HIPAA/HITECH Compliance Training
Did you know that as a Business Associate (BA) you are required to have a documented HIPAA training program in place? Because of HIPAA/HITECH, BA's are now required to implement a proper training program in an effort to ensure that all members of your staff are aware of the proper handling of protected health information (PHI). Current and correct policies and procedures are also mandated. Not only will these help you better protect information, they will help protect your organization when you are audited. Our training program will not only better equip your staff, it will help the entire organization become more compliant.
Tom Dumez has been with KRM since 2000 and serves as the on-staff Compliance Consultant in the Professional Services department. He is a Certified HIPAA Professional and a Certified Security Compliance Specialist. Tom oversees KRM's compliance with local, state, and federal regulations through policies, procedures, audits, documentation, planning and implementing compliance solutions, and KRM is pleased to offer his services to our clients. He also provides consulting services to other RIM companies and their clients to help them regarding compliance matters. Since 2009, Tom has been both marketing and performing an employee HIPAA training program that was created specifically for the RIM industry, and includes scanning and information destruction companies. The program also addresses other regulatory matters such as Sarbanes-Oxley, Gramm-Leach Bliley, FACTA, PCI-DSS, ISO 27002, etc. Tom has traveled internationally as a guest speaker and as a trainer, also presenting many educational sessions for PRISM International, ARMA, NAID and AITP.
HIPAA
New provisions were signed into law in 2009, as part of the ARRA. These laws have affected the RIM industry, and they could impact your business if you fail to educate your employees. They pose one of our greatest risks. Have you noticed any increased pressure from your clients regarding liability? Are you prepared to deal with this? Our clients are now being held more accountable to ensure that the companies that they do business with (business associates) can provide reasonable assurances that they know how to protect information. What, if anything, can you provide to your clients to assure them that you can effectively do what they pay you to do? The costs, fines, and penalties related to a breach of information are staggering. BA's have been specifically named as being found responsible for breaches. Are you willing to risk putting your business in jeopardy because you don't know what to do or where to turn? I would love to help you take the business that you drive to a more compliant level. How? By educating your employees, it can significantly lower the risks.
HITECH
HITECH was designed to ensure that privacy, security, confidentiality, integrity and availability of electronic protected health information (EPHI) are maintained. Business associates are now held to the same level of accountability as covered entities, and because of this additional responsibility, should position themselves to become as educated as possible in order to avoid getting caught in a bad situation. If you handle any tape media, hard drive storage, flash drive/thumb drives, electronic backups or store EPHI on servers, or perform scanning services or send emails that contain EPHI, you can be impacted by HITECH laws. Are your company owned portable devices encrypted? What level of encryption is acceptable?
The reality is that there is now a very blurred line between the covered entity and the business associate. BA's are not expected to follow certain parts of the law, but are held to the same accountability standard if they are found in violation. Help your employees become more knowledgeable about HIPAA and HITECH by providing an opportunity for them to learn.
_________________________________________________________
_________________________________________________________