Internal Audit Checklist for HIPAA

In 1996, the U.S. Congress passed the Health Insurance Portability and Accountability Act, or HIPAA, to regulate how health care institutions disclose patients' medical information. The Department of Health and Human Services (HHS) monitors how medical organizations comply with the law. Auditors use a checklist when testing companies' medical-data recording processes.

  1. Risk Analysis and Assessment

    • HIPAA requires that all medical organizations conduct periodic risk analysis and assessment sessions, especially institutions involved in the collection, retention and transfer of medical information. An auditor reviewing HIPAA compliance ensures that all business units monitor risks that may cause a firm to incur losses due to data breaches. Risk analysis identifies corporate areas posing major operating threats for HIPAA security compliance. Risk assessment determines the extent of losses that an institution may suffer in case of insider or outsider attacks.

    Gap Analysis

    • In HIPAA terminology, gap analysis refers to procedures necessary to map security requirements to a medical organization's existing security infrastructure. In other words, auditors analyze regulatory guidelines and compare them with corporate security systems, verifying whether these systems abide by the act. Gap analysis follows four steps: gap identification, determination of remediation activities, project prioritization and resource allocation. After identifying gaps, or security weaknesses, auditors ensure that department heads have mitigating solutions in place. Then reviewers make sure segment chiefs allocate sufficient resources to mitigation projects.

    Remediation

    • Remediation is an important item on an audit checklist for HIPAA. Auditors rely on HHS directives to ensure that an organization has adequate resources in place to remedy potential security breaches. State-of-the-art technological tools are integral to remediation procedures. These tools include customer relationship management software, enterprise resource planning applications, process re-engineering software and defect-tracking software. Other tools used to remedy potential security threats include categorization or classification software, calendar and scheduling software, patient relations management programs and project management software.

    Contingency Planning

    • Companies engage in contingency planning to ensure that corporate activities do not experience temporary or permanent halts in case of emergency, accident or other operating disruptions. To prevent the substantial losses that may come with operational standstills, firms draw contingency plans, also known as business continuity plans (BCP). HIPAA auditors check a medical organization's BCP to ensure that the plans address important operating issues that may arise in emergencies. Specifically, auditors verify how companies could restore operations at an alternate site and recover operations using alternate equipment, should disaster strike.

    Personnel Policies

    • HIPAA auditors sift through corporate human resources policies to ensure that personnel maintaining medical records possess technical knowledge and the appropriate skills for the job. These personnel include health record technicians, medical records and health information specialists, medical information clerks and coders, according to O*Net Online, the U.S. Department of Labor's occupational research branch.

Related Searches:

References

Comments

You May Also Like

  • What Is a HIPAA Compliance?

    A HIPAA compliance refers to the standards and regulations that hospitals must comply to in order to avoid potentially devastating fines, so...

  • HIPAA Readiness Checklist

    HIPAA Readiness Checklist. The Health Insurance Portability and Accountability Act of 1996 (HIPAA) requires health-related organizations to follow certain guidelines when ...

  • HIPAA Audit Checklist

    HIPAA Audit Checklist. HIPAA is the American act that regulates the exchange of medical information between doctors, health care providers, insurance providers...

  • How do I do a HIPAA Audit?

    Conducting internal HIPAA audits in your place of business helps to assure your establishment is HIPAA compliant. HIPAA, or the Health Insurance...

  • HIPAA Logging Requirements

    HIPAA Logging Requirements. The Health Information Portability and Accountability Act (HIPAA) Security Rule came into final effect in 2006 requiring 18 safeguard...

  • About Medical Coding Auditing Jobs

    A medical coding auditing job is a position in which a coder checks the work of another coder or medical personnel who...

  • Auditor Certification Programs

    The Certified Financial Services Auditor certification applies to audit principles and practices in the accounting, insurance and banking industries.

  • HIPAA & Security Training Program for Employees

    The Health Insurance Portability and Accountability Act (HIPPAA) was passed by Congress in 1996 to protect the safety and security of employees'...

  • IRS Auditing of Medical Deductions

    IRS rules allow taxpayers to deduct medical expenses that exceed 7.5 percent of a taxpayer's adjusted gross income (generally wages plus other...

  • HIPAA Auditing Requirements

    HIPAA Auditing Requirements. According to the U.S. Department of Health and Human Services (HHS), the Health Insurance Portability and Accountability Act (HIPAA)...

  • How to Conduct a HIPAA Assessment

    The Health Insurance Portability and Accountability Act (HIPAA) sets guidelines for accessing and sharing protected health information. HIPAA guidelines are enforced ...

  • The HIPAA Security Risk Assessment Analysis

    The Health Insurance Portability and Accountability Act of 1996 (HIPAA) outlined mandated standards for health care facilities to comply with. Among them...

  • Safety Risk Assessment Checklist

    Safety Risk Assessment Checklist. Risk assessments are the foundation for many safety programs and initiatives, according to the Occupational Safety and Health...

  • Internal Auditing Job Description

    Many firms, especially manufacturers, implement quality assurance programs and systems to continuously improve their ability to produce and deliver goods and services...

  • The Summary of the HIPAA Security Rule

    The Health Insurance Portability and Accountability Act (HIPAA) established federal regulations requiring certain health care entities to protect patients' personal ...

  • Compliance Audit Procedures

    Compliance Audit Procedures. A compliance audit is the review of business functions to determine whether or not a company is meeting specific...

  • What Are Compliance Audits?

    Organizations operate in an environment of federal and state laws, professional codes of practice, donor/granter contracts or agreements, and institutional bylaws ...

  • HIPAA Gap Analysis

    Pursuant to the Health Insurance Portability and Accountability Act of 1996, also known as "HIPAA," a patient's confidential medical information must be...

  • Business Risk Assessment Checklist

    Business Risk Assessment Checklist. Risk assessment is the third step in a basic risk management process. It aims to determine the quantitative...

  • HIPAA Information on Security Requirements and Vulnerability Assessment Required

    The Health Insurance Portability and Accountability Act establishes security and vulnerability assessment requirements to protect electronic health information ...

Related Ads

Featured