Tips for complying with HIPAA Omnibus Rule.

PositionPRIVACY

September 23 marked the compliance deadline for the Health Insurance Portability and Accountability Act (HIPAA) Omnibus Rule that makes business associates accountable for any misuse or failure to safeguard protected health information (PHI).

In a September press release, Karen Carnahan, president and COO of Cintas Document Management, said such HIPAA violations could result in penalties of up to $ 1.5 million each and that non-compliant companies "risk long-term damage to their reputation and brand."

To help achieve compliance under the Omnibus Rule, Cintas offers these tips:

  1. Retrain employees on the updated policies and procedures addressing privacy, security, and PHI breaches.

  2. Inventory vendors and look closely at their associates and subcontractors who handle PHI.

  3. Update your business agreements. The Department of Health and Human Services has posted a sample version of a revised business associate agreement on its website.

  4. Review internal policies and procedures to ensure they reflect the changes made to the HIPAA Privacy Rules. Revisions should reflect changes to the definition of PHI and to the rules governing patient access to records; disclosures to third parties; research; marketing; fundraising and the sale of PHI; notifications to those involved in a patient's care; and...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT