HIPAA Compliance Officer contributing input to ensure technology is compliant.


Are You a Mobile Health App Developer?


Integrating protections into your technology to create HIPAA compliant products is necessary for your company to succeed. Health care providers are subject to the HIPAA rules as covered entities to protect identifiable health information when it is created, received, maintained and/or transmitted. These protections are required under Federal and State Privacy, Security and Breach Notification Rules. A few basic resources to reference are:


The Office for Civil Rights (OCR) HIPAA website devotes a webpage under Special Topics entitled “Resources for Mobile Health Apps Developers.”


The Federal Trade Commission (FTC) offers a webpage entitled “Mobile Health Apps Interactive Tool” to help you locate federal laws to follow.


For Beginners - Basic Telehealth Concepts


Telehealth is also referred to as Telemedicine. It is the use of telecommunications technology to provide health care services to persons who are at some distance from the provider. This type of patient encounter involves a spectrum of technologies.


Coverage and payment for telehealth can include consultation, office visits, individual psychotherapy, pharmacologic management and other services delivered via an interactive audio and video telecommunications system.  

  • Providers are located at the distant site; and
  • Patients are located at the originating site.

Provider at the distant site - As stated above, providers are at the “distant site,” referring to where the provider is at time of service. The provider can communicate with the patient using an interactive audio and video telecommunication system that permits real-time communication with the beneficiary.


When telehealth is used, it is considered to be rendered at the physical location of the patient, and therefore a provider typically needs to be licensed in the patient’s state. During the COVID-19 public health emergency (PHE), many states waived this requirement or provided specific exceptions. Click Here for Cross-State Licensing information.


Medicaid programs often restrict the type of providers that can be reimbursed when delivering services via telehealth. During the COVID-19 PHE, the list of providers in Medicare and many state Medicaid programs expanded to include professionals such as occupational and physical therapists and speech-language pathologists. Federally Qualified Healthcare Centers (FQHCs) and Rural Health Clinics (RHCs) were also allowed to provide services in some cases. These policies are temporary and most will expire at the end of the PHE.


I also recommend utilizing the TELEHEALTH.HHS.GOV website for providers – “Getting Started with Telehealth.” This webpage provides many additional links to more resources your organization can use to navigate this complex topic.


Temporary telehealth policies during the PHE were implemented to provide improved access to health care during the COVID-19 pandemic. The federal government has been encouraging providers to use telehealth to conduct virtual appointments and has made the telehealth “rules” more flexible. For instance, audio-only delivery of care has rarely been reimbursed historically. But due to COVID and the PHE, temporary policies allow this modality to deliver some services.


The PHE is reviewed and potentially extended every 90 days. When the PHE ends, coverage for telehealth may change. Monitor these updates by using the CCPH website referenced earlier in this article found at https://www.cchpca.org/.

Read More
HIPAA Compliance
HIPAA

How to Handle Passwords Like a Boss!

Written by: J. David Sims, CHITSP, CHMSP, Managing Partner at Security First IT, LLC; Board Member with the American Institute of Healthcare Compliance; Podcaster, Speaker, & HIPAA Instructor; Help Me with HIPAA Podcast Contributor and Federal HICP 405(d) Task Group & HIC-TCR Task Group




Cybersecurity starts with the basics, such as appropriately managing passwords within your organization. The Health Insurance Portability & Accountability Act (HIPAA) requires access controls and password management, which requires a top-down approach within your organization. Whether you are a Covered Entity or Business Associate, handle it like a boss!

In a recent article by Joanne Byron, she discussed one of the biggest challenges with proper password management… password sharing! In this article, I’m going to introduce you to some ways that you can overcome this challenge in your organization.

First, let’s start by setting three ground rules that I use for cybersecurity:

Rule #1 – Security is not convenient

Rule #2 – Security is not optional

Rule #3 – Security should not unnecessarily hinder the user

Understand that by design, security is there to hinder or stop an action. Think of your house for a minute. I have a sign in my yard advertising that I have monitored security in my home. I also have an alarm system, a deadbolt, a dog, and a shotgun. All these things represent different levels of security and incident response. They all cost me money and they are all inconvenient in some way. To protect my family, my most precious assets, is not optional. However, I can’t make this level of security so inconvenient that it doesn’t work. Therefore, I’ve ensured that these levels of security do not hinder my family’s ability to quickly enter and exit the home.

Security is there to deter the bad guys and to keep out those who should not be in my home (like the in-laws).

Passwords are just one layer of security for your electronic Protected Health Information and other digital assets. It is also a layer of security that is heavily dependent on the user… the human. The human must follow your password policy so that proper passwords are created and used in the correct manner. However, like a flowing river, humans will often find the path of least resistance (or create one) to get their job done.

Therefore, it is so important to train employees on your password policy, why passwords matter, what can happen when passwords are shared, and so on. Equally important is that the organization should take reasonable measures to make using passwords not a huge hinderance. Let’s take a look at some solutions to help your team be password ninjas!

Password Managers

Password managers are a fantastic tool for… you guessed it… managing passwords! I could not do without a password manager. At last check, I had over 1700 unique passwords stored in my password manager.

Password managers offer an array of other benefits and services but at its core, a password manager allows you to store all your passwords in a single, secure place. Instead of having to remember dozens or hundreds of passwords, the user only has to remember the one password that opens their password manager. Think of it as a vault for your passwords.

Another feature of most password managers that I love is the ability for me to share a password with someone without giving them the password. There are a few ways this can be used. I can set up a user account for someone and program their password into the password manager so that they can login to the application using their own credentials, and they never see the password. This ensures that a user can’t use their credentials outside of the office to access anything business related.

This is also very helpful for those websites that do not allow for multiple user accounts, but you still need multiple users to access it and use it. I see this often in practices where a business website only gives the practice a single account to use. The practice uses the same username and password for every employee that needs access to that website. Even worse, when employees leave the practice the credentials are not changed, which allows the separated employee to assess the site from anywhere.

There are several additional benefits of a good password manager application, so investigate one for your organization. They are well worth the small investment.

Creating Passwords

Whether you use a password manager or not, you still must deal with creating secure, unique passwords. Remember, you do not want to have the same password used more than once. Using the same password for everything is like having one key for your house, your car, your office, as well as all your past houses, cars, and offices. Oh, and the key has your name and address on it. Can you see how important it is to use different passwords everywhere?

Before we continue, it is important for you to understand that the bad guys aren’t trying to login to your online accounts typing in one password at a time hoping to get lucky. The bad guys use software automation and databases of passwords to throw at your accounts. This is called a brute force attack.

They know that most people are lazy and use terrible passwords. The most common password is 123456. You may laugh, but this password has been exposed in breaches more than 23 million times. It seems that no matter how terrible of a password it is, people still use it. For these people convenience is a higher priority than security. I wonder if these same people leave their car and homes unlocked… because, yeah… fumbling for a key is not convenient either.

Just a few months ago, the cybersecurity world learned of a leaked list of passwords called RockYou2021. This massive list of breached passwords and passwords from other sources comprises an impressive list of 8.4 billion unique passwords. 8.4 billion!!! Is there a chance that a password you use will show up on a list that size? Yeah, most likely. Unless you are one of the smart ones that use good password creation practices.

Since I’ve already mentioned password managers, it is worth noting that most password managers come with a password generator built-in that allows you to select a few criteria for your password and presto, it creates a password for you to use. Whether you’re using a password manager or not, here are some criteria to consider for your secure password:

Size Matters

Length is more important than complexity. Forever and a day we’ve heard that password complexity is necessary. Well, after years of research, we’re finding that all that complexity lends itself to creating other problems.

Many users fulfill this complexity requirement the same way by simply capitalizing the first letter of the password and adding a 1 or ! to the end. If I just guessed 25% of your password, you should be relegated to using a manual typewriter for the next month. Your password should be at least 8 characters (I prefer 12 to 16) minimum. The longer the password, the harder it is for software to crack it.

Change Is Good, or Is It?

Consider eliminating or reducing periodic password resets. We are also finding out that having people change their passwords too often means that they can’t remember them. I can often tell how many times someone has changed their password by how many exclamations they have at the end. Every time there was a password change, they simply added an exclamation.

If you are using secure passwords, there is no need to change them unless they become compromised in any way. However, knowing if they are compromised becomes super important and your organization should subscribe to services that monitor your accounts for compromised credentials. This brings us to the next point.

You Made the List! That Sucks.

Every password should be checked against known “blacklists” that include dictionary words, repetitive or sequential strings, passwords taken in prior security breaches, variations on the site name, commonly used passphrases, or other words and patterns that cybercriminals are likely to guess. Using a password that is on a Blacklist makes the password almost useless. Imagine if your home had one of those digital keypads for keyless entry. Now, imagine that there was a list floating around your town that had your home’s key code. How would it make you feel that thousands of strangers can easily walk right into your home if they desire? Using a compromised password is much the same.

Lie… Seriously!

You know those password hints you had to create to set up your bank account? Chances are, those answers are fairly easy to get by just paying attention to your social media accounts and what you share online. Heck, the answers may even be able to be socially engineered out of you.

When presented with these password hints and security questions… lie like crazy! What’s my mother’s maiden name? NunYoBitNess!

Get creative and have fun with it but remember you may need to use these answers at some point to recover or reset your real password, so you need to keep this information. I hate to keep coming back to password managers, but most of them also allow you to keep secure notes in your vault (it’s not just for passwords).

What Do You Have? What Do You Know?

Multi-factor (MFA) or Two-factor (2FA) authentication requires users to authenticate themselves using something they know and something they have.

2FA has been around for a very long time. If you’ve ever used an ATM machine to get cash, you’ve used 2FA. You used your card (something you have) and your PIN (something you know).

Using 2FA will likely require that you use an “Authenticator” app. There are many available but stick with the known companies like Google, Microsoft, Authy, etc.

I highly recommend using 2FA everywhere it is available. Even if someone has your username and password, it will be difficult for them to get past your additional authentication methods.

Wrapping It Up

Now that you know how to create secure passwords, how to store them safely, and how to manage them properly, you are ready to go out into the world and show everyone in your organization how they too can handle passwords like a boss!

Want More Information on HIPAA Compliance?

Help Me With HIPAA is the most popular, longest running podcast of its kind. Patient care starts from the moment a person entrusts you with their personal information. Join Donna and David each week as they deliver HIPAA and humor in a way you've never experienced. Who says learning can't be fun? Not us!


Train Online in HIPAA Privacy & Security Compliance – Click Here for more information.


Only need short refresher courses or targeted training? Check out the AIHC HIPAA short courses.

Read More
HIPAA Compliance
HIPAA

Is Sharing EHR Passwords a Problem?

Written by: Joanne Byron, BS, LPN, CCA, CHA, CHCO, CHBS, CHCM, CIFHA, CMDP, COCAS, CORCM, OHCC, ICDCT-CM/PCS




This article addresses the importance of Electronic Health Record (EHR) security to help health care organizations, health plans, clearinghouses (Covered Entities) and their business associates avoid HIPAA violations under the Security Rule Standard § 164.312(a)(1). To obtain more information about mitigating the risk of a HIPAA violation, please consult with legal counsel or a HIPAA Security Consultant. 

 

What If . . .

 

What would happen if you shared your login and password to your online bank account? How about sharing the password to access your credit cards? How would you feel if you knew your doctor shared his/her password to your personal medical records with an unauthorized user? What if someone in medical billing shared his/her password to your account (containing your medical and financial identity) with someone not authorized to access your information?


What If EHR Passwords Are Shared . . .


Electronic health records (EHRs) incorporate a vast amount of patient information and diagnostic data, most of which is considered protected health information. With the advancement of technology, the emergence of advanced cyber threats has escalated, which hinders the privacy and security of health information systems such as EHRs.


As defined by the Center of Medicare and Medicaid Services (CMS), “An electronic health record (EHR) is an electronic version of a patient’s medical history, that is maintained by the provider over time, and may include all of the key administrative clinical data relevant to that person’s care under a particular provider, including demographics, progress notes, problems, medications, vital signs, past medical history, immunizations, laboratory data and radiology reports.”


Because this protected information and data can easily get into the wrong hands, individuals should not share passwords with anyone.  


Is This Really a Problem? Doesn’t Everyone Share Passwords?


Due to the sensitive nature of the information stored within EHRs, several security safeguards have been introduced through the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.


Prevalence of Sharing Access Credentials in Electronic Medical Records

To summarize an abstract published by PMC (Public Med Central) of the U.S. National Institutes of Health’s National Library of Medicine, it was found that to prevent data leakage, many countries have created regulations regarding medical data accessibility. These regulations require a unique user ID for each medical staff member, and this must be protected by a password, which should be kept undisclosed by all means. A survey was conducted with the following results:

  • A total of 299 surveys were gathered.
  • The responses showed that 220 (73.6%) participants reported that they had obtained the password of another medical staff member.
  • Only 171 (57.2%) estimated how many times it happened, with an average estimation of 4.75 episodes. All the residents that took part in the study (45, 15%) had obtained the password of another medical staff member, while 57.5% (38/66) of nurses reported this.

Their conclusion from this study: the use of passwords is doomed because medical staff members share their passwords with one another. Strict regulations requiring each staff member to have a unique user ID might lead to password sharing and to a decrease in data safety. Click Here to access the full study.


Remember to Comply With the 3 Pillars of Securing ePHI


The three pillars to securing protected health information outlined by HIPAA are administrative safeguards, physical safeguards, and technical safeguards. These three pillars are also known as the three security safeguard themes for healthcare. These themes range from techniques regarding the location of computers to the usage of firewall software to protect health information. A brief list of the HIPAA Security Safeguards:

  • Access control (technical safeguard) is a technique that prevents or limits access to an electronic resource. The intent behind access control techniques is to limit access to only authorized parties. The healthcare facility collects, stores, and secures patients’ data, which is very sensitive. This safeguard can take the form of role-based access control, attribute-based access control, and identity-based access control. Role-based refers to a person’s role in the healthcare facility. For instance, when a provider begins working at a healthcare facility, he/she has access to patient data, but only the patient data for his/her patients. If this provider also serves on a certain committee in the hospital, then another set of privileges is created to enable access to committee resources. When other data is accessed, a log is created that is periodically audited. When a front-desk clerk begins working in a facility, he/she has no reason to access clinical data, but may need access to the administrative data such as address and phone number, depending on the role that the person plays in the organization. Other names for this are media controls, entity authentication, encryption, firewall, audit trails, virus checking, and packet filtering.
  • Physical access control (physical safeguard) is a technique that prevents or limits physical access to resources. The intent of this control is similar to the technical safeguard: It limits access to only authorized parties. A patient in a facility will not have access to any clinic or ward except the one he/she is seen in. A front-desk clerk in the optometry clinic will not typically need access to the emergency room, so his/her access card will not open those doors. A provider in a facility will not typically need access to the server room, so his/her access card will not unlock those doors. Other names for this are physical security, (some) workstation security, assigned security responsibility, media controls (access cards), and physical access control.
  • Administrative safeguards are techniques that are not entirely technical or physical, but may contain a piece of each. These safeguards typically take the form of policies, practices, and procedures in the facility to regularly check for vulnerabilities and continually improve the security posture of the organization. Other names for this control are risk analysis and management, system security evaluation, personnel chosen for certain roles, contingency, business continuity, and disaster recovery planning.

When Someone Shares a Password – It Is a HIPAA Violation Under the HIPAA Security Rule – Technical Safeguard Related to Access Controls. 

 

The Security Rule defines access in § 164.304 as “the ability or the means necessary to read, write, modify, or communicate data/information or otherwise use any system resource. (This definition applies to “access” as used in this subpart, not as used in subpart E of this part [the HIPAA Privacy Rule]).” Access controls provide users with rights and/or privileges to access and perform functions using information systems, applications, programs, or files. Access controls should enable authorized users to access the minimum necessary information needed to perform job functions. Rights and/or privileges should be granted to authorized users based on a set of access rules that the covered entity is required to implement as part of § 164.308(a)(4), the Information Access Management standard under the Administrative Safeguards section of the Rule.


Unique User Identification Requirement - § 164.312(a)(2)(i)

 

The Unique User Identification implementation specification states that a covered entity must: “Assign a unique name and/or number for identifying and tracking user identity.”


User identification is a way to identify a specific user of an information system, typically by name and/or number. A unique user identifier allows an entity to track specific user activity when that user is logged into an information system. It enables an entity to hold users accountable for functions performed on information systems with ePHI when logged into those systems using audit trails (addressed toward the end of this article).


Regardless of the technology or information system used, access controls should be appropriate for the role and/or function of the workforce member. For example, even workforce members responsible for monitoring and administering information systems with electronic protected health information or ePHI, such as administrators or super users, must only have access to ePHI as appropriate for their role and/or job function.


Sample questions for covered entities to consider:

  • Does each workforce member have a unique user identifier?
  • What is the current format used for unique user identification?
  • Can the unique user identifier be used to track user activity within information systems that contain ePHI?

So, What Can Happen If We Have Insufficient ePHI Access Controls?

Violating HIPAA law 104-191 can be costly. The HIPAA Security Rule requires covered entities and their business associates to limit access to ePHI to authorized individuals. The failure to implement appropriate ePHI access controls is also one of the most common HIPAA violations and one that has caused financial penalties. 


Financial penalties issued to covered entities for ePHI access control failures include:


Anthem Inc. – $16,000,000 penalty for access control failures and other serious HIPAA violations

OCR Imposes a $2.15 Million Civil Money Penalty against Jackson Health System for HIPAA Violations

OCR Imposes a $1.6 Million Civil Money Penalty against Texas Health and Human Services Commission for HIPAA Violations

University of California Los Angeles Health System – $865,500 penalty for the failure to restrict access to medical records

Colorado Medical Center – $111,400 penalty for the failure to terminate access to ePHI after an employee termination and a lack of a business associate agreement

Controlling Access to ePHI: For Whose Eyes Only?


The government HIPAA privacy/security enforcement agency is the Office for Civil Rights (OCR). OCR published the Summer 2021 Cybersecurity Newsletter on July 14, 2021, which states:


The rise in data breaches due to hacking as well as threats to ePHI by malicious insiders highlight the importance of establishing and implementing appropriate policies and procedures regarding these Security Rule requirements. Ensuring that workforce members are only authorized to access the ePHI necessary and that technical controls are in place to restrict access to ePHI can help limit potential unauthorized access to ePHI for both threats.


A recent report of security incidents and data breaches found that 61% of analyzed data breaches in the healthcare sector were perpetrated by external threat actors and 39% by insiders.


Without appropriate authorization policies and procedures and access controls, hackers, workforce members, or anyone with an Internet connection may have impermissible access to the health data, including protected health information (PHI), that HIPAA regulated entities hold. News stories and OCR investigations abound of hackers infiltrating information systems, workforce members impermissibly accessing patients’ health information, and electronic PHI (ePHI) being left on unsecured servers.


Information Access Management and Access Control are two HIPAA Security Rule standards that govern access to ePHI.


Download this newsletter:

Monitor Audit Trails


Audit trails automatically register and record where, when and who accessed the system. They also record what users do when they access the system. This tracks every change in patients’ information and documents it.


Since all the data is logged in the EHR system, it enables users to review the data at regular intervals and flag activities that seem suspicious. Regular reviews can also help correct mistakes caused by human error that could be flagged as a HIPAA violation. An audit trail answers the following:

  • Which patients’ data was accessed?
  • What time was it accessed?
  • Who retrieved the data?
  • Where was the data accessed from?

EHR software can also be set to send notifications to patients when their information is accessed. This way patients can report breaches as soon as they happen.


Conclusion


Create strong policies and procedures, then communicate these rules to your workforce. Enforce compliance through auditing and monitoring. Explain that when an individual allows another to use his/her password to access ePHI, that individual can alter and perform unauthorized functions and not be held accountable. The audit trail points back to the person who is assigned that password. 


Conduct on-going training of your workforce, which needs to include your C-Suite executives (who are not exempt from the rules). To gain the BEST results, conduct additional quarterly training with your front-line managers and supervisors.  Give them tools to incorporate HIPAA training at EVERY department meeting. If you think annual HIPAA training is sufficient, then you simply are not doing enough to protect your patient’s ePHI.


Additional Resources


Weekly HIPAA Podcasts (free) at:

OCR “The Security Rule” on the HHS website:

Train Online in HIPAA Privacy & Security:

Read More