DCSIMG
Mercer
Health care consulting HIPAA regulatory compliance US Health Insurance Portability and Accountability Act

HIPAA administrative simplification: Facts and solutions

Last updated: 14 July 2011

 

While many employers have been challenged by the new health care reform mandates, we don’t want you to lose sight of another very important mandate – HIPAA. 

 

In 2009, HIPAA privacy and security rules were expanded by the HITECH Act. Now the agency responsible for overseeing the law – the US Department of Health & Human Services (HHS) – is stepping up HIPAA enforcement with significantly increased penalties and enforcement activities.

Recent HHS Enforcement Activities

The most significant enforcement activity -- and potentially most damaging to employers -- deals with the improper use of personal health information (PHI) or “breach” of PHI. During the last 18 months, more than 265 breach incidents were reported to HHS, with the majority of those violations due to compromises of electronic devices and theft. Under HIPAA, if there is breach, an employer’s obligations can include a notice to major media outlets. 

 

For example

 

  • One large employer agreed to pay a $1 million penalty for the loss of PHI data. Several local and national news articles and periodicals ran the story.

 

  • Another employer compiled a penalty totaling more than $4 million for several violations and made headlines in several news agencies.

 

Complimentary ½ hour HIPAA review teleconference to consult on your HIPAA compliance status

Many of these high profile events can be avoided by undertaking appropriate assessment and risk management.

 

To help avert breach incidents, Mercer is offering a complementary ½ hour HIPAA review teleconference to consult on your HIPAA compliance status. 

 

Interested?

 

 Contact your Mercer consultant using our office locator 

 Send us an email

 

This ongoing regulatory activity, coupled with an increased public interest in personal privacy, it isn’t likely to diminish. Now is the time to revisit your HIPAA privacy and security policies.

 

Depending on what actions you may have recently taken to comply with privacy and security requirements, here are some steps for you to consider:

 

  • Update privacy and security policies to reflect new HITECH Act provisions and advances in IT protections for e-PHI within the organization
  • Train staff on new HIPAA requirements and plan procedures
  • Update notices of privacy practices and business agreements to reflect new requirements and any changes to procedures
  • Put yourself on a schedule to periodically re-evaluate HIPAA privacy and security practices and written policies, and update as required

 

In short, take the necessary steps to avoid any breaches, and thereby avoid the need to send any notices

 

Mercer is here to help

 

  • Private and public sector employers: Mercer's efficient HIPAA services and solutions are specifically designed for private and public sector employers.

 

  • Companies of all sizes: We have provided HIPAA services to many clients, ranging in size from 200 to 50,000 employees, in industries including retail, financial services, technology, construction, hospitality and others.

 

  • Full set of tools: Mercer has developed tools to help employers fulfill their HIPAA privacy and security obligations. 
    These tools include customized policy and procedures, risk analyses, training materials, gap analyses and sample templates, to name just a few!  

 

 Contact your Mercer consultant using our office locator 

 Send us an email

 

HIPAA Update

 

While employers are focused this year on complying with the new health care reform mandates, they shouldn’t overlook other basic requirements affecting health plans. After several years of relative quiet, privacy and security rules under the Health Insurance Portability and Accountability Act (HIPAA) were expanded in 2009. Now, the agency responsible for overseeing the law – the US Department of Health & Human Services (HHS) – is stepping up enforcement. HIPAA also requires covered entities to periodically reassess and update their security safeguards, taking into account technology and environmental changes. For these reasons, many employers should revisit their plans’ privacy and security compliance.

 

 Download the full Update (PDF)


Additional resources

  • Mercer Select members can review HIPAA-related GRIST updates: Mercer Select

 

 


Contact us

For additional information about how Mercer can help your organization meet its HIPAA compliance obligations:

 

Tami Simon

+1 202 263 3949

 Email Tami


Chris Isaacs

+1 412 355 8744

 Email Chris

 

Terry Dailey

+1 202 331 2512

 Email Terry


 Office locator


More on Health and Benefits Services?

 

Read how Mercer can help you in our Health & benefits solutions page