• Our Partners
  • CarePolicy
  • HomeCareConsulting
  • Digit9X
  • Home
  • Assisted Living
  • Elderly
  • Home Care Agency
  • Home Care Worker
  • Home Nursing
Menu
  • Home
  • Assisted Living
  • Elderly
  • Home Care Agency
  • Home Care Worker
  • Home Nursing
Home » HIPAA audits are not effective at improving cybersecurity: OIG
Elderly

HIPAA audits are not effective at improving cybersecurity: OIG

adminBy adminNovember 26, 2024No Comments3 Mins Read
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


listen to article
4 minutes

This voice is automatically generated. Please let us know if you have any feedback.

Diving overview:

The Office of Civil Rights, which oversees HIPAA enforcement, needs to improve its program for auditing compliance with privacy and security laws, according to a report released Monday by the HHS Office of Inspector General. OIG said that while OCR met the requirement to conduct periodic HIPAA audits, the program was too narrow in scope to effectively assess the protection of an organization's health data and reduce risk. Overall, the audit was not effective in improving the cybersecurity of healthcare companies and their business partners. This is a major concern for regulators and lawmakers as cybercriminals increasingly target the industry.

Dive Insight:

The report analyzed how OCR conducted HIPAA audits from 2016 to 2020 and found that the agency's programs rarely evaluated the law's requirements.

The audit assessed only eight of the 180 HIPAA requirements, the OIG said. These eight requirements include the evaluation of two administrative safeguards under HIPAA's Security Rule, which require covered entities to analyze and manage risks to protected health information.

However, according to the OIG, the audit does not require any physical or technical access to a health care organization's data intended to prevent unauthorized actors, such as hackers, from gaining access to technology systems and exposing protected data. The use of protective measures was not assessed.

“(…) HIPAA audits are narrow in scope and may be used by organizations such as hospitals that do not have physical and technical safeguards defined in the security regulations in place to protect ePHI from common cybersecurity threats. ”, the watchdog said. I wrote this in the report.

The agency's audit program also overlooked ways to address noncompliance, the OIG said. OCR did not require corrective actions from the companies it audited, and it rarely initiated additional reviews when significant problems were found during audits.

The agency also did not monitor the results of its audit program or document the frequency of audits as of 2020, according to the report.

The watchdog organization requires OCR to expand the scope of its audit program, document standards to ensure companies remediate issues found during assessments, and define standards for when agencies should conduct compliance reviews. and proposed determining metrics to evaluate the effectiveness of HIPAA audits.

OCR agreed with most of the recommendations, but added that the agency's budget is small and it has not yet received additional funding or personnel to enforce HIPAA.

The agency's budget remained stable at approximately $38 million from fiscal year 2018 to fiscal year 2020. Meanwhile, OCR received more complaints and reports of large-scale data breaches, and the number of investigative staff decreased by 30% from fiscal year 2010 to fiscal year 2023, wrote OCR Director Melanie Fontes Reiner. To O.I.G.

“These requested additional resources were not received, resulting in a lack of sufficient funds to perform all required operational activities, resulting in HIPAA audits being conducted more frequently, on a larger scale, or with a greater number of people.” We have fewer staff and investigators to conduct them,” she wrote.

The agency disagreed with the OIG's recommendation to document and implement standards to ensure that problems found in HIPAA audits are corrected. OCR argued that the law gives covered entities the option of paying a civil penalty in lieu of resolving an investigation with a remediation plan. The agency added that resource constraints have hindered the implementation of corrective action plans and that HIPAA audits are intended to provide technical assistance rather than make corrections.



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Saudi Arabia's Healthcare Information Systems Market Forecast

May 13, 2025

McHenry County College will host the 5th Annual Healthcare Industry Forum

May 12, 2025

HSCC warns about an increasing number of cybersecurity threats to resource-trained healthcare providers and encourages immediate action

May 12, 2025
Leave A Reply Cancel Reply

Top Posts

Concern about ‘skill decay’ in nurses who leave bedside roles

May 13, 2025

How To Unlock A Windows PC Without The Password?

January 14, 2021
7.2

Best Chanel Perfume of 2024 – Top Chanel Fragrance Worth Buying

January 15, 2021

Is It Safe to Use an Old or Used Phone? Report Card

January 14, 2021
Don't Miss

Concern about ‘skill decay’ in nurses who leave bedside roles

By adminMay 13, 2025

Nurses who move away from the bedside to pursue leadership and management roles are experiencing…

Former CNO appointed professor of nursing

May 13, 2025

Government to ban overseas care worker recruitment

May 12, 2025

RCN chief warns of potential strike action over pay this year

May 12, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to HomeCareNews.us, your trusted source for comprehensive information on home healthcare services. Our mission is to empower individuals and families by providing accurate, up-to-date, and insightful information about essential home care services in USA.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Concern about ‘skill decay’ in nurses who leave bedside roles

May 13, 2025

Kim Leadbeater Confirms Support For Marie Curie Amendment

May 13, 2025

Saudi Arabia's Healthcare Information Systems Market Forecast

May 13, 2025
Most Popular

Concern about ‘skill decay’ in nurses who leave bedside roles

May 13, 2025

How To Unlock A Windows PC Without The Password?

January 14, 2021
7.2

Best Chanel Perfume of 2024 – Top Chanel Fragrance Worth Buying

January 15, 2021
  • Home
  • About Us
  • Advertise with Us
  • Contact us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 HomecareNews.US

Type above and press Enter to search. Press Esc to cancel.