Presentation is loading. Please wait.

Presentation is loading. Please wait.

HCCA HIPAA Readiness Survey Results Jody Noon Principal Deloitte & Touche Portland, OR November, 2002 John Steiner Esq. Chief Compliance Officer Cleveland.

Similar presentations


Presentation on theme: "HCCA HIPAA Readiness Survey Results Jody Noon Principal Deloitte & Touche Portland, OR November, 2002 John Steiner Esq. Chief Compliance Officer Cleveland."— Presentation transcript:

1 HCCA HIPAA Readiness Survey Results Jody Noon Principal Deloitte & Touche Portland, OR November, 2002 John Steiner Esq. Chief Compliance Officer Cleveland Clinic Foundation Cleveland, OH Debbie Troklus CHC Asst. VP for Compliance University of Louisville School of Medicine Louisville, KY

2 HCCA HIPAA Readiness Survey Results Survey Demographics Total Respondents: 289 Type of Health Care Entity

3 HCCA HIPAA Readiness Survey Results Survey Demographics (Cont’d) Corporate Status

4 HCCA HIPPA Readiness Survey Results Survey Demographics (cont’d) 289 Total Respondents Facility Location 37%Urban 29%Suburban 18%Rural 16%N/A or Other Bed Size 1%< 100 34%101 – 500 11%501 – 1000 1%1001 – 5000 53%N/A or Other

5 HCCA HIPAA Readiness Survey Results Education HCCA HIPAA Readiness Survey Results Education To date, how much classroom time has been spent on HIPAA education for the following? Board of Directors   60%1-2 hours   10%3-5 hours   6%more than 5 hrs   20%None   4%N/A Executive Staff   36%1-2 hours   33%3-5 hours   26%more than 5 hrs   4%None   1%N/A Medical Staff  49%1-2 hours  10%3-5 hours  6% more than 5 hrs  25% None  10% N/AStaff  54% 1-2 hours  14% 3-5 hours  10% more than 5 hrs  20% None  1% N/A

6 HCCA HIPAA Readiness Survey Results

7 HCCA HIPAA Readiness Survey Results HIPAA Planning 20012002  Established HIPAA Task Force87%96%  Designated Privacy Officer73%93%  Designated Security Officer57%70%  Assigned Privacy and Security responsibilities to one individual54%43%  Developed organization structure delineating responsibilities for privacy and security37%75%  Developed cost estimates for privacy, security, and transaction requirements30%57%

8 HCCA HIPAA Readiness Survey Results HIPAA Assessment Inventories Completed20012002  Contracts and Agreements41%77%  Persons/entities that share electronic health information 44%79%  Qualified Business Associates55%70%  Relationships that may require Chain of Trust or Trading Partner Agreements28%51% of Trust or Trading Partner Agreements28%51%  Consent forms41%61%

9 HCCA HIPAA Readiness Survey Results HIPAA Implementation 20012002  Established security levels for Employees, Medical Staff, and Business Associates25%46%  Determined your organization’s designation as a covered entity (OHCA, SACE, hybrid)75%91%  Developed an applications and data critical analysis, a data backup plan, a disaster recovery plan, and mode operations44%55%  Reviewed employee screening and background checking practices60%78%

10 HCCA HIPAA Readiness Survey Results HIPAA Implementation Forms Developed20012002  Business Associate Agreements30%76%  Chain of Trust or Trading Partner Agreements16%33%  Consent forms32%55%  Notice of privacy practices29%70%

11 HCCA HIPAA Readiness Survey Results HIPAA Policies and Procedures 20012002  Discipline for breaches of privacy principles or security46%68%  Grievance policy for complaints and breaches of confidentiality40%66%  Patient access to records47%74%  Access to “minimum necessary” information21%56%  Disclosure of PHI through viewing, paging or other operational activities19%48%

12 HCCA HIPAA Readiness Survey Results HIPAA Policies and Procedures (cont’d) 20012002  Verbal discussions of PHI by authorized persons25%55%  Disposal of PHI (paper, electronic, etc.)34%65%  De-identification of PHI15%42%  Encryption of PHI14%28%

13 HCCA HIPAA Readiness Survey Results HIPAA Assessment - Security 20012002  Performed a “penetration analysis” to determine where and how security breaches may occur24%38%  Assessed the physical location and the type of storage media to be used for all protected health information25%52%  Addressed issue of authentication of users and receivers of health information (external and internal) and audit trail21%36%

14 HCCA HIPAA Readiness Survey Results HIPAA Standard Transactions and Code Sets 20012002  Identified all transaction standards and code sets56%78%  Determined preparedness of trading partners28%54%  Developed system for ongoing maintenance of standard transactions and code sets25%46%  Educated business office on standard transactions and code sets26%49%  Identified Electronic Data Interchange partners43%67%

15 HCCA HIPAA Readiness Survey Results Change in HIPAA Compliance Activities from 2001 to 2002

16 HCCA HIPAA Readiness Survey Results Special Thanks To: Deloitte & Touche

17 HCCA HIPAA Readiness Survey Results Questions?


Download ppt "HCCA HIPAA Readiness Survey Results Jody Noon Principal Deloitte & Touche Portland, OR November, 2002 John Steiner Esq. Chief Compliance Officer Cleveland."

Similar presentations


Ads by Google