"For Years, HIPAA Insisted On Data Privacy And Security Protections - And For Years, Those Same Requirements Were Ignored With Relative Impunity. The HITECH Act Changes All That." ~ Physician News, December 2010

“Health insurer WellPoint Inc. would provide 600,000 individuals “potentially” affected by a data breach two years of paid credit monitoring and identity theft protection services, and another five years protection to any individuals found to be a victim of identity theft or loss because of the breach, according to a preliminary class action settlement, HealthCareInfoSecurity.com reports. 7/20/11″ – FierceHealthcare February, 2011

When it comes to sensitive information, fines, penalties, organizational reputation and more, the HITECH Act has changed everything.

  • Significantly Increased Fines And Penalties
  • Massively Increased Enforcement
  • Mandatory Federal Breach Notification Requirements
  • Mandatory Media Breach Notification Requirements
  • Mandatory Patient Notification Requirements
  • Business Associate Compliance Requirements
Compliance Is Required Now

From the smallest dental and medical offices to the largest hospitals, all covered entities and business associates must be in compliance now.

Compliance is only part of the problem. There are 4 main challenges of the HITECH Act:

  • Compliance
  • Reducing Your Risk of a Costly Data Breach
  • Protecting Your Valuable Reputation
  • Guarding Your Bottom Line
The Department of Health and Human Services has already begun enforcement, with multiple high profile cases such as a $4.3 million fine against Cignet Health in February 2011.

Unlike HIPAA enforcement in the old days, HITECH enforcement will be strong and expensive.

And This Is Just The Beginning!

Ten new Federal Privacy Advisors are being placed around the country to better investigate and enforce violations and data breaches.

The Health and Human Services Office of Civil Rights has requested an additional $5.6 million in funding, with 76% of these funds going to increased enforcement of the HITECH Act.

And if this wasn’t enough, under the HITECH Act, Attorneys General are now authorized to join in the enforcement effort.

Just 3 months after HITECH became law, the AG Office in Connecticut used the new statutes to sue Health Net and its affiliates over a lost computer disk drive. The resulting settlement, assuming a monthly cost for credit monitoring of just $1 per person, was over $37 million.

Worse, direct fines and out-of-pocket costs do not account for the future revenue lost by angry clients who choose alternate providers because they no longer trust you.

Health Net was the first case brought by an Attorney General. With budgets tighter than ever, all 50 states are motivated to enforce this new law. Happy to oblige, the federal government began conducting regular trainings specifically for Attorneys General in April, 2011.

The increased enforcement, both civil and criminal, is being applied at all levels – from large hospitals to small practices and organizations, even to the individual employee.

In late April, 2010, a heart surgeon working at UCLA was fined and put in prison for 4 months – the very first prosecution to result in incarceration due ONLY to HIPAA violations.
The HITECH act significantly raises the bar for health information privacy and security.

The HITECH act significantly raises the bar for health information privacy and security. Previously, the liability a health care organization faced for the breach of any given provision generally couldn’t exceed $25,000. Today, that same breach can cost an organization up to $1.5 million in fines.

The smallest medical and dental offices have thousands, even tens of thousands, of medical records in their care. Because of the new laws, losing information either in electronic or paper form constitutes a breach.

Organizations need to be proactive about this new legislation in order to minimize the unprecedented risk and liability.

The biggest challenge most organizations are struggling with is the complexity of the problem.

Federal and Media Notification Requirements

Under the new legislation, if you have a breach of any size (even just ONE record), you have multiple reporting and notification requirements.

Worse, if non-encrypted information of 500 or more patients is breached or lost, you ALSO must notify prominent local media outlets AND the government will post your data breach on a public website.

In addition, you face the likelihood of federal investigations, HIPAA/HITECH audits, state Attorney General involvement, and significant loss of patient trust.

For organizations that choose NOT to comply, the consequences are much worse.

When law enforcement or the media discovers an unreported breach the fines are much higher and the loss of public trust much greater. Health Net, for example, waited six months before notifying consumers or law enforcement which concerned the Attorney General and exacerbated the problem.

This is not just an IT issue. In fact, it is more of business process issue that affects your entire organization.

Compliance requires the right policies, procedures, incident response plans, employee training, business associate agreements, record keeping, risk assessments and more. Everything has to be in place, documented, and updated on a regular basis.

                                  And Unfortunately The Burden Of Proof Is On You!

HITECHMADESIMPLE.com is your easy comprehensive source providing all the various assessments, templates, and trainings you need.

First, you will have access to video trainings you can use to train yourself and your staff anytime – even as you hire new employees throughout the year.

Employer/Administrator Level Video Trainings

The HITECH Act, Part I

This training is designed to provide the employer, physician, or administrator with a detailed overview of the HITECH Act including enforcement and accounting provisions, PHI identifiers, deadlines, breaches and breach notification requirements, changes to business associates, marketing, fund raising, and action items.

The HITECH Act, Part II

Designed for the employer, physician, or administrator, this training discusses the financial incentives set forth by the new legislation, including a discussion on meaningful use, eligibility, differences in Medicare and Medicaid providers, the attestation process, the path to getting paid, and much more.

Employee Video Trainings

What Your Staff Must Know About The HITECH Act

This training discusses the elements of the HITECH Act that every employee of a covered entity or business associate must understand such as PHI, fines, penalties, enforcement, notification requirements, and more.

The Cost Of A Data Breach

The costs of a breach are high, whether the information stolen was in electronic or paper form. The HITECH Act increases these costs significantly, through such aspects as patient notification, federal notification, reputation, legal liability, operational cost, fines, fees, penalties, monitoring, and much more.

Why Breaches Occur, and How to Reduce This Risk

There any many reasons why breaches occur – the most common being employee error. This training will discuss these myriad factors and many practical steps that can be taken at every level to reduce this risk.

The High Cost and Impact of Identity Theft

This training reviews real-life examples of how identity theft occurs as well as many practical steps to prevent the employee or the patient from becoming a victim of the #1 crime in America.

Identity Theft Myths and Misconceptions

Contrary to popular belief, identity theft is not just about your credit report.

All video trainings have been specifically designed to help change how your staff thinks about handling sensitive data. When your staff thinks differently, they will behave differently, which reduces your risk and liability.

Employee Documents and Resources

Certificate of Completion

To help document your training and compliance efforts, a Certificate of Completion is provided which we encourage you to keep on file after each of your staff have completed the modules.

 

 

Risk Assessment

You will receive a comprehensive Risk Assessment. HIPAA requires a Risk Assessment, and ours provides you with over 84 questions covering administrative, physical, and technical aspects to help you reduce your risk as comprehensively as possible.

Data Map Template

Also included is a Data Map Template. In order to accurately protect your data, you first need to know where your data actually rests, how it moves, how it is used, and how it is protected in each of those states. This template will provide you with the roadmap to do this.

Business Associate Agreement

Another aspect of the new HITECH legislation is the change to Business Associates. To accommodate this, an updated Business Associate Agreement template is also included.

 

 

Data Breach Resources

Now despite the best laid plans, when a data breach occurs, you need to be ready.

Who will handle the media? Who will be part of your response team? Who needs to be notified? What are the deadlines?

To answer these questions and many others, you will also receive our Incident Response Plan, Breach Response Toolkit, Notification Letter, and Harm Threshold Assessment. These resources are provided to you in fully editable format and are critical in establishing your breach response.

 

If You Suffer A Data Breach You Are Not Alone!

We simplify the anxiety experienced by a data breach by giving you access to our team of affiliate partners including the nation’s leading breach restoration and consulting firm for a Free Consultation.

Free Updates For 12 Months!

The HITECH Act is significant legislation, and changes or updates are occurring regularly. Your membership provides you with 12 months of free updates about changes in legislation, breach prevention tips, power points, videos, related articles, and much more.

HITECHMADESIMPLE.COM is a simple affordable solution for your whole organization – with the resources your organization needs to be ready for the HITECH Act and the risks related to protected information.

What Others Are Saying About Our Training
“We were impacted by this information and became aware about the different ways that information can be breached”
N.Vega, TIH
“Made our whole medical office more aware of how to be safer with our patient and our own personal information”
C. Kremer, Broomfield, CO
“We were more than pleased with the concise, digestible information. It was very helpful in opening our eyes to possible risks in the office. The training helped greatly in evaluating the administrative processes used in handling and securing data as well as policy adoption.”
Jo M, Director – NDC, TX

Our 30 Day 100% Money Back Guarantee

We’re so confident that HITECH Made Simple will help you prepare for and comply with the HITECH Act that we’re offering a “No-Questions-Asked” 100% Money Back Guarantee. If for any reason you don’t believe HITECH Made Simple has provided the training and resources necessary to prepare your practice for the HITECH Act, then we’ll gladly refund your purchase In Full.
LIMITED TIME BONUS OFFER

For a limited time, with your purchase of HITECH Made Simple, you will also receive for FREE our Social Media Policy and Social Networking Training Video and our Social Medial Policy! A $97 value absolutely FREE.

Bonus Employee Video Training – Social Network Awareness and HITECH

Social media sites such as Facebook and MySpace offer both an opportunity and threat to medical and dental offices. Employee misuse of these sites can cause HITECH violations. This training discusses these in detail with practical steps to reduce both organizational AND PERSONAL risks.

Bonus Employer Resource – Social Media Policy

Simply restricting access to social media sites from workplace computers is not an adequate or effective policy, and may actually increase your vulnerability. This document provides you with an editable template policy to better manage this new frontier for your organization.

We have worked hard to develop the resources your organization needs to be ready for the HITECH Act and the risks related to protected information. We know you will find HITECHMADESIMPLE.COM your complete solution.

  • Video Training – The HITECH Act – Parts 1 & 2
  • Video Training – What Your Staff Must Know About the HITECH Act
  • Video Training – The Cost of a Data Breach
  • Video Training – Why Breach Occur and How To Reduce This Risk
  • Video Training – The High Cost of Identity Theft
  • Video Training – Identity Theft – Myths and Misconceptions
  • Resource – Certificate of Completion
  • Resource – Risk Assessment
  • Resource – Data Map Template
  • Resource – Business Associate Template
  • Resource – Data Breach Resources
  • Updates – Free Updates For 12 Months
  • Free Bonus Video Training – Social Media Awareness and HITECH
  • Free Bonus Resource – Social Media Policy Template

The Complete HITECH Made Simple Course Now Only $297!