
Explore how HIPAA and HITECH Part 3 guides assessments and risk analysis to build a comprehensive privacy and security plan, protecting PHI throughout its lifecycle.
Examine the HIPAA and HITECH privacy assessment, including the 10-step protocol, PHI and ePHI scope, OCR audits, and the roles of privacy and security officers in compliance.
Assess the HIPAA security systems assessment by mapping the I.T. infrastructure and PHI data flows to establish a baseline for risk management and audits.
Apply HIPAA/HITECH risk analysis per NIST to identify threats and vulnerabilities to PHI. Develop and test contingency plans, allocate resources, backups, encryption, and data destruction strategies.
Organize and evaluate information and data to establish a baseline PHI management within a unified HIPAA/HITECH compliance plan, aligning standards and training across departments and timelines.
Draft a dynamic HIPAA/HITECH compliance plan from parts 1 through 3, customize it to the entity, and anchor it with workforce training, risk analysis, and regular reviews.
Privacy and Security Assessments and Risk Analysis processes are administrative safeguards mandated by HIPAA/HITECH. The private and secure management of PHI requires mapping out how PHI/ePHI moves into and through various departments and divisions, how PHI/ePHI is used and disclosed by each department and division, and plans for protection of PHI/ePHI in various types of catastrophic events. Documentation derived from these assessments and analyses is essential to a viable Compliance Plan and some of the first documents likely to be requested for review in an OCR audit. In 5 Sections, Part 3 provides guidelines for conducting:
Privacy Assessments - Section 1
Security Assessments - Section 2
Risk Analysis - Section 3
Part 3 also provides guidelines for incorporating the data derived from these processes into its documented Compliance Plan (Sections 4 and 5). Documentation developed from Part 3 can be produced at OCR audits to demonstrate HIPAA/HITECH Compliance efforts.