The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
Episode #10 HIPAA Safe Harbor Act
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
The HIPAA Safe Harbor Rule was signed into law January 5, 2021. This bill requires the Department of Health and Human Services (HHS) to take into account whether a practice has had recognized cybersecurity practices in place for the past 12-months when investigating a data breach. Having adequate cybersecurity practices may result in reduced fines if you have a reportable breach. Identify some of the "must have" recognized security practices for your dental office.
Welcome. I'm Leslie Cannon. I'm Mary Gavoni.
SPEAKER_00I'm Linda Harvey. I'm Olivia Juan, and together we are the Compliance Divas. Welcome to the Compliance Divas podcast. My name is Olivia Juan, and I'm one of the Divas. We are so pleased to bring you the topic of HIPAA's new safe harbor rule. We feel that we have spent quite a bit of time sharing information about OSHA, especially the emergency temporary standard, as well as information from CDC regarding protection from COVID-19. However, it's important to recognize that HIPAA signed into law on January 5th, 2021, the safe harbor rule, and this affects your HIPAA compliance. So the Department of Health and Human Services Secretary indicated that we should consider whether a covered entity, such as a dental office, adequately complied with recognized security best practices for at least 12 months prior to an incident, such as a security incident or breach, in order to reduce the amount of penalties imposed and the amount of time it takes to conduct an audit. Now, I hope that you recognize that when a covered entity is disciplined and there are fines imposed, that the amount of these fines are not $3,000 or $9,000. They are into the millions. So we must take this information very seriously in getting into compliance. And what I share with my clients and at the podium is basically what took place is that HIPAA and cybersecurity married one another. And so we must comply with these best practices. And there may be some areas that you're doing very well with your HIPAA compliance program, but now there are additional practices to take into consideration for compliance. Now remember, with the safe harbor rule, this is fairly new. And as the Divas, we bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. So we want you to subscribe to the Compliance Divas podcast through your favorite podcast channel or on our website, the compliance divas.com. But I'm going to let some of my fellow divas do the talking here to give you information. So, Mary, can you share with our audience what are the five main cybersecurity threats that have been identified? Absolutely. Thank you, Olivia.
SPEAKER_02Um, I usually describe many dental practices cybersecurity program as flying by the seat of their pants. I think that so many practices do not take cybersecurity seriously enough. And it can be as simple as an email phishing attack or something we discovered during the pandemic, which was that many of our connected devices, such as imaging devices or um CAD devices that are connected to the internet and connected to our servers and dental practices, are vulnerable as well. So let's talk about for a few minutes about each of these. A phishing attack, which is spelled with a pH to distinguish it from true um wildlife attacking us, is an attempt to validate that you have an active email address and to see if somebody's going to respond to some kind of a stimulus to connect to someone who's trying to get at your data. Now, all healthcare facilities are vulnerable, primarily because, or I shouldn't say, well, they are vulnerable in many cases, but it's really desirable to hack because there's a lot of information to get, a lot of names and social security numbers and perhaps credit card numbers, even that might be stored. So it's um low-hanging fruit, if you will, um to get information quickly that can be used for identity theft and another number of other things. So, how do you know if you're the victim of a phishing attack? Well, the first thing to do is be very, very discreet about opening up email messages from people you don't know. Um if it really truly is a legitimate email and you don't answer the first time, that person may choose to call you on the phone, or they may send you another email that validates their reason for contacting you. But many times these phishing attacks will use some really compelling message like a discount or a gift card or something that entices you to open up that email. And when you do open up the email, again, you're validating that this is a good operational email address, and a number of things can happen. You can have malware downloaded or viruses downloaded onto your computer because of it. Um, you can then have a ransomware attack because of it. And a good way to detect whether something is legitimate, um, because many of the dental practices will use FedEx and UPS and the postal service for shipping lab cases and so forth. And many times phishing attempts are disguised as messages from those shippers. So, what you have to do is just hover your cursor over the email address that it's being sent from. And unless it says FedEx.com, then it's not legit. A lot of times it's some hacker's personal email, and that's the tip-off right there. And you should send it immediately to your spam folder or make sure that you have adequate security on your email to filter out as many of those phishing attacks as possible. Ransomware attacks is what we've been hearing so much about in the news that shut down the pipeline on the on the East Coast and the meatpacking plants in the Midwest. And now uh IT services have been hacked with ransomware. And so, what a hacker would do is gain access to your computer and in particular to your server and encrypt the data or block you from getting your data from your server. And what they want you to do, of course, is pay them money for them to unencrypt it for you. And most of the time the data's gotten corrupted when they do, because they don't really care what they do to your data, they just want the money and they're gonna run. Um, so they may have already corrupted that data for you. So even if you pay the ransom and get access to your data again, it may not be usable. So one of the things that um I think Linda or Leslie are gonna talk about is how do you protect yourself from that? But even something as simple, not really simple, but um having your server stolen from your office. And we've seen numerous incidents of that called smash and grabs. Somebody breaks in, takes the server, and goes. Um, somebody loses a laptop that has patient information on it or an external hard drive that's used for backup. There are times when, through either power failures or hard drive failures, server failures, that data can be lost unintentionally or accidentally, or sometimes people do it intentionally if they're a disgruntled employee and they want to wreak havoc on an employer who believes that or that who they believe has done something wrong to them, they they um compromise the the data. So there need to be safeguards in place to prevent that. And as I mentioned earlier, one of the vulnerabilities that was discovered during the pandemic was the fact that many of our medical dental devices that we use, whether it's a CBT, CBCT machine or uh uh milling machine or anything that's connected to the internet imaging devices, can also be hacked and there can serve as a pathway to the server. So those are the five main things that I would identify. And if anyone else has anything to add to that, I am open to it.
SPEAKER_00Thank you, Mary. That's so helpful to identify these five main cybersecurity threats. So even if you are contracting with an IT professional and you have a firewall in place, we recognize that building that human firewall is critical. And that involves training, simulations, and that daily awareness of how our practices could be uh vulnerable to an attack. But there's a difference between policies and practices and looking at some of these cybersecurity practices. Linda, can you identify the 10 cybersecurity practices that dental offices should consider to have in place?
SPEAKER_03Absolutely, Olivia. This is so critical because on one end of if we think of security and cybersecurity in specific as a continuum, on one side of that continuum are the threats that Mary just discussed. And then we want to be on the far side of that continuum with these cybersecurity practices. And we may call them best practices, but they are required to be in place now because of the safe harbor rule. And if a practice, the covered entity is not compliant with the safe harbor rule and following these cybersecurity practices, then they won't be able to claim the safe harbor um safe harbor um section of that law and be able to have their fines and penalties reduced in nature. So while I list these 10 things for our listeners, uh please be mindful of this may but make your eyes swallow back in your head because security is a very difficult involved topic. It's only gotten more challenging and more um involved in our own lives all the time, as far as you have the depth of how we're using security and the different ways that we're using different types of electronic programs in our personal and professional lives. So here are 10 cybersecurity practices, and then I'll go into a couple of these in more detail. Email protection systems is one, two, endpoint protection systems, three, access management, four, data protection and loss prevention, five, asset management, six, network management, seven, vulnerability management, eight, incident response, nine, medical device security, and ten, cybersecurity policies. So that's a lot to make us all just feel overwhelmed and not understand what we're supposed to do and end up doing nothing. So let's not end up in an analysis paralysis situation. Let's take a few of these, look at them in just a few more details, and then please know that subsequent podcasts will go into other areas of network security to help you unravel some of these complex situations. So let's look at email protection systems. Mary mentioned phishing attacks being one of the major cybersecurity threats. So to protect yourselves, the low-hanging fruit for this practice would be to be sure that you have a qualified thorough investment in a paid email subscription program that will adequately provide the safeguards you need when data is in transit. Because anytime you are emailing patient data to another practice or another practice is emailing data to you, both sides of the that equation, both of you should be using encrypted email systems. So using a free email program or free encryption email program is probably not the best idea. We all know the phrase, you get what you pay for when something's free, and nevertheless, there won't be the adequate protections. The free systems are updated the least often, and the hackers all know the vulnerabilities in those free systems to begin with. So, second, let's talk about endpoint protection systems. In a dental practice, we have so many different devices that are connected to our patient database and our server, or if we're using a cloud-based program. And it's important that we look at what's called endpoint protection system. This is where your qualified IT partner can help you with the end user devices. These are the desktops, your laptops, and even your mobile devices and tablets, for example, that are used routinely in dental settings. How are those being made secure at the user level? So there's no ability for a hacker to find them, that they're not, they're hidden behind the firewall, for example, and they have all the security protocols in place. This is a good question to have with your IT partner to ask them about the endpoint protection systems in your practice. Third one that I'd like to mention a few points about is network management. And that's simply managing all the different devices on your system and your backup systems, your server, all those different parts of your computer network. And it's really important for our listeners to grasp the concept of having a qualified IT partner that really not only just understands security, but understands and knows and is compliant with the HIPAA laws. Back when the omnibus rule and the HI-Tech Act were passed, it wrapped business associates into being compliant with HIPAA, just like covered entities. So it's important that your IT partner understands that they have a stake in this as well, because they can be fined and penalized for not being compliant themselves. So, as Mary said, a lot of offices are running by the seat of their pants when it comes to their network security and being diligent with cyber threats. And one of the ways that I like to describe that is the fact that if the doctor is still doing his or her own IT, they're running by the seat of their pants. Having a qualified IT company as your partner is so very important. And that brings us to a topic we've mentioned in the past related to budgeting for compliance and having that budget for compliance in place is really important. I'm aware of something, Olivia, that I think is very interesting and that I want to share with our listeners. And I don't know if any of the other divas have seen this, is that some IT vendors will have their customers sign a waiver of declination when the practice or covered entity doesn't want to have all the cybersecurity practices. And so once the doctor signs that, then the IT partner says, Well, you said you didn't want a separate firewall. You said you didn't want that paid antivirus program, or you didn't want this new uh level of security that we're offering. And now it's important for the doctors and the teams to recognize that now you have documentation of your noncompliance that could possibly be used against you in any type of security breach situation. So, that being said, it brings us back then to our last point under the cybersecurity practices that I'd like to address, and that is our policies and procedures. Many times over, I feel like, Olivia, that our teams get focused on where's the manual? They have to have a binder. And they're looking at this manual as on a shelf, and we we call it elf on the shelf because it's like that little elf at Christmas that sits there and maybe gets moved around a little bit, but it's collecting dust. And it may not be complete, it may not be customized to the practice. And we've all, divas, we've all gone into offices where the office has bought a binder, it's still in shrink wrap, and they haven't opened it for months to even know what's in the binder. So, one of the things that's important about policies and procedures is that this is your legal protection for your practice. And I'll I'm gonna talk about that more a little bit later, Olivia. But I just want to mention that having customized cybersecurity policies on how you're handling email and backups and passwords and all that aspects of security needs to be documented. So it's very important.
SPEAKER_00Mary, would you like to add to some of the great things that Linda shared? I would.
SPEAKER_02I wanted to go back to one of the very first things you shared, Linda, about um email protection systems because so many practices love to have free email accounts for the practice. You know, it's dr lindaharvey at gmail.com and gmail, the free accounts are are not secure, and they're also not helping you to brand your practice. So, one of the best resources for secure email accounts is through your website hosting service or your IT security, and that you have a domain name for your practice, and that domain name is part of your email address, just like we've done through the compliancedevas.com or you know, abcdentalpractice.com. And then you can put all the protection services that you need on that, plus you're branding your practice at the same time.
SPEAKER_00Thank you, Mary. Great information. And just like with my practice, we use Google, but it's a paid version of Google. And so there's a level of security when we are emailing each other within my account. So if I'm emailing an employee, there's a level of security. But if we are emailing outside of that account, you lose that security. So as Linda mentioned, we have to look at if you are emailing information that has protected health information, we must add encryption on top of that. So even if you have paid email accounts, then we still have the obligation to encrypt data when it's being transmitted. And so I also loved how Linda pointed out about having qualified IT professional. That resonates with me really well. So even within my practice, we contract with an IT professional that I have on retainer every month. I pay a fixed fee because I don't want to be waiting if I have a security concern or something is not working. So there's a contract in place, which is one of the things that's part of our compliance, so that we have the resources to go to. So, Leslie, who in the world is NIST and how does that affect dental practices?
SPEAKER_01Well, thank you for asking, Olivia. Um, I like to equate NIST with uh ANSI. So, example, everyone's familiar with OSHA regulations requiring uh protective eyewear and uh protective eyewear of various types, whether it's for uh biological fluids or for impact or for uh for radiation. So we have uh laser tearing lights and whatnot. Um, OSHA relies on ANSI standards, American National Standards Institute. Uh rather than saying we approve this eyewear, they go, it meets ANSI standards, so therefore it's considered protective eyewear. NIST stands for the National Institute of Standards and Technology. Now it's kind of interesting. It got its beginning in 1901, and it's part of the US Department of Commerce, but it's not a regulatory agency, not like OCR is. So, in order to help these organizations manage their security risk, NIST has these best practices that can be followed by a small healthcare provider. NIST worked with the private sector and government experts to create a framework. And while it was released back in 2014, The effort went so well that Congress ratified NIST as a responsibility in the Cybersecurity Enhancement Act of 2014. Now, the framework, this is where it kind of boils down to our listeners. It integrates industry standards and best practices to help dental practices manage their cybersecurity risk. And it provides common language, thank goodness, common language that allows staff at all levels within an organization and at all points, like in a supply chain to some of the other cybersecurity threats that we've heard of to the food industry and to the fuel industry to develop a shared understanding of their cybersecurity risks. So let me go through with you what those points are. The actual framework is based on five fundamental elements: identify, protect, detect, respond, and recover. What does this mean for a dental practice? Well, uh, to identify, we make a list of all of our equipment, our hardware and software, uh, laptops and uh smartphones and devices that are used by the practice. As Mary mentioned, we have the Internet of Things, we have milling devices, we have uh imaging machines, the cone beam technology. So all of these different devices, we identify them. Number two, protect. We control who logs on to our network and uses our computers. We also have security software, as Linda mentioned, that we have maybe some endpoint protection to protect the data. We can encrypt data where possible. We encrypt our computer servers. So this grab and run of a server, uh computer server isn't going to do someone any good if our if our data is encrypted. Same with our backup drives. We conduct regular backups, which is uh not only making sure that uh the backups are done, but they're done properly and that the data is restorable. We also need to have formal policies in place and update our software regularly, plus train everyone on anyone who touches our computers in our practice in our network about cybersecurity. It's so important. Number three is detect. We have to monitor our computers for unauthorized access. We also need to check our network for unauthorized users or connection, and that's where your partnership with your IT company will help you to identify unauthorized uh attempts to access your systems. And then if something does appear to be uh perhaps an attack on your computer system to investigate any unusual activity on your network so that staff knows if something looks unfamiliar to them, something doesn't seem to be working right, to immediately bring that to the attention of your HIPAA officer in your practice and your IT partner. Fourth is to respond. You've got to have a plan. In the event that you do have a breach, you've got to notify patients. Employees need to know that there's a potential breach that took place. And we also need to be able to keep our business systems up and running, which might be hard if we've uh been attacked with ransomware where our systems are locked down or encrypted. Uh, then we also have to make sure that we investigate and contain any kind of attack. Again, your IT partner and your cybersecurity partner, uh, which again is a different uh company. Many times you'll your IT partner may partner with a cybersecurity company to keep your system safe. And then uh develop policies, update your policies with any lessons learned if you've had an attack. And then finally, probably the most important thing, because the bottom line, the one-line bottom line is that the patient's data needs to be recoverable. And uh really that's what HIPAA is all about is that patients have access to their protected health information, that we take good care of it. And if something were to happen to interrupt the access to that, that we can restore it. So we have to be able to recover and restore our data immediately. Uh, many uh dental practices rely on uh either uh backup drives or services that might take them up to two weeks to fully restore all that data for as many patients as they have. So again, it's important to uh be closely connected with your IT company to make sure that you can work as efficiently as possible. Because I think one of the biggest detriments besides citations from Health and Human Services or Office for Civil Rights is the downtime that a dental office would experience as a result of an attack. Olivia?
SPEAKER_00Thank you, Leslie. And not only the downtime, as you mentioned, but it really affects the credibility of a dental practice when there's been a breach and patients receive a notification that their information may have been jeopardized. And so, really, a lot of good information that we're covering in this podcast, having identified the five main cybersecurity threats and also identifying the 10 cybersecurity practices. But, Mary, how in the world does a practice actually demonstrate compliance?
SPEAKER_02Oh, such a great question. And there are three key ways. Number one is training of employees and doctors as well, so that everyone on the team understands what are the HIPAA rules, the privacy rules, the security rules, the breach notification rule, and now the safe harbor rule. What do those all mean and how do they apply to us? And that training should be done for new employees as part of their onboarding process. And even if an employee says, Oh, I've had HIPAA training before, you don't know how thorough that training may have been. You don't know if they actually understood what was presented to them in that training. So I would make it clear to any new employee that they will need to have a certain level of HIPAA training and that it should be validated so that they complete a post-test or quiz to answer some um pertinent questions about that to make sure that they have a good level of understanding. And then it is developing policies and it's beyond, as Linda said, it's beyond the manual on the shelf in the shrinker app. Um, it has to be specific to your practice, but it has to be what you do every day to protect the patient's protected health information and protect your livelihood, basically, because if you lose that patient health information, you have a very difficult time treating patients. The one key thing that HIPAA looks for if they if you're selected for a random audit or if there's been a complaint against your practice is documentation that you've done and annual risk assessment. And this is typically in the form of a questionnaire that you answer all types of questions that apply in several areas, both administrative and physical and technical areas of your protected health information, your patient database. And that if you identify with the help of your IT support company, if you identify any shortcomings, that you know what those are and make a plan for fixing those, because you can't just fill out the same questionnaire year after year after year and say, yep, this is a risk for us. We don't change our passwords often enough, and you don't do anything about it, then you certainly can be cited or fined by the Department of Health and Human Services for not mitigating that particular risk. And there are many resources for these security risk assessments. You may do it with a consultant, um, you may do it on your own. Um, the Department of Health and Human Services has an online-based security risk assessment that you can complete, but you need to dedicate some time to it because there are a lot of questions that you need to answer. And again, it needs to be done annually, and you need to document that you did it, and also document that you at least have a plan and have attempted to fix any deficiencies that you have identified.
SPEAKER_00Thank you, Mary. Great information on how dental practices can actually demonstrate compliance, which is a key component. We talk a lot about HIPAA compliance, we provide training, and I know that Linda, you write policies for practices, as do I in helping dental practices align themselves with HIPAA. But how can you explain the difference between having a policy in place versus a practice?
SPEAKER_03Olivia, that's very important for doctors and team members to understand the difference in those because this is so important for to meet the legal requirements to be compliant and to protect themselves legally from fines and other issues, such as say cyber threaten attacks and so forth. So a policy is actually a written document. It's it serves as a guideline or sets a course of action that the staff is going to follow what this policy says. Um, very much like you would have infection control in your HR policies, the guidelines that you follow. So in your HR policies, for example, team members look up how long do I have to be there before I qualify for vacation? That's a policy. Or what are our sick days? What are our vacation days? Those are policies. So likewise, with all the required topics in the privacy rule, the security rule, and the cybersecurity list in these areas, we need to have all the policies written and written down because just like our patient records, if your policies and procedures aren't written down, then it didn't happen. So I use that analogy all the time because it really relates a dental practice to what they're working in day in and out, which is the patient record, and making sure it's it's adequately updated and properly documented. So you can bill the patient, you can code bill the insurance, and you have that continuity of care and that legal documentation. Same principles apply to your policies and procedures. So, on the other hand, then your practices, think of those like your work processes, how you carry out something throughout the day. And it's extremely critical that your work processes follow and align with your policies. So, for example, if you have a policy that you're going to encrypt patient emails when emails with patient data is included, whether it's protected health information or even personally identifiable information, and you're not following your policies, so you're not in compliance with your own set of actions and to be compliant with the federal laws. So it's very important to understand the distinction those two and to help listeners to think about it even more in a day-to-day fashion. Think about a dental practice where a doctor has a policy on how he or she wants their instrument set up for different procedures. And then that has to be set up the same way in the cassette or the bags or laid out on every, you know, on the bracket table. But how the dental assistant sets up the room may be his or her own process to meet that goal for the doctor. So we could use something along those lines from a dental perspective and a day-to-day technique that we follow to be the similar process and concept for following your policies and making sure that you're living them out with your practices, because it boils down to five key words, Olivia. What does our policy say? So anytime there's a question or concern, we should be looking at any policy, whether it's your OSHA, infection control, HR, and including HIPAA.
SPEAKER_00Mary, uh, what would you like to add to Linda's information?
SPEAKER_02Linda, you did such a great job of explaining the difference between the policies and the practices and why they're so important. And so many practices have purchased uh a HIPAA manual from the ADA or another dental organization. And their understanding is that as long as they take the template and they fill in the practice information, the name, the address, and so forth, that they're good to go. But as you stated so succinctly, that has to be customized for what they actually do in the practice. So I loved what you said about what does our policy say, because sometimes that's a surprise if somebody's in the middle even of an OSHA inspection or a HIPAA audit, and somebody describes what their practice is, and the auditor or the inspector will say, but your policy says this, and we don't want that to happen.
SPEAKER_03Mary, to piggyback off that, um, I think it also comes down to you know what you said with the risk analysis too. It can't be cookie-cutter year after year, like he's mentioned, it but it may you may start off with a questionnaire. And I know some of the um preset manuals that are purchased on the market have a questionnaire, they call it a risk assessment, but it's not truly a risk analysis of all the of the different security aspects of their practice. And so making sure that they look at something that's even more customized as time goes over. And like you said, they could use the uh it's the hippie.gov website, hippahit.gov, which is a very complex process to fill out. But if an office takes time, they could certainly do that, but not relying on the same risk analysis over and over again, especially if they're not even resolving the issues that they found.
SPEAKER_00That's so true, Linda. I know that when my office conducts a risk assessment, that's one part of the process to go through and analyze the different aspects of security. But a very important part of that piece is the work plan. What is the work plan generated out of that security risk analysis so that that dental practice has a roadmap to make the necessary changes? And then the following year, when they repeat this process, have they adequately addressed what was in their work plan? And that's why it's really a living document, so to speak, this risk analysis process, because what may have been on last year's assessment may be different than what's what's on our new assessment based on some of the threats that have been identified or some of the new technology that's available. And so one of the divas mentioned about the Office of Civil Rights guidance for the risk analysis. There's actually a free tool online. Uh, I actually took my practice through that process to compare. It is pretty lengthy and daunting, but guess what? It's free. Um, I don't know how current it has been since it's last published, but as I mentioned, this is a wonderful resource to get you started and to start identifying some of these weak links in your practices so you can make some positive changes. So we will make that available on the compliance diva website. We really enjoy bringing this information to you. As the compliance divas, we bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. Please subscribe to the compliance diva podcast through your favorite podcast channel or on our website, thecompliancedeevas.com. And as I mentioned, not only are we bringing you information to save you time, but we're also publishing the resources that we actually use in our individual businesses to help your dental practice. So once again, thanks for tuning in, and we look forward to seeing you next week.