Healthcare Risk Management Quotes John Leardi on HITECH Audits of HIPPA Entities
Buttaci, Leardi & Werner member John W. Leardi was quoted in an article in the July 2024 issue of Healthcare Risk Management titled “HITECH Audits Return: OCR Promised Enforcement Changes for HIPAA.” The article discusses the reopening by the Health and Human Services Office for Civil Rights (HHS OCR) of the Health Information Technology for Economic and Clinical Health (HITECH) audit program. Audits of HIPAA-regulated entities are planned for later in the year and will focus on the Security Rule, particularly the requirements for security risk analyses and risk management.
Leardi, whose clients include physicians and physician groups, clinical laboratories, independent pharmacies, and outpatient surgical facilities, told Healthcare Risk Management that smaller entities may be more at risk than most institutional or large providers.
“My concern here in terms of vulnerability is going to be medium to small practices and independent practices, not part of a health system, not part of a larger institutional system.”
He noted that since the HIPAA Security Rule is about 20 years old, OCR probably wants to update it and the audits may provide some guidance.
“The landscape of how we maintain health information is dramatically different now than it was 20 years ago. A substantial portion of the industry now has adopted electronically based storage as opposed to maintaining manila folders in the office.”
He added, “It’s not surprising that maybe these audits are designed as much about enforcement as they may be gathering data to determine the touch points in industry that are most in need of focus in any proposed rulemaking or adjustments.”
The full article can be read at Healthcare Risk Management (subscription may be required).
- Posted on: Jul 11 2024
