The 10 Step Plan for Health Information Privacy and Security, from the U.S. Department of Health and Human Services, offers a framework for understanding HIPAA requirements, while setting out a process to follow.
If you think of the HIPAA law as a book, each step is a chapter.
Here are the steps, followed by our interpretions of meaning:
-
Confirm you are a covered entity: Understand the breadth of HIPAA
-
Provide leadership: Appoint a chief or two, or a whole squad
-
Document your process, findings and actions: Specify what, why and where
-
Conduct a security risk analysis: Think ahead, like a detective
-
Develop an action plan: Plot steps with the resolve of thwarting thieves
-
Manage and mitigate risk: Don’t slack; Stay vigilant
-
Prevent breaches: Train staff to be enforcers
-
Communicate with patients: Make sure they know their rights
-
Update or execute Business Associate Agreements (BAAs): Hold Business Associates accountable
-
Attest for the security risk analysis Meaningful Use objective: Transform daily communications; Prepare for a data-driven health system