This webinar is for HIPAA Covered Entities (CEs) and Business Associates (BAs). Criminals increasingly focus cyber-attacks on BAs because one hit can give them access to PHI of all the BA’s customers. Growth of serious BA PHI breaches affecting tens of millions of patients put the spotlight on BA HIPAA compliance, attracting HHS Office for Civil Rights investigations and aggressive private class action lawsuits filed within days of a breach targeting BAs and their CE customers. CEs that did nothing wrong can still be held liable to pay the same civil money penalty as their BA for the BA’s HIPAA violation under the Federal Common Law of Agency which is included in the HIPAA Enforcement Rule.
Simple steps, often overlooked but easy to follow, enable CEs and BAs to protect against costs and damage to their reputations caused by violations of HIPAA Rules that apply to BAs. The chain of HIPAA compliance starts with a CE. It extends to a BA that provides a CE with services involving PHI. And the chain of compliance continues on down to any subcontractors of a BA that perform services involving PHI. BA subcontractors are defined by HIPAA as BAs and are fully liable for compliance.

  • CEs must obtain “satisfactory assurances” from each BA, documented in writing, that the BA complies with HIPAA before disclosing PHI to the BA or allowing the BA to create, receive, maintain or transmit PHI on their behalf.
  • BAs must obtain “satisfactory assurances” from each Subcontractor BA, documented in writing, that the Subcontractor BA complies with HIPAA before permitting the Subcontractor BA to perform services involving PHI.

This webinar explains the interconnected HIPAA compliance responsibilities and liabilities of CEs and BAs. HIPAA Rules that apply to both are easy to follow, step-by-step, when you know the steps.

HIPAA Rules that apply to CEs in dealing with BAs and that BAs must follow are discussed and explained including:

  • Serious Business Associate HIPAA Violations
    Brief review of current OCR BA Enforcement and Class Action lawsuits based on BA HIPAA violations
  • Explanation of how HIPAA Rules apply to BAs
    • Security, Privacy and Breach Notification Rules
  • Business Associate Agreements and the key Agency Issue – Don’t make your BA or Subcontractor BA your legal agent by mistake like many do
  • CE Due Diligence for BAs and BA Due Diligence for Subcontractor BAs
  • Who’s in Charge? – Responsibility & Authority – Responsibility of Senior Management and Owners – Delegation of Authority for development and implementation of a BA HIPAA compliance program

Why You Should Attend This Webinar

CEs can find themselves fully liable for HIPAA violations committed by BAs and BAs for violations committed by Subcontractors under the little known Federal Common Law of Agency. However, risks associated with BA HIPAA compliance can be managed calmly and confidently by following the HIPAA Rules that are easy to follow, step-by-step.
CEs should attend to see what to look for in Due Diligence, how to obtain HIPAA required satisfactory assurances that a BA is complying with HIPAA and avoid liability by inadvertently making a BA their agent.
BAs should attend this webinar to see exactly what they must do to comply with HIPAA Rules – Security, Privacy and Breach Notification Rules. And what to look for in Due Diligence and how to obtain HIPAA required satisfactory assurances that a Subcontractor BA is complying with HIPAA while avoiding liability by inadvertently making a Subcontractor BA their agent

Who Should Attend This Webinar

Covered Entities of all types who disclose PHI to BAs and allow BAs to create, receive, maintain and transmit PHI on their behalf
Business Associates of all types including for example:

  • Billing and Coding companies
  • Practice Management Companies
  • IT Vendors
  • Data Storage firms (electronic and paper)
  • Secure and unsecure providers of PHI email and text message services
  • Vendors of patient satisfaction surveys
  • PHI record retrieval and release of information vendors
  • Law and Accounting Firms
  • Health Plan Third Party Administrators
  • CE Owner – CEO – COO Compliance Manager
  • Board of Directors – for profit and non-profit CEs
  • Healthcare Practice Manager
  • Administrator, Long Term Care Facility
  • BA Owner – CEO – COO
  • Security and Privacy Officers
  • Compliance, Information Security and Risk Management Directors
  • Business Manager
  • Attorney – General Counsel, Associate General Counsel, Inside Compliance Attorney, Outside Health Law Attorney

Venue: Recorded Webinar

Enrollment option

Speaker

Paul R. Hales
Paul R. Hales, J.D. is widely recognized for his ability to explain HIPAA Rules clearly in plain language. He is an attorney licensed to practice before the Supreme Court of the United States, a graduate of Columbia University Law School and Senior Counselor of the Missouri Bar with an international practice in HIPAA privacy and…

Related Events

Governing Board, Agreements and Contracted Services, QAPI, Discharge Planning
Compliance Webinars
Live Webinar

Governing Board, Agreements and Contracted Services, QAPI, Discharge Planning

Critical Access Hospitals (CAHs) must comply with the Centers for Medicare & Medicaid Services’ Conditions of Participation located in Appendix W in the manual. This eight-part webinar series will cover the CAH CoP manual. There were changes and new regulations for CAHs in 2020, including a change to all the tag numbers, some which do not include Interpretive Guidelines or Survey Procedures. Changes include infection prevention and control and antibiotic stewardship, QAPI and Swing Bed changes. This seminar will help CAHs comply with specific CoP problem areas, such as nursing care plans, necessary policies and procedures, medication administration and drug storage, and informed consent to name a few.   Part Four of Eight: Governing Board, Agreements and Contracted Services, QAPI, Discharge Planning Objectives Describe that CMS requires the Board enter into a written agreement for telemedicine services Describe requirements for contract management for a CAH Describe the essential elements of a QAPI program and Board responsibilities Recall the requirement for when a discharge evaluation must be completed Organizational Structure and Governing Body/Individual Governing body/Individual’s responsibilities Appointment to medical staff Telemedicine services and requirements Required disclosures Agreements and Contracted Services Agreement with providers or suppliers Lab and diagnostic services Food services Quality Assurance Performance Improvement - QAPI Changes to the QAPI program Requirements of a QAPI program QAPI standards Data collection and analysis Reference: Standards and guidelines for Acute hospitals Discharge Planning Need for effective discharge planning process Discharge evaluation and plan Review of discharge planning process Requirement to assist in PAC selection Appendix and Resources

Emergency Services, Staffing and Responsibilities, Provision of Services, Emergency Procedures and EMTALA
Compliance Webinars
Live Webinar

Emergency Services, Staffing and Responsibilities, Provision of Services, Emergency Procedures and EMTALA

Critical Access Hospitals (CAHs) must comply with the Centers for Medicare & Medicaid Services’ Conditions of Participation located in Appendix W in the manual. This eight-part webinar series will cover the CAH CoP manual. There were changes and new regulations for CAHs in 2020, including a change to all the tag numbers, some which do not include Interpretive Guidelines or Survey Procedures. Changes include infection prevention and control and antibiotic stewardship, QAPI and Swing Bed changes. This seminar will help CAHs comply with specific CoP problem areas, such as nursing care plans, necessary policies and procedures, medication administration and drug storage, and informed consent to name a few.   Part Two of Eight: Emergency Services, Staffing and Responsibilities, Provision of Services, Emergency Procedures and EMTALA Objectives Describe staffing requirements and supervision Recall the required14 emergency department written policies that must be present Describe that CMS has a list of emergency drugs and equipment every CAH must have Recall that a CAH must comply with EMTALA requirements Emergency Services 14 Emergency department policies ED staffing Equipment, Supplies, and Medication Blood and Blood Products Staffing/Personnel Coordination with Emergency Response Systems Staffing and Responsibilities Staffing and responsibilities Physician supervision Transfer of patient Patient admissions Provision of Services Patient care policies Scope of services Emergency medical services Medical management Diagnostic and therapeutic services Supplies Outpatient services Outpatient director Inpatient services Census and Ensuring compliance EMTALA Physician lists Central log Medical Screening examination Admit or transfer Appendix and Resources

Prepare for 2025 ICD-10-CM Code Updates
Compliance Webinars
Live Webinar

Prepare for 2025 ICD-10-CM Code Updates

ICD-10-CM updates for 2025 will become effective on October 1, 2024. These updates will include several guideline changes as well as multiple updates & additions to the specific chapters. This webinar will discuss the new guidelines as well as specific code categories in which you need to be alert to changes that may impact your code selection. All chapters will be included to ensure your specialty is covered. It is important that you be proactive and prepared when submitting your claims with discharge dates of October 1. Missed update information may cause a processing & reimbursement delay. Webinar’s Goals Be aware of guideline changes Learn about chapter specific additions & updates Ensure you are prepared with new code information Align with your software vendors to implement any necessary changes Target Audience Revenue Cycle Managers & staff Billers Coders Clinical Documentation Staff Finance Managers Denial Management Staff Physicians Mid Level Providers Claims Follow Up Staff

Excel - Automate Repetitive Tasks with Macros
Compliance Webinars
Live Webinar

Excel - Automate Repetitive Tasks with Macros

Imagine the thrill of automating those repetitive Excel tasks that have been draining your productivity. Picture the convenience of effortlessly streamlining complex processes, leaving you with more time to focus on what truly matters. Now, consider the positive impact you can have on your team and clients by offering streamlined, error-free solutions. Excel macros are powerful tools that can transform your Excel experience by automating repetitive tasks, freeing up your time for more important work. If you often find yourself performing the same actions or dealing with time-consuming Excel processes that beg for automation, it's time to dive into the world of macros. In this session, we will explore two methods for creating macros in Excel: The Macro Recorder and The Macro Editor, ensuring you have a comprehensive understanding of both. Objectives By the end of this session, you will have gained proficiency in creating and editing macros using Excel's Macro Recorder and the Macro Editing Tool. Why You Should Attend Mastering macro creation and editing is a crucial skill for advanced Excel users. This knowledge will not only save you valuable time but also benefit your colleagues and clients, as you'll be able to automate various Excel-based tasks and processes. If you've never created macros before, this webinar is for you. Topics covered Best practices for planning your macros Creating macros using the Macro Recorder Saving files as macro-enabled Excel workbooks Executing macros effortlessly Adding a macro-triggering button A comprehensive tour of the Macro Editor Making basic modifications to macros (VBA fundamentals) Leveraging the Personal Macro Workbook to share macros across all your files Who Should Attend? This webinar is designed to kickstart your journey into the world of macros. It's suitable for intermediate-to-advanced Excel users across all industries and job roles. Although we will be using the latest version of Excel for Windows, the majority of the functionalities discussed are applicable to earlier versions of the application as well.