{"id":2990,"date":"2020-07-09T11:46:21","date_gmt":"2020-07-09T11:46:21","guid":{"rendered":"https:\/\/www.empowerelearning.com\/blog\/?p=2990"},"modified":"2020-08-21T10:13:48","modified_gmt":"2020-08-21T10:13:48","slug":"is-there-an-official-hipaa-certification","status":"publish","type":"post","link":"https:\/\/www.empowerelearning.com\/blog\/is-there-an-official-hipaa-certification\/","title":{"rendered":"Is there an official HIPAA certification?"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Does HHS certify healthcare providers as HIPAA compliant? Are their third-party firms that provide <strong>HIPAA certification<\/strong>? Can a healthcare provider declare itself as HIPAA compliant?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Several companies claim that their products are HIPAA certified. But, there are no companies or products that have been certified or endorsed by the HHS.\u00a0\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There is no official HIPAA certification.\u00a0<\/span><\/p>\n<h2><b>Is HIPAA compliance important?\u00a0<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">If your organization is covered under HIPAA, then you need to follow the three HIPAA rules. These rules define the standards for handling protected health information. Failure to follow these standards can have severe consequences. Health and Human Services (HHS) can penalize your organization heavily if you fail to follow HIPAA. Criminal violations can even result in jail time.\u00a0\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">So, if you are a covered entity under <a href=\"https:\/\/en.wikipedia.org\/wiki\/Health_Insurance_Portability_and_Accountability_Act\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">HIPAA<\/a>, you must consider HIPAA compliance as the most important task on your list. Again, every healthcare provider who uses, shares or stores protected health information must ensure that it follows the three HIPPA rules.\u00a0<\/span><\/p>\n<h2><b>How to comply with the three HIPAA rules?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The three HIPAA rules include, HIPAA Privacy Rule, Security Rule, and the Breach Notification Rule.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To comply with these rules, covered entities must conduct a risk analysis of their organization. Then they must put in place a security management plan. An information access management system should also be put in place for ensuring minimum exposure of patient information. Moreover, the organization must document their entire compliance process. This would help prove that the management has taken all necessary steps for protecting patient information.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In short, you must ensure that you comply with every \u2018standard\u2019 of the three HIPAA Rules.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You\u2019d also need to assess your policies and procedures periodically for ensuring that they meet the standards set by the Security rule. And you must train your employees about your security policies and procedures.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">There is no other alternative to this process.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When the HHS Office of Civil Rights (OCR) decides to audit your organization, you should be able to show that you went through the entire process as mentioned above. And that you have been doing so since the past six years.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Even passing a HIPAA audit, does not entail that you have become HIPAA compliant. Tomorrow, if HHS announces changes to HIPAA rules, and if you fail to update your systems to account for those changes, the OCR can charge you with HIPAA non-compliance.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">HIPAA Compliance is an ongoing task. You must update your policies and procedures regularly, and ensure that your systems meet the HIPAA standards.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This can be difficult. Especially, if you are a new organization, or a large entity covered under HIPAA. You may choose to use third-party firms to help you with your HIPAA compliance efforts. Specifically \u2013<\/span><\/p>\n<ol>\n<li><span style=\"font-weight: 400;\">Administrative safeguards under the Security rule require that covered entities conduct a risk assessment of their system, and implement security measures to reduce the risk.<\/span>\n<ol>\n<li>It\u2019s a difficult task, if yours is a small practice, and if you do not have the setup necessary for such a task.<\/li>\n<li>Generally, such practices hire third-party services for carrying out risk assessment of their system and developing a security management plan for their practice.<\/li>\n<\/ol>\n<\/li>\n<li><span style=\"font-weight: 400;\">Similarly, covered entities need to access their security policies and procedures periodically for ensuring that they meet the standards set by the security rule. <\/span>\n<ol>\n<li>Again, if a practice does not possess the resources for carrying out such an assessment, then they can take help from third-party auditors for conducting the assessment.<\/li>\n<\/ol>\n<\/li>\n<li><span style=\"font-weight: 400;\">The security rule also requires covered entities to train their employees on security policies and procedures. You can use training vendors for conducting HIPAA training for your employees.<\/span>\n<ol>\n<li>Select a HIPAA training company that offers HIPAA training at a level that meets your expectations. You can also go for vendors who offer tracking and reporting of your training efforts. They could help you track if all your employees have been trained in their HIPAA responsibilities.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<h2><b>Third-party HIPAA certification<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Beware, the certificates of compliance issued by third-parties do not absolve you of your duties under HIPAA. The OCR is not bound to accept third party evaluation of your system. Nor do they accept training certificates from HIPAA training vendors. In fact, HHS and OCR do not endorse any seminars, material or systems. There are no products that have been certified as HIPAA compliant by the HHS. There is no official <a href=\"https:\/\/www.empowerelearning.com\/online-hipaa-training\/\" target=\"_blank\" rel=\"noopener noreferrer\">HIPAA certification<\/a>.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">When the OCR audits your organization, it would check your policies and procedures for compliance with the three HIPAA rules, it would check if your employees are aware of them, and it would confirm if your systems comply with the three HIPAA rules.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Third party certifications act only as confirmation that the necessary policies and procedures are in place; your documentation is accurate; and your employees have been trained properly. So, ensure that you create a documentary trail, if you use a third-party vendor to assist with your HIPAA compliance efforts. Rather than certificates, care more for reports. Rather than cost, care more for the content of the training that you buy.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Remember, even if you have certification from a third-party vendor, you can still get penalized, if the OCR audit finds gaps between your security setup and the expectations set by the three HIPAA rules.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">You can share your queries about HIPAA certification by emailing us at <\/span><a href=\"mailto:info@empowerelearning.com\"><span style=\"font-weight: 400;\">info@empowerelearning.com<\/span><\/a><span style=\"font-weight: 400;\">. It would be our pleasure to assist you. You can also leave comments in the section below.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Does HHS certify healthcare providers as HIPAA compliant? Are their third-party firms that provide HIPAA certification? Can a healthcare provider declare itself as HIPAA compliant?\u00a0 Several companies claim that their products are HIPAA certified. But, there are no companies or products that have been certified or endorsed by the HHS.\u00a0\u00a0\u00a0 There is no official HIPAA [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":2992,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,5,138,140,9],"tags":[12,46,77],"class_list":["post-2990","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","category-education","category-elearning","category-empower","category-hipaa","tag-elearning","tag-empower","tag-hipaa"],"_links":{"self":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/posts\/2990","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/comments?post=2990"}],"version-history":[{"count":0,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/posts\/2990\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/media\/2992"}],"wp:attachment":[{"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/media?parent=2990"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/categories?post=2990"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.empowerelearning.com\/blog\/wp-json\/wp\/v2\/tags?post=2990"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}