HIPAA Privacy & Security

Create an effective compliance program to identify your organization’s level of compliance and prioritize areas of improvement.

Your privacy and security matter.

Today, it’s not a matter of if your IT will be compromised, but when. You must build cyber resilience, the ability to recover and return to normal operations quickly, to protect your IT environment and minimize loss in that inevitable breach.

Data confidentiality is one of the greatest risks you face. Any breach or noncompliance can lead to substantial fines and reputational damage. In addition to the confidentiality concerns that patients have, other stakeholders need assurance that your organization complies with laws. Our HIPAA risk assessments rank privacy and security issues by risk and difficulty, providing you the context to prioritize issues to manage the appropriate protection of electronic health information.

Be proactive and take action to reduce risks and improve your organization’s compliance and security.

Risk of Compliance

Compliance does not ensure protection from all threats; it is just a minimum requirements baseline. Mandatory regulations are designed to protect patient data. As technology advances and your organization continues to grow, a compliance mindset puts your organization at risk. You must do more to protect your patient data, connected medical devices, sensitive corporate data, operations and reputation.

HIPAA

The U.S. Department of Health and Human Services Office for Civil Rights has proposed recent changes to improve HIPAA’s care coordination and better enforce existing policies through increasing enforcement actions in the form of fines.

Patients can now request access to their confidential medical information and expect to receive it in 30 days or less, barring a special exception.

To mitigate the fear of responding too late to information requests, organizations ask third-party applications to help share patient information quickly, resulting in unexpected risks and data breach incidents.

What We Do

  • HIPAA security risk assessments
  • HIPAA compliance gap analysis
  • Comprehensive evaluation of compliance effectiveness
  • Compliance risk assessment
  • Compliance access to information assessment
  • Privacy and security documentation assessment
  • Privacy risk assessment
  • Audit business association agreement
  • Audit business association process

Cybersecurity & Assurance

New applications, devices, vendor connections and even new employees introduce risk and increase the complexity of compliance. We examine your internal control structures, staffing and procedures to offer remediation options and internal controls to reduce IT risks.

Almost everything you do in healthcare can be improved through information technology. While you must take advantage of technological advancements, you also must comply with privacy regulations and maintain strong cybersecurity practices to protect your business data and operations.

Our collaborative, proactive approach to strengthening cyber resilience allows you to leverage technology to improve patient care, power innovation and grow your organization.

Insights and
Resources

SCOTUS, Chevron Deference, and the Future of Healthcare Fraud and Abuse Law

On Friday, in a striking blow to 40 years of administrative law doctrine, the Supreme Court overturned the “Chevron deference”. Previously, this...

READ MORE

Market Dislocations: Bid-Ask Spread and Risk Premium in Healthcare

We have been hearing about a “bid-ask spread” issue in the lower middle market healthcare space for a significant time, and I wanted to discuss...

READ MORE

The Good, the Bad, and the Uncertain News of the 2024 Medicare Trustees Report

Each year around April or May, the Trustees of the Social Security and Medicare Trust Funds release their accounting of the current, short-term...

READ MORE

Navigating the Healthcare Investment Market

With the first quarter behind us, we want to share some insights after talking with several healthcare investors since the beginning of the year....

READ MORE

Designated Health Services Profits: Rules and Regulations

Effective January 1, 2022, the Centers for Medicare and Medicaid Services (CMS) implemented major changes to the Stark Law regulations. The Stark Law...

READ MORE

Comparison of Private Equity-Type Transactions versus Hospital-Type Transactions

Private Equity, an exclusive asset class, attracts accredited investors due to its impressive returns and illiquid nature. It plays a significant...

READ MORE

READ MORE OF OUR LATEST INSIGHTS

SEE AROUND CORNERS.
INDUSTRY EXPERTISE DELIVERED.

Acceleration & Growth

HORNE’s acceleration and growth services help you stay ahead of the change with our technology, people, process and experience solutions.


READ MORE

Talk to an expert today.