Posted

0 replies · 0 reposts · 0 likes

The Catch-22 Dilemma of HIPAA Risk Analysis One problem that many healthcare providers face is how to conduct a proper risk analysis, which is required by HIPAA regulations. While providers are often experts in healthcare, they are rarely also experts in security, risk, and the law. This forces them to rely on outside experts. But all of these consulting firms claim to be experts, so how do you evaluate them if you don't have the knowledge yourself? Will you just end up being yet another firm to spend many thousands of dollars on an expert risk analysis only to have it rejected by HHS' Office for Civil Rights (OCR)? The truth is that the VAST majority of risk analyses submitted to OCR are declared insufficient to comply with federal law. The founder of Fortenza was noticed by the federal government for his expertise in this area and contracted as an outside expert for many years to advise them on enforcement matters, particularly cases involving security breaches and failures in risk analysis and risk management. He was the one who reviewed the case evidence and determined whether risk analyses (and other documents) were sufficient or not. His proprietary methodology has been used for years to conduct countless risk analyses for covered entities and business associates without any of them EVER being rejected by OCR. If it's time for your next (or first) risk analysis and you don't know where to turn and you want to avoid the embarrassment of paying thousands of dollars for a risk analysis that may ultimately be rejected by OCR, then consider reaching out to http://www.fortenza.com to discuss how it can help you safeguard the patient information that you've been entrusted to protect.

View this post on Gab