Categories: Healthcare Technology

4 facts about HIPAA and your IT

HIPAA’s rules pertaining to IT are problematic to say the least, but things have become much clearer over the course of the past year. However, there are still a few areas in which your office might not be compliant. This isn’t necessarily through negligence on your part, but rather a lack of understanding as to the requirements. Let’s look at four concerns your practice should know about HIPAA and your IT.

Telehealth and mHealth are not always compliant

If your practice has invested in, or is thinking about investing in, telehealth or mobile health (mHealth), you need to make sure that the tech you utilize is HIPAA-compliant. While most telehealth technology is HIPAA-approved, one or two additional measures might be required to make it compliant. An IT specialist should have no problem making sure your telehealth is up to code.

On the other hand, mHealth might be a little more problematic. While a lot of hardware and apps, including Fitbit and the Apple Watch, are HIPAA-compliant, it is a field that is still very new and constantly changing. Your best bet is to consult with an expert to make sure your mHealth services are following all the necessary regulations.

All info, not just EHRs, needs to be HIPAA-compliant

If your office has individually identifiable ePHI data on site, including information like billing records, appointment information, and test results, they must be kept on HIPAA-compliant devices and servers. A lot of medical practices that use cloud-based storage for their EHRs overlook this fact and opt for low-cost platforms that don’t meet certain minimums. While it’s good to have your EHRs ready to go on the cloud, make sure that your non-EHR data is protected as well. If it isn’t, you could be facing a fine.

Your protected health information notice must be available online

If your practice has a website, HIPAA’s rules dictate that it must contain a copy of your updated protected health information notice for patients to access. If you have a website and this information is not currently posted, rectify this as soon as possible to avoid any problems.

Healthcare business associates must also be HIPAA-compliant

Conformity to HIPAA regulations is not just limited to medical practices, healthcare clearinghouses, and health plan organizations. Any business that has access, electronic or otherwise, to protected health information is also required by law to be HIPAA-compliant. This includes any accounting or law firms you work with that may already be accessing your files electronically to carry out work.

To avoid any potential trouble for your practice or its partners, it is best to ask them if they are HIPAA-compliant before partnering with them. If they aren’t, revoke all data access privileges, and make sure they take action to correct this issue immediately.

Still not sure if you’re 100% HIPAA-compliant? Our team of experts can run the necessary risk analysis and correct issues with your technology that may not be in line with current regulations. Just give us a call today.

Ron Pierce

Recent Posts

Secure, Not Stiff: Balancing Cybersecurity and Usability for Small Businesses

Small businesses can enhance cybersecurity without sacrificing usability by using password managers, MFA, and SSO.…

12 hours ago

Why Disaster Recovery Needs More Than Just a Backup Plan

When most small business owners think about protecting their data, they usually start with backups.…

2 days ago

Stop Downtime at the Door: Customized IT Support and Network Management for Manufacturers

Customized IT support and proactive network management reduce manufacturing downtime, optimize shop floor Wi-Fi, enhance…

4 days ago

Freedom to Focus: Why Month‑to‑Month Managed IT Beats Long‑Term Contracts

Flexible, month-to-month managed IT contracts offer businesses control, predictable costs, local support, robust cybersecurity, easy…

4 days ago

Transparency First: How Open IT Partnerships Build Trust and Long-Term Wins for SMBs

Transparency in IT partnerships builds SMB trust through clear SLAs, honest pricing, proactive reporting, local…

5 days ago

Compliance, Simplified: How Managed IT Services Keep Small Businesses Audit-Ready

Managed IT services by Trinity Solutions simplify compliance for small businesses by managing audits, documentation,…

6 days ago

This website uses cookies.