The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
#194 HIPAA Must Haves for 2025
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
This year promises to bring many changes related to HIPAA compliance. In this episode, the Divas present three must have's for every HIPAA compliance program. Ensure that you have the basics in place in order to be prepared for the coming changes.
- HIPAA Security Rule Notice of Proposed Rulemaking. https://www.hhs.gov/hipaa/for-professionals/security/hipaa-security-rule-nprm/factsheet/index.html
- Guidance on Risk Analysis: https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html
Welcome. I'm Leslie Cannon. I'm Mary Gavoni.
SPEAKER_02I'm Linda Harvey. I'm Olivia Long, and together we are the Compliance Divas.
SPEAKER_00Welcome to the Compliance Divas Podcast. This is Linda Harvey and I will be your moderator for this session. As the Compliance Divas, we bring clarity and simplicity to compliance by navigating the regulatory world to keep you on course. We invite you to subscribe to our podcast through your favorite podcast channel or on our website, thecompliancedeevas.com. Any of the resources that we mentioned during today's program will be found in the show notes, and we invite you to submit questions to support at thecompliancedivas.com. Well, today we have an interesting topic, and it's the topic of HIPAA. And the Divas are going to talk about three must-haves for compliance in 2025. And we're going to talk about it at a high level because there are some changes coming with the security rule, and the Divas will talk about that at a different time when it becomes effective. But going back to the beginning for just a moment, when we talk about HIPAA rules or HIPAA in general, we have to bear in mind that that's a compilation of four different laws. The privacy rule that became effective in 2003, which established national standards to protect persons and medical records and other protected health information, particularly in written and verbal format. Then the security rule followed in 2005 that set the national standards for protecting electronic protected health information. And that's where the acronym EPHI initiated. Then following that, in 2009 and 2013, where the HI-TEC Act and the Omnibus rule, which updated some of the extensions of HIPAA to reach business associates and strengthened the penalties for violations under the HIPAA laws. But today we're going to talk about three bus halves that are basics. So if you have these in place, then as you build upon the new requirements later this year for the security rule, you will be at a good compliance place to start. So, Mary, if I could ask you to kick us off and let's talk about training. You know, training for our teams, when it should happen. What's the difference between recorded versus live, for example?
SPEAKER_01Well, training is central to almost all of the regulatory issues that we deal with. It's of course very important to OSHA and it's very important to HIPAA so that employees andor employers understand what it is that they are supposed to do. They understand the risks of not doing complying with certain things, and that they understand all the whys of the requirements. So training can should be done or must be done according to the HIPAA rules on hire. So a newly hired person must have HIPAA training. And you may have a little bit of latitude if somebody comes from another work environment, perhaps another dental office where they've had some recent HIPAA training, although it isn't specific to your practice. So there still needs to be some training overlap, even if people complain about it. And then we need to have training on updates at least annually. And there may be times in between those annual trainings when we need to have just a short update, perhaps at a team meeting. That a great uh example of that would be the new rules that are going to become effective this year. And if you just did your HIPAA training towards the end of last year, then you need to have some more training to understand what the new requirements are. So live training is where a member of the staff or somebody comes into your practice, or perhaps electronically comes into your practice via Zoom or some other meeting platform and does a real-time live training for you. And there also are recorded trainings that are available from different entities. The one thing to consider is that if you use a recorded training, there must be a mechanism, and this applies with OSHA as well. There must be a mechanism for attendees to answer questions and to get to ask questions and to get those questions answered, because we can't just leave those things sort of hanging out there as unanswered issues. We need to make sure that everybody understands. So the training consists of the privacy rule, the security rule, the breach notification rule, and of course, the um all the provisions of the Omnibus Act. And now having security training. So someone from your tech support company doing periodic short trainings on internet security, reminders for you about not browsing the internet on the office network, those types of things. You don't have to become a tech expert, but you at least need to understand basic minimum security requirements.
SPEAKER_00Mary, that's outstanding. And I like the fact that you mentioned, you know, browsing on the internet. Sometimes we develop work habits that we don't realize are not particularly compliant and they're less than optimal when it comes to best practices for security of the practice, such as saving your passwords on your browser. So speaking of that and talking about security awareness and the policies that you mentioned, our Diva Leslie wanted to talk about the value and importance of having customized policies and procedures, and she was not able to be with us today. So I'll speak to that for just a moment and say that it's very obvious to an Office of Civil Rights auditor when they received CAN policies and procedures, especially when they have not been completely customized. You recall the divas we all attended, either virtually or live, the Office of Civil Rights Security Conference back the end of October. And I had the opportunity to speak to one of the auditors while I was on site, and she brought that fact up to me that they've reviewed many a policy where the policies actually says insert practice name here and it's never been customized. So when you sign up for any kind of service, especially a subscription service or an online service, there are great benefits to that in such that you have everything electronic, you never lose a binder, you have it's all traceable and when the training was taken and updates to your policies. But sometimes we think the company is going to be handling a certain piece of it and they aren't responsible for it. That's something the practice should be doing, such as completing the blanks in the policy. So it's very important that you read them, make sure they're customized. And also, Mary, I think it's important to include aspects of your policies in your training. So that brings back, you know, the value of having some live training, whether it's just simply something the office manager or the doctor leads in reviewing your policies. For example, with that security awareness training, you could simply take a policy a month and just review a couple of the highlights in it. We're not asking individuals to memorize it, to recite it from by heart or anything, but certainly just being familiar with your policies to know what's in them so you can be safe. That's very important. One of the must-haves. So that's two of our must-haves. It's the training and the policies and procedures. Olivia, could I invite you to talk about our third must-have, and that is the security risk analysis. And why is it so confusing for offices with this requirement?
SPEAKER_02Well, a lot of times, Linda, it's not being done. Or they thought it was done and then a breach occurred and they're looking through their records, there's nothing on file. Or they may wrongfully assume that their IT provider is taking care of this. So we've had to do these risk analysis with the security HIPAA rule. And in listening to some of the OCR speakers, they don't want like a three-page document to include the cover page. You know, that was mentioned in one of the presentations. So it should be a lengthier document that is meaningful. And with some of the newer requirements, they're making it clear that one, it's a it is a written assessment. It's not something that you just talk about. And this assessment should include a review of the technology inventory. You know, some people don't even know what hardware they have. Like in my own office, I know we are aging three or four computers out. So we have all of this written in our inventory, the serial numbers. We know the ones going out, the ones that are coming in. So we know just what exactly do we have. So that's part of the risk assessment. And then the the tricky part is identifying all reasonably anticipated threats to the confidentiality, the integrity, and the availability of electronic protected health information. And I think, Linda, that's a lengthy part of the assessment process, going through different scenarios. And then also the identification of potential vulnerabilities and predisposing conditions to the regulated entities' relevant electronic information systems. And then trying to score it, whether you know it's low, medium, high, what's the likelihood that it's going to occur? Now, the thing is, when you're looking at these assessments, could you just hand it over to IT to do it, or do you does the dental office need to dive in? And I think it's a good idea to have third party because when we're doing these assessments, we're finding that maybe the provider they're working with may be unfortunately incompetent as it relates to health care network systems, or they're only working with the IT provider on a fix-it when broken model, which is not acceptable. And so we want to take a pulse and getting an accurate review. And then those that are working with IT providers, we include them in the process. We're asking them some of these technical questions that the in-office person in the dental office may not be familiar with and how that network is set up. So there are particular questions that we ask of the IT provider. But you know, they're difficult to do, Linda. They are time consuming, but they have to be done every year. And so we just need to allocate our calendars to get it done. And then we have to be able to demonstrate it. So if we're answering a question, yes, for example, whatever that question may be, can the dental office demonstrate that they're doing it? Do they have the document that's being referenced or whatever that process is? Because when it comes down to being audited, what can we present to the OCR to prove that it was being done or it was not done? And I can tell you, if if these assessments have not been done, they're subject to penalty. So we want to get caught up to date, not only what's been required, but some of these uh enlightened changes that have come for this year.
SPEAKER_00Wow, Olivia, that's a whole podcast content in and of itself. Thank you for being so thorough. And Mary, you had some thoughts on this topic as well.
SPEAKER_01I did. Olivia, you did such a great job of explaining about the security risk assessment. And one thing I would add to that, and I have heard from a couple of um HIPAA um auditors, that if you identify something as a risk, and then you should be taking steps to fix that. You should have deadlines, you should have a plan for fixing those items, not just identify the same thing year after year after year if you're doing the assessment and identifying it as a risk, because you will be fined for not addressing that risk. And if there's reasons why you can't do it during one time period, then you document that. We plan to do this, but um, and here's our deadline when we think we need to do it. We can't just say, yep, it's a risk and then walk away from it.
SPEAKER_00By no means, Mary, can you do that? You're absolutely right. And I think offices don't realize it because to that point and to Olivia's great points that she made about the security risk analysis in general, it comes down to cost in a dental practice. And so oftentimes they look at the cost because their IT company will map out a HIPAA compliant security plan for them that includes monitoring their equipment 24-7, just like they're supposed to have under the security rule. And you look at the cost per computer, especially offices that have more than just a few computers, they've got 20 or 30 computers, and the cost adds up. So they typically will go with the break fix person who doesn't have their finger on the pulse and is not keeping them as up to date as possible because you have to install all the patches every time a patch comes through, whether it's for Windows or for your antivirus program, all those things have to be done. And then also it comes into play with aging equipment. That's another piece of the cost in a practice. And when they you when you have legacy equipment in a practice, it's not secure any longer. The company is not providing the updates and the patches, so it's very important. And I believe, and correct me if I'm wrong, divas, that this October the Windows platform is going to be updating the Windows operating system. So you can't function without it compliant in a compliant fashion. And it will come back when you least expect it, because the Office of Civil Rights announced last year that they launched their security risk analysis initiative. Now that's a mouthful. So what it means is that anytime there's a HIPAA complaint against your practice, the Office of Civil Rights, as part of their investigation, will automatically ask to see your security risk analysis. And so if you have one that's incomplete or it's a three-page document that Olivia mentioned, then you're going to fail right from the start. So it is a multi-page document, including the list of all your media and devices, like Olivia mentioned, the threats and vulnerability, what is the assessment of the high, medium, and low risk. And then you take all that information and you create your risk mitigation plan or your risk management plan. And for our listeners, I'd like you to think about that like a treatment plan in a dental practice. You're gathering information from the intro exam, the periodontal probings, the patient history and x-rays. Consider those to be the parts of the security risk analysis. And then when you put them all together, you have this treatment plan, which is your risk mitigation plan to use that HIPAA analysis again. So one thing I'd like to mention to our for our listeners is that with your cyber risk coverage. So doctors, office managers, you may be the ones that are more involved with this aspect in your practice, but it's very important that you have adequate cyber risk coverage and that you know the benefits and the exclusions and what the coverage entails. Because when you have a breach, if you don't have the right coverage to cover your breach, then you're going to be paying the cost out of pocket for the forensics and the compliant type of investigation that has to be covered. And also note that when you renew your cyber risk coverage every year, many of the carriers are now asking more detailed and longer questions about your level of compliance. So you cannot ethically or legally check off that you're HIPAA compliant without understanding all the features in the back and not just saying, oh, yeah, my IT person has me covered, because sometimes, as Olivia mentioned, they don't know the HIPAA requirements. And if they don't know the HIPAA requirements going forward, the changes, then all of our practices are going to be at at risk for HIPAA fines or breaches or ransomware. And speaking of ransomware, I'd like to share the some of the statistics in the year-end review from the Office of Civil Rights in their end-of-the-year publication, which is actually a short video on YouTube. There were 693 HIPAA breach investigations. These were all in dentistry. However, there were quite a few that the Divas noticed, and we'll be talking about those throughout the year as well. And in addition, there were 21 completed cybersecurity and privacy enforcement actions. So that was both in the areas of the privacy rule, not releasing information when patients request information, for example, and cybersecurity and breach information that was that happened. So we ask that you consider these three areas of HIPAA compliance. These are the three must-haves. So as you start building on the new requirements that will be potentially launched in March, we have the importance of the office training. Can you show that you have six years of training, new hires as well as ongoing annual training, and that you have documented security awareness training, and that your policies and procedures have been customized. And to some level in your practice, you've read those policies and you know what's entailed in them. And then that you've taken all of the tips that Olivia provided for the security risk analysis and you have that all together. So please take time to review that in your practice. It does require some little bit of carve-out time because even if you use a qualified compliance consultant or attorney, they still need your attention to the detail and assistance to complete it. So we hope that these tips will help you coming forward in 2025 to have a safe and secure year with your practice and your system and your electronic protected health information. As the Compliance Divas, we bring clarity and simplicity to compliance by navigating the regulatory world to keep you on course. We invite you to subscribe to our podcast through your favorite podcast channel or on our website, thecompliancedivas.com. Any resources that we mentioned today can be found in the show notes. And we always invite you to submit your questions to support at thecompliancedivas.com. Thank you for joining us.