Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

Abyde President, Matt DiBlasi, Featured Article in Optometric Management Magazine

April 20, 2017

The article below was featured in the April edition of Optometric Management Magazine. To see it on their website,  click here.

ARE YOU HIPAA COMPLIANT?

THESE FIVE STEPS CAN HELP YOUR PRACTICE SECURE PATIENT INFORMATION

By Matt DiBlasi, St. Petersburg, Fla.April 1, 2017 

THANKS TO the HITECH Act, Meaningful Use and the Medicare Access and CHIP Reauthorization Act (MACRA)/Merit-based Incentive Payment System (MIPS), the number of optometrists using EHRs will be at an all-time high by the end of 2017. Many practices are trying to implement software, install IT networks, ensure data backups are running properly and integrate diagnostic technology, such as optical coherence tomography devices, into electronic information systems.

For established practices the overwhelming sentiment is, “This is not what I went to school for!” While that statement may be true, O.D.s must embrace this technology. It is tied closely with The Health Insurance Portability and Accountability Act of 1996 (HIPAA) and, thus, the survival of one’s practice.

Whether it is patient names, Social Security numbers, dates of birth or medical histories, the data stored in EHR is extremely profitable to those with malicious intent. In fact, this protected health information (PHI) is 10x more valuable than credit card information on the black market, reports Reuters. This makes optometry practices targets for criminals. (See “Securing Your Practice,” p.23.)

To ensure you’re complying with the latest HIPAA security requirements, consider following these five steps.

1 PERFORM A RISK ANALYSIS

This is a self-evaluation in which a practice must identify safeguards in place to secure PHI, as well as identify potential risks to the confidentiality of that same sensitive information. For example, many practices do not change computer and server passwords on a regular basis — a potential risk. As a result, my company recommends computer and server passwords be changed at least 3x per year, as anything less frequent would be considered an elevated risk.

The Office for Civil Rights (OCR) at the United States Department of Health & Human Services is clear in explaining that the risk analysis is the first step in a practice’s HIPAA security compliance efforts. Without one, a practice cannot be considered HIPAA compliant.

In the case of a HIPAA audit, data breach precaution is the first item the OCR will require from a practice as proof of risk analysis. (The first thing the government will ask for in case of an audit is proof of risk analysis). This makes it vital for practices to have their risk analyses easily accessible and up to date.

The five categories to consider when documenting the risk analysis are (1) physical, (2) technical, (3) administrative, (4) policies and procedures and (5) organizational requirements. (See tinyurl.com/RAHHS .)

Pro tip. Rather than updating the risk analysis once per year, make it a habit to update it, at minimum, on a quarterly basis to save a substantial amount of time.

Securing Your Practice

  • Business Planning
    • Self-risk analysis
    • Review and audit procedures and policies
    • Training and security awareness protocols and schedules
  • Physical Security
    • Physical access control
      • Physical barrier to open access to computers (guest access)
      • Workstation use policies (access through log-ins and passwords)
      • Access notifications and tracking
      • Lost or stolen device protocols
    • Software security
      • Firewalls and malicious software prevention
      • Encryption
    • Media disposal
  • Business continuity
    • Disaster recovery (server outage, etc.) documentation and protocols

2 DOCUMENT POLICIES AND PROCEDURES

No matter the size of your practice, it is imperative to document all HIPAA policies and procedures for your organization, as the 2016 HIPAA Audit Protocol mandates policies and procedures be reviewed in the case of an OCR audit.

While it may seem like overkill for smaller optometry practices to have a full complement of documented policies, doing so can be beneficial in the case of disaster recovery efforts or streamlining the onboarding/off boarding process for employees.

Pro tip. Make sure policies and procedures are specific to your organization’s processes. In other words, avoid using generic online or purchased templates that can give a false sense of security that you are meeting the HIPAA policy and procedure requirement. Examples of policies: access authorization, disaster recovery plan, email and fax transmission and employee hiring and termination.

3 CREATE A HIPAA TRAINING PROGRAM

Many practices conduct HIPAA training for all staff (full/part-time), but few may be meeting OCR’s training requirement. This requirement: Not only must HIPAA training be completed, at minimum, once per year for all employees, but training requirements also mandate that it be concluded in a modular format. This means documented proof is required that a quiz was taken by each employee.

Pro tip. Make sure new employees go through a formal HIPAA training program and take an associated quiz within 90 days of being hired, or “in a reasonable time frame.”

4 REQUIRE BUSINESS ASSOCIATE CONTRACTS

Also known as BACs, these offset liabilities in the case of a data breach. With the majority of data breaches caused by business associates (CPA firms, attorneys, consultants) and not internal employees, the importance of getting BACs signed cannot be understated. If a business associate will not sign a BAC, realize that by continuing to work with him or her, the practice is taking on a huge liability risk. (See tinyurl.com/BACHHS .)

Pro tip. Every BAC is worded differently, so be sure to identify when the BAC expires.

5 ENCRYPT OR SECURE PHI

You may understand the importance of ensuring servers and backups are encrypted properly, but have you ensured other applications, such as your email, are secure? Emails containing PHI should never be sent under any circumstance unless encrypted or secured. Also, remember that every time a document is scanned or printed to a multi-function device, a copy is saved to the internal hard drive. If hard drives are not encrypted or wiped properly and the device is returned at the completion of a lease or sold to another business, a data breach can occur.

Pro tip. Most all-in-one printers/copiers/scanners provide a HIPAA-compliant security or encryption package. If these are not available for your device, work with an IT professional to wipe and delete hard drives properly before disposing of the system.

Total Complaints Investigated 36,048
Source: HHS.gov

PROTECT YOUR BUSINESS

While many practices feel burdened by the added responsibilities of technology, such as EHR, lack of time to interpret HIPAA security requirements is not an accepted excuse when a HIPAA audit reveals problems. Follow the steps outlined above, and consider reaching out to a third party for questions, concerns or if you just need help. OM

MR. DIBLASI is president of Abyde (continualcompliance.com ), a Florida-based consulting firm that specializes in helping medical practices with HIPAA compliance. The company recently launched an automated cloud-based software. Email him at mdiblasi@continualcompliance.com, or visit tinyurl.com/OMComment to comment on this article.

RECENT POSTS

  • OSF Healthcare HIPAA Settlement
    What OSF Healthcare's Ransomware Fine Teaches Every Practice About SRAs
  • Spencer Gifts HIPAA Fine
    Spencer Gifts HIPAA Settlement: Ransomware, Risk Analysis, and What Comes Next
  • OCR Ransomware Settlements
    OCR Ransomware Settlements: 4 Massive HIPAA Fines from April 2026 & How to Avoid Them
NextAbyde and IDOC Partner Up!Next

Related posts

Top 50 Florida Companies to Watch
Abyde News

Abyde Takes the Spotlight: Named One of Florida’s Top 50 Companies to Watch

October 15, 2025 Penelope Schweitzer No comments yet

October 16, 2025 We are incredibly proud to announce that GrowFL has recognized our team at Abyde as one of Florida’s Top 50 Companies to Watch! This prestigious, statewide award is a tremendous honor for us and a powerful testament to the impact Abyde has across the medical compliance industry and our local community right here in Florida. As we officially take our spot among Florida’s top growing companies, we’re reminded that this achievement is built entirely on two things: the dedication and success of our incredible team, and the trust of our amazing customers. This award validates our core commitment to creating an environment where our team can thrive and grow, and our continued mission to simplify HIPAA and OSHA compliance for every practice we serve.  What does this mean for Abyde? The Annual GrowFL Florida Companies to Watch Award is a coveted honor for Florida companies with six to 150 employees. Even being named a nominee is an incredible honor, as it highlights a business’s economic performance and organizational growth, outstanding achievements that have significantly impacted Florida’s economy. After a thorough judging process involving a competitive pool of Florida-based companies from various industries, Abyde has been named a top 50 finalist!  With 500 nominations for this award, we ranked in the top 10 percent of Florida companies during the 15th Annual GrowFL Florida Companies to Watch Awards. These honorees’ impact on Florida’s economy is significant. With over $700 million in revenue annually and nearly 2,250 employees as of 2024, these numbers are projected to be almost $900 million in revenue and 2,500 employees for 2025. Want to join our journey as we simplify compliance for healthcare practices? Follow Abyde on LinkedIn for company news and the latest career opportunities!

Abyde Updates 2024-2025
Abyde News

Ahead of the Curve: Abyde’s Latest Updates Keep You Covered

May 29, 2025 Penelope Schweitzer No comments yet

May 29, 2025   It’s been a pivotal year for healthcare compliance. The largest ever healthcare data breach occurred at the beginning of 2024, and now the HHS Office for Civil Rights is reviewing and soon implementing new HIPAA legislation.  Don’t worry; as an Abyde customer, we’ve got you covered. Our cloud-based software is rapidly updated with features to address the latest legislation.  To help you keep up with all the compliance changes, Abyde is committed to providing an adaptable software platform to maintain compliance within an ever-changing regulatory environment. We’ve compiled a quick rundown of the most significant Abyde updates from the past year. These updates assist your practice in automating, simplifying, and streamlining compliance.    Business Associate Accountability Abyde expanded our ecosystem with a new product, HIPAA for Business Associates, to serve the vendors of Covered Entities. Even if they don’t directly care for patients, they still play an essential role in keeping that information safe.  Like your Abyde experience, Business Associates (BAs) now have a centralized hub for HIPAA responsibilities. With the Abyde for Business Associates solution, your BAs can take control of their compliance program. Your practice can also have peace of mind that the businesses you work with take compliance seriously.  We’ve also made it easier to manage Business Associate Agreements (BAAs) within our Covered Entities software. Now, BAAs are dynamically updated to be location-specific. BAs can be assigned to one or more locations within multi-location accounts. This helps everyone stay accurate and accountable when handling PHI.  Additionally, when completing your Security Risk Analysis (SRA), your BAs can now assist in answering questions with the new SRA Contributor feature. With the SRA Contributor, BAs or fellow staff can help answer questions you may be unsure of, allowing your practice to receive and review answers while completing the SRA. This enables your BA to provide support with technical questions and permits your practice to complete the SRA more quickly and accurately.  Staying Ahead of the Latest Legislation  Abyde is committed to proactively updating our software to maintain your practice’s compliance with evolving healthcare regulations.  We’ve kept this commitment with our Compliance Task Force team, a team of our experts dedicated to thoroughly addressing new legislation. Our Compliance Task Force reviews and researches new legislation in advance, ensuring Abyde’s software remains compliant with the latest laws.  One example is recent legislation on workplace violence. As healthcare staff is five times as likely to experience workplace violence compared to other workers, federal OSHA legislation is incoming. Abyde quickly updated its platform to reflect Cal/OSHA’s new Workplace Violence Prevention legislation, which requires substantial changes to compliance programs, such as new logs and training. Because Cal/OSHA’s rules frequently become federal standards, Abyde users gain the advantage of early compliance, ensuring they’re ready for future national mandates. In addition, we provided a webinar about these new requirements, ensuring all were aware of their responsibilities.  Another major recent legislative change was introducing a reproductive healthcare attestation form. Initiated by the Biden administration, reproductive healthcare is handled separately, requiring additional paperwork to share PHI. While this update has been contested, practices are prepared with the additional paperwork in the Forms section of the Policies & Procedures module. Abyde software is tailored to federal and state laws. For example, we recently adjusted the New York Breach Notification Policy based on recent state regulations.  Overall, Abyde’s software is equipped to deliver necessary updates promptly in response to new legislation. With new incoming legislation, like the updated Security Rule, it’s vital to use software that makes change easy.    Training Tailored to Your Schedule We understand your time is valuable, so we’ve made managing your team’s HIPAA training easier than ever.  Abyde’s training overhaul in the HIPAA solutions allows HCOs to schedule training. Training for the entire subscription year is now available up front, allowing HCOs to schedule it at their earliest convenience. If you prefer Abyde’s automated scheduling, worry not! The original cadence remains in place as a default.  The new updates, tailored to your practice, also allow for training to be resent. For example, after a breach, reviewing training is key, as is ensuring staff are retrained on best practices to mitigate future risk.  New training has also been revolutionized into three bite-sized pieces, making it more palatable for viewers to retain the information. The update also included structuring insights into three tabs in the training section in both HIPAA solutions to organize the videos easily. Abyde’s streamlined and simplified training process provides flexibility for your practice, empowering your team to create a training schedule that fits your availability.    Reduce Risk for Your Practice Your practice was likely affected by the Change Healthcare Breach in the past year. This massive breach was a wake-up call for everyone in the healthcare industry. The fundamental security oversight was the absence of multi-factor authentication.  As a result of this discovery, Abyde implemented MFA to access our solutions, following best practices. Now, a unique code will be sent when attempting to log into Abyde’s software.  While this update might add a few seconds to your login routine, this extra layer of protection keeps your account secure. It also serves as a great reminder to review passwords and add MFA when possible. This additional cybersecurity measure will also likely become required as part of the new Security Rule updates.    Making Abyde Even Easier If you ever need a quick refresher on the Abyde HIPAA for Covered Entities solution, we’ve recently implemented in-app explainer videos.  These videos can be found throughout the software, providing a short video on each module. Get the answers you need instantly, right where you need them. These short clips ensure everyone feels confident navigating the solution, which means less time searching and more time focused on patient care. And remember, if you ever need any compliance assistance, the subscription includes access to our compliance experts.    Abyde Updates – Protecting your Practice  It’s been a busy year for HIPAA, with legislation updates,

Warby Parker HIPAA Fine
Abyde News, Fines, HIPAA

Warby Parker’s $1.5 Million HIPAA Fine: A Security Risk Analysis Eye-Opener

March 6, 2025 Penelope Schweitzer No comments yet

March 6, 2025 Warby Parker, the popular prescription eyewear retailer with a strong online presence and expanding physical stores, was recently fined $1.5 million for a HIPAA violation. This enforcement highlights that no matter how big your organization is, the government can and will investigate breaches of PHI. In 2025, the Office for Civil Rights (OCR) has issued over $5 million in fines so far, almost all of which involved a missing Security Risk Analysis (SRA). The SRA thoroughly assesses your practice’s physical, technical, and administrative safeguards for securing patient Protected Health Information (PHI). The Warby Parker fine is a stark reminder that the SRA, a detailed examination of your PHI safeguards, is not just a recommendation; it’s a necessity. What Happened? In late 2018, Warby Parker experienced numerous unusual login attempts on its site. It was discovered that customer logins were breached through credential stuffing or when information was pulled from unrelated breaches. For example, a customer’s login was likely reused on another hacked site. The OCR began its investigation in December 2018, but the flurry of attacks continued. Warby Parker, which also provides eye exams, issued several addendums to its initial breach report, revealing that additional customer and patient accounts were compromised. Additional attacks occurred in 2020 and 2022. Overall, these cybercrimes impacted almost 200,000 patients. As the OCR investigated Warby Parker, it discovered that Warby Parker did not conduct an adequate security risk analysis, implement sufficient technical safeguards to prevent further attacks, or regularly review system access. These failures to protect PHI led to a $1.5 million Civil Monetary Penalty (CMP), demonstrating that even massive organizations need to comply with HIPAA requirements. How to Protect Your Organization The first step to HIPAA compliance for your practice is proactively maintaining an SRA. By evaluating and identifying your vulnerabilities, your practice can address these weaknesses before they become serious problems. As stated before, no matter how small or large your organization is, you must complete the SRA annually. Regular reviews of PHI access are essential to identify and address breaches promptly, minimizing the number of affected patients. Implementing an access log is crucial as well, ensuring staff is held accountable for documenting when they interact with PHI. Utilizing a compliance software solution can alleviate the stress of managing numerous requirements. Software solutions can streamline compliance and offer a SRA and an access log within the program. By outsourcing compliance, your team can focus more time on patient care. To learn how to simplify HIPAA compliance for your practice, schedule a consultation with a compliance expert today.

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS