Compliance New Year’s Resolutions

As we turn the page on what can only be described as a “one of a kind” year we have a tremendous opportunity to look back at 2020 and really evaluate how the compliance program performed, and where 2021 might provide some opportunities to improve, change direction or re-tool the program. The pandemic forced providers […]

Consider the Annual Review of Compliance Policies in a New Light

As part of the annual compliance program plan of work, nearly every provider includes a review of the policies that make up the program.  You may not want to admit it for your organization, but typically that annual review of policies takes about 5 minutes when the compliance officer asks the members of the compliance […]

Do I Have to Report This as a Breach?

One of the most common questions I get is whether a particular disclosure constitutes a breach that requires notification to the individual and completing a breach notification report with the Office for Civil Rights.  No one likes to “fess up” that their organization has had a breach; consequently I see organizations doing some pretty interesting […]

The Hits Just Keep Coming!

On November 6, 2020 the Office for Civil Rights issued a press release announcing the settlement of its Tenth investigation under the Right to Access Initiative. I have written about this initiative before in this blog but in light of the fact it seems like there is a new press release on the subject every […]

Dynamic and Evolving

In June 2019, when the Criminal Division of the Department of Justice, (DOJ), updated its guidance document on how prosecutors are to evaluate an organization’s compliance program, (Evaluation of Corporate Compliance Programs), one theme comes through loud and clear.  Compliance policies, procedures and controls should never become stale or stagnant.  Rather, the DOJ takes the […]

The Sequence is Important

Compliance program, policies, procedures, Code of Conduct

As I write this blog post I am watching the crew working on the road in front of my office. It has been a long 5 months, yes COVID has impacted us, but we have also been unable to get into our office parking lot due to a complete reconstruction of First Street where our […]

Dust Off the Code of Conduct and Bring It Back to Life

Most every compliance program has a document called the Code of Conduct, Code of Ethics or some other title that indicates the organization’s “commitment” to doing the right thing. Typically the document was drafted when the compliance program was first developed, and likely has not received much attention since then. It may be printed in […]

“Systemic Noncompliance” – The New OCR Buzz Phrase

privacy, security, HIPAA, compliance, OCR, fines, penalties, health information

On September 21, 2020, the Office for Civil Rights (OCR) issued a press release announcing a $1.5 million settlement with Athens Orthopedic Clinic.  The basis for the breach report that led to the settlement was the fact a journalist notified Athens Orthopedic a database of their patient records had been posted online for sale.  Two […]

What is the Role of Reflection in Compliance?

There is no way to deny the fact life seems to move faster each and every year. New and exciting technology allows us to cut the amount of time it takes to do everything from downloading a movie to our phone to fixing dinner. The ability to obtain reams of information has never been easier. […]

The Value of Stepping Back and Looking in the Mirror

Reflecting on the effectiveness of a compliance program

Michael Gerber wrote a book about being an entrepreneur called “The E Myth” in which he emphasized the importance of working “on” the business and not just “in” the business.  The point of his recommendation is that often, when we are deeply embroiled in the day-to-day operation of the business, we often lose sight of […]

Recent HIPAA Enforcement Actions Send a Clear Message

In the last week the Office for Civil Right (OCR) has issued press releases on two enforcement actions which involve very different types of providers but send a consistent message regarding what is expected in terms of HIPAA compliance. July 23, 2020 – Metropolitan Community Health Services, a Federally Qualified Health Center serving an impoverished […]

I hear you knocking….

At some point in time every organization will face a search warrant, receive a subpoena for records, or a request from a law enforcement official for copies of medical records. Not responding appropriately, and not knowing the difference between a search warrant and a subpoena can have a detrimental impact on a health care organization. […]