Many physicians and physician practices have gotten a break from the Red Flags Rule—the law intended to prevent identity theft and medical identity theft—thanks to Congress.
HIPAA privacy officers don’t have eyes in the back of their heads. Nor can they be everywhere at once. But they can increase their ability to monitor compliance by sharing the responsibility with other staff members.
It appears OCR and state attorneys general will be taking a more serious approach to enforcing HIPAA and HITECH. It’s essential that covered entities (CE) and business associates (BA) who haven’t begun a security compliance review do so. This is a requirement of the HIPAA Security Rule evaluation standard.