Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

April 2017

Abyde Featured in Optometric Management Magazine
Abyde News

Abyde President, Matt DiBlasi, Featured Article in Optometric Management Magazine

April 20, 2017 Gaurav Modi Comments Off on Abyde President, Matt DiBlasi, Featured Article in Optometric Management Magazine

April 20, 2017 The article below was featured in the April edition of Optometric Management Magazine. To see it on their website,  click here. ARE YOU HIPAA COMPLIANT? THESE FIVE STEPS CAN HELP YOUR PRACTICE SECURE PATIENT INFORMATION By Matt DiBlasi, St. Petersburg, Fla.April 1, 2017  THANKS TO the HITECH Act, Meaningful Use and the Medicare Access and CHIP Reauthorization Act (MACRA)/Merit-based Incentive Payment System (MIPS), the number of optometrists using EHRs will be at an all-time high by the end of 2017. Many practices are trying to implement software, install IT networks, ensure data backups are running properly and integrate diagnostic technology, such as optical coherence tomography devices, into electronic information systems. For established practices the overwhelming sentiment is, “This is not what I went to school for!” While that statement may be true, O.D.s must embrace this technology. It is tied closely with The Health Insurance Portability and Accountability Act of 1996 (HIPAA) and, thus, the survival of one’s practice. Whether it is patient names, Social Security numbers, dates of birth or medical histories, the data stored in EHR is extremely profitable to those with malicious intent. In fact, this protected health information (PHI) is 10x more valuable than credit card information on the black market, reports Reuters. This makes optometry practices targets for criminals. (See “Securing Your Practice,” p.23.) To ensure you’re complying with the latest HIPAA security requirements, consider following these five steps. 1 PERFORM A RISK ANALYSIS This is a self-evaluation in which a practice must identify safeguards in place to secure PHI, as well as identify potential risks to the confidentiality of that same sensitive information. For example, many practices do not change computer and server passwords on a regular basis — a potential risk. As a result, my company recommends computer and server passwords be changed at least 3x per year, as anything less frequent would be considered an elevated risk. The Office for Civil Rights (OCR) at the United States Department of Health & Human Services is clear in explaining that the risk analysis is the first step in a practice’s HIPAA security compliance efforts. Without one, a practice cannot be considered HIPAA compliant. In the case of a HIPAA audit, data breach precaution is the first item the OCR will require from a practice as proof of risk analysis. (The first thing the government will ask for in case of an audit is proof of risk analysis). This makes it vital for practices to have their risk analyses easily accessible and up to date. The five categories to consider when documenting the risk analysis are (1) physical, (2) technical, (3) administrative, (4) policies and procedures and (5) organizational requirements. (See tinyurl.com/RAHHS .) Pro tip. Rather than updating the risk analysis once per year, make it a habit to update it, at minimum, on a quarterly basis to save a substantial amount of time. Securing Your Practice 2 DOCUMENT POLICIES AND PROCEDURES No matter the size of your practice, it is imperative to document all HIPAA policies and procedures for your organization, as the 2016 HIPAA Audit Protocol mandates policies and procedures be reviewed in the case of an OCR audit. While it may seem like overkill for smaller optometry practices to have a full complement of documented policies, doing so can be beneficial in the case of disaster recovery efforts or streamlining the onboarding/off boarding process for employees. Pro tip. Make sure policies and procedures are specific to your organization’s processes. In other words, avoid using generic online or purchased templates that can give a false sense of security that you are meeting the HIPAA policy and procedure requirement. Examples of policies: access authorization, disaster recovery plan, email and fax transmission and employee hiring and termination. 3 CREATE A HIPAA TRAINING PROGRAM Many practices conduct HIPAA training for all staff (full/part-time), but few may be meeting OCR’s training requirement. This requirement: Not only must HIPAA training be completed, at minimum, once per year for all employees, but training requirements also mandate that it be concluded in a modular format. This means documented proof is required that a quiz was taken by each employee. Pro tip. Make sure new employees go through a formal HIPAA training program and take an associated quiz within 90 days of being hired, or “in a reasonable time frame.” 4 REQUIRE BUSINESS ASSOCIATE CONTRACTS Also known as BACs, these offset liabilities in the case of a data breach. With the majority of data breaches caused by business associates (CPA firms, attorneys, consultants) and not internal employees, the importance of getting BACs signed cannot be understated. If a business associate will not sign a BAC, realize that by continuing to work with him or her, the practice is taking on a huge liability risk. (See tinyurl.com/BACHHS .) Pro tip. Every BAC is worded differently, so be sure to identify when the BAC expires. 5 ENCRYPT OR SECURE PHI You may understand the importance of ensuring servers and backups are encrypted properly, but have you ensured other applications, such as your email, are secure? Emails containing PHI should never be sent under any circumstance unless encrypted or secured. Also, remember that every time a document is scanned or printed to a multi-function device, a copy is saved to the internal hard drive. If hard drives are not encrypted or wiped properly and the device is returned at the completion of a lease or sold to another business, a data breach can occur. Pro tip. Most all-in-one printers/copiers/scanners provide a HIPAA-compliant security or encryption package. If these are not available for your device, work with an IT professional to wipe and delete hard drives properly before disposing of the system. Total Complaints Investigated 36,048Source: HHS.gov PROTECT YOUR BUSINESS While many practices feel burdened by the added responsibilities of technology, such as EHR, lack of time to interpret HIPAA security requirements is not an accepted excuse when a HIPAA audit reveals problems. Follow the steps outlined above, and consider reaching out to a third party for questions, concerns or if you just need help. OM MR.

Recent Posts

  • What OSF Healthcare’s Ransomware Fine Teaches Every Practice About SRAs
  • Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
  • 2026 OSHA HazCom Deadlines: How the GHS Update Impacts Your Practice
  • 15 Million Reasons to Review Your Business Associates: Lessons from the MMG Fusion Settlement

Recent Comments

No comments to show.

Archives

  • August 2026
  • June 2026
  • May 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • September 2019
  • October 2018
  • July 2018
  • May 2018
  • November 2017
  • April 2017

Categories

  • Abyde News
  • Audits
  • Best Practices
  • Business Associates
  • Cybersecurity
  • Fines
  • HIPAA
  • Legislation
  • OSHA
  • Partner News
  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS