Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Insider Threat Example: Former Cox Employee Sent To Jail (And More) For Hacking System | Main | Social Engineering Schemes Increase: Great Case Study From An Actual Event »

CMS Announces Plans To Actively Audit Hospitals For HIPAA Compliance

The U.S. Centers for Medicare and Medicaid Services (CMS) announced last week that they plan to audit 10 - 20 hospitals for HIPAA compliance in the next 9 months according to a Government Health IT article.

Last week I blogged about how the CMS had contracted with PwC to perform HIPAA audits between September 2007 - September 2008.

The article indicates PwC will "help with the reviews."

Perhaps the PwC auditors will provide some on-the-job training to the CMS auditors so they can eventually start doing the HIPAA audits themselves.

According to the Government Health IT article

"Until now, the agency has focused on outreach and education to promote compliance with the rules, said Tony Trenkle, director of CMS’ Office of E-health Standards and Services. After the reviews, CMS will publish the results and the lessons learned about data security issues in organizations that have individuals’ health information. However, Trenkle said, CMS will not publicize the names of the organizations reviewed."

Hmm...

I can certainly see reasons for not publishing the names of the organizations *IF* the results of the audits would put the patients at risk. However, until we see what the CMS will actually report...and how long it takes them to report the results following the actual results of the audit...it cannot be determined if this will be reasonable or not.

I certainly don't want to see patients and their personally identifiable information (PII) put at risk by the CMS providing too much information from the audits to the public. However, on the other hand I think the public should be aware if the hospital they go to has poor security and privacy practices so that they can do whatever they can, and ask the questions they need to ask their doctors and nurses, to help protect their privacy and secure their PII.

If the regulatory oversight agencies won't strongly enforce security and privacy laws, then the public must be sure to ask their medical providers what they are doing to protect their privacy and secure their PII, and then hold them to it.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/632

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold,CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for over 18 years. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the 25 top privacy experts and on their list of the 9 best privacy consulting firms. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 11th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.