Welcome to the March module of HIPAA MMM. As you complete each activity, please print and place the completed documents in your HIPAA Manual in a location you will remember and be able to easily locate if needed.
Instructions for the routine repeated monthly QUICK CHECK review audit
Monthly Quick Check Audit
It is advised that every month you do this same QUICK CHECK audit by using the following audit tool and place any written updates in your HIPAA manual – make sure to review the QUICK CHECK every month as items are added periodically based on changes in focus and enforcement activities within the federal government.
Below are the Instruction to correspond with each item on the Monthly Audit List;
1. If yes, perform a risk analysis for that device, as you did for the devices when you prepared your original risk analysis from the Survival Kit or by copying the format for the risk analysis used in the Silver or Gold program originally provided for you (you can also use your Survival Kit as a reference/templates) Add this newly prepared document to your HIPAA manual.
2. If yes, then remember to document what you did to assure that the device had no patient health information /electronic data remaining on it (i.e. had a service clean the hard drive, destroyed the hard drive, shredded information –if paper etc., at the time of disposition).
3. If yes, remember to have them sign an employee confidentiality form and assure that you perform a full HIPAA training within 45 days of hire.(Remember; You can use this training video Annual Staff Inservice or there is an audio training in the Survival KIT that can be paired with giving your new employee a copy of your office HIPAA policies and having them sign off that they agree to read, understand and abide by those policies to satisfy this training. Don’t forget to document this in your HIPAA manual.)
4-8. Regardless of the specific customized evaluation/review/audit you will perform THIS month, due to the increase in Ransom ware, it is advised to assure and document that all patches, updates, firewalls, antivirus, malware etc. are current and installed on at least a monthly basis.
9. Again, especially due to ransom ware, the required HIPAA contingency plan, most especially focused on the area of data recovery, has become a major center of attention. One of the key components is that your backups are readily available and your data can be restored in the event of an attack on your patient data that shuts down your main computers etc.
Monthly security reminder
Instructions: This months’ reminder will likely require modifications to fit the circumstances in your specific office. While you may need to eliminate some items, as they do not apply to your particular office, there may also be items to add.
Activity for this month:
Download the document provided below to complete the audit for your Physical Plant Walk through.
It is critical to protect patient health information from being accessed/seen/overheard by other patients (and individuals accompanying patients) in our office.
Example: All locations within the office that contain PHI and are NOT utilized for patient treatment are marked with signage that indicates that these are non-public areas for authorized individuals only. Y/N