Although the Trump Administration has a $6.194 million budget cut slated for the Office of Civil Rights (OCR), the office which administers HIPAA, compliance will still be enthusiastically enforced, according to OCR director Roger Severino. The Congressional Justification for FY2018 predicts a shift from routine HIPAA investigations to larger actions with sizable fines.
Here’s more on what to expect for HIPAA in 2018:
Fewer, but larger enforcement actions
Director Severino’s goal is to find a “big, juicy, egregious” breach case which could mean they will seek out more complex issues with a broad impact for enforcement. At a conference in 2017, Severino said he hasn’t decided yet on a particular area for increased investigations, but he did mention cybersecurity, ransomware and physical security as possibilities.
OCR plans to mitigate their budget decrease with increased enforcement settlement fines. So, while the department is leaner, it also may be meaner.
Possible new guidelines for medical records fees Current OCR guidance regarding patients’ access to and fees for medical records has garnered concern from businesses. The current method gives HIPAA-covered entities the ability to charge “reasonable, cost-based fees” for records, which has been interpreted as restrictive and adding to the cost of HIPAA compliance. Plus, on top of federal regulations, HIPAA entities also contend with a patchwork of state laws regarding medical record fees. The business-sympathetic Congress may require OCR to provide additional clarification regarding medical records fees to allay business concerns.
States may become more involved With OCR reducing its number of HIPAA enforcements, state attorneys generals have begun to step up enforcement activities to ensure privacy for their constituents. Privacy issues in the medical sector and other areas regarding personal information are increasingly important to the public and state AGs may lead the way to protecting citizens.
CompuTech City remains poised to facilitate medical practices’ efforts to be HIPAA compliant. We take a proactive approach to keeping your data secure and are experts in ensuring your network meets stringent HIPAA standards with device encryption, network security, intrusion prevention, gateway anti-virus, anti-spyware, content/URL filtering.
Let us know if you are interested in learning more about 2018 HIPAA compliance. Find out more about CompuTech City’s Medical Managed IT Services – 800-641-CITY (2489) or www.computechcity.com. Check out our social media: