Remain HIPAA Compliant While Transitioning to Digital
Question: I’m a manager at an office that still uses a lot of paper. We are looking to finally transition to a more digital approach, including using email communication for the bulk of our patient contact. I'm concerned about HIPAA compliance and the potential for security breaches. Are there any pointers you can provide to help us avoid trouble during and after this transition? Tennessee Subscriber Answer: Yes, this question is asked a lot and there are definitely helpful tips we can give you to help you stay ahead of security threats as your office does its part to go digital and reduce waste. When you begin training your employees, teach them to be skeptical and to look closely when reading email addresses. Many phishing attacks come from email addresses made to look like legitimate or familiar accounts. It’s crucial to keep your software consistently updated, as many updates address firewall complications and security vulnerabilities. Be sure to back up important data — then if your office is the victim of a cyberattack, you won’t lose all of your files. Email encryption services are always a smart option, and these add one more layer of security to keep HIPAA safe from prying eyes. Continue to train your employees in HIPAA and email safety practices throughout the year in coordination with your IT department. As new threats emerge, your team will be better prepared to handle them when the training is fresh in their minds. Finally, conduct regular audits in the form of test emails to ensure compliance and identify potential security risks within your team. Lindsey Bush, BA, MA, CPC, Production Editor, AAPC
