Red Flags Rule Enforcement Starts on Saturday
Dom Nicastro, for HealthLeaders Media, July 28, 2009
Apgar says the Red Flags requirements are similar to the HIPAA Security Rule and state/federal breach notification requirements. His suggested "required elements" of a compliant Red Flag Rule program that can be incorporated into existing policies are:
- Risk analysis
- Threat or vulnerability identification ("Red Flag" identification)
- Alerts, notification requirements and investigation
- Mitigation as necessary (including breach notification)
- Documentation of investigations and, if appropriate, mitigation
- Workforce member training
- Business associate implementation and maintenance of an identity theft protection program (requires an amendment to the business associate contract)
And if there ever were a time to be compliant, it's now–especially with new HIPAA laws signed into the American Recovery and Reinvestment Act of 2009 (ARRA).
"Given the expansion of federal enforcement included in ARRA and the significant increase in civil penalties," Apgar says, "it is important now to make sure the security program is sound and reasonably ensures patient PHI is protected from inappropriate access, breach or exposing the patient to identity or medical identity theft."
Dom Nicastro is a senior managing editor at HCPro, Inc. in Danvers, MA. He edits the Briefings on HIPAA newsletter and manages the HIPAA Update Blog. E-mail him at dnicastro@hcpro.com.
1
|
2
Most Viewed
Most Emailed
- New Facebook Page Gathers Stories of Medical Harm
- Urologists 'Outraged' Over PSA Test Challenge
- Five Hospitals Share Three Secrets to Improve Knee Surgery Outcomes
- Luxury Hospital Facilities Put Patient Experience First
- Beleaguered Fairview Health CEO to Retire in July
- Heartland Health Joins Mayo Clinic Network
- Challenging Physicians to Help Improve the ED
- Health Insurance Exchanges Put Defined Benefits to the Test
- The Power of Plugged-In Physicians
- For hospitals and insurers, new fervor to cut costs


Comments are moderated. Please be patient.