In our practice, we conduct HIPPA and HiTECH compliance audits for health care clients and business associates (companies that service health care companies). We also represent them when a HIPAA complaint has been filed or reported.
We do this as a law firm since our communications are protected by the attorney-client privilege unlike regular consultants.
Most small and mid-sized practices are not fully compliant and have not had audits. We go in, evaluate all existing policies and documents, create or revise a HIPAA compliance plan and employee handbook, document updated employee training, and peform a HIPAA HITECH initial audit which is confidential.
We work on a flat fee that gets spread out over the year and includes phone calls, emails and meetings to avoid high hourly charges and encourages efficiencies. We help make sure that HIPAA is integrated into the culture.
Some companies or practices have staff to implement changes and other times we perform them. During our attorney-client privileged meetings, we have a master list and then implement a master action plan that will culminate in a final HIPAA audit to be documented. We bring in less expensive consultants as needed to save money for the company or practice as needed.
Why is it important these audits be documented? If there is a HIPAA complaint by a patient or a data breach reported to OIG or Office for Civil Rights (who handles HIPAA complaints) or to the State of Californa DHCS Officeof HIPAA Compliance, they conduct audits. If there is a breach but it is found that there was prior compliance, proper policies and procedures, documented training, and a documented audit in place - the fines and punishment will be far less. It also helps avoid civil lawsuits by patients for state privacy breaches (since HIPAA does not give a private right of action).