Top Banner
HIPAA IT Pitfalls to Avoid in 2015 Understanding Compliance & Exceptions Brad Spannbauer Director, Product Development eFax Corporate® [email protected]
26
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

HIPAA IT Pitfalls to Avoid in 2015Understanding Compliance & Exceptions

Brad Spannbauer

Director, Product Development

eFax Corporate®

[email protected]

Page 2: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

The information provided in this presentation does not constitute, and is no substitute for, legal or other professional advice. We strongly encourage you to consult your own legal or other professional advisors for individualized guidance regarding the application of the law to your particular situations, and in connection with any compliance-related concerns.

Page 3: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Are you HIPAA compliant or not?

Page 4: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Today’s Agenda

• 7 common incorrect HIPAA assumptions

• Putting it all together:– The Conduit Exception

– The BAA: Does it transfer your responsibility?

– The Encryption requirement

• So, are you compliant or not?

• Q & A

Page 5: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Document Concerns

Page 6: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

More Questions Than Answers?

Page 7: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

HIPAA Misconception #1:

Our vendor’s service is HIPAA

compliant…

so we’re HIPAA compliant. Right?

Page 8: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

HIPAA Misconception #2:

Our vendor signed a BAA…

so we’re covered. Right?

Page 9: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

HIPAA Misconception #3:

We don’t use cloud services…

because they’re not secure. Right?

Page 10: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

HIPAA Misconception #4:

Our corporate policies restrict access to

PHI… so we’re in compliance. Right?

Page 11: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

HIPAA Misconception #5:

We use an in-house fax server, so our transmissions

are… secure behind our firewall. Right?

Page 12: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

HIPAA Misconception #6:

Our EHR system has a well-documented audit trail…

so a document-sharing policy would be redundant.

Right?

Page 13: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

HIPAA Misconception #7:

Our email provider offers TLS encryption…

so we’re secure sending email

attachments. Right?

Page 14: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Putting the Pieces Together

Page 15: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Fax for PHI

Page 16: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Putting It All Together

The Conduit Exception

Page 17: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Conduit Exception Scenario #1: Hosted Fax Without Archiving

The Conduit

Exception

HOSTED FAX

Page 18: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Conduit Exception Scenario #2: Hosted Fax With Archiving

The Conduit

Exception

HOSTED FAX

Page 19: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

A BAA Doesn’t Transfer Responsibility to Your Vendor.

It Means You Share Responsibility.

Page 20: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

We Recommend Sending Encrypted Notifications, Not Documents

HOSTED FAX

Page 21: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Consider Data Encryption to be a de facto Requirement

It’s definitely Best Practice

Page 22: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Data Security is Key for Patient Records

Both at Rest… and in Transit

Page 23: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate
Page 24: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Next Steps

• Read “7 HIPAA Compliant Assumptions”http://www.hitechanswers.net/7-hipaa-compliant-assumptions-can-trip/

• Whitepaper: “Is Cloud-based Faxing Right for You?”

• 30 day free trial offer.

Page 25: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Q&A

Page 26: HIPAA IT Pitfalls to Avoid in 2015 - eFax Corporate

Thank you for your time.

enterprise.efax.com