HIPAA for the Clinician, Part 2: The Security Risk Analysis You’re Probably Not Doing Correctly

HIPAA for the Clinician, Part 2 The Security Risk Analysis You’re Probably Not Doing Correctly Will Evertsen Introduction The questionnaire arrives in your inbox from your EHR vendor. It’s labeled something like “Annual HIPAA Security Assessment” or “Compliance Review Checklist.” You spend twenty minutes clicking

Your Completed Risk Assessment Just Became a Liability

Your Completed Risk Assessment Just Became a Liability Will Evertsen Introduction A data breach hits your practice. OCR opens an investigation. You pull out your completed Security Risk Analysis, hand it over, and wait for the process to run its course. After all, OCR has

Small Practice, Big Target: Why Solo and Group Practices Are Healthcare’s Most Vulnerable Entities

Small Practice, Big Target: Why Solo and Group Practices Are Healthcare’s Most Vulnerable Entities Will Evertsen Introduction You run a small practice. You see patients, manage a lean staff, keep the lights on, and do your best to stay current on clinical obligations. Cybersecurity, if

HIPAA for the Clinician, Part 1: What You’re Actually Responsible For

HIPAA for the Clinician, Part 1: What You’re Actually Responsible For Abstract This is the first installment of “HIPAA for the Clinician,” a series dedicated to cutting through the noise around healthcare compliance and giving practitioners a clear-eyed view of what the law

Your EHR Is Not Your Compliance Program

Your EHR Is Not Your Compliance Program   The call to the EHR vendor’s support line goes something like this: A practice administrator has just received an OCR data request letter and is trying to figure out what documentation they need to produce. Somewhere in the conversation, they ask the support rep

Securing Success: How Cybersecurity Practices Drive Improved Patient Outcomes

Securing Success: How Cybersecurity Practices Drive Improved Patient Outcomes When considering patient outcomes, one of the things that probably doesn’t come to mind is cybersecurity.  After all, that’s computer stuff, not patient stuff.  Or is it?  Patient outcomes are a critical measure of the effectiveness of medical interventions and the overall

HIPAA for the Clinician, Part 2: The Security Risk Analysis You’re Probably Not Doing Correctly