Contact Us
Categories
- Coronavirus Aid, Relief and Economic Security Act
- Code Enforcement
- Department of Labor ("DOL")
- Employment Law
- FFCRA
- CARES Act
- Nursing Home Reform Act
- SB 150
- COVID-19
- Families First Coronavirus Response Act
- Family and Medical Leave Act (“FMLA”)
- KBML
- medication assisted therapy
- Acute Care Beds
- Clinical Support
- Coronavirus
- Emergency Medical Services
- Emergency Preparedness
- Department of Health and Human Services
- Legislative Developments
- Corporate
- United States Department of Justice ("DOJ")
- Employee Contracts
- Non-Compete Agreement
- Opioid Epidemic
- Sexual Harassment
- Health Resource and Services Administration
- Litigation
- Medical Malpractice
- House Bill 333
- Senate Bill 79
- locum tenens
- Senate Bill 4
- Physician Prescribing Authority
- HIPAA
- Chronic Pain Management
- Prescription Drugs
- "Two Midnights Rule"
- 340B Program
- Hospice
- Kentucky minimum wage
- Minimum wage
- Skilled Nursing Facilities (“SNFs”)
- Uncategorized
- EHR Systems
- ICD-10
- Primary Care Physicians ("PCPs")
- Electronic Health Records (“EHR")
- Drug Screening
- KASPER
- Mental Health Care
- Urinalysis
- Affordable Insurance Exchanges
- Fraud
- Health Care Fraud
- HIPAA Risk Assessment
- Kentucky’s Department for Medicaid Services
- Office for Civil Rights ("OCR")
- Qui Tam
- Stark Laws
- Compliance
- Department of Health and Human Services (HHS)
- HPSA
- Kentucky Board of Medical Licensure
- Office of Inspector General of the United States Department of Health and Human Services (OIG)
- Pharmacists
- Physician Assistants
- Accountable Care Organizations (“ACO”)
- Affordable Care Act
- Anti-Kickback Statute
- Centers for Medicare & Medicaid Services (“CMS”)
- Certificate of Need ("CON")
- Data Breach
- Electronic Protected Health Information (ePHI)
- False Claims Act
- Federally Qualified Health Centers (“FQHCs”)
- Fee for Service
- Health Information Technology for Economic and Clinical Health Act (HITECH Act)
- Health Insurance Portability and Accountability Act of 1996 (HIPAA)
- Hospitals
- Medicaid
- Medicare
- Part D
- Patient Protection and Affordable Care Act (“ACA”)
- Rural Health Centers (“RHCs”)
- Telehealth
- Alternative Payment Models
- Charitable Hospitals
- Health Professional Shortage Area ("HPSA")
- HRSA
- Limited Services Clinics
- Medical Staff By-Laws
- Medically Underserved Area ("MUA")
- Mid-Level Practitioners
- Rural Health Clinic
- Kentucky Board of Nursing
- American Telemedicine Association (“ATA”)
- Criminal Division of the Department of Justice (“DOJ”)
- Health Care Fraud Prevention and Enforcement Action Team (“HEAT”)
- Qualified Health Care Centers (“FQHC”)
- Telemedicine
- Hydrocodone
- Kentucky Pharmacists Association
- Webinar
- APRNs
- United States ex. Rel. Kane v. Continuum Health Partners
- Agreed Order
- Chain and Organization System (“PECOS”)
- Drug Enforcement Agency ("DEA")
- Hinchy v. Walgreen Co.
- Jimmo v. Sebelius
- Maintenance Standard
- Overpayments
- Vitas Innovative Hospice Care
- Chiropractic services
- Clinical Laboratory Improvement Amendments of 1988 (“CLIA”)
- Douglas v. Independent Living Center of Southern California
- Emergency Rooms
- Enrollment
- Kentucky Senate Bill 7
- Medicare Part D
- Minors
- Ophthalmological services
- Physician Compare website
- Re-validation
- Texting
- 2014 Medicare Physician Fee Schedule (“PFS”)
- All-Payer Claims Database ("APCD")
- Chronic Care Management
- Compliance Officer
- CPR
- Essential Health Benefits
- ICD-9
- Sustainable Growth Rate (“SGR”)
- 501(c)(3)
- Appeal
- Centers for Disease Control and Prevention
- Compounding
- Dispenser
- Drug Quality and Security Act (“DQSA”)
- Food and Drug Administratio
- HealthCare.gov
- House Bill 3204
- Kindred v. Cherolis
- Kynect
- Long-term care communities
- Mobile medical applications ("apps")
- National Drug Code ("NDC")
- National Institutes of Health
- New England Compounding Center ("NECC")
- Outsourcing facility
- Ping v. Beverly Enterprises
- Power of Attorney ("POA")
- Prescriber
- State Health Plan
- Affinity Health Plan
- Cadillac tax
- Community health needs assessment (“CHNA”)
- Condition of Participation ("CoP")
- Denied Claims
- Department of Medicaid Services’ (“DMS”)
- Federation of State Medical Boards (“FSMB”)
- Form 4720
- Grace Period
- Home Health Prospective Payment System
- Home Medical Equipment Providers
- Individual mandate
- Inpatient Care
- Kentucky Medical Practice Act
- Licensure Requirements
- Long-Term Care Providers ("LTC")
- Low-utilization payment adjustment ("LUPA")
- Medicare Shared Saving Program (MSSP)
- Model Policy for the Appropriate Use of Social Media and Social Networking in Medical Practice (“Model Policy”)
- Nonprofit hospitals
- Nonroutine medical supplies conversion factor (“NRS”)
- Personal Service Entities
- Physician Payments
- Qualified Health Plan ("QHP")
- Quality reporting
- Social Media
- Spousal coverage
- UPS
- “Superuser”
- "Plan of Correction"
- Arbitration
- Audit
- Daycare centers
- Decertification
- Division of Regulated Child Care
- EHR vendor
- Employer Group Health Plans
- Employer Mandate
- ERISA
- Fair Labor Standards Act (FLSA)
- False Billings
- Health Professional Shortage Areas (“HPSA”)
- Health Reform
- Hospitalists
- Intermediate Sanctions Agreement
- Kentucky Health Benefit Exchange
- Licensed practical nurses (LPN)
- List of Excluded Individuals and Entities
- LLC v. Sutter
- Meaningful use incentives
- Medicare Administrative Coordinators
- Medicare Benefit Policy Manual
- Network provider agreement
- Nurse practitioners (NP)
- Office of the National Coordinator for Health Information Technology (“ONC”)
- Part A
- Part B
- Payors
- Physician Recruitment
- Physician shortages
- Provider Self Disclosure Protocol
- Registered nurses (RN)
- Residency Programs
- Self-Disclosure Protocol
- Statement of Deficiency ("SOD")
- Trade Association Group Coverage
- Upcoding
- Advanced Practice Registered Nurses
- Business Associate Agreements
- Business Associates
- Call Coverage
- Doe v. Guthrie Clinic
- Group Purchasing Organizations ("GPO")
- House Bill 104
- Kentucky House Bill 217
- Patient Autonomy
- Patient Privacy
- Personal Health Information
- Senate Bill 39
- Senate Finance Committee Report
- State Medicaid Expansion
- Autism/ASD
- Compliance Programs
- Genetic Information Nondiscrimination Act ("GINA")
- Kentucky House Bill 159
- Kentucky Primary Care Centers (“PCCs”)
- Managed Care Organizations (“MCOs”)
- Center for Disease Control
- Consumer Operated and Oriented Plan programs (“CO-OPS”)
- Critical Access Hospitals (“CAHs”)
- Essential Health Benefits (“EHBs”)
- Healthcare Information and Management Systems Society (HIMSS)
- Kentucky Health Cooperative (“KYHC”)
- Medicare Audit Improvement Act of 2012
- Occupational Safety and Health Administration (“OSHA”)
- Recovery Audit Contractors (“RAC”)
- Small Business Health Options Program (“SHOP”)
- Sunshine Act
- Abuse and Waste
- Kentucky Cabinet for Health and Family Services
- Kentucky Health Care Co-Op
- Kentucky “Pill Mill Bill”
- Employee Agreement
- Free Conference Committee Report
- Health Care Fraud and Abuse Control Program
- House Bill 1
- House Bill 4
- Pain Management Facilities
- Health Insurance
- Healthcare Regulation
- Health Care Law
McBrayer Blogs
Healthcare Entities: How is Your Cyber Security?
In an evolving world of cyber terrorism where individuals such as Edward Snowden grab headlines by stealing national secrets, it should come as no surprise that protected healthcare information (“PHI”) kept by providers has become a “target rich environment” for foreign governments and individual hackers alike. In addition to threats from outside entities, healthcare providers must also realize and appreciate that state and federal regulatory and statutory requirements govern the creation, maintenance and protection of PHI, including through but not limited to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) and the Health Information Technology for Economic and Clinical Health (“HITECH”) Act. Failure to abide by these complex and stringent rules can lead to significant penalties.
When patients see healthcare professionals, they anticipate that their medical problems will be solved, not that the information they give to their provider will become public knowledge. Patients, now more than ever, have come to expect that their PHI is secure and safe from hackers. Yet ransomware –the holding hostage of electronic data and the threat to publish or continuously block the health care entities’ access – is unfortunately now an almost daily occurrence. Hacking of the healthcare industry is especially profitable as the breach and potential exposure of PHI can force affected healthcare entities to pay significant monetary amounts to re-secure their data or simply to re-gain access to their systems. In fact, according to Becker’s Hospital Review, 77% of organizations recently surveyed suffered a form of cyber-attack in 2017. Just over half of those organizations, 55%, fell victim to a ransomware infection in 2017.
Assessment of your cyber security risk is the most important initial step in determining how exposed your healthcare entity is and how effectively your entity can respond to a known cyber security threat. However, an assessment is just one step in a multi-layered approach to protect your healthcare entity, patients and employees. In determining how to better secure your operating systems and PHI, your entity should consider the following steps:
1. Encourage and grow a culture of governance and compliance among your employees to properly utilize and retain PHI and other data;
2. Ensure that your entity has a dedicated IT system and qualified personnel to operate not only the system, but respond to known threats;
3. Always provide the opportunity for your employees to continually train and improve their IT / cyber security knowledge without hesitation;
4. Establish effective and efficient policies, procedures and protocols for data compliance, security and responses to potential breaches; and
5. Utilize up-to-date encryption software and processes.
The cyber security threat continues to evolve every day. To ensure that your healthcare entity is up to speed on the wide array of federal and state requirements, or to assist with a known breach, McBrayer’s healthcare team is online and able to remote in to assist. Feel free to contact me with any questions.
Services may be performed by others.
This article does not constitute legal advice.