After conducting numerous HIPAA gap analyses, we’ve seen what happens when necessary safeguards are missing or ignored. This post explains what a HIPAA gap analysis involves, who should conduct it, and why it’s essential. For any organization handling PHI, a proactive approach can prevent costly mistakes.
Table of contents
- What Is a HIPAA Gap Analysis and Why Does It Matter?
- What Are Some Issues Covered in a HIPAA Gap Analysis?
- Who Should Perform Your HIPAA Gap Analysis?
- Preparing for a HIPAA Gap Analysis
- Key Issues Addressed in a HIPAA Gap Analysis Report
- Lessons Learned from Multiple HIPAA Gap Analyses
- Summary of Key Areas to Review in a HIPAA Gap Analysis
What Is a HIPAA Gap Analysis and Why Does It Matter?
A gap analysis is usually defined as the process of an accurate and thorough assessment of a business entity to compare current performance to expected or desired performance. So for covered entities — health care provider organizations, health care insurance companies and healthcare claims clearinghouses — a HIPAA gap analysis would consist of an accurate and thorough assessment of how the Covered Entity is complying with the HIPAA Privacy and Security Rules.
For medical groups, hospitals, and other provider organizations who must be HIPAA compliant, a HIPAA gap analysis is an important tool to help determine the current performance of your organization in relation to the desired level of HIPAA compliance.
What Are Some Issues Covered in a HIPAA Gap Analysis?
A HIPAA gap analysis helps by asking and answering several important questions, including:
Of course, these issues are only the tip of a very large iceberg that the HIPAA Rules represent!
Who Should Perform Your HIPAA Gap Analysis?
In our experience, even capable internal teams can overlook critical gaps without repeated exposure to HIPAA audits. It might seem practical to rely on your staff, provided they’ve conducted multiple compliance evaluations and understand how to deliver an unbiased report. These reports, after all, will be used to close privacy and security gaps.
Relying on a reputable, third-party firm to perform your HIPAA gap analysis is a good course of action. A reputable consulting firm means the difference between some experience and expert level experience. With a HIPAA gap analysis, you want experts who have done this many times as well as experts who will notice hard-to-detect deficiencies that are easy to miss.
Preparing for a HIPAA Gap Analysis
After you have assigned a third-party auditor or assembled a team, it’s time to properly prepare and assemble materials within your organization, including:
Key Issues Addressed in a HIPAA Gap Analysis Report
The final report you receive should cover privacy and security issues discovered through the HIPAA gap analysis. Examples of issues you may encounter include:
It’s important to note that data sharing is not limited to one department when running a gap analysis.
The final report will give you the necessary tools to manage or improve risks, such as (1) putting security measures in place to diminish risks and close gaps, (2) implementing immediate policies or taking fast disciplinary action against employees who are not in line with privacy/security regulations, and (3) incorporating review procedures to regularly evaluate information system activity.
Lessons Learned from Multiple HIPAA Gap Analyses
The Fox Group has perform literally dozens of HIPAA gap analyses. The gap analysis is often paired with developing a comprehensive HIPAA Privacy Manual to address all of the HIPAA Privacy Rule regulations, as well as a HIPAA Security Compliance Manual. Although some of our previous clients have had policy and procedure manuals, most of the time they only addressed a portion of all of the regulations that must be addressed by any health care provider Covered Entity that utilizes a electronic health record system.
A few of the more egregious things we have seen:
Compliance by healthcare providers with HIPAA regulations is an expectation of literally everyone, from patients to licensing/regulatory bodies to community members in general. A HIPAA gap analysis is a good place to start if you are at all worried about how your organization would to fare if it were subject to an audit by the Office for Civil Rights (OCR) of the Health and Human Services Department (HHS). Those are the folks who come to investigate if/when they get reports of unauthorized disclosures large and small. They are also the people who decide how big your fine will be, and if you belong on the “Wall of Shame“! Hint: don’t get top billing on the Wall of Shame!
Summary of Key Areas to Review in a HIPAA Gap Analysis
Below is a summary you can refer to as a high-level checklist when evaluating how well your organization is addressing HIPAA’s privacy and security requirements. Or use it as a high-level guide to what should be included if outsourced to a qualified consulting firm. They reflect what we’ve found to be among the most critical items.
Section 1: Organizational Accountability
|
Focus Area |
What to Look For or Ask |
Rule |
|---|---|---|
|
Privacy & Security Oversight |
Are Privacy and Security Officers assigned and empowered? |
Privacy / Security |
|
Risk Analysis & Governance |
Are risk and gap analyses conducted regularly and acted upon? |
Security |
|
Policies, Training & Notice of Privacy Practices |
Do policies address all relevant portions of the HIPPA regulations; is staff trained, and NPPs distributed? |
Privacy / Security |
Section 2: Protecting PHI Across Environments
|
Focus Area |
What to Look For or Ask |
Rule |
|---|---|---|
|
Facility & Device Controls |
Are physical access points and ePHI devices inventoried and secured? |
Security |
|
Access Controls & Logins |
Are credentials unique, deactivation timely, and role-based access enforced? |
Security |
|
System Security Measures |
Are encryption, audit logs, and patches properly implemented and tested? |
Security |
|
Backup and Disaster Recovery |
Are daily backups completed reliably; are disaster procedures in place and tested? |
Security |
Section 3: Respecting Patients and Managing Risk
|
Focus Area |
What to Look For or Ask |
Rule |
|---|---|---|
|
Uses and Disclosures |
Are PHI uses/disclosures tracked, minimal, and patient authorizations documented? |
Privacy |
|
Patient Rights |
Can patients access, request amendments or request restrictions on disclosures of their PHI? |
Privacy |
|
Business Associate Oversight |
Are BAAs in place, and do vendors meet HIPAA expectations? |
Privacy / Security |
|
Incident Response & Insurance |
Are breaches logged and managed, and is insurance in place for regulatory and recovery costs? |
Security |
