Who Must Comply With HIPAA?
If you provide health care insurance or plans or are a government program that deals with insurance, such as Medicare and Medicaid, Company health plans, HMOs, and other health coverage companies and you transmit sensitive health information, you likely also fall under covered entities. There are two other types of covered entities, including health care providers that get paid to provide health care and healthcare clearinghouses.
This sensitive information can be in oral, electronic, or paper form and will have some form of “individually indentifiable health information” as named by HSS such as an address, name, social security number, etc.
If your company or organization must follow HIPAA regulations as a “covered entity,” it’s important that you comply with these regulations year round.
As part of an HIPAA Audit conducted by the OCR, there are various documents or requests that may be made, which include:
- A list of all business associates and their contact information;
- Both desk and onsite audits;
- Submission of documents through an online portal with 10 days of their request;
- Responding to draft findings;
If you are a covered entity, business associate, choosing to work with a third-party professional team to conduct an assessment of your HIPAA compliance can be very beneficial. It not only prepares you for a Federal audit but proves to your consumers and partners that you are completely transparent and serious about ensuring proper protocols are being followed.
Varsity can help your team organize what is needed so that no errors are made that can draw out the audit process. We will increase efficiency of your HIPAA audit, remove stressors that can occur when a organization takes on the audit itself, and aid in future organizational techniques that will have your company ready for the next audit.