Generated by All in One SEO v4.9.5, this is an llms.txt file, used by LLMs to index the site. # Eagle Consulting Partners Inc. Management and Technology Solutions for Healthcare ## Sitemaps - [XML Sitemap](https://eagleconsultingpartners.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Blog Index](https://eagleconsultingpartners.com/news/) - [Ohio Senate Bill 29 Impacts DD Boards with Schools](https://eagleconsultingpartners.com/general-news/ohio-senate-bill-29-impacts-dd-boards-with-schools/) - Ohio Senate Bill 29 (SB29) went into effect last month on October 24, 2024. The focus of this bill is to improve student data privacy and school cybersecurity. The reason for the bill is to ensure that technology companies don’t misuse student data for students who use school-provided devices. Some of the key provisions - [Ransomware Protection for DD Boards - Robust Backup and Recovery Capability](https://eagleconsultingpartners.com/general-news/ransomware-protection-for-dd-boards-robust-backup-and-recovery-capability/) - Superintendents and other organizational leadership might wonder why county and city government, including agencies right here in Ohio, continue to be hit with ransomware. Weren’t these victims backing up their data? While most organizations have a backup, many organizations fail to implement all the best practices necessary to ensure a rapid recovery from a ransomware - [Top 4 Actionable Security Items for Health Tech Businesses](https://eagleconsultingpartners.com/business-associates-others/top-4-actionable-security-items/) - Health IT vendors need to ensure security of their applications. Conventional wisdom for health IT vendors says to begin with the HIPAA Security Regulations, which specify 45 "Standards and Implementation Specifications". While these requirements are essential for governmental compliance, they are not sufficient for ensuring organizational security. The main reason? The HIPAA Security Regulations have - [2022-2023 Privacy and CyberSecurity Trends and Updates](https://eagleconsultingpartners.com/information-security/2022-2023-privacy-and-cybersecurity-trends-and-updates/) - Now is a good time to review 2022-2023 privacy and cyberSecurity trends and updates? A number of regulations and security concerns are on the table for this year and trending into next year. Ransomware continues to be the major concern for HIPAA-regulated entities. Eagle reviews and recommends solutions you can implement now. - [Work-From-Home Security Management During COVID](https://eagleconsultingpartners.com/dd-board-solutions/avoiding-attacks-during-covid-19-work-from-home/) - Do not let weak security from hasty work-from-home result in a data breach or ransomware during work-from-home security management. Move from reaction mode to proactive security protocols. - [Do I Need a Data Backup Strategy for Office 365?](https://eagleconsultingpartners.com/hipaa/do-i-need-a-data-backup-strategy-for-office-365/) - Are you prepared with a data backup strategy for Office 365? Eagle helps you with security, access and control of your data residing in Office 365. - [COVID-19 and HIPAA: Social Distancing Using Video Chat](https://eagleconsultingpartners.com/general-news/covid-19-and-hipaa-social-distancing/) - HIPAA telehealth rules relaxed for video chat during COVID-19 crisis. Learn how to serve your consumers remotely: FaceTime is OK, TikTok is not! - [Cybersecurity Guide for DD Board Superintendents](https://eagleconsultingpartners.com/dd-board-solutions/cybersecurity-guide-for-superintendents/) - Are you making the right IT security investments for your DD Board? Unsure of cyber risks or where to start? We have the guide you need. - [Sell More to Hospitals with a HITRUST Certification](https://eagleconsultingpartners.com/general-news/sell-more-to-hospitals-with-a-hitrust-certification/) - The Provider Third Party Risk Management Council, made of a consortium of leading hospitals, introduced a new approach to third-party risk management. How can you better serve them? The solution is simple – any vendor of a certain size who wishes to do business with one the member hospitals must successfully complete – and annually maintain -- a certification using the HITRUST CSF. Member hospitals will accept a HITRUST certification as evidence of a robust security program. No questionnaires or further dialog is necessary. - [Act Now to Avoid Bottlenecks/Delays with Remote Workforce](https://eagleconsultingpartners.com/dd-board-solutions/act-now-to-avoid-bottlenecks-delays-with-remote-workforce/) - Many Ohio DD Boards are experiencing challenges / roadblocks with the shift to remote work. Act NOW to avoid three potential bottlenecks. - [Free Online Course: COVID-19 -- How to be Safe and Resilient](https://eagleconsultingpartners.com/general-news/free-online-course-covid-19-how-to-be-safe-and-resilient/) - A short online course that provides life-saving skills for dealing with the COVID-19 outbreak. Please share this with your colleagues. - [CMS Relaxes Reimbursement Rules and HIPAA Enforcement for Telehealth amid COVID-19 Crisis](https://eagleconsultingpartners.com/general-news/cms-relaxes-reimbursement-rules-and-hipaa-enforcement-for-telehealth-amid-covid-19-crisis/) - CMS relaxes reimbursement rules and HIPAA enforcement for telehealth amid COVID-19; Medicare will pay E&M encounters at same rate as in-person visits. - [Hackers using Coronavirus Phishing Emails – Protect Your Employees](https://eagleconsultingpartners.com/general-news/hackers-using-coronavirus-phishing-emails/) - Hackers are using coronavirus phishing emails to attack organizations of all sizes. Employee Security Awareness Training helps you spot the warning signs! - [Secure Work-From-Home with Free Toolkit from SANS](https://eagleconsultingpartners.com/general-news/secure-work-from-home-toolkit/) - Quickly train and enable your workforce to securely work from home with this free toolkit, including an easy-to-follow action plan and training materials. - [Message from Our President: Supporting DD Boards During the COVID-19 Crisis](https://eagleconsultingpartners.com/dd-board-solutions/message-from-our-president-supporting-dd-boards-during-the-covid-19-crisis/) - Eagle President Gary Pritts offers a special message of support for Ohio DD Boards during this national health emergency. - [Does HIPAA Permit Texting Patients? - Part 1](https://eagleconsultingpartners.com/general-news/hipaa-texting-part-1/) - What does HIPAA say about texting your patients? That depends on several factors, including what type of phone you use, and what data you're transmitting. - [New Guidance Published by HHS and DoE for HIPAA/FERPA Interaction for Ohio DD Boards](https://eagleconsultingpartners.com/general-news/ferpa-and-hipaa-updates/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″][et_pb_row _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Text: Intro” _builder_version=”4.0.9″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”]Regulatory Confusion and Complexity County DD Boards navigate the complexities of multiple overlapping regulations — HIPAA, FERPA, IDEA, Ohio Revised Code, and Ohio Administrative Code. This is not easy. Yesterday, the Department of Education (DoE) and the Department of - [CryptoWall firsthand account - Mitigating ransomware attacks](https://eagleconsultingpartners.com/hipaa/crytowall-firsthand-account-mitigating-ransomware-attacks/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Text” _builder_version=”4.2.2″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″]Health care organizations are constantly challenged to invest adequate resources in IT technology and services. This inside account of a ransomware attack (CryptoWall) and one organization’s response to it sheds some light on the importance of implementing - [Secure Remote Access: Third-Party Risks](https://eagleconsultingpartners.com/general-news/secure-remote-access/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text _builder_version=”4.0.3″ hover_enabled=”0″] Some of the most infamous hacking incidents have arisen from third-party access to a corporate network that does not have secure remote access. Perhaps most infamously, the 2013 Target hack which compromised 110 million credit/debit cards used remote access granted - [Iran Cyberattack: DHS and National Terrorism Advisory System Issue Bulletin](https://eagleconsultingpartners.com/general-news/iran-cyberattack-dhs-bulletin/) - The Department of Homeland Security issued a bulletin warning of a possible Iran cyberattack. Read about warning signs and how to protect your organization. - [Heard in the Hallways at the OACB: Free Cybersecurity for County Boards!](https://eagleconsultingpartners.com/general-news/oacb-cybersecurity-for-dd-boards/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Text” _builder_version=”4.0.9″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”]In the corridors during the OACB Convention, I had the opportunity to chat with the Information Technology leadership from an Eagle client, one of the state’s largest DD Boards, who shared the benefits of their participation in the Multi-State - [Business Email Compromise](https://eagleconsultingpartners.com/general-news/business-email-compromise/) - A Business Email Compromise (BEC) threat targets accounting and finance departments, and looks like it comes from an official email account. Don't get caught in a phishing scam! - [OACB Reflections: Improving the Customer Experience While Maintaining HIPAA Compliance](https://eagleconsultingpartners.com/general-news/oacb-improving-the-customer-experience/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″][et_pb_row _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text _builder_version=”4.0.9″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” min_height=”146px” custom_padding=”||0px|||”]Eagle Consulting Partners was pleased to participate in the OACB Annual Conference in Columbus, which included a focus on improving the customer experience. Over our 18 years of working with over 70 of the Ohio County Boards in the - [Security Awareness Training: Third-Quarter 2019 Phishing Surge Highlights Need for New Service](https://eagleconsultingpartners.com/general-news/security-awareness-training-phishing/) - [et_pb_section fb_built=”1″ _builder_version=”4.0.7″][et_pb_row _builder_version=”4.0.7″][et_pb_column type=”4_4″ _builder_version=”4.0.7″][et_pb_text _builder_version=”4.0.7″]Third Quarter 2019 Phishing Surge and Business Email Compromise Highlight Need for Security Awareness Training Based on data through the third quarter of 2019, email phishing attacks climbed to the highest level in more than 3 years. Email remains one of the top attack vectors for a variety of - [Office 365 Users, Time to Upgrade your Email Security!](https://eagleconsultingpartners.com/general-news/email-security-upgrade/) - [et_pb_section fb_built=”1″ _builder_version=”4.0.7″][et_pb_row _builder_version=”4.0.7″][et_pb_column type=”4_4″ _builder_version=”4.0.7″][et_pb_text _builder_version=”4.0.7″]Office 365 Users… The booming popularity of the Office 365 solution from Microsoft has brought with it a nasty side effect – unwanted phishing emails. By default, Microsoft offers an email filtering service to eliminate spam and malware called “Exchange Online Protection,” or EOP for short. In 2019, security - [Recovering from a 3rd Generation Ransomware Attack](https://eagleconsultingpartners.com/general-news/recovering-from-a-3rd-generation-ransomware-attack/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Text” _builder_version=”4.0.6″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″] Recovering from Third-Generation Ransomware Attack Decision-makers need to understand the impacts of a third-generation ransomware attack so that they can properly allocate budgets and set priorities for recovering from ransomware, including: Safeguards that can reduce the - [Proposed Changes to 42 CFR Part 2 will affect Community Health Centers and other Clinics](https://eagleconsultingpartners.com/general-news/42-cfr-part-2-changes/) - Proposed changes to 42 CFR Part 2 (Substance Abuse and Confidentiality) will make coordination of care easier! Are you subject to this law? - [2020 Final MIPS Rule is Out!](https://eagleconsultingpartners.com/general-news/2020-final-mips-rule-is-out/) - On November 1, the Centers for Medicare and Medicaid Services released the 2020 final MIPS rule. - [DD Boards Need Disaster Recovery Plans](https://eagleconsultingpartners.com/general-news/dd-boards-need-disaster-recovery-plans/) - If the worst happens, does your Developmental Disabilities Board have a Disaster Recovery Plan to restore operations and computer systems? Read on to learn more about this important preparation. - [HIPAA Compliance with Google’s G Suite (Google Apps)](https://eagleconsultingpartners.com/general-news/google-apps-hipaa-compliance-googles-g-suite-google-apps/) - Eagle’s opinion is that the agreement meets the minimum requirements of a HIPAA BAA, and as such Google accepts the minimum liability in the event of a data breach which is to send you “applicable Breach notifications” via email in the event of a breach. Google will not indemnify you, reimburse you for your breach notification costs, or pay any other damages. - [45 CFR 164.308(a)(1), 45 CFR 164.312(a)(2)(iv) and 45 CFR 164.306(d)(3) Explained](https://eagleconsultingpartners.com/cms-qpp/meaningful-use-rules-hitech-act/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Text” _builder_version=”4.0.6″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″]5/23/2018 Editor’s Note: In April 2018, the Meaningful Use rules program has been renamed “Promoting Interoperability”. Nonetheless, the language of this requirement are unchanged and this post remains relevant in 2018. The Meaningful Use rules, part of - [I’m a Specialist, Should I Join an ACO?](https://eagleconsultingpartners.com/general-news/im-a-specialist-should-i-join-an-aco/) - While Primary Care Physicians are integral to the proliferation of a successful ACO, its unrealistic to think that beneficiaries will not need specialty treatment at some (or many) points in their episodes of care. ACOs need specialists, too! So... I'm a specialist, should I join an ACO? The short answer: Maybe. Are you willing and - [Primary Care Physicians and ACOs – Should You Join?](https://eagleconsultingpartners.com/general-news/primary-care-physicians-and-acos/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” collapsed=”off”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Text” _builder_version=”4.0.6″ text_font=”|700|||||||” text_font_size=”20px” header_2_font=”|700|||||||” background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″]Primary Care Physicians and ACOs ACO Series: Part 2 ACOs are groups of clinicians and organizations that band together to save Medicare money by keeping beneficiaries healthy. Click here for a basic overview - [What is an ACO?](https://eagleconsultingpartners.com/general-news/what-is-an-aco/) - Medicare incentivizes providers to lower spending through participation as an ACO in the Medicare Shared Savings Program. - [3rd Generation Ransomware - Worst Cyber Threat Yet for DD Boards](https://eagleconsultingpartners.com/general-news/3rd-generation-ransomware-worst-cyber-threat-yet-for-dd-boards/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″][et_pb_row _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text _builder_version=”4.0.3″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″] 3rd Generation Ransomware – Worst Cyber Threat Yet Eagle Consulting Partners has been writing about the threats of ransomware for several years. We estimate that at least 25% of our customer base has had at least 1 ransomware incident - [Telework Security: Securing Home and Remote Workers](https://eagleconsultingpartners.com/general-news/telework-security/) - [et_pb_section fb_built=”1″ _builder_version=”4.0.3″][et_pb_row _builder_version=”4.0.3″][et_pb_column type=”4_4″ _builder_version=”4.0.3″][et_pb_text _builder_version=”4.0.3″]Telework Security: Securing Home and Remote Workers It goes by many names: Telework. Telecommute. Work from home. Remote work. According to recently released data from the US Census, 5.2% of Americans – 8 million people – worked from home in 2017. Home workers include those in traditional employment relationships, - [Top 10 Brands used in Phishing Attacks](https://eagleconsultingpartners.com/general-news/top-10-brands-used-in-phishing-attacks/) - The top 10 brands used for phishing have been named. See who made the list! - [SaaS Providers can reduce HITRUST certification costs with HITRUST Inheritance Program](https://eagleconsultingpartners.com/general-news/reduce-hitrust-certification-costs/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″][et_pb_row _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text _builder_version=”4.0.3″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”]SaaS providers can reduce HITRUST certification costs with HITRUST Inheritance Program Vendors who use the Software as a service (SaaS) distribution model have enjoyed considerable success in the healthcare marketplace. A challenge that they face is increased scrutiny from customers – - [Infected by your Computer Company](https://eagleconsultingpartners.com/general-news/managed-services-provider-infected-by-your-computer-company/) - Last week, two Wisconsin companies that provide an online service to dental offices, Digital Dental Record and PerCSoft, told 400 dental office customers of a ransomware attack. The files on the computer networks of the dental offices were scrambled in a ransomware attack. PerCSoft had remote access to the dental office networks, and to all - [Health Data Breaches Appear on "Wall of Shame"](https://eagleconsultingpartners.com/general-news/health-data-breaches-appear-on-wall-of-shame/) - Are you susceptible to a healthcare data breach? More practices and hospitals are finding themselves on the Department of Health and Human Services' "wall of shame" — a website listing health data breaches affecting 500 or more individuals. - [Patient Privacy- Will Walgreens be OCR’s newest poster child for HIPAA non-compliance?](https://eagleconsultingpartners.com/hipaa/hipaa-non-compliance-and-walgreens/) - Walgreens’ new pharmacy model may be unintentionally violating customers' patient privacy rights. Named the “Well Experience,” this new store layout/business model gets pharmacists out in the store, with the intention of increasing the pharmacists’ accessibility to patients and making the customer experience more personal. However, this movement away from the traditional behind-the-counter method of operation - [Disaster Recovery Plan Development is a MUST!](https://eagleconsultingpartners.com/general-news/disaster-recovery/) - If the worst happens, does your organization have a Disaster Recovery Plan ready to get things back on track? Don't be victimized by hackers! - [Ransomware Causes Delay in Start of School Year and State of Emergency Declaration](https://eagleconsultingpartners.com/general-news/ransomware-causes-delay-in-start-of-school-year-and-state-of-emergency-declaration/) - Targeted ransomware attacks hit 4 Louisiana school districts, causing the governor to declare a State of Emergency. - [Privacy Risk Assessment for DD Boards](https://eagleconsultingpartners.com/general-news/privacy-risk-assessment-for-dd-boards/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″ fb_built=”1″ _i=”0″ _address=”0″][et_pb_row _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” _i=”0″ _address=”0.0″][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” _i=”0″ _address=”0.0.0″ custom_padding__hover=”|||”][et_pb_image src=”https://eagleconsultingpartners.com/wp-content/uploads/2019/08/documents.jpeg” alt=”Privacy Risk Assessment for DD Boards for protected health information” align=”center” _builder_version=”3.27.3″ _i=”0″ _address=”0.0.0.0″][/et_pb_image][et_pb_text _builder_version=”3.29.3″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″ _i=”1″ _address=”0.0.0.1″]Most County Boards of Developmental Disabilities are performing at least a periodic Security Risk Assessment (SRA). - [More Health Data Breaches Coming, 2018 Data Suggests](https://eagleconsultingpartners.com/general-news/2018-data-breaches/) - 15 million health data records breached in 2018. "At least one breach per day." We highlight the challenges so you don't become a statistic! - [Promoting Interoperability: Hardship Exception Application Due Dec 31](https://eagleconsultingpartners.com/general-news/promoting-interoperability-hardship-exception-application-available/) - Want Eagle to do it for you? Contact us today and have your approval within the hour. MIPS-eligible clinicians looking to apply for the hardship exception from the Promoting Interoperability (formerly Advancing Care Information) category can now submit their applications. The hardship exception, if approved, would allow individual clinicians and groups to re-weight the Promoting - [Max MIPS Incentive - No EHR Required](https://eagleconsultingpartners.com/general-news/max-mips-incentive-no-ehr-required/) - No EHR? No problem. Eagle Consulting has extensive experience working with practices that still do paper charting. - [NY Presbyterian, Columbia University Settlement highlights importance of PHI application inventory](https://eagleconsultingpartners.com/hipaa/phi-application-inventory/) - The recent situation at NY Presbyterian Hospital/Columbia University Medical Center that resulted in the largest-to-date HIPAA settlement of $4.8 Million, highlighted that security leadership wasn’t aware of all of the applications running on their system. Reading between the lines, we get the picture of an out of control environment where physicians are installing personally owned - [FQHCs in the Hot Seat with tougher HRSA Audits](https://eagleconsultingpartners.com/hipaa/fqhc-hipaa-compliance/) - HIPAA Compliance among items to be scrutinized in upcoming HRSA Federally Qualified Health Center (FQHC) Audits At the Ohio Association of Community Health Centers (OACHC) Annual Conference today, Jacki Leifer of Feldesman Tucker Leifer Fidell presented about Federally Qualified Health Center (FQHCs) in the “Hot Seat” and the need for them to be compliant in - [Preventing and Mitigating Ransomware Attacks](https://eagleconsultingpartners.com/general-news/preventing-mitigating-ransomware-attacks/) - Recently, entire hospital networks have been shut down for time periods between 3 days and 3 weeks due to ransomware attacks. What can be done? Fortunately, there are established best practices which can prevent one of these attacks in the first place, or reduce the impact if a network is infected. We have some advice for you. - [Does HIPAA Require Encryption?](https://eagleconsultingpartners.com/general-news/hipaa-require-encryption/) - The HIPAA Security Rule include two separate implementation specifications involving encryption. The first is contained at 45 CFR 164.312(a)(2)(iv): "Encryption and decryption (Addressable). Implement a mechanism to encrypt and decrypt electronic protected health information." From context (this requirement is in the "access controls" section), this first encryption requirement involves "data at rest," for example, hard drives - [HITRUST Certification: Our New Partnership with Drummond Group](https://eagleconsultingpartners.com/general-news/hitrust-certification-our-new-partnership-with-drummond-group/) - [et_pb_section fb_built=”1″ _builder_version=”3.26.6″ fb_built=”1″ _i=”0″ _address=”0″][et_pb_row column_structure=”1_2,1_2″ make_equal=”on” _builder_version=”3.26.6″ _i=”0″ _address=”0.0″][et_pb_column type=”1_2″ _builder_version=”3.26.6″ custom_padding=”60px||||false|false” _i=”0″ _address=”0.0.0″][et_pb_image src=”/wp-content/uploads/2019/08/hitrust.jpg” _builder_version=”3.26.6″ _i=”0″ _address=”0.0.0.0″][/et_pb_image][/et_pb_column][et_pb_column type=”1_2″ _builder_version=”3.26.6″ _i=”1″ _address=”0.0.1″][et_pb_image src=”/wp-content/uploads/2019/08/Drummond.png” _builder_version=”3.26.6″ _i=”0″ _address=”0.0.1.0″][/et_pb_image][/et_pb_column][/et_pb_row][/et_pb_section][et_pb_section fb_built=”1″ _builder_version=”3.26.6″ background_color=”#d2e4f9″ min_height=”598px” custom_margin=”||-72px|||” fb_built=”1″ _i=”1″ _address=”1″][et_pb_row _builder_version=”3.26.6″ _i=”0″ _address=”1.0″][et_pb_column type=”4_4″ _builder_version=”3.26.6″ _i=”0″ _address=”1.0.0″][et_pb_text _builder_version=”3.26.6″ text_text_align=”justify” text_text_color=”#025c72″ text_font_size=”33px” text_line_height=”1.3em” _i=”0″ _address=”1.0.0.0″]The Drummond Group is proud to - [PSA: Ransomware Outbreak Insights from CISA](https://eagleconsultingpartners.com/general-news/homeland-security-advice-protect-your-agency/) - The DHS Cybersecurity and Infrastructure Security Agency (CISA) just issued a special publication about ransomware protection and recovery. Read it here. - [Free Download! Redlined MIPS 2020 Proposed Rule](https://eagleconsultingpartners.com/general-news/free-download-redlined-mips-2020-proposed-rule/) - [et_pb_section fb_built=”1″ admin_label=”Section” _builder_version=”3.22″ fb_built=”1″ _i=”0″ _address=”0″][et_pb_row admin_label=”Row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” _i=”0″ _address=”0.0″][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||” _i=”0″ _address=”0.0.0″][et_pb_text admin_label=”Text” _builder_version=”3.27″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″ _i=”0″ _address=”0.0.0.0″]CMS released the MIPS 2020 Proposed Rule a few weeks ago and Eagle Consulting Partners is proud to provide a redlined version showing changes from 2019. Our intent - [PSA: Gift Card Business Email Compromise](https://eagleconsultingpartners.com/general-news/psa-gift-card-bec/) - The FBI is alerting organizations to a "gift cards" Business Email Compromise attack. Eagle clients have reported experiencing these BEC attempts. - [Partner Webinar: Prevent 81% of Phishing Attacks with DMARC](https://eagleconsultingpartners.com/general-news/partner-webinar-prevent-phishing/) - Eagle partner KnowBe4 is presenting a webinar Aug. 22 to show how to cut down on phishing email, a top threat to organizations. Check it out! - [BREAKING: 2020 MIPS Proposed Rule!](https://eagleconsultingpartners.com/general-news/breaking-2020-mips-proposed-rule/) - BREAKING NEWS: CMS Releases the 2020 MIPS Proposed Rule! CMS released the 2020 proposed rule for the MIPS program yesterday. Here are the key details: Performance Threshold CMS proposes to increase the performance threshold to 45 points in 2020 and 60 points in 2021. It is currently 30 points for the 2019 performance year. Exceptional - [MIPS Results: Eagle Clients Take Home Thousands of Dollars in Bonuses](https://eagleconsultingpartners.com/general-news/mips-results/) - MIPS results for Eagle clients from 2017 and 2018 performance years. We are pleased to share the financial benefits of our consulting work. - [10 Cybersecurity Basics for Small Practices](https://eagleconsultingpartners.com/general-news/cybersecurity-basics-small-practice/) - Small medical practices are not immune from cyberattacks, but complex defensive recommendations can seem overwhelming. Here we break down our top 10 list of cybersecurity basics that will help small practices protect themselves from data breaches and other cybersecurity risks. - [Breaking: Costly Ransomware Targeting Local Governments](https://eagleconsultingpartners.com/general-news/costly-ransomware-targeting-local-governments/) - Ransomware attacks target local governments, resulting in hundreds of thousands of dollars in ransom payments and tens of millions in financial impacts. Protect your agency. - [100 Days of HIPAA Enforcement under President Trump](https://eagleconsultingpartners.com/general-news/100-days-hipaa-enforcement-president-trump/) - It hasn't been widely publicized, but President Trump's administration brought five HIPAA enforcement actions, totaling $11,631,000, during his first 100 days in office. The appointment of Roger Severino as the Director, Office of Civil Rights (OCR), on March 22, 2017, was done quietly without the customary press release. These initial enforcement actions have all been in the - [Cloud Storage HIPAA Compliance Recommendations](https://eagleconsultingpartners.com/hipaa/cloud-storage-hipaa-compliance-recommendations/) - How do you ensure cloud storage HIPAA compliance? There are a number of file storage services in the cloud and if you are designated a business associate for a healthcare payer or provider you need to form the right policies and agreements. - [Eagle Releases 2018 Edition of HIPAA/FERPA/IDEA Policies and Procedures for Ohio DD Boards](https://eagleconsultingpartners.com/hipaa/eagle-releases-2018-edition-hipaa-ferpa-idea-policies-procedures-ohio-dd-boards/) - Eagle Consulting Partners is pleased to announce the release of its 2018 update of its Policies and Procedures for Ohio County Boards of Developmental Disability. These policies simultaneously comply with HIPAA, FERPA, IDEA and the Ohio law. - [Healthcare Industry Lagging in Cybersecurity (Part II)](https://eagleconsultingpartners.com/general-news/healthcare-lagging-cybersecurity-ii/) - A recent report on healthcare cybersecurity shows the industry 15th out of the 18 major US industries surveyed. In Part II of this two-part article, we investigate why healthcare organizations struggle to keep up with cybersecurity threats. - [HIPAA Policy Templates for Business Associates Help You Avoid Fines](https://eagleconsultingpartners.com/hipaa/hipaa-policy-templates-for-business-associates-help-you-avoid-fines/) - HIPAA Business Associates have experienced HIPAA breach fines in the millions of dollars. Eagle Consulting offers HIPAA Policy Templates specifically tailored to different types of Business Associates, including cloud computing vendors, IT managed services companies, and third-party administrators. - [Private Legal Actions for "HIPAA Violations" Gain Momentum](https://eagleconsultingpartners.com/general-news/private-legal-actions-for-hipaa-violations-gain-momentum/) - Confidentiality violations are leading to civil lawsuits in addition to HIPAA enforcement actions. Until recently, courts have dismissed civil actions against healthcare providers for conduct related to possible HIPAA violations, asserting that HIPAA's restriction of private right of action preempts state and local privacy, confidentiality, and negligence laws. But some states are now starting to - [Ohio DODD Initiates HIPAA Review of DD Boards](https://eagleconsultingpartners.com/general-news/dodd-hipaa-review/) - Information on the HIPAA compliance review of Ohio county Developmental Disability Boards by the Ohio DODD, including the security assessment method. - [2018 Was a Record Year for HIPAA Penalties](https://eagleconsultingpartners.com/general-news/ocr-hipaa-enforcement-2018/) - OCR totaled a record $28.7 million in HIPAA enforcement actions in 2018. OCR targets a wide variety of organizations. Eagle Consulting Partners offers an array of services to assist you with HIPAA compliance. - [HIPAA Policy Templates for Business Associates](https://eagleconsultingpartners.com/general-news/hipaa-policy-templates-for-business-associates/) - Are you a HIPAA business associate with an information technology product or service that needs to stay in compliance with HIPAA policies? According to HHS, a "Business Associate" is defined as a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services - [New Eagle HIPAA Policy Templates](https://eagleconsultingpartners.com/general-news/new-eagle-hipaa-policy-templates/) - Eagle has added three new downloadable HIPAA Policy templates bringing the total to six now available, ranging from HIPAA Privacy & Security Policy Templates for Medical Practices to Confidentiality & Computer Security Policies for Ohio DD Boards. - [EHRs can Kill Patients](https://eagleconsultingpartners.com/general-news/ehrs-can-kill-patients/) - Ten years after the EHR-promoting HITECH Act was passed, many EHRs still struggle with functionality, are not user friendly, don't "talk to each other", and even malfunction, according to Fortune and Kaiser Health News. Most of of the time, these issues merely result in frustration among physicians and staff. The Fortune/Kaiser article makes clear that EHR problems are resulting in outcomes far worse -- including patient injury, permanent disability and even death. Effective risk analyses will factor the impact of EHR errors. - [Windows 7 or Windows Server 2008? Time To Upgrade!](https://eagleconsultingpartners.com/general-news/windows-7-server-2008/) - Microsoft is ending support for Windows 7, Server 2008, and Server 2008 R2 operating systems in January 2020. Upgrade to modern operating systems this year to avoid security vulnerabilities. - [Portuguese Hospital Fined For GDPR Violations](https://eagleconsultingpartners.com/general-news/portuguese-hospital-fined-for-gdpr-violations/) - In October 2018, a Portuguese hospital was fined 400,000 euros for 3 GDPR violations. The violations stem from the hospital's alleged improper data access controls, failure to apply basic technical and organizational safeguards to prevent access to personal data, and failure to test the safeguards that ensure the security of data processing. The hospital is contesting the decision. - [HIPAA/GDPR Policy Templates Now Available!](https://eagleconsultingpartners.com/general-news/hipaa-gdpr-policies/) - With the General Data Protection Regulation (GDPR) in effect, US-based healthcare organizations and HIPAA business associates who handle data of European Union citizens may have to comply with GDPR and HIPAA simultaneously. Our comprehensive and customizable HIPAA and GDPR policy templates help you comply with both. - [Selecting an EHR (for physicians)](https://eagleconsultingpartners.com/healthit/selecting-an-ehr/) - The ARRA imperative to implement electronic records leaves many physicians feeling daunted. With hundreds of vendors touting their wares, health reform and uncertain change on the horizon, and colleagues' stories of EHR disasters, the task can seem frightening and overwhelming. Here is a roadmap for moving forward. - [Top 10 Computer Security List for Medical Practices](https://eagleconsultingpartners.com/hipaa/top-10-computer-security-list-for-medical-practices/) - Physician practices have become more reliant on computer technology, the internet has connected most computers, and small mobile devices are everywhere. The net result is that practices are more exposed to computer security problems than ever before. With a small or medium sized practice's limited resources, what are the most important computer security steps to take? Here is the top 10 computer security list for medical practices. - [“Meaningful Use” – the Computer Security Risk Assessment](https://eagleconsultingpartners.com/cms-qpp/achieving-meaningful-use-the-risk-assessment/) - To achieve "meaningful use" and to earn incentive payments, medical practices must perform a HIPAA-mandated computer security risk analysis -- and use it. So what is a computer security risk analysis? - [Eagle Case Study: VAR Partnership](https://eagleconsultingpartners.com/hipaa/business-associate-hipaa-compliance/) - Eagle consulted and helped manage HIPAA compliance for a medical practice management software vendor as part of a program that included review and guidance for software features, client training classes, and a smart business associate agreement. Some of the costs of this major transition were defrayed with client training revenues. - [MyFitnessPal Data Breach](https://eagleconsultingpartners.com/business-associates-others/myfitnesspal-data-breach/) - MyFitnessPal, a fitness app with 150 million users, experienced a large data breach in February. Use of obsolete hashing algorithms put users at risk. - [What Is GDPR?](https://eagleconsultingpartners.com/physician-practices/what-is-gdpr/) - GDPR is an EU regulation that governs the handling and processing of EU citizen data. What does this mean for healthcare data compliance in the U.S.? - [Ransomware Still a Threat to Government Agencies.](https://eagleconsultingpartners.com/general-news/ransomware-government-thread/) - Ransomware remains a threat to governments all across the country, and recovery is a tremendous financial burden, as seen in the recent attack on Atlanta. - [Free Redlined 2019 MIPS Rule!](https://eagleconsultingpartners.com/general-news/free-redlined-2019-mips-rule/) - Each year, succeeding with MIPS becomes progressively harder. Eagle Consulting is providing a resource, a redlined version of this MIPS rule showing changes from the previous year to aid organizations in maximizing their success under MIPS. It covers the CMS' 2019 MIPS rule published on November 1, 2018. - [Am I Required to Submit for MIPS in 2018?](https://eagleconsultingpartners.com/general-news/am-i-required-to-submit-for-mips-in-2018/) - The first step to determining MIPS eligibility is a review of the eligible clinician types: physician, physician assistant, nurse practitioner, clinical nurse specialist, and certified registered nurse anesthetics. If you fall under one of these 5 categories in 2018, you may be eligible for a reimbursement (or a penalty). Learn more. - [CMS Releases MIPS 2019 Proposed Rule: Top 3 Items to Be Aware Of](https://eagleconsultingpartners.com/general-news/cms-releases-mips-2019-proposed-rule-top-3-items-to-be-aware-of/) - As we are moving through through year 2 of the MIPS program, it is imperative that eligible clinicians simultaneously prepare for the next few years and the prospective changes to come. With the release of the proposed rule for 2019, participants can get a sense of the impending challenges of the MIPS program moving forward; - [Disappointing MIPS Incentives: Where’s My Money?](https://eagleconsultingpartners.com/general-news/where-is-my-mips-money/) - Disappointingly low MIPS bonuses are a result of a MIPS "transition" period which calls for the MIPS program to be fully implemented in 5 years. When the transition period is over, the advertised bonus amounts will be achieved. - [Top 5 MIPS Mistakes to Avoid in 2019](https://eagleconsultingpartners.com/general-news/mips-mistakes/) - The MIPS rules are complex and this complexity creates many opportunities to make mistakes. Make sure that you avoid these top 5 mistakes that we have seen! - [New State of Ohio Standard Medical Release Form](https://eagleconsultingpartners.com/general-news/ohio-medical-release-form/) - The Ohio Department of Medicaid created two medical release forms. One form complies with the HIPAA requirements; the other form complies with 42 CFR Part 2 requirements regarding substance use confidentiality. These forms, if properly completed, must be accepted by any recipient in Ohio. - [Not Familiar with 42 CFR Part 2? Perhaps You Should Be.](https://eagleconsultingpartners.com/physician-practices/not-familiar-with-42-cfr-part-2-perhaps-you-should-be/) - 42 CFR Part 2 is a federal law aimed at protecting the confidentiality of substance abuse patient records. It is more restrictive than HIPAA in numerous ways, so you have to be careful with these records should you receive them. Under 42 CFR Part 2, the restrictions on the disclosure of these particular records apply - [New Guidance from OCR: Patching Software is Not Optional!](https://eagleconsultingpartners.com/hipaa/new-guidance-from-ocr-patching-software-is-not-optional/) - The Department of Health and Human Services Office of Civil Rights (OCR) published its Guidance titled "Guidance on Software Vulnerabilities and Patching", in its June 2018 newsletter. In this Guidance, OCR stated that "identifying and mitigating the risks unpatched software poses to ePHI is important to ensure the protection of ePHI and in fulfilling HIPAA - [Who are the Threats to Public Health Information?](https://eagleconsultingpartners.com/general-news/phi-threats/) - A key component of any risk analysis and risk management program is understanding who the threats to your organization’s PHI data are. - [Don't Use Internet Explorer, says Microsoft Cybersecurity Chief](https://eagleconsultingpartners.com/general-news/internet-explorer/) - Internet Explorer is a "compatibility solution" not a "modern browser", explains Microsoft's lead for cybersecurity in a recent blog post. - [Mid-level Practitioners & Meaningful Use (Promoting Interoperability)](https://eagleconsultingpartners.com/general-news/mid-level-practitioners-meaningful-use/) - Editor's Note: Subsequent to the publication of this article, CMS has renamed the "Meaningful Use" programs and MIPS "Advancing Care Information" category to "Promoting Interoperability". The Meaningful Use program uses the terms "Eligible Professional" and "Eligible Hospital" to designate those individuals and institutions who may choose to participate, may receive incentives, or may receive payment - [UPDATE - MIPS: Small Practices May Claim a "Promoting Interoperability" (ACI) Exception](https://eagleconsultingpartners.com/general-news/update-mips-small-practices-may-claim-a-promoting-interoperability-aci-exception/) - New for MIPS in 2018 is the "Significant Hardship Exception" for small practices, which exempts them from the "Promoting Interoperability" category. While claiming the exception will reduce cost and labor, practices should do a breakeven analysis to determine if it is profitable to complete the PI category. - [Prepare NOW for MIPS 2019 Quality Category Changes!](https://eagleconsultingpartners.com/general-news/prepare-now-for-mips-2019-quality-category-changes/) - As 2018 comes to a close, and we get ready to report, eligible clinicians need also be preparing for 2019 and the changes it will bring for their practice. Practices should be on the lookout for the following: Weight: Comprising 60 percent of the final score beginning in 2017, the quality category has understandably been - [MIPS Cost Category: What Can You Do About It? Pt. 1](https://eagleconsultingpartners.com/physician-practices/mips-cost-category-what-can-you-do-about-it-pt-1/) - There are four categories to the 2018 MIPS program: quality, promoting interoperability (formerly advancing care information), improvement activities, and the cost category. Though seemingly new to the program for 2018, the cost performance category was being tracked in 2017. However, it did not contribute to your MIPS score. This year the cost category will be - [Security Risk Analysis deadline under ACI is 12/31/2017](https://eagleconsultingpartners.com/general-news/security-risk-analysis-aci-2017/) - The Security Risk Analysis (SRA) remains a requirement for the new Advancing Care Information (ACI) category of MIPS. A change enacted this year requires that the SRA be complete by 12/31/2017 under ACI, the Medicaid Meaningful Use program for physicians, and Hospital Meaningful Use programs. Practices who need outside help are advised to schedule their early to ensure that it is completed on time, and to avoid - [Former OCR Official Reveals Top Reason for Risk Analysis Audit Failure](https://eagleconsultingpartners.com/general-news/ocr-risk-analysis-audit-failure/) - A key reason for risk analysis failure during an audit by the HHS Office for Civil Rights is mistaking a technical or non-technical evaluation for a risk analysis. - [MIPS Final Scores Not What You Were Expecting?](https://eagleconsultingpartners.com/general-news/mips-final-scores-not-what-you-were-expecting/) - Eligible clinicians and groups that participated in MIPS performance year 2017 can now view their final scores as well as review the calculation of their 2019 payment adjustment. Per the MIPS regulation, the final scores received for performance year 2017 will dictate whether an eligible clinician and/or group receive a positive, negative, or neutral payment - [Top 20 Security Controls Updated, and “Compliance vs. Security”](https://eagleconsultingpartners.com/hipaa/top-20-security-controls-updated/) - “Top 20 Critical Security Controls” began in 2008 as an effort by U.S. and international agencies, including our own NSA, which has been the subject of so much media attention recently. Eventually, recommendations for what became the “Critical Security Controls” (Controls) were coordinated through SANS Institute. In 2013, the stewardship and sustainment of the controls - [Model Business Associate Agreements (BAAs) for Business Associates](https://eagleconsultingpartners.com/business-associates-others/model-business-associate-agreements-baas-for-business-associates/) - Entities who are Business Associates need a model BAA to use with their customers, and may also have subcontractors for which a BAA is also needed. Should you use the same agreement? Probably not! Eagle recently updated the model BAA included in our various HIPAA policy templates for Business Associates, which available in our store. - [Email Encryption Considerations for DD Boards](https://eagleconsultingpartners.com/hipaa/email-encryption-considerations-for-dd-boards/) - Email encryption is a major area of non-compliance for DD boards. Read more to explore some of the typical challenges and a possible solution. - [Urgent Threat: VPNFilter Malware Affects Hundreds of Thousands of Internet Routers](https://eagleconsultingpartners.com/general-news/vpnfilter/) - VPNFilter malware infected over 500k routers to intercept internet traffic, steal passwords, pass malware onto your network, and create botnets. - [Cyber-Attacks on Healthcare on the Rise](https://eagleconsultingpartners.com/general-news/cyber-attacks-on-the-rise/) - Cyber-attacks on healthcare providers increased from 2016 to 2017, and are still trending upwards. Extensive private data plus inadequate security makes healthcare organizations attractive targets for attackers and, all too often, victims of their own errors. - [CMS Releases MIPS Preliminary Scores](https://eagleconsultingpartners.com/physician-practices/cms-releases-mips-preliminary-scores/) - Preliminary MIPS scores have been released by the Centers for Medicare and Medicaid Services. While this information is useful, it is important to note that these are not your final scores for MIPS performance year 2017. Final scores are slated to be available summer 2018, though past trends have proved early fall may be a - [Phishing and Eagle's New Security Awareness Program](https://eagleconsultingpartners.com/general-news/phishing-security-awareness-program/) - Phishing is a big threat to healthcare, and employees are the weak link. You need regular, effective security awareness training for staff. Eagle can help. - [Allied Physicians Among SamSam's Latest Victims](https://eagleconsultingpartners.com/general-news/allied-physicians-among-samsams-latest-victims/) - Allied Physicians, a 40-physician practice in South Bend, Indiana, was attacked by a particular strain of ransomware called SamSam. Allied Physicians discovered the ransomware on May 17 and shut down its network. By May 26, the network was restored. Nine days without computer capabilities is a significant disruption. Whether patient information was exfiltrated is yet - [Was County Agency Employee's Facebook Post a HIPAA Violation?](https://eagleconsultingpartners.com/dd-board-solutions/was-county-agency-employees-facebook-post-a-hipaa-violation/) - A Roane County, Tennessee, EMS responder posted on her Facebook page, “well, we had a first…We worked a code in a chicken coop! Knee deep in chicken droppings.” according to HealthITSecurity.com. Lessons from this incident can be useful for County DD Boards. The EMS team was called to the scene because a man, Leon Raymond, - [Updating Your Risk Analysis for 2011](https://eagleconsultingpartners.com/hipaa/updating-your-risk-analysis-for-2011/) - Hospitals, physician practices, government agencies, business associates and others who must comply with the HIPAA Security regulations should dust off the previous HIPAA Security Risk Analysis and update it for 2011. Hospitals and Physician practices qualifying for meaningful use incentive payments have a great motivation already. But even if you are not in line for - [Common Mistakes in the HIPAA Security Risk Analysis](https://eagleconsultingpartners.com/general-news/common-mistakes-in-the-hipaa-security-risk-analysis/) - With the advent of the Meaningful Use program, including the current Stage 2 requirements, healthcare organizations across the country have instituted the annual risk analysis, or risk assessment. When Eagle Consulting Partners conducts a risk analysis, we always seek to build upon work that has already been completed. This involves reviewing one or more risk - [What the MIPS!?!](https://eagleconsultingpartners.com/general-news/another-cms-incentive-program/) - The CMS “incentive” programs over the past several years -- Meaningful Use, PQRS, ePrescribing, and the Value-modifier -- have been used both the "carrot" and "stick" approach. CMS provides both cash bonuses and penalties. The Merit-based Incentive Payment System or MIPS was created as a way to simplify the procedural process for clinicians. Over the past - [Understanding the MIPS Scoring](https://eagleconsultingpartners.com/general-news/understanding-scoring-mips/) - As we mentioned in our initial post (What the MIPS?), the payment modifier for MIPS will be determined by a performance threshold (PT) set by CMS and your individual or group Composite Performance Score (CPS). This CPS is a number between 0 and 100 is calculated by weighting the scores attained in 4 performance categories. - [The PQRS replacement](https://eagleconsultingpartners.com/general-news/pqrs-replacement/) - The Merit-based incentive Payment System (MIPS) introduces 4 measure categories to the Medicare incentive program space. As we have mentioned in previous posts, MIPS is the new law of the land, replacing Medicare's Meaningful Use, PQRS and Value Modifier incentive programs. Reporting for MIPS starts in 2017 so it is important to start learning what you - [2016 is Biggest HIPAA Enforcement Year, $19 Million in Fines](https://eagleconsultingpartners.com/general-news/2016-biggest-hipaa-enforcement-year/) - While only in the 8th month of the year, 2016 is already the biggest HIPAA enforcement year as tallied by the dollar amount of fines, which exceed $19 Million. Here is a roundup of enforcement actions this year: Advocate Health Care, $5.55 Million. Advocate Health Care Network, the largest health system in Illinois with 12 - [Quality Payment Programs, the final rule](https://eagleconsultingpartners.com/general-news/quality-payment-programs-final-rule/) - The Quality Payment Program final rule has been released. What payment adjustments will physicians see in the upcoming years? How quickly will the new payment methodologies be implemented? - [Health Care Direction under President Trump](https://eagleconsultingpartners.com/general-news/health-care-direction-under-president-trump/) - While most of the political attention has focused on the GOP and Trump administration's efforts to repeal Obamacare, aging Baby Boomers continue to challenge the finances of Medicare and the entire U.S. Federal budget. After the recent passage of an Obamacare repeal bill in the House, it is likely that political attention will remain on Obamacare repeal efforts, leaving recently enacted programs affecting Medicare, MACRA and MIPS, intact. It is possible that practices who maximize their performance under MIPS could earn a big payday, as high as - [Security Risk Analysis: Doctors believe EHR outages harm patients](https://eagleconsultingpartners.com/general-news/security-risk-analysis-ehr-outages/) - According to a recent survey, physicians believe that EHR downtime harms patients. This is supported by the the Office of the National Coordinator of Health Information Technology (ONC), which states that medication errors and other impacts can occur. An effective HIPAA Security Risk Analysis (SRA) will - [Updated Rule for CMS Quality Payment Program](https://eagleconsultingpartners.com/general-news/cms-quality-payment-program/) - Are you prepared for the changes from CMS for the Quality Payment Program? Eagle has prepared an updated rule for proposed changes through 2018. - [Security Risk Analysis Required For MU Stages 2 and 3](https://eagleconsultingpartners.com/general-news/security-risk-analysis-for-mu-stages-2-and-3/) - What's going on with new privacy and security objectives for Meaningful Use in healthcare? New MU Stage 2 Rules affirm that an annual Security Risk Analysis (SRA) must be conducted, and that the scope of this SRA may be limited to the data in the EHR. - [Achieving Meaningful Use Stage 1 for Privacy and Security](https://eagleconsultingpartners.com/hipaa/meaningful-use-stage-1-for-privacy-and-security/) - (Editor's Notes: 5/23/2018: Over the last 7 years, this program has morphed annually, although this post remains relevant. The Meaningful Use program is now called "Promoting Interoperability". 10/1/2016: The scope of the Security Risk Analysis for Meaningful Use Stages 2 and 3 has changed. As a companion to this post, readers seeking guidance regarding Stage - [Meaningful Use Audits Underway](https://eagleconsultingpartners.com/cms-qpp/meaningful-use-audits-underway/) - CMS has announced that providers – hospitals and physicians – who received meaningful use incentive payments are now being audited. CMS has outsourced this function to the New York audit contractor Figliozzi & Company. Providers who fail to produce documentation to support their Stage 1 Meaningful Use incentive payment are at risk for losing that - [Meaningful Use Audits](https://eagleconsultingpartners.com/cms-qpp/meaningful-use-audits/) - The meaningful use audits are in full swing and both hospitals and physicians are being audited. For most hospital or physician practice that retained careful documentation prior to submission, these audits are relatively painless. Unfortunately, some organizations, particularly smaller physician practices, did not fully understand the meaningful use requirements or did not retain careful documentation. - [Deadline extended for eligible professionals attesting to Meaningful Use](https://eagleconsultingpartners.com/cms-qpp/deadline-extended-eligible-professionals-attesting-meaningful-use/) - The Centers for Medicare & Medicaid Services (CMS) has extended the deadline for physicians and other eligible professionals to attest to meaningful use for the Medicare EHR Incentive Program 2013 reporting year. Also, some hospitals are being offered the opportunity to attest retroactively and possibly avoid 2015 penalties for missing the Nov. 30 2013 deadline. - [CFO Indicted for Fraudulent Statements in Meaningful Use Attestation](https://eagleconsultingpartners.com/cms-qpp/cfo-indicted-for-fraudulent-statements-in-meaningful-use-attestation/) - Eagle Consulting, Inc. has worked with healthcare providers who have failed meaningful use audits in the last two years. In each of these cases, the providers contacted us after the auditors found that they had not completed a legitimate risk analysis as required by Core Objective #15 (#14 in Stage 2). The maximum penalty that - [Audits and the Meaningful Use Risk Analysis – Update from HIMSS 2014](https://eagleconsultingpartners.com/cms-qpp/audits-and-the-meaningful-use-risk-analysis-update-from-himss-2014/) - Several officials from CMS spoke at HIMSS 2014 in Orlando regarding meaningful use audits. Approximately 5% of both physician and hospital providers are being audited, and these audits are split about 50/50 between post-payment and pre-payment audits. “Document, Document, Document” is the advice of one CMS official. One best practice, presented by an executive of - [Meaningful Use: Audit, Assessment or Analysis?](https://eagleconsultingpartners.com/hipaa/meaningful-use-audit-assessment-or-analysis/) - Conducting a meaningful use security risk assessment has been a requirement for HIPAA Covered entities since 2005, and now their business associates must also comply. The Meaningful Use program (Stage 1) also includes the requirement: "Conduct or review a security risk analysis in accordance with the requirements under 45 CFR 164.308(a)(1) and implement security updates - [Meaningful Use Audits Evolve to Require Security Corrective Actions to be Complete](https://eagleconsultingpartners.com/cms-qpp/meaningful-use-audits-evolve-require-security-corrective-actions-complete/) - (Editor's Note: For the Stage 2 Rules effective 10/16/2015, the Privacy and Security Objective is now Objective #1) Eagle Consulting Partners is working with three clients, participants in the Medicare Meaningful Use program, to assist them with responses to meaningful use audits. All of these audits began during the last 30 days. These audits were - [The Cost of Not Being a Meaningful User](https://eagleconsultingpartners.com/general-news/cost-meaningful-user/) - Medicare Payment Adjustments will produce significant, long-term financial loss for physicians who do not participate in Meaningful Use As part of the American Recovery and Reinvestment Act of 2009 (ARRA), Congress mandated payment adjustments be applied to Medicare eligible professionals who are NOT meaningful users. Beginning in 2015, if you do not successfully demonstrate meaningful - [Overhaul of Meaningful Use Stages 1 & 2 Proposed](https://eagleconsultingpartners.com/general-news/overhaul-of-meaningful-use-stages-1-2-proposed/) - (Editor's Note 11/14/2015: If you have arrived here, check our post on the final update of these rules at CMS Unveils Long Awaited Meaningful Use Rule Changes for 2015.) On April 15, 2015, CMS published a proposed new rule simplifying the Meaningful Use rules. Overall, this proposed new rule provides relief for physicians who are - [Meaningful Use Proposed Changes, Details](https://eagleconsultingpartners.com/general-news/meaningful-use-proposed-changes-details/) - On April, 15, 2015, HHS proposed significant restructuring of the Meaningful Use rules for Stages 1 & 2. Overall this is good news for healthcare providers, many of whom struggled under the tough Stage 2 rules. Here is a more detailed look at the changes: Measures that have been eliminated Record Demographics Record Vital Signs - [Meaningful Use Objectives & Measures for Stage 2 Proposed by CMS on 4-15-2015](https://eagleconsultingpartners.com/general-news/meaningful-use-objectives-measures-stage-2-proposed-cms-4-15-2015/) - On 4/15/2015 CMS proposed significant simplifications to the Meaningful Use Stage 2 rules. For physicians, this provides significant relief from the complexities of Stage 2. Highlights include: For 2015, reporting period is changed to any 90 day period Stage 2 obligations restructured from 17 Core Objectives plus 3 of 6 Menu Set Objectives to a - [Meaningful Use Stage 3 Rules Unveiled](https://eagleconsultingpartners.com/general-news/meaningful-use-stage-3-rules-unveiled/) - The proposed Stage 3 rules were released on March 30, 2015. This rule defines Meaningful Use Stage 3 which is intended to be the final stage and in this process to be required for all providers from 2018 and beyond. The rule includes 8 objectives (with multiple measures) and will require an upgrade of the - [SGR Repeal to Restructure Meaningful Use Penalties](https://eagleconsultingpartners.com/general-news/sgr-repeal-to-restructure-meaningful-use-penalties/) - On April 16, 2015 the President signed legislation to repeal the Medicare sustainable growth-rate (SGR) formula for paying doctors. This repeal, of course, was welcomed by the physician community tired of the annual fight to restore reimbursement. Also included in this legislation is a repeal, effective in 2018, of the existing penalty structure for - [Electronic Transmission of the Summary of Care for 2015 Meaningful Use](https://eagleconsultingpartners.com/general-news/electronic-transmission-summary-care-2015-meaningful-use/) - Under the proposed changes to Meaningful Use for 2015 through 2017, the Summary of Care measure has been simplified to allow providers to transmit the Summary of Care electronically to a provider who does not have an EHR and still get credit for Meaningful Use. Under the current Stage 2 rules, "The EP who transitions - [Credentialing of Staff Members Requred for EHR Order Entry under Meaningful Use](https://eagleconsultingpartners.com/general-news/credentialing-staff-members-requred-ehr-order-entry-meaningful-use/) - According to the Stage 2 measure specifications for Computerized Provider Order Entry, only "licensed healthcare professionals" may enter orders into an EHR if the order is to count for Meaningful Use: "Any licensed healthcare professionals and credentialed medical assistants, can enter orders into the medical record for purposes of including the order in the numerator - [Meaningful Use Stage 2, Measure 5: Health Information Exchange - What Must Be Transmitted](https://eagleconsultingpartners.com/general-news/meaningful-use-stage-2-measure-5-health-information-exchange-must-transmitted/) - Under the new Meaningful Use Stage 2, Measure 5: when referring or transitioning a patient to another provider or setting of care, an electronic record must be transmitted to the other provider at least 10% of the time. - [Meaningful Use Stage 2, Measure 5: Health Information Exchange, Now More Flexible](https://eagleconsultingpartners.com/general-news/meaningful-use-stage-2-measure-5-health-information-exchange-now-flexible/) - Now that meaningful use Stage 2, Measure 5 has been clarified, providers have some more flexibility including the use of secure email. We discuss some options for your consideration including secure email that could be obtained for under $25 per month. - [Meaningful Use and the Evolution of Privacy and Security Objective](https://eagleconsultingpartners.com/general-news/meaningful-use-and-the-security-objective/) - After the Oct. 2015 update from CMS, meaningful use and the security objective as this objective has moved from last, Core Measure 15 of 15, to first, Measure 1 of 10. We review what this means for provider in the latest edition of our newsletter. - [CMS Unveils Long Awaited Meaningful Use Rule Changes for 2015](https://eagleconsultingpartners.com/general-news/cms-posts-meaningful-use-rules-for-2015/) - Did you know that Stage 2 is restructured from 17 core objectives and 6 menu set objectives to a simplified 10 required objectives? CMS has released its meaningful use rules for 2015 -- we've reviewed them and have some analysis of objectives and measures for you. - [2016 OIG Work Plan includes HIPAA and Meaningful Use Items](https://eagleconsultingpartners.com/general-news/2016-oig-work-plan-includes-hipaa-and-meaningful-use-items/) - This week the HHS Office of the Inspector General (OIG) released its Work Plan for Fiscal Year 2016. Combing through this 76 page document revealed some items of interest relating to HIPAA and Meaningful Use. In particular, we note two areas of investigation: 1) Hospitals' electronic health record system contingency plans. They will determine the - [2015 Meaningful Use Hardship Exception available to All Eligible Providers](https://eagleconsultingpartners.com/general-news/2015-meaningful-use-hardship-exception-available-to-all-physicians/) - All physicians and other Eligible Providers (EPs), whether you have an EHR or not, whether you were successful with Meaningful Use or not, can apply for a hardship exception for the calendar year 2015. A one-year only, liberalized exception is available to all because of the hardship created by CMS' late release of the 2015 - [Senators Portman and Bennet introduce Bill to Shorten Meaningful Use Reporting Period](https://eagleconsultingpartners.com/general-news/senators-portman-and-bennet-introduce-bill-to-shorten-meaningful-use-reporting-period/) - Yesterday, Senators Rob Portman (R-Ohio) and Michael Bennet (D-Colorado), along with U.S. Representatives Renee Elmers, Tom Price, M.D., Bobby Rush and Ron Kind introduced the Flexibility in Electronic Health Record (EHR) Reporting Act, which would shorten, in statute, the MU reporting period from one year to 90 days. "Our hospitals and medical professionals work long, - [CMS and ONC: Meaningful Use is Not Dead!](https://eagleconsultingpartners.com/general-news/cms-and-onc-meaningful-use-is-not-dead/) - Why is Meaningful Use not dead? For hospitals, and for physicians participating in the Medicaid MU program, no imminent change is expected in the Meaningful Use rules. However, CMS is exploring options for updating these programs to reward providers for outcomes, to allow providers flexibility, to promote innovation and new technologies and to encourage interoperability. - [Meaningful Use, PQRS and Value Modifier for 2016](https://eagleconsultingpartners.com/general-news/understanding-and-completing-2016-meaningful-use-measures/) - Editor's Note: Subsequent to the publication of this article, CMS has renamed the "Meaningful Use" programs and MIPS "Advancing Care Information" category to "Promoting Interoperability". For 2016 the three Medicare Incentive programs -- Meaningful Use, PQRS and the Value-Based Payment Modifier apply to physician practices. As is usually the case, the rules have been updated. - [Meaningful Use morphs into "Advancing Care Information" under MACRA/MIPS](https://eagleconsultingpartners.com/general-news/beyond-meaningful-use/) - Editor's Note: Subsequent to the publication of this article, CMS has renamed the MIPS "Advancing Care Information" category to "Promoting Interoperability". The MACRA legislation established the Medicare Incentive Payment System (MIPS) program. In April 2016 CMS released a proposed rule which defines the MIPS program. MIPS will assimilate the Physician-Medicare version of the Meaningful Use - [Meaningful Use in 2016 and 2017](https://eagleconsultingpartners.com/general-news/meaningful-use-in-2016-and-2017/) - Meaningful Use is still on for 2016 and 2017. Learn what Acting Administrator has said about Meaningful Use and the MACRA implementation. - [Meaningful Use Changes for 2016](https://eagleconsultingpartners.com/general-news/meaningful-use-changes-2016/) - Editor's Note: Subsequent to the publication of this article, CMS has renamed the "Meaningful Use" programs to "Promoting Interoperability". Once again we are sitting in the beginning of August with the potential for CMS to change program requirements for the EHR Incentive Programs for Physicians, other professionals and Hospitals. Luckily this time, they aren't talking about - [Physician's Quality Reporting System Key in 2016](https://eagleconsultingpartners.com/general-news/physicians-quality-reporting-system-key-in-2016/) - Did you know that how you follow the Physician's Quality Reporting System (PQRS) in 2016 will have a significant impact on your practice revenue in coming years? CMS has stated that failure to comply will cut your Medicare reimbursement by 2% starting in 2018... and it is part of a consolidation of upcoming reporting requirements. - [MACRA and Quality Payment Programs](https://eagleconsultingpartners.com/general-news/macra-quality-payment-programs/) - The Medicare Access and CHIP Reauthorization Act (MACRA) was passed on April 16, 2015. This legislation was landmark because it repealed the Sustainable Growth Rate (SGR). This legislation also created two new payment systems for Medicare Providers. These two programs are known collectively as the Quality Payment Programs (QPP). MACRA was passed with overwhelming from both - [Paying for Quality at a new level](https://eagleconsultingpartners.com/general-news/paying-quality-new-level/) - As we mentioned in the last post, both MIPS and Advanced APMs are a part of the Quality Payment Programs. These programs replace the reimbursement structure in place for practices in 2017. So what is the difference between MIPS and Advanced APMs? CMS estimates that the vast majority of Clinicians will be subject to MIPS, - ["Meaningful Use" and "Advancing Care Information" renamed "Promoting Interoperability"](https://eagleconsultingpartners.com/general-news/mips-news-advancing-care-information-renamed-promoting-interoperability/) - CMS has renamed its various EHR incentive programs to "Promoting Interoperability". The Meaningful Use and Advancing Care Information names will be dropped. - [MIPS Strategy: Topped Out Measures](https://eagleconsultingpartners.com/general-news/mips-strategy-topped-out-measures/) - During 2018, CMS has classified six of the MIPS quality measures "topped out" which makes achieving a high final score a bit tougher. In subsequent years, more measures will become topped out so providers will need to identify new measures in order to achieve the same MIPS final score. - [The QRUR and MIPS](https://eagleconsultingpartners.com/general-news/the-qrur-and-mips/) - The 2015 QRUR have been released. Practices can download them and learn about their potential payment adjustments in 2017. They can also begin to understand how to perform well in MIPS. - [Eagle Consulting Releases its MIPS Impact Estimates for 2018](https://eagleconsultingpartners.com/general-news/eagle-consulting-releases-mips-impact-estimates-2018/) - The CMS Merit-Based Incentive Payment System (MIPS) rules have changed for 2018, and the financial impact for physician practices has edged higher. Based on performance in 2018, physician reimbursement for Medicare Part B in calendar year 2020 will be reduced by as much as 5%. - [Healthcare Industry Lagging in Cybersecurity (Part I)](https://eagleconsultingpartners.com/general-news/healthcare-lagging-cybersecurity-i/) - A recent report on healthcare cybersecurity shows the industry 15th out of the 18 major US industries surveyed. In Part I of this two-part article, we explore this poor rating and investigate why healthcare records are so appealing to criminals. - [Kansas Dept. for Aging and Disability Services Employees Fired Over Email Containing PHI](https://eagleconsultingpartners.com/dd-board-solutions/kansas-dept-for-aging-and-disability-services-employees-fired-over-email-containing-phi/) - 2 Kansas Department for Aging and Disability Services employees were terminated after sending an email containing PHI of 11,000 individuals to improper recipients. - [Ohio DD Boards – Confidentiality Contracts with PT, OT and ST Independent Contractors](https://eagleconsultingpartners.com/hipaa/ohio-dd-boards-confidentiality-contracts-with-pt-ot-and-st-independent-contractors/) - Ohio DD Boards are responsible for ensuring confidentiality when working with third parties. The appropriate method varies depending on whether a 3rd party provider is HIPAA Covered Entity or not. Eagle offers a model confidentiality agreement for contract providers who are not HIPAA Covered Entities. - [MIPS: Small Practices May Claim a "Promoting Interoperability" (ACI) Exception](https://eagleconsultingpartners.com/general-news/mips-for-small-physicians-practices/) - New for MIPS in 2018 is the "Significant Hardship Exception" for small practices, which exempts them from the "Promoting Interoperability" category. While claiming the exception will reduce cost and labor, practices should do a breakeven analysis to determine if it is profitable to complete the PI category. - [Partners HealthCare Informs 2,600 Patients of Malware Attack After 7-Month Investigation](https://eagleconsultingpartners.com/hipaa/partners-healthcare-informs-2600-patients-malware-attack-7-month-investigation/) - Partners issued a press release stating that it would begin notifying patients whose information was at risk after a malware attack in May 2017. An outside forensics team determined that sensitive data for approximately 2,600 patients was vulnerable. - [Meltdown & Spectre Part IV: Updating Your Computer (Continued)](https://eagleconsultingpartners.com/threat-intelligence/meltdown-spectre-iv/) - In Part IV of our series on the Meltdown and Spectre vulnerabilities, we finish the process of updating your computers' firmware and key applications to protect you, your systems, and your patients and clients. - [Meltdown & Spectre Part III: Checking and Updating Your Computer](https://eagleconsultingpartners.com/threat-intelligence/meltdown-spectre-iii/) - Meltdown and Spectre computer vulnerabilities affect HIPAA Covered Entities and Business Associates. Every computer, phone, and tablet is impacted. Take these steps to protect yourself and update your systems. - [Wake-up Call for Business Associates – Comply with HIPAA Now](https://eagleconsultingpartners.com/hipaa/wake-up-call-for-business-associates-comply-with-hipaa-now/) - Last month Minnesota Attorney General Lori Swanson filed suit against Accretive Health, Inc., a company which provides revenue cycle management services for two Minnesota Health Systems – Fairview Health Services and North Memorial Health Care. According to the complaint, a computer laptop with sensitive information on 23,500 patients was stolen from a rental car. Eight - [Compliance Risk for Business Associates](https://eagleconsultingpartners.com/general-news/compliance-risk-for-business-associates/) - Risk analysis for business associates is one of Eagle's smart services, and it's always needed both for business associate firms themselves and for the hospital, clinic and other healthcare entities relying on their associates for compliance to help avoid breaches and resulting government penalties. Compliance failures can cost up to $50,000 per incident. - [Healthcare Cyber Security, Penalties & Solutions](https://eagleconsultingpartners.com/general-news/healthcare-cyber-security-penalties-solutions/) - When it comes to healthcare cyber security, the Government is stepping up audits and taking a closer look at business associates right now. Are you ready? What can you expect as the government changes and updates its rules, and brings a new focus on compliance? Audits. More rule changes. Enforcement. The bottomline is privacy through security. - [Orthopaedic Practice Fined $750,000 for HIPAA Violation](https://eagleconsultingpartners.com/general-news/practice-fined-750000-for-hipaa-violation/) - An Orthopaedic Practice fined $750,000 for HIPAA Violations, is learning the hard way that they needed to have a business associate agreement (BAA) in place. The settlement comes after an alleged breach 17,300 patient's information. - [Research-based Dietary Interventions for Autism](https://eagleconsultingpartners.com/general-news/research-based-dietary-interventions-autism/) - Specialists assisting early-childhood and school-aged children, as well as service and support administrators may appreciate the latest research-based findings regarding any beneficial dietary interventions for autism. Alternative health practitioners and advocacy groups promote special diets such as the gluten-free/casein-free diet. What does the research say about diet and autism? What can a public servant responsibly - [Phishing for Healthcare Providers](https://eagleconsultingpartners.com/general-news/phishing-for-healthcare-providers/) - Don't become the next Catch of the Day! Healthcare providers are worse than their peers at identifying phishing emails and preventing these attacks. What is phishing? How can you protect yourself? Read this article to find out. - [Meltdown & Spectre Part I: What Are They?](https://eagleconsultingpartners.com/general-news/meltdown-spectre-i/) - Meltdown and Spectre computer vulnerabilities affect HIPAA Covered Entities and Business Associates. Every computer, phone, and tablet is impacted. What are they and what do you need to know? Read our series to find out. - [Ransomware Targeting Hospitals and Health IT Systems](https://eagleconsultingpartners.com/threat-intelligence/ransomware-targeting-hospitals-health-systems/) - SamSam ransomware is making a name for itself by attacking healthcare-related organizations. Prior to its famous attack on Allscripts, SamSam infected three hospitals. Ransomware remains a significant risk for organizations in 2018. - [Cover Your PC Camera - Someone May Be Watching!](https://eagleconsultingpartners.com/general-news/cover-pc-camera-someone-may-watching/) - Phillip Durachinsky was charged for his role in deploying malware called "Fruitfly". Fruitfly infected thousands of computers and harvested millions of pictures and other files which were allegedly stored by Durachinsky. Fruitfly also has the capability to turn on webcams and microphones remotely. - [Meltdown & Spectre Part II: Impacts to Healthcare Organizations](https://eagleconsultingpartners.com/general-news/meltdown-spectre-ii/) - Meltdown and Spectre computer vulnerabilities affect HIPAA Covered Entities and Business Associates. Every computer, phone, and tablet is impacted. What are they and what do you need to know? Read our series to find out. - [Ransomware Destroys Small Practice EHR Database](https://eagleconsultingpartners.com/general-news/ransomware-destroys-small-practice-ehr-database/) - Hermes ransomware attacks small physician practice. Ransomware encrypted database files prior to routine backup. Entire EHR database lost and backup unusable. Attack illustrates the importance of multiple generations of backup and separating backup from computer network. - [OIG Issues Report to State DD Agencies to Address Group Home Problems](https://eagleconsultingpartners.com/dd-board-solutions/oig-issues-report-state-dd-agencies-address-group-home-problems/) - Given the increasing awareness of abuse toward the developmentally disabled, the Health and Human Services Office of Inspector General has issued a report for CMS to counter this abuse. Recommendations are directed toward the states. - [Federal Substance Use Confidentiality Regulations (42 CFR Part 2) Updated!](https://eagleconsultingpartners.com/general-news/federal-substance-use-confidentiality-regulations-42-cfr-part-2-updated/) - Updates to Federal Substance Use Confidentiality Regulations take effect on February 2, 2018. Eagle Consulting Partners has made available a Redlined version of 42 CFR Part 2 to download. Eagle Consulting can assist with policy development, audits and training in light of these updates. - [Allscripts EHR Down for 1 Week; Is Your Cloud EHR Next?](https://eagleconsultingpartners.com/general-news/allscripts-ehr-1-week-cloud-ehr-next/) - Allscripts' EHR taken down by ransomware for extended period of time. All clients were affected. Case study emphasizes the importance of backups and emergency plans. - [Community Solutions hacked via Heartbleed Vulnerability](https://eagleconsultingpartners.com/general-news/community-solutions-hacked-via-heartbleed-vulnerability/) - Since the initial report of the Community Health Solutions breach, in which attackers hacked into the CHS network to gain personal data of a whopping 4.5 million patients, details of the hack are emerging. According to security firm TrustedSec, owned by David Kennedy, “a trusted and anonymous source close to the CHS investigation” has confirmed - [Hackers target Community Health Systems, steal personal data of 4.5M patients](https://eagleconsultingpartners.com/general-news/hackers-target-community-health-systems-steal-personal-data-4-5m-patients/) - Community Health Systems announced on Monday that outside hackers gained access to their network and stole the non-medical, personal information of 4.5 million patients. The data included names, addresses, birth dates, telephone numbers and Social Security numbers—all information that is protected under the HIPAA regulations. The affected patients had all either been referred for or - [OCR Provides Guidelines for Encryption of Data in Motion](https://eagleconsultingpartners.com/general-news/encryption-data-motion/) - HIPAA Security’s 42 requirements, many of which are merely one sentence in length, understandably result in many questions for organizations seeking to comply. To resolve some of this ambiguity, the HHS Office of Civil Rights, in April 2009, issued guidance to clarify the terse regulations referenced above. This 20 page guidance document, which describes detailed - [Security Lessons from the Nude Photos of Jennifer Lawrence, Kate Upton and Rihanna](https://eagleconsultingpartners.com/general-news/security-lessons-nude-photos-jennifer-lawrence-kate-upton-rihanna/) - Several celebrities had their privacy compromised this week when nude photos they had uploaded to Apple’s iCloud were stolen by hackers and shared on the Internet. On Tuesday, Apple said that the theft of the photos was due to “very targeted attacks” on the celebrities’ individual iCloud accounts and did not result from a widespread - [Hospital Employee takes ER Logs to State Department of Health – A case of whistleblowing?](https://eagleconsultingpartners.com/general-news/hospital-employee-takes-er-logs-state-department-health-case-whistleblowing/) - Recently, 6,500 patients of Tri-City Medical Center in Oceanside, California were notified of a breach of their protected health information. A former employee (on his last day of employment in August) removed the medical records of the patients and brought them to the California Department of Public Health. Many have speculated that the employee was - [HIPAA Audits for Healthcare Entities Delayed Again](https://eagleconsultingpartners.com/general-news/hipaa-audits-healthcare-entities-delayed/) - The HHS Office for Civil Rights (OCR) announced yet another delay in the start of the long-awaited HIPAA Audit Program. This time, a technology upgrade is to blame. In June, we blogged about the OCR’s plan for Phase 2 of its audit program, which was projected to include 100 Privacy audits, 100 breach audits and - [Gmail password leak sheds light on importance of cybersecurity awareness training](https://eagleconsultingpartners.com/general-news/gmail-password-leak-sheds-light-importance-cybersecurity-awareness-training/) - A list of nearly 5 million Gmail email addresses linked with passwords were leaked on a Russian Bitcoin security forum this week, but Google says not to worry. According to this article from Forbes.com, “There’s speculation that the addresses may hay been stolen from other sites where people used their Gmail address as a log-in. - [Unencrypted CD containing Jersey City Medical Center patient info lost in mail](https://eagleconsultingpartners.com/general-news/unencrypted-cd-containing-jersey-city-medical-center-patient-info-lost-mail/) - Identifying routine disclosures is key to safeguarding patient PHI During what Jersey City Medical Center called “a part of routine hospital operations,” an employee sent a UPS package containing to a company engaged by the New Jersey State Medicaid program. The patient information on the CD was required by the state so they can review - [Tampa General Hospital breach highlights need for robust access controls](https://eagleconsultingpartners.com/general-news/tampa-general-hospital-breach-highlights-need-for-robust-access-controls/) - During a traffic stop and arrest August, the Tampa Police found patient documents regarding patients of Tampa General Hospital in the car. According to the hospital’s statement regarding the incident, a subsequent internal investigation by the hospital revealed that the documents included information about 675 patients including names, dates of birth, admitting diagnoses, names of - [The Ex-Employee Menace](https://eagleconsultingpartners.com/general-news/ex-employee-menace/) - Can former employees still access your organization's PHI? A 014 survey of employees by Osterman Research found that a whopping 89% of respondents retained access (in the form of a login and password) to at least one system of a former employer – such as Salesforce, PayPal, email, SharePoint or other sensitive programs and applications. - [VoIP Phones and HIPAA Compliance](https://eagleconsultingpartners.com/general-news/voip-phones-hipaa-compliance/) - Many years ago, the federal government issued guidance that clarified that traditional analog phone systems are NOT subject to the HIPAA Security rule provisions. So, what about your VoIP phone system? Many organizations have migrated to VoIP service. VoIP (or “Voice over Internet Protocol”) is a method for taking analog audio signals and turning them - [Federally Qualified Health Centers on the Rise](https://eagleconsultingpartners.com/general-news/federally-qualified-health-centers-on-the-rise/) - Under current Healthcare policies and climate, this could be a good year for FQHC's -- Federally Qualified Health Centers. Take, for example, the findings of one industry group based at the University of Michigan -- CHRT (the Center for Healthcare Research & Transformation) which has as a mission, "to promote evidence-based care delivery, improve population - [CMS to Provide Additional ICD-10 End-to-End Testing Opportunity](https://eagleconsultingpartners.com/general-news/cms-to-provide-additional-icd-10-end-to-end-testing-opportunity/) - The final chance is approaching for those interested in conducting ICD-10 end-to-end testing with Medicare -- July 20-24, 2015. CMS has issued updated guidance on July 2, 2015, which covers ICD-10 acknowledgement testing as well as end-to-end testing. No registration is required for acknowledgement testing and it can be done at any time with a - [Lahey Hospital and Medical Center settles HIPAA issues for $850,000](https://eagleconsultingpartners.com/general-news/lahey-hospital-and-medical-center-settles-hipaa-issues-for-850000/) - HIPAA rule enforcement is stepping up. On November 25, 2015, Lahey Hospital and Medical Center (Lahey) agreed to settle potential violations of HIPAA regulations for $850,000. This enforcement action highlights the importance of addressing the security of all ePHI, not simply the PHI contained in the electronic medical record. - [U. of Wa. Medicine settles potential HIPAA violations for $750k](https://eagleconsultingpartners.com/general-news/university-of-washington-medicine-settles-potential-hipaa-violations-for-750000/) - The University of Washington Medicine (UWM) has agreed to a $750,000 settlement regarding potential HIPAA violations and a corrective action plan and annual reports on the organization's compliance efforts. Had effective protection been in place, the breach most likely would not have occurred. - [Health IT Security Risks and Vulnerability Management](https://eagleconsultingpartners.com/general-news/do-you-have-a-healthcare-it-vulnerability/) - How can you guard against the increasing HIPAA related breach danger and avoid fines? We'll look at some common breach sources and review solutions. - [Lincare Inc. Ordered to Pay $239k HIPAA Violation Fine](https://eagleconsultingpartners.com/general-news/lincare-inc-ordered-to-pay-239k-hipaa-violation-fine/) - The cost of proactive measures are far less than what Lincare paid for a HIPAA Violation Fine. Lincare believed that it had not violated HIPAA because the PHI was “stolen” by an individual who discovered it on the premises — but they were wrong. - [Healthcare Targeted in Ransomware Attacks](https://eagleconsultingpartners.com/general-news/healthcare-targeted-in-ransomware-attacks/) - Ransomware is a type of malware that quickly encrypts the files of the host computer system, rendering them unusable, and then displays a message demanding a ransom within a short period of time. If the ransom is paid, the victim may receive a decryption key to unscramble the files. This threat could ultimately shut down a healthcare organization's systems - [OCR Active with HIPAA Enforcement](https://eagleconsultingpartners.com/general-news/ocr-active-with-hipaa-enforcement/) - Over the last 6 months the HHS Office of Civil Rights (OCR) has announced an average of a settlement or other enforcement action per month. While most affected organizations were hospital systems or national companies, one small organization also was included. Here is a quick review of the cases which include a mix of HIPAA - [OCR Launches Random HIPAA Audits, Phase 2](https://eagleconsultingpartners.com/general-news/ocr-launches-random-hipaa-audits-phase-2/) - The HITECH Act, enacted by Congress in February 2009, mandated that the HHS Office for Civil Rights (OCR) enhance its enforcement efforts through the use of random HIPAA audits. OCR conducted a pilot audit program in which an audit protocol was created and 115 covered entities were audited. Based on what it learned in that - [HIPAA Breach Reports - Spring 2015](https://eagleconsultingpartners.com/general-news/hipaa-breach-reports-spring-2015/) - Despite the high stakes, some healthcare providers have been rather blasé about security. But, a failure to comply with HIPAA rules can lead not only to penalties of up to $50,000 per record depending on the level of negligence but also to a class action suit in a civil court and criminal charges. What can you do about that? - [Vendor Risk Highlighted by Medhost Backdoor](https://eagleconsultingpartners.com/general-news/vendor-risk-highlighted-by-medhost-backdoor/) - This month Carnegie Mellon University's CERT Division issued an advisory regarding a flaw in Medhost's Perioperative Information Management System (PIMS). PIMS is a widely used suite of applications for surgery departments to manage surgical cases from initial consult through post-surgery discharge. The flaw, for which a patch was issued by Medhost, was the inclusion of a - [The HIPAA Internal Audit](https://eagleconsultingpartners.com/general-news/the-hipaa-internal-audit/) - Because the Honor System Doesn't Work Electronic record systems contain a vast trove of interesting information – which can be a great temptation for a curious employee when they know that their relative, friend or neighbor was in the clinic. It has been 15 years since the HIPAA regulations were enacted so most organizations instruct - [OCR Details 5 Most Common HIPAA Mistakes](https://eagleconsultingpartners.com/general-news/ocr-details-5-most-common-hipaa-mistakes/) - The Health and Human Services Office of Civil Rights (OCR) recently detailed the 5 most common mistakes that organizations make in their HIPAA compliance programs, as reported by TechTarget's SearchHealthIT coverage. According to OCR, the 5 most common HIPAA violations and mistakes are: Improper handling of Business Associates including lack of a HIPAA Business Associate - [Ransomware Guidance from OCR](https://eagleconsultingpartners.com/general-news/ransomware-guidance-ocr/) - The Office of Civil Rights issued a Fact Sheet regarding Ransomware and HIPAA. During 2016, ransomware attacks have increased 300% and healthcare organizations are being targeted. This increase in threat activity increases the consequences of a weak security program. An effective HIPAA compliance program can significantly both reduce the probability that a ransomware - [2016: Hospitals targeted with Ransomware, patients harmed, losses incurred](https://eagleconsultingpartners.com/general-news/2016-hospitals-targeted-ransomware-patients-harmed-losses-incurred/) - Ransomware attacks are rampant throughout the healthcare industry, affecting a high percentage of organizations. After a healthcare provider becomes a victim of ransomware, the response is typical – these organizations recognize that attacks could occur again, with impacts even more severe, and invest both in safeguards to prevent future attacks and protections to mitigate the impact should they occur. - [Locky Ransomware Targets Healthcare organizations](https://eagleconsultingpartners.com/general-news/locky-ransomware-targets-healthcare-organizations/) - Research shows that a massive spam campaign with "locky ransomware" has been targeting healthcare organizations. We review malware and countermeasures. - [HHS issues Guidance regarding HIPAA and Cloud Computing](https://eagleconsultingpartners.com/general-news/hhs-issues-guidance-regarding-hipaa-cloud-computing/) - Healthcare organizations are increasingly using cloud computing vendors for electronic records, billing and revenue cycle management, file sharing, backup, and a wide variety of other functions -- and HHS Office for Civil Rights (OCR) has released important new guidance for these companies. - [Ransomware - First Person Account](https://eagleconsultingpartners.com/general-news/ransomware-first-person-account/) - An Eagle Consulting Partners client, a 10 physician practice, shared their ransomware story. In the words of the system administrator: It was about 6PM on a Wednesday evening and I needed to do some maintenance on the EMR server. I was at home. Typically I wait until later in the evening for this kind of - [URGENT - International Ransomware Attack in Progress - Action Needed](https://eagleconsultingpartners.com/general-news/urgent-international-ransomware-attack/) - U.S. Homeland Security and Health and Human Services have issued an urgent alert to healthcare, government and other organizations regarding an unprecedented, rapidly ransomware attack. It has infected over 10,000 organizations and 200,000 individuals worldwide. - [Data Breach at Beverly Hills Plastic Surgery Practice Highlights Need for Internal Audit and Physical Security](https://eagleconsultingpartners.com/general-news/data-breach-beverly-hills/) - Approximately 15,000 documents of patients from 16 states and five countries were breached and stolen by a disgruntled employee of an LA based plastic surgery center. We review steps you can take to protect yourself from similar breaches. - [Molina Healthcare Online Breach Shows Need for Web Application Security](https://eagleconsultingpartners.com/general-news/molina-healthcare-online-breach-shows-need-for-web-security/) - Molina Healthcare, a leading Medicaid and Affordable Care Act insurer across 12 states, recently suffered a security breach in which patient records were exposed on their online subscriber portal. The application flaw, which was present on the web for nearly a month before it was corrected, allowed patients to view claims and other sensitive information, - [School Counselor Fraudulent Billing Highlights Need for Internal Audit Program](https://eagleconsultingpartners.com/general-news/school-counselor-fraudulent-billing-highlights-need-internal-audit-program/) - In recent news, a school counselor and the owner of Western Carolina Counseling Services, Joseph Frank Korzelius, pleaded guilty to health care fraud having used the personal information from his students to submit false Medicaid billings. In total, Korzelius was reimbursed $436,229.08 through the North Carolina Medicaid Program over the course of three years for - [Medicare payments to FQHCs may increase by $1.3 billion](https://eagleconsultingpartners.com/general-news/medicare-payments-to-fqhcs-may-increase/) - On April 29, 2014, The Centers for Medicare and Medicaid Services (CMS) published a final rule that proposes a new reimbursement system that increases payments to Federally Qualified Health Centers (FQHC’s) by as much as $1.3 billion over the next 5 years. Medicare patients, including the elderly and disabled individuals, account for 9% percent of - [County DD Boards -- Don't update those HIPAA policies!](https://eagleconsultingpartners.com/dd-board-solutions/county-dd-boards-dont-update-those-hipaa-policies/) - All of Ohio's County Boards of Developmental Disability have received a beautifully bound set of freshly updated HIPAA policies from the County Board Association. These changes are based on the new HIPAA law enacted in 2009. Don't give into the temptation to simply add these policies to the "HIPAA section" of your policy manual. - [HIPAA “Business Associate” Definition Updated – a note for the County Board of Developmental Disabilities](https://eagleconsultingpartners.com/dd-board-solutions/hipaa-business-associate-definition-updated-a-note-for-the-county-board-of-developmental-disabilities/) - The HIPAA Omnibus Rule – with a compliance deadline of September 23, 2013 – updated the definition of the term "Business Associate". The definition includes a laundry list of business functions and services that cause a vendor to be a HIPAA Business Associate. The service needs to involve the disclosure of protected health information. For - [County Boards – Review HIPAA Compliance for your Non-Profit](https://eagleconsultingpartners.com/dd-board-solutions/county-boards-review-hipaa-compliance-for-your-non-profit/) - We all know that new HIPAA regulations – with a compliance deadline of September 23, 2013 – affect all of Ohio's County Boards of Developmental Disability. Hopefully, policy development and other compliance activity is well underway. In most cases, the affiliated non-profit that secures contracts and provides employment for adults in the sheltered workshops is - [OCR Presents to Ohio Developmental Disability Boards](https://eagleconsultingpartners.com/dd-board-solutions/ocr-presents-ohio-developmental-disability-boards/) - OCR Investigators Wandah Hardy and Jeffrey Dunifon, both from Office of Civil Rights Region 5, presented today to approximately 70 representatives from Ohio Developmental Disability (DD) Boards at a special program organized by the Ohio DD Board Tech Alliance. We will cover several of the items presented in the next few posts. Of initial interest - [Elements of an Effective Compliance Program](https://eagleconsultingpartners.com/dd-board-solutions/elements-effective-compliance-program/) - Wanda Hardy and Jeffrey Dunifon, both of the Office of Civil Rights Region 5, yesterday presented to the OACBDD Tech Alliance yesterday at the Delaware County Board facilities. The 1 day program was dedicated to HIPAA compliance. Among the many best-practices presented, they provided an overview of what elements they felt should be included in - [OCR to OACBDD Tech Alliance - Key Take Aways](https://eagleconsultingpartners.com/dd-board-solutions/ocr-oacbdd-tech-alliance-key-take-aways/) - Two representatives from HHS Office of Civil Rights (OCR) presented on February 19, 2014 to about 70 members of the Ohio Association of County Boards of Developmental Disabilities Tech Alliance (OACBDD Tech Alliance). Sifting through the information presented, here are a few random points of interest: OCR's guiding enforcement principle is voluntary compliance. The vast - [New HIPAA Privacy & Security Policies for Ohio DD Boards Available](https://eagleconsultingpartners.com/dd-board-solutions/new-hipaa-policies-for-dd-boards-available/) - Eagle Consulting Partners has released the 2014 edition of its Confidentiality and Computer Security Policies specifically crafted for Ohio DD Boards. In addition to HIPAA compliance, these policies also address compliance with FERPA, IDEA and State of Ohio Regulations that relate to confidentiality. Developmental Disability Boards in Ohio are challenged with the need to comply - [Protect yourself from CryptoLocker and other RansomWare](https://eagleconsultingpartners.com/hipaa/protect-cryptolocker-ransomware/) - [Editor's Note: During 2016 Healthcare experienced a dramatic increase of virulent ransomware attacks. Please also see a more a more comprehensive list of security contols in the post Preventing and Mitigating Ransomware Attacks, posted 10/4/2016.] A nasty piece of ransomware, CryptoLocker, has caught yet another victim. A small law firm in North Carolina admitted to - [Mass General and Cignet Health Hit with $5.3M HIPAA Fines](https://eagleconsultingpartners.com/hipaa/massachusetts-general-hospital-and-cignet-health-hit-with-hipaa-fines/) - The Obama Administration continues to accelerate its enforcement of the HIPAA Privacy and Security rules. This month saw two additional $1M+ fines. On February 4, 2011, the Department of Health and Human Services (HHS) issued its first-ever Civil Monetary Penalties. The fines were levied against a Washington DC area clinic/health plan, Cignet Health, which received - [Several healthcare organizations are new target of tax fraud gang](https://eagleconsultingpartners.com/hipaa/several-healthcare-organizations-new-target-tax-fraud-gang/) - A tax fraud gang appears to be targeting a large number of healthcare and senior living organizations that all use the same vendor for payroll and HR services. KrebsOnSecurity previously covered this gang's criminal activity in April, when they encountered a Web-based control panel the gang used to track tax returns they filed "on behalf" - [Dermatology practice settles HIPAA case for $150,000](https://eagleconsultingpartners.com/hipaa/dermatology-practice-settles-hipaa-case-for-150000/) - Adult & Pediatric Dermatology, P.C. (APD), a 12 physician dermatology practice with offices in Massachusetts and New Hampshire, has become the first covered entity to settle “potential” HIPAA violations, involving the lack of breach notification policies. The settlement requires a $150,000 payment and a corrective action plan. The practice was investigated by the HHS Office - [Eagle Consulting Releases Redlined HIPAA Regulations showing Omnibus Rule Changes](https://eagleconsultingpartners.com/hipaa/eagle-consulting-releases-redlined-hipaa-regulations-showing-omnibus-rule-changes/) - Eagle Consulting has released a redlined version of the HIPAA Privacy, Security and Breach regulations highlighting the changes introduced by the Omnibus Rule, which was officially published January 25, 2013. The redlined version allows covered entities, business associates and covered entities to quickly see the changes. This resource is particularly useful for organizations who must - [CryptoLocker Ransomware tamed by new free service](https://eagleconsultingpartners.com/hipaa/cryptolocker-ransomware-tamed-new-free-service/) - We’ve blogged previously about a nasty piece of ransomware called CryptoLocker, which gives its victims a difficult choice: Either pay the “ransom” ($400, although other variants may have different fees) to re-gain access to your files or lose your valuable data forever. However, as of earlier this month, victims have a third choice that may - [Russian hackers steal 1.2 Billion passwords in gigantic breach, says security firm](https://eagleconsultingpartners.com/hipaa/russian-hackers-steal-1-2-billion-passwords-in-gigantic-breach-says-security-firm/) - An August 5th report from Hold Security, a private security firm in Milwaukee, alleged that a Russian gang of hackers stole the personal data of more than half a billion people. Experts at Hold Security estimate that 420,000 web and FTP sites were accessed by the hackers in order to compile the largest-known database of - [HIPAA Violation Results in Criminal Indictment for East Texas Hospital Worker](https://eagleconsultingpartners.com/hipaa/hipaa-violation-results-criminal-indictment-east-texas-hospital-worker/) - A former employee of an East Texas Hospital is facing criminal charges for violating the Health Insurance Portability and Accountability Act, more commonly known as HIPAA. On July 3, 2014, the US Department of Justice announced that charges would be filed against Joshua Hippler, for alleged wrongful disclosure of individually identifiable health information. According to reports - [Cyber Espionage Verizon Report sheds light on risk analysis process](https://eagleconsultingpartners.com/hipaa/verizon-2014-data-breach-investigations-report-key-findings-cyber-espionage-2/) - Incidents of cyber-espionage have shown consistent, significant growth and display a wider variety of threat actions than any other pattern discovered in Verizon’s recent 2014 Data Breach Investigations Report, which analyzed of over 63,000 confirmed security incidents which collected data from 50 contributing organizations across 93 countries. While cyber-espionage is a very significant threat --only - [Deadline for updating grandfathered Business Associate Agreements Looms](https://eagleconsultingpartners.com/hipaa/deadline-updating-grandfathered-business-associate-agreements-looms/) - The HIPAA Omnibus/Final Rule, published on January 25, 2013, grandfathered valid HIPAA Business Associate agreements prior to that date until September 22, 2014. That grace period is rapidly coming to an end. Department of Health and Human Services (HHS) defines “business associate” associate as “a person or entity, other than a member of the workforce - [PHI of 400 found in street near Connecticut Health Exchange](https://eagleconsultingpartners.com/hipaa/phi-400-found-street-near-connecticut-health-exchange/) - AccessHealthCT, the health insurance exchange in Connecticut, announced that an employee of a contractor left a backpack containing the protected health information of 400 of the state’s residents on the street. The information left behind was written on a notepad and included various combinations of the customers’ names, birth dates and Social Security numbers. The - [U.S. DOJ indicts IRS Tax Fraud ring in Alabama](https://eagleconsultingpartners.com/hipaa/u-s-doj-indicts-irs-tax-fraud-ring-alabama/) - The U.S. Department of Justice announced indictments for a criminal ring involving individuals working at multiple facilities in Alabama. Other individuals in the fraud ring were former employees of a hospital located on Ft. Benning Army base. The ring allegedly used personal information of those served by the facilities to file tax returns in 2011 - [Verizon 2014 Data Breach Investigation Report: Key findings on insider misuse and human error](https://eagleconsultingpartners.com/hipaa/verizon-2014-data-breach-investigation-report-part-2-key-findings-insider-misuse-human-error/) - Verizon’s 2014 Data Breach Investigations Report categorized 63,000 security incidents from 95 countries into 9 categories of causes. For the healthcare organizations surveyed, just 3 of those categories accounted for 73% of the security incidents experience—Theft and Loss (46%), Insider and Privilege Misuse (15%) and Miscellaneous Errors (12%).Our thoughts about Theft and Loss, the largest - [Mitigating Heartbleed’s lingering effects on networked medical devices](https://eagleconsultingpartners.com/hipaa/mitigating-heartbleeds-lingering-effects-networked-medical-devices/) - Many healthcare organizations remain unaware that the Heartbleed bug can affect more than just websites and web servers. The bug, discovered separately by Neel Mehta and his team from Google Security in late March and later by Finnish security firm Codenomicon in early April, is a vulnerability caused by a coding error in the popular - [HHS Releases Annual Report of Breaches of Protected Health Information to Congress: Part 2](https://eagleconsultingpartners.com/hipaa/hhs-releases-annual-report-breaches-protected-health-information-congress/) - HHS Report of Breaches, 2011-2012, Part #2 The U.S. Department of Health and Human Services (HHS) recently submitted their Annual Report to Congress on Breaches of Unsecured Protected Health Information (PHI), for the calendar years 2011-2012. We blogged previously about the major breaches (those affecting 500 individuals or more) and their causes. Looking at location - [HHS Releases Annual Report of Breaches of Protected Health Information to Congress: Part 1](https://eagleconsultingpartners.com/hipaa/hhs-releases-annual-report-of-breaches-of-protected-health-information-to-congress/) - HHS Report of Breaches, 2011-2012, Part #1 The U.S. Department of Health and Human Services (HHS) submitted their Annual Report to Congress on Breaches of Unsecured Protected Health Information (PHI), for the calendar years 2011-2012. Theft and loss of computing equipment are consistently the most common causes of breach, while hacking began an uptick in - [Jocelyn Samuels Joins OCR to Oversee Civil Rights, Privacy](https://eagleconsultingpartners.com/hipaa/jocelyn-samuels-joins-ocr-oversee-civil-rights-privacy/) - Recently confirmed Health and Human Services Secretary Sylvia Mathews Burwell has named Jocelyn Samuels as director of the HHS Office for Civil Rights (OCR). In this role, her duties also include enforcement of the HIPAA privacy, security and breach notification rules. Samuels previously served as acting Assistant Attorney General for the Civil Rights division of - [Major breaches in Healthcare pass 1,000 milestone mark in June](https://eagleconsultingpartners.com/hipaa/major-breaches-pass-1000-milestone-mark-in-june/) - One in ten individuals living in the United States have had their medical records exposed through known and reported major data breaches by healthcare providers, payers and their business associates. By law, the Secretary of Health and Human Services posts details of PHI breaches affecting 500 or more individuals. This last month alone saw 34 new - [Former radiologist at NRAD Medical Associates takes 97,000 patient records](https://eagleconsultingpartners.com/hipaa/former-radiologist-nrad-medical-associates-takes-97000-patient-records/) - On April 24, Nassau Radiologic Group Medical Associates (NRAD) in Long Island, New York discovered that a radiologist employed by the organization had accessed the billing systems without authorization and acquired the protected health information of almost 100,000 patients. This included the patient’s names and addresses, dates of birth, social security numbers and health insurance, - [Customizable Digital Notices of Privacy Practices Now Available for HIPAA Covered Entities](https://eagleconsultingpartners.com/hipaa/customizable-digital-notices-of-privacy-practices-now-available-for-hipaa-covered-entities/) - Webinar on June 26 will explain how your organization can install and use these model notices. HHS Office for Civil Rights and the Office of the National Coordinator for Health Information Technology invite health care providers and health plan representatives to check out their free Digital Notices of Privacy Practices, available for your organization to - [Parkview Health pays $800,000 in HIPAA Privacy violations settlement](https://eagleconsultingpartners.com/hipaa/parkview-health-pays-800000-hipaa-privacy-violations-settlement/) - Parkview Health System, Inc. (Parkview Health) has agreed to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule with the Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Parkview Health will pay $800,000 in a settlement fee and adopt a corrective action plan to - [Sloppy HIPAA implementation at Rady Children’s Hospital exposes 20,000 patient records](https://eagleconsultingpartners.com/hipaa/sloppy-hipaa-implementation-at-rady-childrens-hospital/) - An employee at Rady Children's Hospital in San Diego inadvertently emailed a spreadsheet containing the protected health information of more than 14,000 patients to a handful of job applicants on June 6th, 2014. The investigation of this breach uncovered a second incident that took place in 2012 which exposed the protected health information of another - [Preparing for the New OCR Audits](https://eagleconsultingpartners.com/hipaa/preparing-new-ocr-audits/) - The HHS Office for Civil Rights (OCR) has shared information about Phase 2 of its HIPAA Audit Program – including the timing, focus and approach of these audits. Rebecca Williams, RN, JD of Partner at Davis Wright Tremaine offered insights and tips for health care providers preparing for Phase 2 Audits in a recent presentation - [Younger Workers Resist BYOD Policy Restrictions](https://eagleconsultingpartners.com/hipaa/younger-workers-resist-byod-policy-restrictions/) - As more and more workers purchase and become dependent upon mobile devices, the IT landscape in organizations has dramatically changed. As organizations evolve and develop new “Bring-Your-Own-Device” (BYOD) policies and procedures, they are discovering that many younger workers resist, oppose, and even violate these new attempts to manage IT security. A survey released earlier this - [Medicaid Fraud in Ohio: HHS releases data for fiscal year 2013](https://eagleconsultingpartners.com/hipaa/medicaid-fraud-ohio-hhs-releases-data-fiscal-year-2013/) - HHS's Office of the Inspector General (OIG) released their annual report for the Fiscal Year 2013, which highlights statistical achievements from the Medicaid Fraud Control Unit investigations and prosecutions nationwide. Medicaid Fraud Control Units (MFCU) investigate and prosecute Medicaid fraud as well as patient abuse and neglect in health care facilities. The report's methodology include - [Indian Health Service fails OIG penetration test](https://eagleconsultingpartners.com/hipaa/indian-health-service-fails-oig-penetration-test/) - In March, 2014 the OIG published details of a penetration test that they conducted on the Indian Health Service (IHS), to determine whether IHS network systems were susceptible to compromise by cyber attacks. In 2011, during a separate IT general controls audit of the IHS, OIG found their network security controls to be adequate and - [Major Computer Breach at Montana Public Health Department](https://eagleconsultingpartners.com/hipaa/major-computer-breach-at-montana-public-health-department/) - A computer in Montana's Department of Public Health that stored large databases of employee and client personal information was accessed by unknown hacker (or hackers) through the Internet. The unauthorized intrusion was discovered earlier this month and the computer was immediately taken offline. A private security contractor was hired after "suspicious activity" was noticed on - [HHS uncovers nationwide Medicare Fraud schemes involving 27 doctors, other medical professionals](https://eagleconsultingpartners.com/hipaa/hhs-uncovers-nationwide-medicare-fraud-schemes-involving-27-doctors-other-medical-professionals/) - In what's being called a "nationwide takedown" by Medicare Fraud Strike Force operations, charges have been filed against 90 individuals who allegedly submitted over $260 Million in false claims to Medicare. The individuals charged with the fraud include 27 doctors, nurses and other medical professionals in six cities across the nation. This is the seventh - [Data breach at eBay compromises 150 million user accounts](https://eagleconsultingpartners.com/hipaa/data-breach-ebay-compromises-150-million-user-accounts/) - eBay has asked 150 million users worldwide to reset their passwords, after learning of a cyber-attack on a database including encrypted passwords and other user data. Initially, eBay provided few details about the actual attack, which is under investigation by the FBI and a cyber-forensics firm. They did, however, indicate that the email addresses, physical - [Verizon 2014 Data Breach Investigations Report: Key Findings on Theft and Loss](https://eagleconsultingpartners.com/hipaa/verizon-2014-data-breach-investigations-report-key-findings-theft-loss/) - Incidents of lost and stolen assets are amount the most common causes of data loss or exposure, as reported by data breach incidents analyzed in Verizon's 2014 Data Breach Investigations Report. This recent study collected data on over 63,000 confirmed security incidents, compiled from 50 contributing organizations across 93 countries. While the incidents are not - [Employee security awareness training may have prevented Centura Health breach](https://eagleconsultingpartners.com/hipaa/employee-security-awareness-training-may-have-prevented-breach/) - On February 11, 2014, Centura Health, the nonprofit umbrella that owns Mercy Regional Medical Center in Durango, Colorado, experienced a phishing attack on employees that resulted in a breach of privacy that left the personal information of about 1,000 patients accessible to unauthorized individuals. A small group of employees responded to a "phishing" email, in - [PHI breach affects 5,261 former Molina Healthcare members](https://eagleconsultingpartners.com/hipaa/phi-breach-affects-former-molina-healthcare-members/) - On May 2nd, Molina Healthcare alerted 5,261 former members of Molina Healthcare of New Mexico of a data breach that took place around March 18, 2014. A postcard mailing about the Health Insurance Marketplace was sent to these former members that contained their address and possibly their social security number, which was inadvertently printed on - [HHS provides details on Phase 2 of random HIPAA audit program](https://eagleconsultingpartners.com/hipaa/hhs-provides-details-on-phase-2-of-random-hipaa-audit-program/) - On March 31, the HHS Office for Civil Rights (OCR) finally provided details on what the next phase of its HIPAA audit program will look like. These are outlined in detail in their presentation (slides here) and also in this article written by Adam Greene and Rebecca Williams. According to Greene & Williams, the Phase - [Medical identity theft is on the rise in the U.S.](https://eagleconsultingpartners.com/hipaa/medical-identity-theft-is-on-the-rise/) - A recent survey by The Identity Theft Resource Center (ITRC) reported that medical identity theft accounted for 43.8 percent of all identity thefts reported in the US last year. The medical/healthcare segment accounted for the largest number of breaches, with other segments including business (34.4% of breaches), government/military (9.1%), educational (9.0%), and banking/credit/financial (3.7%). The - [N.Y. Presbyterian, Columbia Resolution Clarify HHS Expectations for IT Asset Inventory in Largest HIPAA Settlement](https://eagleconsultingpartners.com/hipaa/n-y-presbyterian-columbia-resolution-clarify-hhs-expectations-for-inventory-in-largest-hipaa-settlement/) - The largest HIPAA settlement ever, in the amount of $4.8 Million, by two affiliated organizations, NY Presbyterian and Columbia University, sheds light on HHS expectations for HIPAA compliance, at least for a large academic medical center with 24,000 employees. The settlement arises from a 2010 data breach in which 6800 patient records were made available - [Over 2,400 patients affected by data breach at UMass Memorial Medical](https://eagleconsultingpartners.com/hipaa/2400-patients-affected-data-breach-umass-memorial-medical/) - Employee misbehavior using access privileges for the purpose of identity theft has led to yet another data breach. Notice was sent to more than 2,400 patients at UMass Memorial Medical Center (UMMMC) in Worcester, MA regarding potential identify theft. On March 6, 2014, the hospital learned that 4 patients’ data had been accessed and used - [4th Annual Patient Privacy and Data Security Survey Results Released by Ponemon](https://eagleconsultingpartners.com/hipaa/4th-annual-patient-privacy-data-security-survey-results-released-ponemon/) - The Fourth Annual Patient Privacy and Data Security Survey, published in March, revealed new and expanded threats to the security and privacy of patient information in the U.S. healthcare system. The independent survey was completed by the Ponemon Institute and analyzed responses from 91 hospitals and clinics collected over a three month period ending in - [Boston Medical Center vendor causes data breach](https://eagleconsultingpartners.com/hipaa/boston-medical-center-vendor-causes-data-breach/) - Boston Medical Center, a 496-bed academic medical center in Boston, discovered a data breach on March 3 when the records of 15,000 patients were posted online by a vendor. The records, which contained patients’ names, addresses, and medical information, including what drugs they were taking, were potentially compromised as a result of a website posting - [Data Breach at UPMC leaked personal information of 27,000 employees](https://eagleconsultingpartners.com/hipaa/data-breach-at-upmc-leaked-personal-information-of-27000-employees/) - A data breach at the University of Pittsburgh Medical Center (UPMC) originally thought to have compromised the privacy of 332 employees, may actually have over 27,000 victims according to a recent Pittsburgh Tribune-Review report. The alleged breach involved the unauthorized access of the confidential, personal information of UPMC employees, including their full legal names, addresses, - [FBI Expects Increase in Cyber Attacks Targeting Healthcare Industry](https://eagleconsultingpartners.com/hipaa/fbi-expects-increase-cyber-attacks-targeting-healthcare-industry/) - The FBI recently issued two private industry notices (PINs) to the healthcare sector, warning that cyber-attacks against devices and systems in that industry are likely to increase. The notices were issued to a number of undisclosed and unidentified organizations in the healthcare sector on April 8 and April 17. According to comments made by an - [Windows XP Users at Risk – Upgrade now if at all possible!](https://eagleconsultingpartners.com/hipaa/windows-xp-users-at-risk-upgrade-now-if-at-all-possible/) - Microsoft announced over the weekend that all versions of Internet Explorer have a “serious security hole” that hackers can use to take over a computer and hijack your computer.  In their announcement, Microsoft stated that they are aware of limited, targeted attacks that have exploited this vulnerability. The vulnerability, which is found in Internet - [Tufts Health Plan data breach affects 9,000 Medicare subscribers](https://eagleconsultingpartners.com/hipaa/tufts-health-plan-data-breach-affects-9000-medicare-subscribers/) - Tufts Health Plan, who offers health insurance plans for Medicare Advantage, individual or group health insurance in Massachusetts and Rhode Island, announced in an April 24 press release that a security breach had exposed the personal information of 8,830 seniors who are Medicare subscribers. The breach was brought to the company’s attention during a federal - [Encryption is key to prevent healthcare security breach, per Joy Pritts](https://eagleconsultingpartners.com/hipaa/encryption-is-key-to-prevent-breach/) - Encryption is the single most essential technology to use for healthcare security breach prevention, according to Joy Pritts, chief privacy officer at the Office of the National Coordinator for Health IT. In an interview with Healthcare Info Security, Pritts states that encryption is "much more advanced" than it was five years ago and anyone purchasing - [Encryption with BitLocker – Protecting against Attacks](https://eagleconsultingpartners.com/hipaa/encryption-bitlocker-protecting-attacks/) - Covered entities and business associates who need to comply with HIPAA encryption standards first have some high-level planning which is addressed in the post Encrypting Mobile Devices - First Create a Plan. Many organizations will choose to use Microsoft's BitLocker since it is built into many versions of Windows and supports centralized management. But is - [Encrypting Mobile Devices – First Create a Plan](https://eagleconsultingpartners.com/hipaa/encrypting-mobile-devices-first-create-plan/) - The recent enforcement actions against Concentra Health Services and QCA Health Plan, Inc. are two more messages to HIPAA covered entities (and business associates!) to encrypt their PHI. For most organizations, encrypting mobile devices is usually the first priority because of the high probability that a mobile device will be lost or stolen. How does - [Concentra Health and QCA Health Plan settle with OCR over HIPAA violations](https://eagleconsultingpartners.com/hipaa/concentra-health-and-qca-health-plan-settle-with-ocr-over-hipaa-violations/) - Stolen laptops have led to major HIPAA enforcement actions, announced yesterday, for two more covered entities. Concentra Health Services (Concentra) and QCA Health Plan, Inc. of Arkansas have paid the HHS Office for Civil Rights (OCR) $1,975,220 collectively to resolve potential violations of the HIPAA Privacy and Security Rules. These significant settlements underscore the importance - [Unauthorized EHR access causes data breach of 1,400 medical records Lubbock, Texas](https://eagleconsultingpartners.com/hipaa/unauthorized-ehr-access-causes-data-breach-of-1400-medical-records-lubbock-texas/) - Lubbock Cardiology Clinic in Lubbock, Texas posted an online notification of a data breach that affected 1,400 patient medical records and patient demographics (names, addresses, phone numbers and social security numbers). The breach was caused when an unauthorized individual accessed LCC’s EHR (electronic health record) system between December 15, 2013 to January 30, 2014. When accessed, - [Data breach in MI Health Department affects 2,595 individuals](https://eagleconsultingpartners.com/hipaa/data-breach-mi-health-department-affects-2595-individuals/) - On February 3, the Michigan Department of Community Health announced that thousands of individuals had their compromised in a data breach caused by the theft of a laptop and flash drive. The equipment was stolen on the evening of January 30 or the morning of January 31 from the office of an employee of the - [Widespread Internet Security Flaw Affects Web Users Worldwide](https://eagleconsultingpartners.com/hipaa/widespread-internet-security-flaw-affects-all-web-users-worldwide/) - Details about the Heartbleed bug, a serious vulnerability in the popular OpenSSL cryptographic software library, were published earlier this week. This vulnerability has the potential to affect web users worldwide. The bug, caused by a programming error, allows the theft of information that is normally protected by the SSL/TLS encryption used to secure the Internet. - [Pending bill would standardize breach response process](https://eagleconsultingpartners.com/hipaa/pending-bill-breach-response-process/) - Large hospitals and national organizations would benefit from a single, national security breach response process. The recent breaches at Target, Neiman Marcus and other retailers have gotten the attention of our national legislators. Last month, US Legislators introduced the “Data Privacy and Breach Notification Act of 2014.” The bill, introduced by the Senate’s Commerce, Science, and - [Skagit County, Washington, settles HIPAA Violation case](https://eagleconsultingpartners.com/hipaa/public-health-authority-in-wa-settles-hipaa-violation-case/) - By eagleconsultingpartners | Published: April 4, 2014 Skagit County, located in Northwest Washington, has agreed to settle potential violations of the HIPAA Privacy, Security and Breach Notification Rules. The County was fined $215,000 and must work closely with the Department of Health and Human Services (HHS) to correct deficiencies in its HIPAA compliance program. “This case - [Many data breaches never reported](https://eagleconsultingpartners.com/hipaa/many-data-breaches-never-reoprted/) - By eagleconsultingpartners | Published: April 2, 2014 Undisclosed breaches are common in large healthcare enterprises according to recent survey According to a recent security survey by ThreatTrack, nearly 6 in 10 enterprise malware analysts from healthcare organizations admit that they investigated or addressed a data breach that was never reported by their company. The survey, - [Windows XP Users--Upgrade now to protect your network from security vulnerabilities](https://eagleconsultingpartners.com/hipaa/windows-xp-users-upgrade-now-to-protect-your-network-from-security-vulnerabilities/) - In just under 3 weeks, Microsoft will end the Windows XP era ending support for both Windows XP and Microsoft Office 2003 on April 8, 2014. Most Microsoft products have a life cycle of about a decade, but these two products have been around longer. What prompted the decision to retire them and what does - [Risk Analysis Threat Update – IRS Tax Fraud](https://eagleconsultingpartners.com/hipaa/risk-analysis-threat-update-irs-tax-fraud/) - At HIMSS 2014, James Robnet, IRS Special Agent in charge of the IRS Tampa, FL field office, presented an update regarding IRS tax fraud and how fraudsters present data breach risks to hospitals, physicians and other health providers. When conducting a meaningful use risk analysis, it is helpful to think about actors who would be - [HIPAA Breach Impact Updates from HIMSS 2014](https://eagleconsultingpartners.com/hipaa/risk-analysis-hipaa-breach-impact-update/) - Evaluating the Potential Impact of a HIPAA Security Breach in Your Risk Analysis HIMSS 2014 included multiple presentations and updates regarding breach risk. Attorney Tatiana Melnik of Melnik Legal presented an update on civil actions which provides important information to anyone conducting a HIPAA Security/meaningful use risk analysis and needs to estimate the potential impact - [OIG 2014 Work Plan Highlights, Part 3: EHR Security Audits](https://eagleconsultingpartners.com/healthit/oig-work-plan-highlights-part-3-ehr-security-audits/) - Covered entities have been complying with the HIPAA Security Rule since 2005, with the HHS’ Office for Civil Rights (OCR) as the main enforcer starting in 2009. Industry watchers know that compliance across the provider community was limited, so, when CMS designed the Meaningful Use regulations, a Privacy and Security Objective was included to require - [OIG 2014 Work Plan Highlights, Part 2: Biomedical Equipment Security](https://eagleconsultingpartners.com/hipaa/oig-work-plan-highlights-part-2-biomedical-equipment-security/) - One item in the OIG 2014 Work Plan is to examine the controls over networked medical devices. That’s right. Yet another government entity, the OIG, plans to scrutinize hospital IT / Biomedical security. The OIG indicates that biomedical equipment is “increasingly integrated with EMRs and the larger health network” and poses “a growing threat to the - [OIG 2014 Work Plan Highlights, Part 1: Secure ePHI and portable devices](https://eagleconsultingpartners.com/healthit/oig-2014-work-plan-highlights-part-1-secure-ephi-portable-devices/) - OIG Work Plan Highlights, Privacy and Security Measures – Part 1 The U.S. Department of Health and Human Services (HHS) Office of Inspector General (OIG) Work Plan for fiscal year 2014 was published on January 31st. It includes several measures related to privacy and security, which we will summarize and discuss in our next few - [Latest HIPAA News from the OCR](https://eagleconsultingpartners.com/hipaa/latest-hipaa-news-ocr/) - There has been quite a bit of activity from the HHS Office of Civil Rights (OCR) related to health information privacy. Consumers and medical providers should take note of the following: A Spanish version of the Model Notices of Privacy Practices (NPP) has been issued by the U.S. Department of Health and Human Services OCR - [Linksys Routers being attacked by Worm “The Moon”](https://eagleconsultingpartners.com/healthit/linksys-routers-attacked-worm-moon/) - Medical practices and other healthcare organizations who use consumer-grade networking equipment made by Linksys should take immediate steps to mitigate attacks that are spreading after researchers at the SANS Institute reported the outbreak of a self-replicating worm on Thursday. According to, Johannes B. Ullrich, chief technology officer at SANS, an ISP in Wyoming alerted SANS - [OCR enforcement highlights importance of the Security Risk Analysis, Inventory](https://eagleconsultingpartners.com/hipaa/ocr-enforcement-highlights-importance-of-the-security-risk-analysis-inventory/) - Several recent enforcement actions from the HHS Office of Civil Rights, along with OCR's consistent messaging, have highlighted the importance of the HIPAA security risk analysis for healthcare organizations. Further, recent cases make it clear that a comprehensive inventory of hardware, software and PHI is an essential control. Here are a few recent of examples - [Smart devices - including a fridge- were used to distribute malicious emails](https://eagleconsultingpartners.com/hipaa/smart-devices-including-fridge-used-distribute-malicious-emails/) - That’s right, even a refrigerator can now fall victim to hackers. According to security firm Proofpoint, more than 750,000 malicious emails were sent between Dec. 23, 2013 and Jan. 6, 2014, when hackers gained access to smart devices, such as common appliances, left accessible on public networks. What’s interesting to note is that the hackers - [HIPAA watchdog, the OCR, is non-compliant with mandated HIPAA audits](https://eagleconsultingpartners.com/hipaa/hipaa-audits/) - 2014 is here and that means the long-delayed U.S. Department of Health and Human Services (HHS) random audit HIPAA audits may be starting soon. As we shared in another recent post (“Rodriguez of OCR discusses HIPAA Enforcement, other topics,”) the Director of the HHS Office for Civil Rights (OCR), Leon Rodriguez, disclosed the start of - [HIPAA Risk Assessment – Nation States and Terrorists](https://eagleconsultingpartners.com/hipaa/hipaa-risk-assessment-nation-states-and-terrorists/) - Healthcare organizations have good reason to adjust their threat assessments when updating their HIPAA Security risk analysis as required for HIPAA and meaningful use compliance. Based on a number of recent events, we know more about the capabilities and activities of nation states and terrorist groups in the cyber arena. The New York Times revealed - [Rodriguez of OCR discusses HIPAA Enforcement, other topics](https://eagleconsultingpartners.com/hipaa/rodriguez-ocr-discusses-hipaa-enforcement-topics/) - Leon Rodriguez, Director of the Office for Civil Rights (OCR) of the U.S. Department of Health and Human Services, celebrated September 23, 2013, the first day for enforcement of the HIPAA Omnibus Rule, by addressing the HIMSS Health Privacy Forum in Boston. Rodriguez shared his 3 priorities for enforcement: cases of major security failures that - [Risk Reduction with Email Breach Notification](https://eagleconsultingpartners.com/hipaa/risk-reduction-with-email-breach-notification/) - HIPAA Covered entities across the country are updating their policies in advance of the September 23, 2013 compliance deadline for the HIPAA Omnibus rule changes. Covered entities – hospitals, physician practices and other providers – can reduce their risks with a simple adjustment to their intake paperwork and recordkeeping. For organizations with large numbers of - [OCR Releases attractive Notices of Privacy Practices](https://eagleconsultingpartners.com/hipaa/ocr-releases-attractive-notices-of-privacy-practices/) - Yesterday the Department of Health and Human Services Office of Civil Rights (OCR), the agency responsible for enforcing the HIPAA regulations, released model notices of privacy practices. Eight versions were released, 4 for health providers and 4 for insurers. These are colorful designs with attractive and easy-to-read layouts. Because the HIPAA Omnibus rule changed the - [Computer Security Risk Analysis – Medical Identity Theft](https://eagleconsultingpartners.com/hipaa/computer-security-risk-analysis-medical-identity-theft/) - Medical Identity Theft is on the rise according to the latest Ponemon Institute research released yesterday. Ponemon estimates that 1.8 million people, just under 1% (0.8%) of U.S. adults, were affected in 2013, a 19% increase over 2012. Based on survey data from self-reported cases analyzed by Ponemon, these cases rarely arose from a computer - [Is your Cloud Backup Company a HIPAA Business Associate?](https://eagleconsultingpartners.com/hipaa/is-your-cloud-backup-company-a-hipaa-business-associate/) - More and more organizations are using cloud providers for computer backup. Internet upload speeds have increased, and the technology of cloud providers to provide incremental backup has become more sophisticated. And, very importantly, using cloud backup provides the all-important off-site backup that will protect the organization in the event of theft, fire, flood or other - [Compliance is not Security](https://eagleconsultingpartners.com/hipaa/compliance-is-not-security/) - HIPAA requires covered entities – and now business associates – to comply with the HIPAA Security Rule. However, compliance with these requirements is not the same as effective security. This fact can be illustrated in the case of business associates offering cloud-based computer services to the healthcare industry. These companies write and deliver complex software - [Long Delayed HIPAA Omnibus Rule released](https://eagleconsultingpartners.com/hipaa/long-delayed-hipaa-omnibus-rule-released/) - After years of waiting, the Federal Department of Health and Human Services released last week what has come to be called the HIPAA Omnibus Rule. "The new rule will help protect patient privacy and safeguard patients' health information in an ever expanding digital age," said HHS Secretary Kathleen Sebelius. "This final omnibus rule marks the - [OCR Unveils Guidance regarding De-identification under HIPAA](https://eagleconsultingpartners.com/hipaa/ocr-unveils-guidance-regarding-de-identification-under-hipaa/) - The Office of Civil Rights yesterday published detailed guidance regarding the provisions in the HIPAA Privacy regulations that deal with de-identification of protected health information (PHI). The general idea of this provision is that healthcare data sets may be shared as long as the recipient is unable to identify the specific individuals involved. De-identification is - [Risk Analysis – Hurricane Sandy, the Cloud, and System Downtime](https://eagleconsultingpartners.com/hipaa/risk-analysis-hurricane-sandy-the-cloud-and-system-downtime/) - With the meaningful use incentives, hospitals and physician practices are conducting their HIPAA Security Risk Analysis per 45 CFR 164.308(a)(1). The risk analysis focuses on the confidentiality, integrity and availability of health information. The last of these goals, availability, was brought to the forefront with Hurricane Sandy. They experienced a 2-day outage because their cloud - [Determining Probabilities in the Risk Analysis](https://eagleconsultingpartners.com/hipaa/determining-probabilities-in-the-risk-analysis/) - The HITECH Act, in particular the meaningful use incentive program for physicians and hospitals, has placed the computer security risk analysis in the spotlight. Meaningful use requires a risk analysis, also called a risk assessment, as per the HIPAA Security rules in 45 CFR 164.308(a)(1). Multiple methodologies are published, and the federal government has provided - [Alaska Medicaid pays $1.7M in first HIPAA Enforcement Action against public agency](https://eagleconsultingpartners.com/hipaa/alaska-medicaid-pays-1-7m-in-first-hipaa-enforcement-action-against-public-agency/) - Yesterday, the Alaska Department of Health and Social Services (DHSS), the state Medicaid agency, agreed to pay the U.S. Department of Health and Human Services (HHS) $1,700,000 to settle possible violations of the HIPAA Security rule. DHSS further agreed to a Corrective Action Plan (CAP) to properly safeguard the electronic protected health information (ePHI) of - [State Attorney General HIPAA Training Revealed; OCR Retains Big Hammer](https://eagleconsultingpartners.com/hipaa/state-attorney-general-hipaa-training-revealed-ocr-retains-big-hammer/) - The HITECH Act extended HIPAA enforcement authority to State Attorney Generals. As part of a cooperative enforcement effort, last year the HHS Office of Civil Rights (OCR) provided all expense paid training to the staff of the AGs. Yesterday, OCR posted the contents of last year's State Attorney General HIPAA training for all of us - [Small Physician Practice Settles HIPAA Complaint for $100,000](https://eagleconsultingpartners.com/hipaa/small-physician-practice-settles-hipaa-complaint-for-100000/) - Phoenix Cardiac Surgery, PC, a small physician practice, settled a HIPAA privacy and security complaint for $100,000 and agreed to a Corrective Action Plan. The settlement agreement (in which the practice does not admit liability) is the culmination of an investigation that found minimal compliance with HIPAA Privacy and Security. This 5 physician practice, with - [Risk Analysis – Probability of Smartphone loss/theft](https://eagleconsultingpartners.com/hipaa/risk-analysis-probability-of-smartphone-losstheft/) - In this latest installment about risk analysis we continue the difficult quest to quantify risk of data breach. Hospitals and physician practices are conducting computer security risk analyses for HIPAA compliance and for meaningful use (per HIPAA Security 45 CFR 164.308(a)(1)) and must assess the threats and likelihood of occurrence. Today the Wall Street Journal - [Risk Analysis – Quantifying Risk and Impact – Part 2](https://eagleconsultingpartners.com/hipaa/risk-assessment-quantifying-risk-and-impact-part-2/) - Hospitals and physician practices conducting computer security risk analyses for HIPAA compliance and for meaningful use (per HIPAA Security 45 CFR 164.308(a)(1)) must assess the threats and likelihood of occurrence. Because most breaches are never reported, accurate information on likelihood of occurrence is difficult to come by. Another study was recently published, by identity and - [A Tale of Two Presidents – Lessons for ACOs](https://eagleconsultingpartners.com/cms-qpp/a-tale-of-two-presidents-lessons-for-acos/) - OK, Dick Cheney wasn't president but was a heartbeat away. Both Dick Cheney and another former leader, Bill Clinton, have been in the news recently as a result of their heart conditions. Their previous histories of heart treatments have been widely reported in the media. What lessons do these contrasting stories have for ACOs? - [Risk Assessment: Quantifying Risk and Impact](https://eagleconsultingpartners.com/hipaa/risk-assessment-quantifying-risk-and-impact/) - HIPAA Covered entities, including hospitals and physicians who are implementing electronic records with hopes of attaining Meaningful Use and qualifying for federal incentives, are performing a computer security risk analysis, or risk assessment. Conducting regular risk assessments has been a requirement of HIPAA since 2005. However, many organizations have been weak in their compliance. Organizations - [Risk Assessment: Forget the PHI, they want your money](https://eagleconsultingpartners.com/hipaa/risk-assessment-forget-the-phi-they-want-your-money/) - (Editor's note, December 2015: while the information in this post remains relevant, 2015 could be called the year of the health care breach. During 2015 alone, approximately 1 out of every 3 Americans had some of their health care data stolen. New threats and actors have emerged and the health care data is increasingly at - [Securing your Home Wi-Fi Network](https://eagleconsultingpartners.com/hipaa/securing-your-home-wi-fi-network/) - Virtually everyone has a home wi-fi network. It provides convenient access for laptops, smartphones, tablets and gaming devices. How do you protect yourself? Administration Account. The first step is to secure the administration account for your wireless router or wireless access point. Change the factory admin account name, and use a strong password (at least - [First OCR HIPAA Audits Underway](https://eagleconsultingpartners.com/hipaa/first-ocr-hipaa-audits-underway/) - Adam Greene, JD, MPH, a former regulator in HHS, recently shared details about the random audit program begun by the HHS Office of Civil Rights (OCR). The audit targets are selected using stratified random samples based on a database of covered entities created by OCR by consulting firm Booz Allen Hamilton. Four categories of organizations - [Common Wireless Feature, WPS, Readily Hacked](https://eagleconsultingpartners.com/hipaa/common-wireless-feature-wps-readily-hacked/) - An industry-standard feature on wireless routers marketed to consumers and small businesses, Wi Fi Protected Setup (WPS), is vulnerable to a simple "brute force" attack. Free tools are already available to gain access to these routers. Making matters worse, it has been discovered that some router brands are unable to disable WPS, making it impossible - [New HIPAA Obligations for EHR vendors and VARs are Coming](https://eagleconsultingpartners.com/hipaa/new-hipaa-obligations-for-ehr-vendors-and-vars-are-coming/) - EHR Authors and Value Added Resellers (VARs) will soon have their own HIPAA obligations. At present, EHR Authors and VARs are contractually obligated by the terms of any HIPAA Business Associate Agreements (BAAs) they have signed. Soon, EHR Authors and VARs (and all other types of Business Associates) will be directly regulated by HIPAA. This - [HIPAA and Facebook](https://eagleconsultingpartners.com/hipaa/hipaa-and-facebook/) - Facebook, and other Social Media including Twitter, Google+, LinkedIn, and others are a reality of mainstream society. Employers in general, including HIPAA covered entities, are grappling with this new reality. On the one hand, social media have been proven to be a powerful vehicle to advance the aims of the organization. Social media are being - [JCAHO Weighs in: “No texting of physician orders”](https://eagleconsultingpartners.com/hipaa/jcaho-weighs-in-no-texting-of-physician-orders/) - The Joint Commission (JCAHO) weighed in recently regarding the issue of physicians using text messages to transmit orders. They didn't explicitly state that their opinion was related to the HIPAA regulations, but we infer that HIPAA was part of the thought process. "It is not acceptable for physicians or licensed independent practitioners to text orders - [OIG To Review Portable Device Security, OCR HIPAA Enforcement](https://eagleconsultingpartners.com/hipaa/oig-to-review-portable-device-security-ocr-hipaa-enforcement/) - The Department of Health and Human Services Office of the Inspector General, the agency's watchdog, has released its annual work plan. It is 117 pages specify hundreds of work items reviewing every nook and cranny of the health system. Medicare and Medicaid contractors, and hospitals will be scrutinized for their security controls to prevent the - [Random HIPAA Compliance Audits Begin](https://eagleconsultingpartners.com/hipaa/random-hipaa-compliance-audits-begin/) - The random HIPAA compliance audits mandated under the HITECH Act will begin this month. Yesterday, the HHS Office of Civil Rights (OCR) announced that every covered entity and business associate is eligible for an audit. To guide future audit efforts, a wide range of types and sizes of covered entities will be selected. Based on - [New Texas Medical Privacy Regulations More Stringent than HIPAA](https://eagleconsultingpartners.com/hipaa/new-texas-medical-privacy-regulations-more-stringent-than-hipaa/) - Texas Governor Perry recently signed House Bill 300 -- which further strengthens Texas medical privacy laws, which were already more stringent than HIPAA. To begin, HIPAA currently covers only providers, insurers, and clearinghouses -- while Texas law covers virtually any business that has patient health information including traditional HIPAA Business Associates, billing companies, computer support - [OCR Details HIPAA Audit plans for 2011-2012](https://eagleconsultingpartners.com/hipaa/ocr-details-hipaa-audit-plans-for-2011-2012/) - On August 11, 2011, the HHS Office of Civil Rights, the agency responsible for enforcement of the HIPAA regulations, delivered its first annual report on HIPAA Compliance and Enforcement to Congress. OCR shed a little light on the subject of random compliance audits which were mandated by the HITECH act. OCR reported that it has - [OIG Criticizes CMS for Poor HIPAA Security Enforcement](https://eagleconsultingpartners.com/hipaa/oig-criticizes-cms-for-poor-hipaa-security-enforcement/) - In May 2011 The HHS Office of the Inspector General (OIG) published their findings regarding CMS's oversight and enforcement of the HIPAA Security Rule. The findings state that the oversight and enforcement actions "were not sufficient" to insure that covered entities "effectively implemented the Security Rule." As a result, ePHI was "vulnerable to attack and - [At its Beijing facility, Microsoft Hurries Fix to Windows](https://eagleconsultingpartners.com/hipaa/at-its-beijing-facility-microsoft-hurries-fix-to-windows/) - Reporting from Beijing, China. Microsoft is hurrying to fix a significant problem with windows at its Beijing facility. Recently, Microsoft constructed a new, dual-tower facility in the Haidian district of Beijing to consolidate its 3000 software engineers here in China's capital city. This facility houses multiple Microsoft R&D units under the umbrella Microsoft Asia-Pacific Research - [OCR To Train State AGs on HIPAA Enforcement](https://eagleconsultingpartners.com/hipaa/ocr-to-train-state-ags-on-hipaa-enforcement/) - Fresh news from the National HIPAA Summit, held March 9-11 in Washington DC, is that the HHS Office of Civil Rights has scheduled "HIPAA Enforcement Training" for State Attorneys General. Susan McAndrew, OCR's Deputy Director for Health Information Privacy spoke at the Summit and said that her office would pay all training expenses for 2 - [HIPAA Enforcement Update](https://eagleconsultingpartners.com/hipaa/hipaa-enforcement-update/) - With reports about multi-million dollar HIPAA fines in the news for the first time, and discussion of stiff new HIPAA penalties from the HITECH Act, administrators and physicians are asking about the new enforcement activities. Recently, a small organization was hit with a $4.3 million fine. What is the likelihood of a huge fine for ## Pages - [Home](https://eagleconsultingpartners.com/) - Eagle - Leading Experts in Privacy and Security Compliance. Specializing in HIPAA, GDPR, SOC 2, and ISO/IEC 27001, 23 NYCRR 500, and DOL - [Eagle Consulting Partners Privacy Policy](https://eagleconsultingpartners.com/eagle-consulting-partners-privacy-policy/) - WHAT THIS PRIVACY POLICY COVERS Eagle Consulting Partners takes your privacy seriously. Please read the following to learn more about our privacy policy. How Eagle Consulting Partners Uses Your Personal Information This policy covers how Eagle Consulting Partners treats personal information that the Eagle Consulting Partners website collects and receives as well as how we use - [Privacy Policy](https://eagleconsultingpartners.com/about/privacy-policy/) - SMS Terms & Conditions Eagle Consulting Partners generally does not engage in any SMS text messaging. In other words, you won't get any SMS text messages reminding you of appointments, promoting our products, or asking about your satisfaction. Nonetheless, in order for text messaging to operate on our phones we are obliged to create this - [FERPA Policies for Education Software-as-a-Service Companies](https://eagleconsultingpartners.com/ferpa-policies-for-education-software-as-a-service-companies/) - [et_pb_section fb_built=”1″ admin_label=”Section: Fixed Right Sidebar for Sales Pages” _builder_version=”4.16″ custom_padding=”1px|27.5312px|36.7188px|27.5312px|false|false” global_colors_info=”{}”][et_pb_row column_structure=”3_4,1_4″ admin_label=”row” _builder_version=”4.16″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_padding=”0|0px|17.25px|0px|false|false” global_colors_info=”{}”][et_pb_column type=”3_4″ _builder_version=”4.16″ custom_padding=”|||” global_colors_info=”{}” custom_padding__hover=”|||”][et_pb_text admin_label=”Text: DOWNLOAD Copy Here.” _builder_version=”4.27.3″ text_font=”||||||||” header_font=”||||||||” global_colors_info=”{}”] Cloud and/or Software-as-a-Service companies serving the Education market are required by their customers to comply with FERPA and various state laws protecting - [Job Openings](https://eagleconsultingpartners.com/job-openings/) - [et_pb_section fb_built=”1″ fullwidth=”on” _builder_version=”4.16″ global_colors_info=”{}”][et_pb_fullwidth_header title=”Job Openings At Eagle Consulting” subhead=”Enjoy a Rewarding Career in Healthcare IT & HIPAA Compliance Consulting” content_max_width=”none” admin_label=”Fullwidth Header: Job Openings At Eagle Consulting” _builder_version=”4.16″ background_color=”#000660″ custom_css_main_element=”padding-top: 0px;||padding-bottom: 9px;” global_colors_info=”{}” button_one_text_size__hover_enabled=”off” button_two_text_size__hover_enabled=”off” button_one_text_color__hover_enabled=”off” button_two_text_color__hover_enabled=”off” button_one_border_width__hover_enabled=”off” button_two_border_width__hover_enabled=”off” button_one_border_color__hover_enabled=”off” button_two_border_color__hover_enabled=”off” button_one_border_radius__hover_enabled=”off” button_two_border_radius__hover_enabled=”off” button_one_letter_spacing__hover_enabled=”off” button_two_letter_spacing__hover_enabled=”off” button_one_bg_color__hover_enabled=”off” button_two_bg_color__hover_enabled=”off”][/et_pb_fullwidth_header][/et_pb_section][et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”4.16″ custom_padding=”|30px||30px” global_colors_info=”{}”][et_pb_row column_structure=”1_4,1_2,1_4″ - [Confirmation](https://eagleconsultingpartners.com/checkout/confirmation/) - Thank you for your purchase! - [FAQ: PII Protect Security Awareness Training Platform](https://eagleconsultingpartners.com/pii-protect-faq/) - PII Protect Security Awareness Training Platform Frequently Asked Questions To help with your PII Protect training journey, here are the answers to a few of the most frequently asked questions when using Eagle's PII Protect security awareness training platform. Why Do I Have To Take a Cybersecurity Course? It seems like we can’t go a - [About Cleveland - A World Class Healthcare Hub](https://eagleconsultingpartners.com/about/cleveland-healthcare-hub/) - [et_pb_section fb_built=”1″ module_class=” et_pb_specialty_fullwidth” _builder_version=”4.9.4″ background_color=”#050b5b” inner_width_tablet=”80%” inner_width_last_edited=”on|desktop” inner_max_width_tablet=”80%” inner_max_width_last_edited=”on|desktop” custom_padding=”0px||0px|” hover_enabled=”0″ custom_css_main_element=”margin-bottom: 0px;||margin-top: -35px;” transparent_background=”off” make_fullwidth=”on” use_custom_width=”off” width_unit=”on” sticky_enabled=”0″][et_pb_row admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_margin=”0px||0px|” custom_padding=”4px||0px|” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”||0px|” custom_padding__hover=”|||”][et_pb_text admin_label=”Text: %22Cleveland is an Internationally…%22″ _builder_version=”3.27.4″ text_font=”Open Sans Condensed||||” text_font_size=”28″ text_letter_spacing=”1px” background_size=”initial” background_position=”top_left” background_repeat=”repeat” text_orientation=”center” background_layout=”dark” module_alignment=”center” custom_margin=”||0px|” custom_padding=”||0px|” use_border_color=”off” border_color=”#ffffff” - [Eagle Consulting Partners Leadership](https://eagleconsultingpartners.com/about/leadership/) - [et_pb_section fb_built=”1″ fullwidth=”on” _builder_version=”3.22″ background_color=”#ffffff” custom_padding=”|0px||0px” custom_css_main_element=”width: 100%;”][et_pb_fullwidth_post_title meta=”off” featured_image=”off” text_color=”light” text_background=”on” text_bg_color=”rgba(2,7,104,0.9)” _builder_version=”3.0.74″ title_font_size=”32px” text_orientation=”center”][/et_pb_fullwidth_post_title][/et_pb_section][et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding=”||0px|” box_shadow_style=”preset3″][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_padding=”|||45px”][et_pb_column type=”2_3″ _builder_version=”3.25″ background_position=”top_left” custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Text: Gary Pritts, Founder and President” _builder_version=”4.5.7″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″]Gary Pritts, Founder and President Gary is an IT Governance, Risk, - [Government Agency Solutions](https://eagleconsultingpartners.com/government-agency-solutions/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.0.87″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_method=”off” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”4.5.7″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off”]Government agencies including school districts and schools, health districts, law enforcement units and others - [Contact Us](https://eagleconsultingpartners.com/contact-us/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.27.4″][et_pb_row _builder_version=”4.4.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_code admin_label=”Code: Contact Form” _builder_version=”4.4.4″]Please enable JavaScript in your browser to complete this form.Name *FirstLastJob Title *Organization *Email *AddressAddress Line 1Address Line 2CityStateAlabamaAlaskaArizonaArkansasCaliforniaColoradoConnecticutDelawareDistrict of ColumbiaFloridaGeorgiaHawaiiIdahoIllinoisIndianaIowaKansasKentuckyLouisianaMaineMarylandMassachusettsMichiganMinnesotaMississippiMissouriMontanaNebraskaNevadaNew HampshireNew JerseyNew MexicoNew YorkNorth CarolinaNorth DakotaOhioOklahomaOregonPennsylvaniaRhode IslandSouth CarolinaSouth DakotaTennesseeTexasUtahVermontVirginiaWashingtonWest VirginiaWisconsinWyomingStateZip CodePhone *By checking the box below, you agree to - [Information Security Risk Analyst](https://eagleconsultingpartners.com/job-openings/information-security-risk-analyst/) - Information Security Risk Analyst At Eagle Consulting Partners, we provide cybersecurity, compliance, and IT risk management consulting to a variety of Small and Medium Business clients nationwide. We specialize in HIPAA-regulated organizations, including healthcare providers, local government agencies, and technology service vendors, and provide services in other industries. We are seeking an intermediate-level information security - [Download Free Resource Kit](https://eagleconsultingpartners.com/hp-download-resource-kit/) - [et_pb_section fb_built=”1″ admin_label=”Download Resource Kit” _builder_version=”4.5.7″ top_divider_color=”#011e8c” bottom_divider_height=”25px” border_color_bottom=”#011e8c” collapsed=”off”][et_pb_row admin_label=”Intro Text” _builder_version=”4.5.7″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” collapsed=”off”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text _builder_version=”4.5.7″]Download Your Free Resource Kit! Click each item below to download![/et_pb_text][/et_pb_column][/et_pb_row][et_pb_row column_structure=”1_4,1_4,1_4,1_4″ make_equal=”on” admin_label=”Downloads Row” _builder_version=”4.5.7″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” border_color_bottom=”#0c71c3″ border_style_bottom=”inset” collapsed=”off”][et_pb_column type=”1_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text _builder_version=”4.5.7″ min_height=”20px” custom_margin=”||0px|||” link_option_url=”https://eagleconsultingpartners.com/wp-content/uploads/2020/09/ModelPolicyKit_EagleConsultingPartners.docx”]Model Policy Kit [/et_pb_text][et_pb_image src=”https://eagleconsultingpartners.com/wp-content/uploads/2020/09/ModelPolicyKit_EagleConsultingPartners-cover.jpg” - [Optimizing Telehealth and Work-From-Home Governance during COVID-19](https://eagleconsultingpartners.com/hospitalportal/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″][et_pb_row _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” collapsed=”off”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”https://eagleconsultingpartners.com/wp-content/uploads/2020/09/Eagle-Logo-1710×1580-1.jpg” alt=”Eagle Logo” title_text=”Eagle Logo 1710×1580″ align=”center” admin_label=”Image” _builder_version=”4.5.7″ max_width=”30%” module_alignment=”center” max_height=”200px” custom_margin=”||||false|false” hover_enabled=”0″][/et_pb_image][et_pb_text _builder_version=”4.5.7″]Thank you for attending Optimizing Telehealth and Work-From-Home Governanceduring COVID-19 Effectively Manage and Secure Your Telehealth and Work-from-hometo Keep Patients and Staff Safe while Protecting Revenue and Operations Exclusively - [Download Free Resource Kit](https://eagleconsultingpartners.com/frha-download-resource-kit/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″][et_pb_row _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” collapsed=”off”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text _builder_version=”4.5.7″]Download Your Free Resource Kit! Click each item below to download![/et_pb_text][/et_pb_column][/et_pb_row][et_pb_row column_structure=”1_3,1_3,1_3″ make_equal=”on” _builder_version=”4.5.7″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” collapsed=”off”][et_pb_column type=”1_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text _builder_version=”4.5.7″]Model Policy Kit[/et_pb_text][et_pb_image src=”https://eagleconsultingpartners.com/wp-content/uploads/2020/08/FRHA_ModelPolicyKit_Cover-scaled.jpg” title_text=”FRHA_ModelPolicyKit_Cover” url=”https://eagleconsultingpartners.com/wp-content/uploads/2020/08/FRHA_ModelPolicyKit_EagleConsultingPartners.docx” use_overlay=”on” overlay_icon_color=”#f0b800″ hover_overlay_color=”rgba(0,0,0,0)” hover_icon=”%%233%%” show_bottom_space=”off” align=”center” _builder_version=”4.5.7″ _module_preset=”default” width=”70%” module_alignment=”center” box_shadow_style=”preset1″][/et_pb_image][et_pb_text _builder_version=”4.5.7″]Format: Microsoft Word (.docx)[/et_pb_text][/et_pb_column][et_pb_column - [FRHA Summer Educational Series: Optimizing Telehealth and Work-From-Home Governance during COVID-19](https://eagleconsultingpartners.com/frha/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″][et_pb_row _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” collapsed=”on”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”https://eagleconsultingpartners.com/wp-content/uploads/2020/08/combined-logos.png” title_text=”combined logos” align=”center” admin_label=”Image” _builder_version=”4.5.3″ max_width=”60%” module_alignment=”center” max_height=”300px” custom_margin=”|-167px||||”][/et_pb_image][et_pb_text _builder_version=”4.5.7″]Thank you for attending Optimizing Telehealth and Work-From-Home Governanceduring COVID-19 Effectively Manage and Secure Your Telehealth and Work-from-hometo Keep Patients and Staff Safe while Protecting Revenue and Operations Part of the Florida Rural - [HIPAA Policy Templates Store](https://eagleconsultingpartners.com/hipaa-policy-templates-store/) - [et_pb_section fb_built=”1″ fullwidth=”on” _builder_version=”3.22.3″ background_color=”#ffffff” box_shadow_style=”preset3″][et_pb_fullwidth_image src=”/wp-content/uploads/2013/03/StoreHeader3.jpg” _builder_version=”3.0.86″ custom_margin=”|0px||0px” custom_padding=”|0px||0px” animation_style=”fade”][/et_pb_fullwidth_image][/et_pb_section][et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22.3″ background_color=”#ffffff” custom_margin=”||20px|” custom_padding=”||0px|”][et_pb_row column_structure=”2_5,3_5″ _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_margin=”||0px|” custom_padding=”||0px|”][et_pb_column type=”2_5″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Intro Text” _builder_version=”3.29.3″ text_font=”|700|||||||” text_font_size=”20px” header_2_font=”|700|||||||” background_size=”initial” background_position=”top_left” background_repeat=”repeat” module_alignment=”left”]Comprehensive HIPAA Policy Templates… Get in Compliance Today. Eagle Consulting Partners, Inc., guarantees all of its comprehensive downloadable - [Cybersecurity, Compliance, and IT Risk Management for Healthcare Organizations and Business Associates](https://eagleconsultingpartners.com/services/healthcare-solutions/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”rgba(255,255,255,0)” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” custom_css_main_element=”margin-top: 0px; padding-top: 0px;” transparent_background=”on” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” custom_width_px=”1080px” custom_width_percent=”80%”][et_pb_row column_structure=”1_3,2_3″ padding_mobile=”off” column_padding_mobile=”on” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” make_fullwidth=”off” use_custom_width=”off” width_unit=”off” custom_width_px=”1080px” custom_width_percent=”80%”][et_pb_column type=”1_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”/wp-content/uploads/2013/03/Eagle109.png” alt=”Eagle Consulting Partners HIPAA and Meaningful Use Services” align=”center” align_tablet=”center” align_phone=”” align_last_edited=”on|desktop” admin_label=”LOGO” _builder_version=”3.23″ custom_margin=”-5px|||” animation_style=”fade” animation_duration=”500ms” animation=”fade_in” sticky=”off” - [Security Risk Assessment](https://eagleconsultingpartners.com/security-risk-assessment/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.27.3″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”4.2.2″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” min_height=”669px” custom_margin=”|auto|-27px|auto||” custom_padding=”0px||27px|||”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.27.3″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_method=”off” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”4.2.2″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” min_height=”297px” custom_margin=”||-1px|||” use_border_color=”off”]Eagle consultants bring years of experience in assessing information security risk across - [IT Risk Management Services](https://eagleconsultingpartners.com/it-risk-management/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.0.87″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text _builder_version=”4.2.2″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″ use_border_color=”off”]Risk management begins where a security risk assessment leaves off. Eagle assists organizations with maturation of their risk management approach and helps comply with regulatory obligations - [Security Policies and Procedures](https://eagleconsultingpartners.com/security-policies-and-procedures/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.0.87″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_method=”off” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”4.2.2″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″ use_border_color=”off” ab_goal=”on”]Comprehensive security policies, clearly written and communicated, are a cornerstone of effective data governance. Eagle - [Vendor Management](https://eagleconsultingpartners.com/vendor-management/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.0.87″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_method=”off” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”4.2.2″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off” ab_goal=”on”]Security Officers often focus on locking down their network, training their employees, and securing their facilities. - [Cybersecurity, Compliance, and IT Risk Management for Financial Services Companies](https://eagleconsultingpartners.com/financial-services/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”4.2.1″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_method=”off” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_image src=”https://eagleconsultingpartners.com/wp-content/uploads/2020/01/Slider-finance-1024×518.jpg” align=”center” admin_label=”Image” _builder_version=”4.2.1″ max_width=”800px”][/et_pb_image][et_pb_text admin_label=”Main Copy” _builder_version=”4.2.2″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″ use_border_color=”off”]Headlines are full of breaches, cyberattacks, and data - [Security Awareness Training](https://eagleconsultingpartners.com/security-awareness-training/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.11″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_method=”off” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”4.2.2″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” min_height=”887px” use_border_color=”off”]Eagle Consulting Partners can implement a comprehensive Security Awareness Training program for your organization to reduce - [HIPAA Services for Healthcare Providers](https://eagleconsultingpartners.com/services/healthcare-providers/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″][et_pb_row column_structure=”1_3,2_3″ padding_mobile=”off” column_padding_mobile=”on” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_margin=”12px|12px|12px|” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_column type=”1_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”/wp-content/uploads/2013/03/Eagle109.png” alt=”Eagle Consulting Partners HIPAA and Meaningful Use Services” url=”/” align=”center” align_tablet=”center” align_phone=”” align_last_edited=”on|desktop” admin_label=”LOGO” _builder_version=”3.23″ animation_style=”fade” animation_duration=”500ms” animation=”fade_in” sticky=”off” use_border_color=”off” border_color=”#ffffff” border_style=”solid” always_center_on_mobile=”on”][/et_pb_image][et_pb_text admin_label=”(216) 503-0333″ _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off” border_color=”#ffffff” border_style=”solid”](216) 503-0333[/et_pb_text][et_pb_text admin_label=”HIPAA Privacy & - [Disaster Recovery Plan Development](https://eagleconsultingpartners.com/dr-plan/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.27.3″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.27.3″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_method=”off” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off”]If the worst happens, does your organization have a Disaster Recovery Plan to restore operations and computer - [Technical Vulnerability Analysis](https://eagleconsultingpartners.com/services/technical-vulnerability-analysis/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.0.87″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_method=”off” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”A Blockquote subheading – Performing a Vulnerability Analysis is a proven method …” _builder_version=”4.2.1″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” min_height=”50px” custom_margin=”||-15px||false|false” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] Performing - [About Eagle Consulting Partners](https://eagleconsultingpartners.com/about/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.29.3″ title_level=”h2″ title_font=”|700|||||||” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”][/et_pb_post_title][/et_pb_column][/et_pb_row][et_pb_row column_structure=”1_2,1_2″ _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”1_2″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”/wp-content/uploads/2015/06/Physician.jpg” alt=”Doctors prefer Eagle Consulting Soluions” align_tablet=”center” align_phone=”” align_last_edited=”on|desktop” admin_label=”Image: Smiling Dr.” _builder_version=”3.23″ animation_style=”slide” animation_direction=”left” animation_duration=”500ms” animation_intensity_slide=”10%” border_style=”solid” sticky=”off” always_center_on_mobile=”on”][/et_pb_image][et_pb_button button_url=”https://eagleconsultingpartners.com/contact-us/” - [HIPAA Policy and Procedures Development](https://eagleconsultingpartners.com/hipaa-policy-procedures-development/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″][et_pb_row _builder_version=”3.25″ custom_margin=”||0px|” custom_padding=”||0px|”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Text: COMPLIANCE: HIPAA Policy and Procedures Development” _builder_version=”4.2.2″ custom_margin=”||0px|” custom_padding=”||0px|” hover_enabled=”0″]COMPLIANCE: HIPAA Policies and Procedures Development[/et_pb_text][/et_pb_column][/et_pb_row][et_pb_row column_structure=”1_2,1_2″ _builder_version=”3.25″ custom_margin=”0px||0px|” custom_padding=”0px||6px|”][et_pb_column type=”1_2″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Text: Eagle offers a variety of services to assist with HIPAA Policy and Procedures development…” _builder_version=”4.2.2″ hover_enabled=”0″]Eagle offers a variety of - [Industries Served](https://eagleconsultingpartners.com/industries-served/) - [et_pb_section fb_built=”1″ _builder_version=”4.2.1″][et_pb_row _builder_version=”4.2.1″ custom_margin=”|auto|-71px|auto||”][et_pb_column type=”4_4″ _builder_version=”4.2.1″][et_pb_text admin_label=”Text: Industries served” _builder_version=”4.2.1″]Cybersecurity, Compliance, and IT Risk Management Solutions for Healthcare, Government, Finance, and Legal Eagle Consulting Partners helps organizations solve their cybersecurity, compliance, and IT risk management concerns. Our consultants bring years of experience supporting hundreds of organizations in highly-regulated industries. Some of our key services include:[/et_pb_text][/et_pb_column][/et_pb_row][et_pb_row - [Cybersecurity, Compliance, and IT Risk Management for Law Firms](https://eagleconsultingpartners.com/legal/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”4.2.1″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_method=”off” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_image src=”https://eagleconsultingpartners.com/wp-content/uploads/2020/01/Slider-cybersecurity.jpg” align=”center” admin_label=”Image” _builder_version=”4.2.1″ max_width=”800px”][/et_pb_image][et_pb_text admin_label=”Main Copy” _builder_version=”4.2.1″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″ use_border_color=”off”]Headlines are full of breaches, cyberattacks, and data - [Government Solutions](https://eagleconsultingpartners.com/government-solutions/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”rgba(255,255,255,0)” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” custom_css_main_element=”margin-top: 0px; padding-top: 0px;” transparent_background=”on” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” custom_width_px=”1080px” custom_width_percent=”80%”][et_pb_row column_structure=”1_3,2_3″ padding_mobile=”off” column_padding_mobile=”on” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” make_fullwidth=”off” use_custom_width=”off” width_unit=”off” custom_width_px=”1080px” custom_width_percent=”80%”][et_pb_column type=”1_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”/wp-content/uploads/2013/03/Eagle109.png” alt=”Eagle Consulting Partners HIPAA and Meaningful Use Services” align=”center” align_tablet=”center” align_phone=”” align_last_edited=”on|desktop” admin_label=”LOGO” _builder_version=”3.23″ custom_margin=”-5px|||” animation_style=”fade” animation_duration=”500ms” animation=”fade_in” sticky=”off” - [Security Risk Assessment - Meaningful Use](https://eagleconsultingpartners.com/sra-mu/) - The risk assessment is the foundation of the organization's computer security program. Because of its importance, the federal government requires that physicians and hospitals must conduct a security risk analysis in order to obtain "meaningful use" incentives. Eagle Consulting Partners works with physician practices, hospitals, and other organizations to conduct this risk analysis. The analysis - [Tennessee Pain Management Clinic Solutions](https://eagleconsultingpartners.com/tnpain/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.17.6″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off” ab_goal=”on”]Caught in the cogs of compliance? Eagle Consulting understands the compliance challenges Tennessee pain management clinics - [Electronic Health Record Selection and Implementation](https://eagleconsultingpartners.com/services/healthcare-solutions/electronic-health-record-selection-implementation/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.0.87″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off”]EHR Selection and Implementation ServicesEagle assists you with development of system requirements, helps identify candidate systems, solicits and reviews - [Meaningful Use / Promoting Interoperability Services](https://eagleconsultingpartners.com/services/healthcare-solutions/meaningful-use-services/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.17.2″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”3.29.3″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off”] Specialists to Manage Promoting Interoperability for Your Practice.Helping hospital & physician clients gain compliance with Meaningful Use Stage - [GDPR (General Data Protection Regulation)](https://eagleconsultingpartners.com/gdpr-general-data-protection-regulation/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.0.87″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off” ab_goal=”on”]The General Data Protection Regulation (GDPR) is the most comprehensive data protection regulation in the - [Services](https://eagleconsultingpartners.com/services/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row column_structure=”1_3,2_3″ padding_mobile=”off” column_padding_mobile=”on” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_margin=”12px|12px|12px|” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_column type=”1_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”/wp-content/uploads/2013/03/Eagle109.png” alt=”Eagle Consulting Partners HIPAA and Meaningful Use Services” url=”/” align=”center” align_tablet=”center” align_phone=”” align_last_edited=”on|desktop” admin_label=”LOGO” _builder_version=”3.23″ animation_style=”fade” animation_duration=”500ms” animation=”fade_in” sticky=”off” use_border_color=”off” border_color=”#ffffff” border_style=”solid” always_center_on_mobile=”on”][/et_pb_image][et_pb_text admin_label=”(216) 503-0333″ _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off” border_color=”#ffffff” border_style=”solid”](216) 503-0333[/et_pb_text][et_pb_text admin_label=”HIPAA Privacy - [Blog](https://eagleconsultingpartners.com/hipaa-guidance-blog/) - [et_pb_section fb_built=”1″ inner_shadow=”on” fullwidth=”on” admin_label=”section” _builder_version=”3.22″ background_color=”#2ea3f2″][et_pb_fullwidth_header title=”Health IT, HIPAA, and the CMS Incentive Programs Blog” subhead=”For physicians, hospitals, government agencies, and business associates” content_max_width=”none” admin_label=”Fullwidth Blog Header” _builder_version=”4.0.11″ background_color=”#041966″ hover_enabled=”0″ custom_css_main_element=”padding: 0px;||margin: 0px;” button_one_letter_spacing_hover=”0″ button_two_letter_spacing_hover=”0″ button_one_text_size__hover_enabled=”off” button_two_text_size__hover_enabled=”off” button_one_text_color__hover_enabled=”off” button_two_text_color__hover_enabled=”off” button_one_border_width__hover_enabled=”off” button_two_border_width__hover_enabled=”off” button_one_border_color__hover_enabled=”off” button_two_border_color__hover_enabled=”off” button_one_border_radius__hover_enabled=”off” button_two_border_radius__hover_enabled=”off” button_one_letter_spacing__hover_enabled=”on” button_one_letter_spacing__hover=”0″ button_two_letter_spacing__hover_enabled=”on” button_two_letter_spacing__hover=”0″ button_one_bg_color__hover_enabled=”off” button_two_bg_color__hover_enabled=”off”][/et_pb_fullwidth_header][/et_pb_section][et_pb_section fb_built=”1″ specialty=”on” admin_label=”section” - [Eagle Site Index](https://eagleconsultingpartners.com/about/site-index/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row admin_label=”Row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” make_fullwidth=”off” use_custom_width=”on” width_unit=”on”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” text_color=”light” admin_label=”Post Title” _builder_version=”3.0.87″ title_font=”Droid Sans|on||on|” title_text_color=”#ffffff” title_font_size=”24px” title_letter_spacing=”1px” background_color=”rgba(5,10,89,0.9)” parallax=”on” parallax_method=”off” text_orientation=”center” custom_margin=”5px|||” custom_padding=”0px||0px|” parallax_effect=”on” module_bg_color=”rgba(5,10,89,0.9)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”][/et_pb_post_title][/et_pb_column][/et_pb_row][et_pb_row column_structure=”1_3,1_3,1_3″ admin_label=”Row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”1_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_sidebar area=”et_pb_widget_area_3″ admin_label=”Sidebar: Index Col. 1″ _builder_version=”3.0.74″ remove_border=”off”][/et_pb_sidebar][/et_pb_column][et_pb_column - [HIPAA Omnibus Rule](https://eagleconsultingpartners.com/hipaa-omnibus-rule/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row padding_mobile=”off” column_padding_mobile=”on” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_margin=”||2px|” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Headline: %22HIPAA Privacy and Security Rule…%22″ _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_margin=”||0px|” custom_padding=”||0px|” use_border_color=”off” border_color=”#ffffff” border_style=”solid”]HIPAA Privacy and Security Rule (as amended by HIPAA Omnibus Rule)[/et_pb_text][/et_pb_column][/et_pb_row][et_pb_row column_structure=”1_2,1_2″ padding_mobile=”off” column_padding_mobile=”on” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_column type=”1_2″ _builder_version=”3.25″ - [EHR Implementation & Support](https://eagleconsultingpartners.com/ehr-implementation-support/) - [et_pb_section fb_built=”1″ fullwidth=”on” _builder_version=”3.22″][et_pb_fullwidth_header title=”EHR Implementation and Support” subhead=”Experienced support for EHR and Epic Implementations” logo_image_url=”https://eagleconsultingpartners.com/wp-content/uploads/2018/07/Eagle109.png” _builder_version=”4.0.8″ title_level=”h2″ background_color=”#00095e” custom_margin=”||0px|” custom_padding=”0px||0px|” hover_enabled=”0″ custom_css_logo=”float: left;||margin: 11px;||max-height: 90px;” custom_css_title=”padding-top: 15px;” button_one_text_size__hover_enabled=”off” button_two_text_size__hover_enabled=”off” button_one_text_color__hover_enabled=”off” button_two_text_color__hover_enabled=”off” button_one_border_width__hover_enabled=”off” button_two_border_width__hover_enabled=”off” button_one_border_color__hover_enabled=”off” button_two_border_color__hover_enabled=”off” button_one_border_radius__hover_enabled=”off” button_two_border_radius__hover_enabled=”off” button_one_letter_spacing__hover_enabled=”off” button_two_letter_spacing__hover_enabled=”off” button_one_bg_color__hover_enabled=”off” button_two_bg_color__hover_enabled=”off”][/et_pb_fullwidth_header][/et_pb_section][et_pb_section fb_built=”1″ _builder_version=”3.22″ custom_margin=”0px|||” custom_padding=”9px|||”][et_pb_row column_structure=”1_2,1_2″ _builder_version=”3.25″ custom_margin=”0px|||” custom_padding=”0px|||”][et_pb_column type=”1_2″ _builder_version=”3.25″ custom_padding=”0px|||” custom_padding__hover=”|||”][et_pb_blurb title=”EPIC - [Ohio County DD Board Solutions](https://eagleconsultingpartners.com/ohio-county-dd-boards-solutions/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off”][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.11″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_method=”off” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”4.0.6″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″ use_border_color=”off”]Eagle Consulting Partners (EAGLE) has extensive experience serving organizations that serve the developmentally disabled, both public - [HIPAA Policies and Procedures for Technology Companies](https://eagleconsultingpartners.com/services/technology-company-services/hipaa-policies-and-procedures-for-technology-companies/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off”][et_pb_row column_structure=”1_3,2_3″ padding_mobile=”off” column_padding_mobile=”on” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_margin=”12px|12px|12px|”][et_pb_column type=”1_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”/wp-content/uploads/2013/03/Eagle109.png” alt=”Eagle Consulting Partners HIPAA and Meaningful Use Services” url=”/” align=”center” align_tablet=”center” align_phone=”” align_last_edited=”on|desktop” admin_label=”LOGO” _builder_version=”3.23″ animation_style=”fade” animation_duration=”500ms” use_border_color=”off”][/et_pb_image][et_pb_text admin_label=”(216) 503-0333″ _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off” border_color=”#ffffff” border_style=”solid”](216) 503-0333[/et_pb_text][et_pb_text admin_label=”Solutions Bullets” _builder_version=”3.29.3″ background_size=”initial” background_position=”top_left” - [Other HIPAA & Compliance Services](https://eagleconsultingpartners.com/other-services/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” transparent_background=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_row column_structure=”1_3,2_3″ padding_mobile=”off” column_padding_mobile=”on” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_margin=”12px|12px|12px|” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_column type=”1_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”/wp-content/uploads/2013/03/Eagle109.png” alt=”Eagle Consulting Partners HIPAA and Meaningful Use Services” url=”/” align=”center” align_tablet=”center” align_phone=”” align_last_edited=”on|desktop” admin_label=”LOGO” _builder_version=”3.23″ animation_style=”fade” animation_duration=”500ms” animation=”fade_in” sticky=”off” use_border_color=”off” border_color=”#ffffff” border_style=”solid” always_center_on_mobile=”on”][/et_pb_image][et_pb_text admin_label=”(216) 503-0333″ _builder_version=”3.27.4″ background_size=”initial” - [Eagle's Experience and Capabilities](https://eagleconsultingpartners.com/eagles-experience-and-capabilities/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”rgba(255,255,255,0)” custom_padding_tablet=”50px|0|50px|0″ custom_padding_phone=”” custom_css_main_element=”margin-top: 0px; padding-top: 0px;” transparent_background=”on” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” custom_width_px=”1080px” custom_width_percent=”80%”][et_pb_row column_structure=”1_3,2_3″ padding_mobile=”off” column_padding_mobile=”on” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” make_fullwidth=”off” use_custom_width=”off” width_unit=”off” custom_width_px=”1080px” custom_width_percent=”80%”][et_pb_column type=”1_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”/wp-content/uploads/2013/03/Eagle109.png” alt=”Eagle Consulting Partners HIPAA and Meaningful Use Services” align=”center” align_tablet=”center” align_phone=”” align_last_edited=”on|desktop” admin_label=”LOGO” _builder_version=”3.23″ custom_margin=”-5px|||” animation_style=”fade” animation_duration=”500ms” animation=”fade_in” sticky=”off” - [Technology Company Services](https://eagleconsultingpartners.com/services/technology-company-services/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″][et_pb_row column_structure=”1_3,2_3″ padding_mobile=”off” column_padding_mobile=”on” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” make_fullwidth=”off” use_custom_width=”off” width_unit=”on”][et_pb_column type=”1_3″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”/wp-content/uploads/2013/03/Eagle109.png” alt=”Eagle Consulting Partners HIPAA and Meaningful Use Services” align=”center” align_tablet=”center” align_phone=”” align_last_edited=”on|desktop” admin_label=”LOGO” _builder_version=”3.23″ custom_margin=”-25px|||” animation_style=”fade” animation_duration=”500ms” animation=”fade_in” sticky=”off” use_border_color=”off” border_color=”#ffffff” border_style=”solid” always_center_on_mobile=”on”][/et_pb_image][et_pb_text admin_label=”(216) 503-0333″ _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off” border_color=”#ffffff” border_style=”solid”](216) 503-0333[/et_pb_text][et_pb_slider admin_label=”Tech Services Slider” - [Subscribe to the Eagle Newsletter](https://eagleconsultingpartners.com/subscribe/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″ fb_built=”1″ _i=”0″ _address=”0″][et_pb_row admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” _i=”0″ _address=”0.0″][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||” _i=”0″ _address=”0.0.0″][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.26.6″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid” _i=”0″ _address=”0.0.0.0″][/et_pb_post_title][/et_pb_column][/et_pb_row][et_pb_row column_structure=”3_5,2_5″ _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” _i=”1″ _address=”0.1″][et_pb_column type=”3_5″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||” _i=”0″ _address=”0.1.0″][et_pb_text admin_label=”Text: Headline… %22We Keep You Informed…%22″ _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” - [Public Health Agency Solutions](https://eagleconsultingpartners.com/public-health-agency-solutions/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ transparent_background=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” fb_built=”1″ bb_built=”1″ _i=”0″ _address=”0″][et_pb_row column_structure=”2_3,1_3″ admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” _i=”0″ _address=”0.0″][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” _i=”0″ _address=”0.0.0″ custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.11″ title_all_caps=”off” background_color=”rgba(255,255,255,0)” parallax=”on” parallax_method=”off” parallax_effect=”on” module_bg_color=”rgba(255,255,255,0)” use_border_color=”off” border_color=”#ffffff” border_style=”solid” _i=”0″ _address=”0.0.0.0″] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off” _i=”1″ _address=”0.0.0.1″]Eagle has served - [MIPS Solutions - Eagle MIPS Maximizer](https://eagleconsultingpartners.com/mips/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”#ffffff” custom_padding_tablet=”50px|0|50px|0″ transparent_background=”off” padding_mobile=”off” fb_built=”1″ _i=”0″ _address=”0″][et_pb_row column_structure=”2_3,1_3″ padding_mobile=”off” column_padding_mobile=”on” admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” _i=”0″ _address=”0.0″][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” _i=”0″ _address=”0.0.0″ custom_padding__hover=”|||”][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.7″ title_all_caps=”off” parallax=”on” parallax_method=”off” parallax_effect=”on” use_border_color=”off” border_color=”#ffffff” border_width=”1px” border_style=”solid” _i=”0″ _address=”0.0.0.0″] [/et_pb_post_title][et_pb_image src=”https://eagleconsultingpartners.com/wp-content/uploads/2019/02/ThreeMIPSicons.png” align_tablet=”center” align_last_edited=”on|desktop” admin_label=”IMAGE: 3 Benefits from Flyer” _builder_version=”3.27.4″ custom_padding=”0px||0px” animation_style=”fade” _i=”1″ _address=”0.0.0.1″][/et_pb_image][et_pb_text admin_label=”Text: - [SEMINAR: Understanding, Preventing, and Mitigating Ransomware Attacks](https://eagleconsultingpartners.com/noransomware/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″ fb_built=”1″ _i=”0″ _address=”0″][et_pb_row _builder_version=”3.29.2″ column_structure=”1_2,1_2″ hover_enabled=”0″][et_pb_column _builder_version=”3.29.2″ type=”1_2″][et_pb_image src=”https://eagleconsultingpartners.com/wp-content/uploads/2019/09/Understanding-preventing-and-mitigating-ransomware-attacks.png” align=”center” _builder_version=”3.29.2″ _i=”0″ _address=”0″ custom_margin=”|-167px||||”][/et_pb_image][/et_pb_column][et_pb_column _builder_version=”3.29.2″ type=”1_2″][et_pb_button button_text=”Register Now” _builder_version=”3.29.2″ button_url=”#RegistrationForm” hover_enabled=”0″ button_alignment=”center” custom_padding=”||||false|false” custom_margin=”100px|||92px|false|false” min_height=”101px”][/et_pb_button][/et_pb_column][/et_pb_row][et_pb_row _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” _i=”0″ _address=”0.0″][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” _i=”0″ _address=”0.0.0″ custom_padding__hover=”|||”][et_pb_text _builder_version=”3.28″ hover_enabled=”0″ _i=”1″ _address=”0.0.0.1″]A very bad day at work . . . “Boss, all the - [Purchase Confirmation](https://eagleconsultingpartners.com/purchase-confirmation/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22″ _i=”0″ _address=”0″][et_pb_row admin_label=”row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” _i=”0″ _address=”0.0″][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” _i=”0″ _address=”0.0.0″ custom_padding__hover=”|||”][et_pb_text admin_label=”Text” _builder_version=”3.29.2″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″ use_border_color=”off” border_color=”#ffffff” border_style=”solid” _i=”0″ _address=”0.0.0.0″]Thank you for your purchase! You may immediately download your purchase by clicking on the link below. Sorry, trouble retrieving order receipt. [/et_pb_text][/et_pb_column][/et_pb_row][/et_pb_section] - [Test Contact Forms](https://eagleconsultingpartners.com/test-contact-forms/) - Benefit Headline (ie. Contact Experienced Eagle Consultants) - should be split tested Free initial consultation: We'll be pleased to review your HIPAA and security needs and chat with you to find the right testing and consulting program for your situation. - [MIPS FAQs](https://eagleconsultingpartners.com/hipaa-guidance-blog/mips-faqs/) - [et_pb_section fb_built=”1″ admin_label=”FAQ” _builder_version=”3.26.5″ background_color=”rgba(0,0,0,0.49)” background_image=”/wp-content/uploads/2019/03/PleasedPhysWithConsultant2.jpg” background_blend=”overlay” fb_built=”1″ _i=”0″ _address=”0″][et_pb_row _builder_version=”3.26.3″ custom_padding=”0|0px|0|0px|false|false” _i=”0″ _address=”0.0″][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”180px|||” custom_padding_tablet=”40px|||” custom_padding_last_edited=”on|tablet” custom_padding__hover=”|||” _i=”0″ _address=”0.0.0″][et_pb_text admin_label=”Text: MIPS FAQs” _builder_version=”3.27.4″ text_font=”Lato||||||||” text_text_color=”#ffffff” text_font_size=”24px” text_line_height=”1.8em” text_text_shadow_style=”preset3″ header_font=”Lato|900|||||||” header_font_size=”90px” header_line_height=”1.2em” background_layout=”dark” width=”99.9%” min_height=”133px” custom_margin_tablet=”0px||30px||false|false” custom_margin_last_edited=”on|desktop” custom_padding=”0px||6px|||” text_font_size_tablet=”24px” text_font_size_phone=”16px” text_font_size_last_edited=”on|phone” header_font_size_tablet=”50px” header_font_size_phone=”32px” header_font_size_last_edited=”on|phone” _i=”0″ _address=”0.0.0.0″]MIPS FAQs Don’t see your question?[/et_pb_text][et_pb_button button_url=”mailto:adighero@eagleconsultingpartners.com” button_text=”Ask - [EPIC Consulting & Implementation](https://eagleconsultingpartners.com/epic-consulting-implementation/) - [et_pb_section fb_built=”1″ _builder_version=”3.22″ custom_padding=”|0px||0px” hover_enabled=”0″ fb_built=”1″ _i=”0″ _address=”0″][et_pb_row module_class=” et_pb_row_fullwidth” _builder_version=”3.27.4″ background_color=”rgba(0,0,0,0)” background_image=”https://eagleconsultingpartners.com/wp-content/uploads/2018/05/NewEagleSlides-EPIC.jpg” width=”89%” width_tablet=”80%” width_last_edited=”on|desktop” max_width=”89%” max_width_tablet=”80%” max_width_last_edited=”on|desktop” module_alignment=”center” custom_margin=”|0px||0px” custom_padding=”|0px||0px” animation_style=”fade” hover_enabled=”0″ custom_css_main_element=”width: 100%;||min-height: 400px;||” make_fullwidth=”on” _i=”0″ _address=”0.0″][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|0px||0px” padding_left=”0px” padding_right=”0px” _i=”0″ _address=”0.0.0″ custom_padding__hover=”|||”][et_pb_text _builder_version=”3.27.4″ _i=”0″ _address=”0.0.0.0″][/et_pb_text][/et_pb_column][/et_pb_row][et_pb_row _builder_version=”3.25″ custom_margin=”|20px||12px” custom_padding=”|16px||12px” _i=”1″ _address=”0.1″ column_structure=”2_3,1_3″][et_pb_column type=”2_3″ _builder_version=”3.25″ custom_padding=”|||” _i=”0″ _address=”0.1.0″ custom_padding__hover=”|||”][et_pb_text admin_label=”Text: Services - [HIPAA Risk Analysis for Business Associates](https://eagleconsultingpartners.com/services/technology-company-services/hipaa-security-risk-analysis-business-associates/) - [et_pb_section fb_built=”1″ custom_padding_last_edited=”on|desktop” admin_label=”section” _builder_version=”3.22″ background_color=”rgba(255,255,255,0)” custom_padding_tablet=”50px|0|50px|0″ custom_css_main_element=”margin-left: 12px;” transparent_background=”on” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” _i=”0″ _address=”0″][et_pb_row padding_mobile=”off” column_padding_mobile=”on” admin_label=”Row” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” _i=”0″ _address=”0.0″ column_structure=”3_4,1_4″][et_pb_column type=”3_4″ _builder_version=”3.25″ custom_padding=”|||” _i=”0″ _address=”0.0.0″ custom_padding__hover=”|||”][et_pb_text admin_label=”HEADLINE: Experienced HIPAA Risk Analysis” _builder_version=”3.0.87″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_margin=”||-5px|” use_border_color=”off” border_color=”#ffffff” border_style=”solid” _i=”0″ _address=”0.0.0.0″]Experienced HIPAA Risk Analysis for Business - [Thanks for Requesting Eagle – Risk Assessment Jump Start](https://eagleconsultingpartners.com/hipaa-security-risk-analysis-assessment/thanks-for-requesting-eagle-risk-assessment-jump-start/) - [et_pb_section fb_built=”1″ _builder_version=”3.22.3″][et_pb_row _builder_version=”3.22.3″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”3_4″ _builder_version=”3.0.47″][et_pb_post_title meta=”off” featured_image=”off” _builder_version=”3.23.3″][/et_pb_post_title][et_pb_text _builder_version=”3.23.3″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”]Now you can download four page guide — Eagle – Risk Assessment Jump Start — to help you assess your security risk and begin taking the right steps to avoid penalties and cyber attacks. To download, click image at right. - [Sitemap](https://eagleconsultingpartners.com/sitemap/) - [wp_sitemap_page] - [Eagle Security Awareness Training Webinar](https://eagleconsultingpartners.com/securityawarenesstng/) - Computer Security Awareness Training provided by Eagle Consulting Partners This webinar provides introductory training in safe web browsing, safe email usage, identification of phishing and other social engineering, and a summary of online threats and threat actors. After viewing this training, users will be familiar with the basics of how to keep their business and - [Thank You MIPS Inquiry](https://eagleconsultingpartners.com/thank-you-mips-inquiry/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.0.47″][et_pb_row admin_label=”row” _builder_version=”3.0.48″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.0.47″ parallax=”off” parallax_method=”on”][et_pb_text admin_label=”Text” _builder_version=”3.19.9″]Thank you for your inquiry! We will review your inquiry and respond as soon as we can.[/et_pb_text][/et_pb_column][/et_pb_row][/et_pb_section] - [Thank You for Signing Up For Our Newsletter](https://eagleconsultingpartners.com/thankyou-newsletter/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.0.47″][et_pb_row admin_label=”row” _builder_version=”3.0.48″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.0.47″ parallax=”off” parallax_method=”on”][et_pb_text _builder_version=”3.19.9″ admin_label=”Text”]Thank you for signing up for our newsletter! You’ll be able to stay up-to-date on the latest in healthcare security, compliance, and enforcement.[/et_pb_text][/et_pb_column][/et_pb_row][/et_pb_section] - [Glennwood Systems EHR Solutions](https://eagleconsultingpartners.com/glennwood-systems-ehr-solutions/) - [et_pb_section bb_built=”1″ fullwidth=”on” specialty=”off” next_background_color=”#000000″ _builder_version=”3.14″ custom_margin=”-10px|0px||0px” custom_padding=”0px|0px||0px”][et_pb_fullwidth_post_title _builder_version=”3.14″ meta=”off” featured_image=”off” background_color=”#0c71c3″ text_color=”light” custom_margin=”0px|0px|0px|0px” custom_padding=”10px|10px|10px|10px” /][/et_pb_section][et_pb_section bb_built=”1″ prev_background_color=”#000000″][et_pb_row][et_pb_column type=”1_3″][et_pb_image admin_label=”Image: Glenwood Brand Image” _builder_version=”3.14″ src=”/wp-content/uploads/2018/07/security-1163108_1920.jpg” animation_style=”zoom” /][/et_pb_column][et_pb_column type=”2_3″][et_pb_text admin_label=”Text: Glenwood Overview” _builder_version=”3.14″]Eagle & Glenwood Systems Team up for EHR HIPAA Security[142 words] Lorem ipsum dolor sit amet, consectetur adipiscing elit. Nullam ac lacinia elit. Nullam at - [HIPAA Audits](https://eagleconsultingpartners.com/hipaa-audits-2/) - [et_pb_section bb_built=”1″ admin_label=”section” transparent_background=”off” background_color=”#ffffff” allow_player_pause=”off” inner_shadow=”off” parallax=”off” parallax_method=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” make_equal=”off” use_custom_gutter=”off” custom_padding_tablet=”50px|0|50px|0″ custom_padding_last_edited=”on|desktop”][et_pb_row admin_label=”row” background_position=”top_left” background_repeat=”repeat” background_size=”initial”][et_pb_column type=”2_3″][et_pb_post_title title=”on” meta=”off” author=”on” date=”on” categories=”on” comments=”on” featured_image=”off” featured_placement=”below” parallax_effect=”on” parallax_method=”off” text_orientation=”left” text_color=”dark” text_background=”off” text_bg_color=”rgba(255,255,255,0.9)” module_bg_color=”rgba(255,255,255,0)” title_all_caps=”off” use_border_color=”off” border_color=”#ffffff” border_style=”solid” parallax=”on” background_color=”rgba(255,255,255,0)”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” use_border_color=”off” ab_goal=”on” background_position=”top_left” background_repeat=”repeat” background_size=”initial” _builder_version=”3.11.1″]Do you wonder if your - [HIPAA Training](https://eagleconsultingpartners.com/hipaa-training/) - [et_pb_section bb_built=”1″ admin_label=”section” transparent_background=”off” background_color=”#ffffff” allow_player_pause=”off” inner_shadow=”off” parallax=”off” parallax_method=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” make_equal=”off” use_custom_gutter=”off” custom_padding_tablet=”50px|0|50px|0″ custom_padding_last_edited=”on|desktop”][et_pb_row admin_label=”row” background_position=”top_left” background_repeat=”repeat” background_size=”initial”][et_pb_column type=”2_3″][et_pb_post_title title=”on” meta=”off” author=”on” date=”on” categories=”on” comments=”on” featured_image=”off” featured_placement=”below” parallax_effect=”on” parallax_method=”off” text_orientation=”left” text_color=”dark” text_background=”off” text_bg_color=”rgba(255,255,255,0.9)” module_bg_color=”rgba(255,255,255,0)” title_all_caps=”off” use_border_color=”off” border_color=”#ffffff” border_style=”solid” parallax=”on” background_color=”rgba(255,255,255,0)”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” use_border_color=”off” ab_goal=”on” background_position=”top_left” background_repeat=”repeat” background_size=”initial” _builder_version=”3.11.1″]Eagle Consulting provides HIPAA training - [Incident Response](https://eagleconsultingpartners.com/incident-response/) - [et_pb_section bb_built=”1″ admin_label=”section” transparent_background=”off” background_color=”#ffffff” allow_player_pause=”off” inner_shadow=”off” parallax=”off” parallax_method=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” make_equal=”off” use_custom_gutter=”off” custom_padding_tablet=”50px|0|50px|0″ custom_padding_last_edited=”on|desktop”][et_pb_row admin_label=”row” background_position=”top_left” background_repeat=”repeat” background_size=”initial”][et_pb_column type=”2_3″][et_pb_post_title title=”on” meta=”off” author=”on” date=”on” categories=”on” comments=”on” featured_image=”off” featured_placement=”below” parallax_effect=”on” parallax_method=”off” text_orientation=”left” text_color=”dark” text_background=”off” text_bg_color=”rgba(255,255,255,0.9)” module_bg_color=”rgba(255,255,255,0)” title_all_caps=”off” use_border_color=”off” border_color=”#ffffff” border_style=”solid” parallax=”on” background_color=”rgba(255,255,255,0)”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” use_border_color=”off” ab_goal=”on” background_position=”top_left” background_repeat=”repeat” background_size=”initial” _builder_version=”3.11.1″]One client described a security - [Meaningful Use Solutions](https://eagleconsultingpartners.com/meaningful-use-solutions/) - Prompt Meaningful Use Solutions Specialists to Conduct Your Security Risk Analysis, and Help You Take Corrective Action... Confused about the requirements? With years of experience consulting on risk, security and other HIPAA compliance concerns for medical practices and community hospitals, Eagle Consulting Partners offers a proven program to help you meet the meaningful use requirements. - [Other HIPAA Services](https://eagleconsultingpartners.com/other-hipaa-services/) - [et_pb_section bb_built=”1″][et_pb_row][et_pb_column type=”4_4″][et_pb_text]Eagle Consulting provides other services to help you strengthen your compliance program. These services include, but are not limited to: HIPAA Training HIPAA Audits Incident Response Security Officer [/et_pb_text][et_pb_code admin_label=”Code: NEW LP Contact Form” _builder_version=”3.11.1″ saved_tabs=”all”] - [Privacy and Security Officer](https://eagleconsultingpartners.com/privacy-and-security-officer/) - [et_pb_section bb_built=”1″ admin_label=”section” transparent_background=”off” background_color=”#ffffff” allow_player_pause=”off” inner_shadow=”off” parallax=”off” parallax_method=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” make_equal=”off” use_custom_gutter=”off” custom_padding_tablet=”50px|0|50px|0″ custom_padding_last_edited=”on|desktop”][et_pb_row admin_label=”row” background_position=”top_left” background_repeat=”repeat” background_size=”initial”][et_pb_column type=”2_3″][et_pb_post_title title=”on” meta=”off” author=”on” date=”on” categories=”on” comments=”on” featured_image=”off” featured_placement=”below” parallax_effect=”on” parallax_method=”off” text_orientation=”left” text_color=”dark” text_background=”off” text_bg_color=”rgba(255,255,255,0.9)” module_bg_color=”rgba(255,255,255,0)” title_all_caps=”off” use_border_color=”off” border_color=”#ffffff” border_style=”solid” parallax=”on” background_color=”rgba(255,255,255,0)”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” use_border_color=”off” ab_goal=”on” background_position=”top_left” background_repeat=”repeat” background_size=”initial” _builder_version=”3.11.1″]The title “HIPAA Privacy Officer” - [Risk Management Solutions](https://eagleconsultingpartners.com/risk-management-solutions/) - Successfully Attest to HIPAA Meaningful Use Stage 2... We're HIPAA Specialists who provide everything necessary for compliance with the Stage 2 Privacy and Security Objective Our clients know that the HIPAA risk analysis is complex. With years of experience consulting on risk, security and other HIPAA compliance concerns for medical practices and community hospitals, - [Risk Analysis for Meaningful Use -- Hospitals](https://eagleconsultingpartners.com/services/healthcare-providers/risk-assessments-for-meaningful-use-community-hospitals/) - [et_pb_section admin_label=”section” transparent_background=”off” background_color=”#ffffff” allow_player_pause=”off” inner_shadow=”off” parallax=”off” parallax_method=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” make_equal=”off” use_custom_gutter=”off”][et_pb_row admin_label=”row”][et_pb_column type=”2_3″][et_pb_post_title admin_label=”Post Title” title=”on” meta=”off” author=”on” date=”on” categories=”on” comments=”on” featured_image=”off” featured_placement=”below” parallax_effect=”on” parallax_method=”on” text_orientation=”left” text_color=”dark” text_background=”off” text_bg_color=”rgba(255,255,255,0.9)” module_bg_color=”rgba(255,255,255,0)” title_all_caps=”off” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”(A) Our unique Risk Assessment measures both compliance ” background_layout=”light” text_orientation=”left” use_border_color=”off” border_color=”#ffffff” border_style=”solid” ab_subject=”on” ab_subject_id=”1″]Our unique - [Risk Assessments for Meaningful Use - Physician Practices](https://eagleconsultingpartners.com/services/healthcare-solutions/risk-assessments-for-meaningful-use-physician-practices-2/) - [et_pb_section admin_label=”section”][et_pb_row admin_label=”row”][et_pb_column type=”2_3″][et_pb_post_title admin_label=”Post Title” title=”on” meta=”off” author=”on” date=”on” categories=”on” comments=”on” featured_image=”off” featured_placement=”below” parallax_effect=”on” parallax_method=”on” text_orientation=”left” text_color=”dark” text_background=”off” text_bg_color=”rgba(255,255,255,0.9)” module_bg_color=”rgba(255,255,255,0)” title_all_caps=”off” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” background_layout=”light” text_orientation=”left” use_border_color=”off” border_color=”#ffffff” border_style=”solid”]Eagle Consulting Partners provides a comprehensive computer security risk analysis, fully consistent with the requirements of the HIPAA Security regulations as required in - [Hospital and Physician Services](https://eagleconsultingpartners.com/services/hospital-and-physician-services/) - [Eagle MIPS Overview](https://eagleconsultingpartners.com/test-eagle-mips-animation/) - [et_pb_section fb_built=”1″ admin_label=”section: MIPS Busters Animation” _builder_version=”3.0.74″ transparent_background=”off”][et_pb_row admin_label=”Row” _builder_version=”3.0.48″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.0.47″ parallax=”off” parallax_method=”on”][et_pb_text admin_label=”Text (head): MIPS Busters Calculation: How much will you earn?” _builder_version=”3.0.87″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” use_border_color=”off” border_color=”#ffffff” border_style=”solid”]MIPS Busters Calculation: How much will you earn?[/et_pb_text][/et_pb_column][/et_pb_row][et_pb_row admin_label=”row” _builder_version=”3.0.48″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.0.47″ parallax=”off” parallax_method=”on”][et_pb_code admin_label=”Code: MIPS Payouts Animation”][/et_pb_code][et_pb_text admin_label=”Text: - [Thanks Compliance inquiry](https://eagleconsultingpartners.com/contact-us/thanks-compliance-inquiry/) - [et_pb_section bb_built=”1″ _builder_version=”3.0.47″][et_pb_row _builder_version=”3.0.48″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″][et_pb_text admin_label=”Text: Thanks for request for compliance solutions” _builder_version=”3.17.6″] (216) 503-0333 Thanks for your inquiry about Eagle Computer Security Risk Analysis we will contact you shortly! [/et_pb_text][/et_pb_column][/et_pb_row][/et_pb_section] - [Thanks for EHR Inquiry](https://eagleconsultingpartners.com/contact-us/thanks-for-ehr-inquiry/) - [et_pb_section bb_built=”1″][et_pb_row][et_pb_column type=”4_4″][et_pb_text admin_label=”Text: Thanks for request for EHR Implementation ” _builder_version=”3.17.6″] (216) 503-0333 Thanks for your inquiry about Eagle EHR Implementation Solutions…we will contact you shortly! [/et_pb_text][/et_pb_column][/et_pb_row][/et_pb_section] - [42 CFR Part 2](https://eagleconsultingpartners.com/42-cfr-part-2/) - [et_pb_section bb_built=”1″ admin_label=”section” transparent_background=”off” background_color=”#ffffff” allow_player_pause=”off” inner_shadow=”off” parallax=”off” parallax_method=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” make_equal=”off” use_custom_gutter=”off” custom_padding_tablet=”50px|0|50px|0″ custom_padding_last_edited=”on|desktop”][et_pb_row admin_label=”row” background_position=”top_left” background_repeat=”repeat” background_size=”initial”][et_pb_column type=”2_3″][et_pb_post_title title=”on” meta=”off” author=”on” date=”on” categories=”on” comments=”on” featured_image=”off” featured_placement=”below” parallax_effect=”on” parallax_method=”on” text_orientation=”left” text_color=”dark” text_background=”off” text_bg_color=”rgba(255,255,255,0.9)” module_bg_color=”rgba(255,255,255,0)” title_all_caps=”off” use_border_color=”off” border_color=”#ffffff” border_style=”solid” parallax=”on” background_color=”rgba(255,255,255,0)”] [/et_pb_post_title][et_pb_text admin_label=”Main Copy” use_border_color=”off” ab_goal=”on” background_position=”top_left” background_repeat=”repeat” background_size=”initial” _builder_version=”3.11.1″]42 CFR Part 2 regulations - [Thank you for your inquiry!](https://eagleconsultingpartners.com/contact-us/thank-you-for-your-inquiry/) - [et_pb_section bb_built=”1″ admin_label=”section”][et_pb_row background_position=”top_left” background_repeat=”repeat” background_size=”initial”][et_pb_column type=”1_4″][et_pb_image src=”/wp-content/uploads/2013/03/Eagle109.png” use_border_color=”off” animation_style=”slide” animation_duration=”500ms” animation_intensity_slide=”10%” animation_direction=”left” _builder_version=”3.7″ align=”center”] [/et_pb_image][et_pb_image _builder_version=”3.7″ src=”/wp-content/uploads/2016/08/HIPPACompliant.png” animation_style=”zoom” /][/et_pb_column][et_pb_column type=”3_4″][et_pb_text admin_label=”Text: We appreciate your inquiry ” text_font_size=”16″ use_border_color=”off” custom_padding=”30px|||” text_line_height=”1.2em” background_position=”top_left” background_repeat=”repeat” background_size=”initial” _builder_version=”3.7″]We appreciate your inquiry and will contact you shortly for healthcare IT solutions! You may also wish to review our Health IT, HIPAA - [Checkout](https://eagleconsultingpartners.com/checkout/) - Eagle products are Guaranteed or your money back! checkout securely - [Thanks for requesting Updated Quality Payment Program Rule Changes](https://eagleconsultingpartners.com/contact-us/thanks-requesting-updated-quality-payment-program-rule-changes/) - [et_pb_section bb_built=”1″][et_pb_row background_position=”top_left” background_repeat=”repeat” background_size=”initial” _builder_version=”3.0.60″ background_position_1=”top_left” background_repeat_1=”no-repeat” background_position_2=”top_left” background_repeat_2=”no-repeat”][et_pb_column type=”1_4″][et_pb_image src=”/wp-content/uploads/2013/03/Eagle109.png” show_in_lightbox=”off” url_new_window=”off” animation=”left” sticky=”off” align=”left” force_fullwidth=”off” always_center_on_mobile=”on” use_border_color=”off” border_color=”#ffffff” border_style=”solid” /][/et_pb_column][et_pb_column type=”3_4″][et_pb_text admin_label=”Text: Thanks for requesting our updated Quality Payment Program Rule Changes” background_layout=”light” text_orientation=”left” text_font=”|on|||” text_font_size=”26″ text_text_color=”#0b147a” border_style=”solid” custom_padding=”30px|||” text_line_height=”1.2em” background_position=”top_left” background_repeat=”repeat” background_size=”initial” _builder_version=”3.0.60″]Thanks for requesting our updated Quality Payment Program Rule - [Aurora Hotline Success](https://eagleconsultingpartners.com/aurora-hotline-success/) - Your Aurora Hotline Enrollment entry has been successfully entered into the system. Enter next enrollment... [field name="Enrollment-Form"] - [We're Hiring!](https://eagleconsultingpartners.com/help-wanted/) - Eagle Consulting Partners is currently recruiting a Support Engineer: Job Description: Provide support to clients, primarily physician practices, to comply with requirements for federal government health information technology programs. This support includes conducting computer security risk analyses, consistent with HIPAA requirements and providing assistance with any necessary corrective action. Other areas of support include assistance - [Thanks for Signing Up](https://eagleconsultingpartners.com/contact-us/thanks-signing/) - You'll receive our Eagle Security Newsletter -- sent monthly. We cover HIPAA Security Risk Analysis, Electronic Health Record Selection & Implementation, and other related matters for healthcare managers. Have a look at some of our recent articles here... - [Transaction Failed](https://eagleconsultingpartners.com/checkout/transaction-failed/) - Your transaction failed, please try again. If you continue to have difficulty, please contact us either at gpritts@eagleconsultingpartners.com, or 216-503-0333. - [Purchase History](https://eagleconsultingpartners.com/checkout/purchase-history/) - [Lost Password](https://eagleconsultingpartners.com/lost-password/) - [woocommerce_lost_password] - [Logout](https://eagleconsultingpartners.com/logout/) ## HIPAA-Guides - [§ 164.312 Technical safeguards](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-312-technical-safeguards/) - A covered entity or business associate must, in accordance with §164.306: (a) (1) Standard: Access control. Implement technical policies and procedures for electronic information systems that... - [§ 164.534 Compliance dates for initial implementation of the privacy standards](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-534-compliance-dates-initial-implementation-privacy-standards/) - (a) Health care providers. A covered health care provider must comply with the applicable requirements of this subpart no later than April 14, 2003. Also covered are Health plans, and Health care clearinghouses... - [§ 164.532 Transition provisions](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-532-transition-provisions/) - (a) Standard: Effect of prior authorizations. Notwithstanding §§164.508 and 164.512(i), a covered entity may use or disclose protected health information, consistent with paragraphs (b) and (c) of this section, pursuant to an authorization or... - [§ 164.530 Administrative requirements](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-530-administrative-requirements/) - (a) (1) Standard: Personnel designations. (i) A covered entity must designate a privacy official who is responsible for the development and implementation of the policies and procedures of the entity. (ii) A covered entity must... - [§ 164.526 Amendment of protected health information](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-526-amendment-protected-health-information/) - (a) Standard: Right to amend. (1) Right to amend. An individual has the right to have a covered entity amend protected health information or a record about the individual in a designated record set for as long a... - [§ 164.524 Access of individuals to protected health information](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-524-access-individuals-protected-health-information/) - (a) Standard: Access to protected health information. (1) Right of access. Except as otherwise provided in paragraph (a)(2) or (a)(3) of this section, an individual has... - [§ 164.522 Rights to request privacy protection for protected health information](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-522-rights-request-privacy-protection-protected-health-information/) - (a) (1) Standard: Right of an individual to request restriction of uses and disclosures. (i) A covered entity must permit an individual to request that the covered entity restrict... - [§ 164.520 Notice of privacy practices for protected health information](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-520-notice-privacy-practices-protected-health-information/) - (a) Standard: notice of privacy practices. (1) Right to notice. Except as provided by paragraph (a)(2) or (3) of this section, an individual has a right to adequate notice of the uses and disclosures of protected health information that may be... - [§ 164.514 Other requirements relating to uses and disclosures of protected health information](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-514-requirements-relating-uses-disclosures-protected-health-information/) - (a) Standard: De-identification of protected health information. Health information that does not identify an individual and with respect to which there is no reasonable basis to believe that... - [§ 164.512 Uses and disclosures for which an authorization or opportunity to agree or object is not required](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-512-uses-disclosures-authorization-opportunity-agree-object-not-required/) - A covered entity may use or disclose protected health information without the written authorization of the individual, as described in §164.508, or the opportunity for the individual to agree or object as described in... - [§ 164.510 Uses and disclosures requiring an opportunity for the individual to agree or to object](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-510-uses-disclosures-requiring-opportunity-individual-agree-object/) - A covered entity may use or disclose protected health information, provided that the individual is informed in advance of the use or disclosure and has the opportunity to agree to or prohibit or restrict the use... - [§ 164.508 Uses and disclosures for which an authorization is required](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-508-uses-disclosures-authorization-required/) - (a) Standard: Authorizations for uses and disclosures (1) Authorization required: General rule. Except as otherwise permitted or required by this subchapter, a covered entity may not use or disclose protected health information without... - [§ 164.506 Uses and disclosures to carry out treatment, payment, or health care operations](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-506-uses-disclosures-carry-treatment-payment-health-care-operations/) - (a) Standard: Permitted uses and disclosures. Except with respect to uses or disclosures that require an authorization under §164.508(a)(2) and (3) through (4) or that are prohibited under §164.502(a)(5)(i), a covered entity may use or disclose... - [§ 164.504 Uses and disclosures: Organizational requirements](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-504-uses-disclosures-organizational-requirements/) - (a) Definitions. As used in this section: Plan administration functions means administration functions performed by the plan sponsor of a group health plan on behalf of the group health plan and excludes... - [§ 164.502 Uses and disclosures of protected health information: general rules](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-502-uses-disclosures-protected-health-information-general-rules/) - (a) Standard. A covered entity or business associate may not use or disclose protected health information, except as permitted or required by this subpart or by subpart C of part 160 of this subchapter. (1) Covered entities... - [§ 164.501 Definitions](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-501-definitions/) - As used in this subpart, the following terms have the following meanings: Correctional institution means any penal or correctional facility, jail, reformatory, detention center, work farm, halfway house, or residential community program center operated by, or under contract... - [§ 164.500 Applicability](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-500-applicability/) - (a) Except as otherwise provided herein, the standards, requirements, and implementation specifications of this subpart apply to covered entities with respect to protected health information... - [Subpart E—Privacy of Individually Identifiable Health Information](https://eagleconsultingpartners.com/HIPAA-Guide/subpart-e-privacy-individually-identifiable-health-information/) - Authority: 42 U.S.C. 1320d-2, 1320d-4, and 1320d-9; sec. 264 of Pub. L. 104-191, 110 Stat. 2033-2034 (42 U.S.C. 1320d-2 (note)); and secs. 13400-13424, Pub. L. 111-5, 123 Stat. 258-279... - [§ 164.414 Administrative requirements and burden of proof](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-414-administrative-requirements-burden-proof/) - (a) Administrative requirements. A covered entity is required to comply with the administrative requirements of §164.530(b), (d), (e), (g), (h), (i), and (j) with respect to the requirements of this subpart... - [§ 164.412 Law enforcement delay](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-412-law-enforcement-delay/) - If a law enforcement official states to a covered entity or business associate that a notification, notice, or posting required under this subpart would impede a criminal investigation or cause damage to national security, a covered entity or business associate shall... - [§ 164.410 Notification by a business associate](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-410-notification-business-associate/) - (a) Standard. (1) General rule. A business associate shall, following the discovery of a breach of unsecured protected health information, notify the covered entity of such breach. (2) Breaches treated as discovered. For purposes of paragraph (a)(1) of this section, a breach shall be treated as... - [§ 164.408 Notification to the Secretary](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-408-notification-secretary/) - (a) Standard. A covered entity shall, following the discovery of a breach of unsecured protected health information as provided in §164.404(a)(2), notify the Secretary. (b) Implementation specifications: Breaches involving 500 or more individuals. For breaches of unsecured protected health information involving 500 or more individuals... - [§ 164.406 Notification to the media](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-406-notification-media/) - (a) Standard. For a breach of unsecured protected health information involving more than 500 residents of a State or jurisdiction, a covered entity shall, following the discovery of the breach... - [§ 164.404 Notification to individuals](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-404-notification-individuals/) - (a) Standard— (1) General rule. A covered entity shall, following the discovery of a breach of unsecured protected health information, notify each individual whose unsecured protected health information has... - [§ 164.402 Definitions](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-402-definitions/) - As used in this subpart, the following terms have the following meanings: Breach means the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of this part which compromises... - [§ 164.400 Applicability](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-400-applicability/) - The requirements of this subpart shall apply with respect to breaches of protected health information occurring on... - [§ 164.318 Compliance dates for the initial implementation of the security standards](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-318-compliance-dates-initial-implementation-security-standards/) - (a) Health plan. (1) A health plan that is not a small health plan must comply with the applicable requirements of this subpart no later than April 20, 2005. (2) A small health plan must comply with... - [§ 164.316 Policies and procedures and documentation requirements](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-316-policies-procedures-documentation-requirements/) - A covered entity or business associate must, in accordance with §164.306: (a) Standard: Policies and procedures. Implement reasonable and appropriate policies and procedures to comply with the standards, implementation specifications... - [§ 164.314 Organizational requirements](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-314-organizational-requirements/) - (a) (1) Standard: Business associate contracts or other arrangements. (i) The contract or other arrangement between the covered entity and its business associate required by §164.308(b)(4) must meet the requirements of... - [§ 164.310 Physical safeguards](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-310-physical-safeguards/) - A covered entity or business associate must, in accordance with §164.306: (a) (1) Standard: Facility access controls. Implement policies and procedures to limit physical access to its... - [§ 164.308 Administrative safeguards](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-308-administrative-safeguards/) - (a) A covered entity or business associate must, in accordance with §164.306: (1) (i) Standard: Security management process. Implement policies and procedures to prevent... - [§ 164.306 Security standards: General rules](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-306-security-standards-general-rules/) - (a) General requirements. Covered entities and business associates must do the following: (1) Ensure the confidentiality, integrity, and availability of all electronic protected health information... - [§ 164.304 Definitions](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-304-definitions/) - As used in this subpart, the following terms have the following meanings: Access means the ability or the means necessary to read, write, modify, or communicate data/information or otherwise... - [§ 164.302 Applicability](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-302-applicability/) - A covered entity or business associate must comply with the applicable standards, implementation specifications... - [§ 164.106 Relationship to other parts](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-106-relationship-parts/) - In complying with the requirements of this part, covered entities, and, where provided, business associates, are required to comply with... - [§ 164.105 Organizational requirements](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-105-organizational-requirements/) - (a) (1)Standard: Health care component. If a covered entity is a hybrid entity, the requirements of subparts C and E of this part, other than the requirements of this section... - [§ 164.104 Applicability](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-104-applicability/) - (a) Except as otherwise provided, the standards, requirements, and implementation specifications adopted under this part apply to the following entities... - [§ 164.103 Definitions](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-103-definitions/) - As used in this part, the following terms have the following meanings: Common control exists if an entity has the power, directly or indirectly, significantly to influence ... - [§ 164.102 Statutory basis](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-102-statutory-basis/) - The provisions of this part are adopted pursuant to the Secretary's authority to prescribe standards, requirements, and implementation specifications under part C of title XI of the Act, section 264 of Public Law 104–191... - [§ 160.101 Statutory basis and purpose](https://eagleconsultingpartners.com/HIPAA-Guide/§-160-101-statutory-basis-purpose/) - The requirements of this subchapter implement sections 1171-1180 of the Social Security Act (the Act), sections 262 and 264 of Public Law 104-191, section 105 of 491 Public Law 110-233... - [§ 160.102 Applicability](https://eagleconsultingpartners.com/HIPAA-Guide/§-160-102-applicability/) - (a) Except as otherwise provided, the standards, requirements, and implementation specifications adopted under this subchapter apply to the following entities... - [§ 164.528 Accounting of disclosures of protected health information](https://eagleconsultingpartners.com/HIPAA-Guide/§-164-528-accounting-disclosures-protected-health-information/) - [et_pb_section admin_label=”section” transparent_background=”off” background_color=”#ffffff” allow_player_pause=”off” inner_shadow=”off” parallax=”off” parallax_method=”off” padding_mobile=”off” make_fullwidth=”off” use_custom_width=”off” width_unit=”on” make_equal=”off” use_custom_gutter=”off”][et_pb_row admin_label=”Row” make_fullwidth=”on” use_custom_width=”off” width_unit=”on” use_custom_gutter=”off” padding_mobile=”off” allow_player_pause=”off” parallax=”off” parallax_method=”off” make_equal=”off” parallax_1=”off” parallax_method_1=”off” parallax_2=”off” parallax_method_2=”off” column_padding_mobile=”on”][et_pb_column type=”1_4″][et_pb_image admin_label=”Eagle Logo” src=”/wp-content/uploads/2016/06/Eagle109.png” alt=”Eagle Consulting Partners” show_in_lightbox=”off” url_new_window=”off” use_overlay=”off” animation=”fade_in” sticky=”off” align=”center” force_fullwidth=”off” always_center_on_mobile=”on” use_border_color=”off” border_color=”#ffffff” border_style=”solid”][/et_pb_image][et_pb_text admin_label=”Phone Number” background_layout=”light” text_orientation=”left” use_border_color=”off” border_color=”#ffffff” border_style=”solid”] (216) ## Downloads - [HIPAA Policy Templates for Third Party Administrators (Business Associates)](https://eagleconsultingpartners.com/downloads/hipaa-policies-for-tpas/) - Eagle's HIPAA policies for TPAs are designed to meet the regulatory requirements of small to medium-sized third-party administrators (TPAs) who administer health benefit plans covered by HIPAA. Notably, under the HIPAA regulations, TPAs are obligated to have detailed, written policies and procedures. All policies have been updated for HIPAA compliance with the latest requirements, including the HITECH Act of 2009, the Breach Notification Rule, and the 2013 HIPAA Omnibus Rule. Download today! - [FERPA Policies for Education Software-as-a-Service Companies](https://eagleconsultingpartners.com/downloads/ferpa-policies-for-education-software-as-a-service-companies/) - [TPA Compliance Program: Templates, Portal, Training](https://eagleconsultingpartners.com/downloads/tpa-compliance-program/) - [et_pb_section fb_built=”1″ admin_label=”Section: Fixed Right Sidebar for Sales Pages” _builder_version=”4.16″ custom_padding=”1px|27.5312px|36.7188px|27.5312px|false|false” global_colors_info=”{}”][et_pb_row column_structure=”3_4,1_4″ admin_label=”ROW: Download Sales” _builder_version=”4.16″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_padding=”0|0px|17.25px|0px|false|false” global_colors_info=”{}”][et_pb_column type=”3_4″ _builder_version=”4.16″ custom_padding=”|||” global_colors_info=”{}” custom_padding__hover=”|||”][et_pb_image src=”/wp-content/uploads/edd/2019/05/2ScreensAndMen.jpg” alt=”Eagle’s policy template helps you increase security, gain compliance, and avoid fines” align=”center” align_tablet=”center” align_phone=”” align_last_edited=”on|desktop” admin_label=”Image: 2 guys with computers” _builder_version=”4.16″ custom_margin=”||0px” custom_padding=”||0px” animation_style=”zoom” global_colors_info=”{}”][/et_pb_image][et_pb_text admin_label=”A - [HIPAA Policies and Procedures for Healthcare Cloud Computing Vendors](https://eagleconsultingpartners.com/downloads/hipaa-policies-and-procedures-business-associates-saas-vendors/) - [et_pb_section fb_built=”1″ admin_label=”Section: Fixed Right Sidebar for Sales Pages” _builder_version=”4.16″ custom_padding=”1px|27.5312px|36.7188px|27.5312px|false|false” global_colors_info=”{}”][et_pb_row column_structure=”3_4,1_4″ admin_label=”ROW: Download Sales” _builder_version=”4.16″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_padding=”0|0px|17.25px|0px|false|false” global_colors_info=”{}”][et_pb_column type=”3_4″ _builder_version=”4.16″ custom_padding=”|||” global_colors_info=”{}” custom_padding__hover=”|||”][et_pb_text admin_label=”TEXT: Sales copy for Healthcare Cloud Computing Vendor Download” _builder_version=”4.16″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” global_colors_info=”{}”] Your customers are demanding robust HIPAA compliance. These policy templates are designed specifically for - [HIPAA Policy Template for Medical Billing Companies](https://eagleconsultingpartners.com/downloads/hipaa-policy-template-for-medical-billing-companies/) - [et_pb_section fb_built=”1″ admin_label=”Section: Fixed Right Sidebar for Sales Pages” _builder_version=”4.16″ custom_padding=”1px|27.5312px|36.7188px|27.5312px|false|false” global_colors_info=”{}”][et_pb_row column_structure=”3_4,1_4″ admin_label=”ROW: Download Sales” _builder_version=”4.16″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_padding=”0|0px|17.25px|0px|false|false” global_colors_info=”{}”][et_pb_column type=”3_4″ _builder_version=”4.16″ custom_padding=”|||” global_colors_info=”{}” custom_padding__hover=”|||”][et_pb_text admin_label=”TEXT: Sales Copy for IT Companies Download” _builder_version=”4.16″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” global_colors_info=”{}”]Eagle’s policy template helps you increase security, gain compliance, and avoid fines.HIPAA Policies and Procedures Designed for - [HIPAA Privacy & Security Policy Templates for Medical Practices](https://eagleconsultingpartners.com/downloads/hipaa-privacy-security-policy-templates-medical-practices/) - [et_pb_section fb_built=”1″ admin_label=”Section: Fixed Right Sidebar for Sales Pages” _builder_version=”4.16″ custom_padding=”1px|27.5312px|36.7188px|27.5312px|false|false” global_colors_info=”{}”][et_pb_row column_structure=”3_4,1_4″ admin_label=”ROW: Download Sales” _builder_version=”4.16″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_padding=”0|0px|17.25px|0px|false|false” global_colors_info=”{}”][et_pb_column type=”3_4″ _builder_version=”4.16″ custom_padding=”|||” global_colors_info=”{}” custom_padding__hover=”|||”][et_pb_text admin_label=”TEXT: Sales copy for Small Practices Download” _builder_version=”4.16″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” global_colors_info=”{}”]Eagle’s product helps you increase security, gain compliance, and avoid fines. Avoid fines — HIPAA random audits are ongoing - [Confidentiality & Computer Security Policies for Ohio DD Boards (2021)](https://eagleconsultingpartners.com/downloads/confidentiality-computer-security-policies-ohio-dd-boards/) - [et_pb_section fb_built=”1″ admin_label=”Section: Fixed Right Sidebar for Sales Pages” _builder_version=”3.22.3″ custom_padding=”1px|27.5312px|36.7188px|27.5312px|false|false”][et_pb_row column_structure=”3_4,1_4″ admin_label=”ROW: Download Sales” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_padding=”0|0px|17.25px|0px|false|false”][et_pb_column type=”3_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”TEXT: Sales Copy for DD Boards Download” _builder_version=”4.5.7″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” hover_enabled=”0″]Eagle policies help DD Boards in Ohio get in compliance quickly.Ohio DD Boards are subject to multiple regulations regarding privacy, - [HIPAA Privacy & Security Policy Templates for IT Managed Service Providers](https://eagleconsultingpartners.com/downloads/hipaa-policies-itcompanies-vars/) - [et_pb_section fb_built=”1″ admin_label=”Section: Fixed Right Sidebar for Sales Pages” _builder_version=”3.22.3″ custom_padding=”1px|27.5312px|36.7188px|27.5312px|false|false”][et_pb_row column_structure=”3_4,1_4″ admin_label=”ROW: Download Sales” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_padding=”0|0px|17.25px|0px|false|false”][et_pb_column type=”3_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_image src=”https://eagleconsultingpartners.com/wp-content/uploads/2020/01/IT-Managed-Service-Provider.jpg” _builder_version=”4.1″][/et_pb_image][et_pb_text admin_label=”TEXT: Sales Copy for IT Companies Download” _builder_version=”4.1″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”] Eagle’s policy template helps you increase security, gain compliance, and avoid fines.HIPAA Policies and Procedures Designed for IT - [HIPAA Policies for Health Insurance Brokers](https://eagleconsultingpartners.com/downloads/health-insurance-brokers/) - [et_pb_section fb_built=”1″ admin_label=”Section: Fixed Right Sidebar for Sales Pages” _builder_version=”4.4.5″ custom_padding=”1px|27.5312px|36.7188px|27.5312px|false|false”][et_pb_row column_structure=”3_4,1_4″ admin_label=”ROW: Download Sales” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_padding=”0|0px|17.25px|0px|false|false”][et_pb_column type=”3_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”TEXT: Sales copy for TPA Download” _builder_version=”4.5.7″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”]Eagle’s policy template helps you increase security, gain compliance, and avoid fines.HIPAA Policies and Procedures Designed for Health Insurance Brokers Eagle’s HIPAA - [HIPAA and GDPR Policy Templates for Service Providers](https://eagleconsultingpartners.com/downloads/hipaa-and-gdpr-policy-templates-for-service-providers/) - Eagle's GDPR & HIPAA policy template for service providers eliminates the headache of drafting policies for simultaneous HIPAA and GDPR compliance. These templates were drafted for service providers of cloud or hosted information systems, data analytics services, or other similar service. - [Comprehensive Policy Templates for Tennessee Pain Clinics](https://eagleconsultingpartners.com/downloads/hipaa-osha-policy-templates-tennessee-pain-clinics/) - Eagle's comprehensive Tennessee Pain Clinic policy templates help keep your practice safe, secure, and compliant. - [Group Health Plans for Self-insured Employers HIPAA Policy Templates](https://eagleconsultingpartners.com/downloads/group-health-plans-for-self-insured-employers/) - [et_pb_section fb_built=”1″ admin_label=”section” _builder_version=”3.22.3″][et_pb_row admin_label=”row” _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”][et_pb_column type=”4_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”Text” _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_margin=”-70px||||false|false”]Eagle’s policy template helps you increase security, gain compliance, and avoid fines.Group Health Plans for Self-insured Employers HIPAA Policy Templates These policies are designed for employers with group health plans that are outsourced to TPAs, and whose role - [HIPAA Policies and Procedures for Public Health Departments](https://eagleconsultingpartners.com/downloads/hipaa-policies-and-procedures-for-public-health-departments/) - [et_pb_section fb_built=”1″ admin_label=”Section: Fixed Right Sidebar for Sales Pages” _builder_version=”3.22.3″ custom_padding=”1px|27.5312px|36.7188px|27.5312px|false|false”][et_pb_row column_structure=”3_4,1_4″ admin_label=”ROW: Download Sales” _builder_version=”3.25″ background_size=”initial” background_position=”top_left” background_repeat=”repeat” custom_padding=”0|0px|17.25px|0px|false|false”][et_pb_column type=”3_4″ _builder_version=”3.25″ custom_padding=”|||” custom_padding__hover=”|||”][et_pb_text admin_label=”TEXT: Sales Copy for Public Health Departments Download” _builder_version=”3.27.4″ background_size=”initial” background_position=”top_left” background_repeat=”repeat”] Finally, HIPAA Policies that match unique processes for public health departments Public Health Departments have unique functions: Disease Surveillance; Communicable ## Categories - [General News](https://eagleconsultingpartners.com/category/general-news/) - Eagle provides a free newsletter each month for customers on HIPAA and Meaningful Use security matters. You can subscribe to the Eagle Healthcare IT Security Newsletter free. - [HIPAA](https://eagleconsultingpartners.com/category/hipaa/) - Redlined version of the HIPAA rules, as amended on 1/25/2013 by the HIPAA Omnibus Rule amendments. Eagle Omnibus Rule INDEX Eagle works with clients in healthcare and healthcare business associates to ensure HIPAA Security compliance. We provide a set of policy templates for a variety of business associate types including Cloud Vendors, Third Party Administrators, and Information Technology companies. - [ICD-10](https://eagleconsultingpartners.com/category/icd-10/) - [Revenue Cycle Management](https://eagleconsultingpartners.com/category/revenue-cycle-management/) - [Threat Intelligence](https://eagleconsultingpartners.com/category/threat-intelligence/) - [CMS Quality Payment Programs](https://eagleconsultingpartners.com/category/cms-qpp/) - CMS Quality Payment Programs are a key element of CMS’ effort to transform the Medicare system from a “Pay for Volume” model to “Pay for Value”. The Quality Payment Programs include Alternative Payment Models (APMs) such as ACOs and Patient Centered Medical Homes (PCMH). For physician practices not participating in an APM, the Merit-Based Incentive Payment System (MIPS) will apply. MIPS, which will be effective 1/1/2017, incorporates the legacy Meaningful Use, PQRS and Value Modifier programs. - [Health Information Technology](https://eagleconsultingpartners.com/category/healthit/) - Eagle specializes in services related to Health Information Technology, including services to help physician practices select and implement electronic health record and other technologies, performing a wide variety of HIPAA security related services including creation of HIPAA Security Policies, conducting HIPAA audits, performing the HIPAA Security Risk Analysis, conducting technical vulnerability analyses and a variety of other services. - [DD Boards](https://eagleconsultingpartners.com/category/dd-board-solutions/) - Eagle provides a free newsletter each month for customers on HIPAA and Meaningful Use security matters. You can subscribe to the Eagle Healthcare IT Security Newsletter free. - [HIPAA Policy Templates](https://eagleconsultingpartners.com/category/hipaa/hipaa-policy-templates/) - Eagle works with clients in healthcare and healthcare business associates to ensure HIPAA Security compliance. We provide a set of HIPAA policy templates for a variety of business associate types including Cloud Vendors, Third Party Administrators, and Information Technology companies. Here we follow and report on breaches, fines, and ways to protect yourself in the industry. - [Physician Practices](https://eagleconsultingpartners.com/category/physician-practices/) - [Large Providers](https://eagleconsultingpartners.com/category/large-providers/) - [Business Associates & Others](https://eagleconsultingpartners.com/category/business-associates-others/) - [Telehealth](https://eagleconsultingpartners.com/category/telehealth/) - [Information Security](https://eagleconsultingpartners.com/category/information-security/) ## Tags - [HIPAA Security](https://eagleconsultingpartners.com/topic/hipaa-security/) - HIPAA Security is vital in healthcare. Eagle writes about breaches and ways to protect yourself. Eagle works with clients in healthcare and healthcare business associates to ensure HIPAA Security compliance. We provide a set of policy templates for a variety of business associate types including Cloud Vendors, Third Party Administrators, and Information Technology companies. - [HIPAA Privacy](https://eagleconsultingpartners.com/topic/hipaa-privacy/) - HIPAA privacy is the key concept in the legislation for keeping all American’s healthcare records secure and private. Eagle works with clients in healthcare and healthcare business associates to ensure HIPAA Security compliance. We provide a set of policy templates for a variety of business associate types including Cloud Vendors, Third Party Administrators, and Information Technology companies. - [HIPAA Topics](https://eagleconsultingpartners.com/topic/hipaa-topics/) - This archive includes a variety of HIPAA topics including best practices for compliance, techniques for staff training, expert interpretations of the requirements and other topics. Eagle works with clients in healthcare and healthcare business associates to ensure HIPAA Security compliance. We provide a set of policy templates for a variety of business associate types including Cloud Vendors, Third Party Administrators, and Information Technology companies. - [HIPAA Enforcement](https://eagleconsultingpartners.com/topic/hipaa-enforcement/) - This topic includes reports and details of HIPAA Privacy and Security Rule enforcement. We discuss the actions that the HHS Office of Civil Rights (OCR), the Department of Justice, as well as the State Attorneys General take. Eagle works with clients in healthcare and healthcare business associates. In addition, we work with other HIPAA covered entities to ensure HIPAA Security compliance. HIPAA covered entities are essential. It’s important to note that there is a HIPAA privacy and security rule to follow. And, we work with healthcare businesses to make certain they have protected health information. Hospitals and businesses are responsible for enforcing HIPAA security and we can assist. We provide a set of policy templates for a variety of business associate types. Our templates include Cloud Vendors, Third Party Administrators, Healthcare, and Information Technology companies. - [HIPAA News](https://eagleconsultingpartners.com/topic/hipaa-news/) - This topic includes news regarding the HIPAA regulations such as new resources or tools provided by CMS, presentations or statements by the Office of Civil Rights, proposed legislation in Congress and other news. Eagle works with clients in healthcare and healthcare business associates to ensure HIPAA Security compliance. We provide a set of policy templates for a variety of business associate types including Cloud Vendors, Third Party Administrators, and Information Technology companies. - [HIPAA Data Breaches](https://eagleconsultingpartners.com/topic/hipaa-data-breaches/) - News and reports regarding recent major data breaches reported by HIPAA Covered Entities and Business Associates, including analysis, assessments and guidance to help others avoid similar incidents. Eagle works with clients in healthcare and healthcare business associates to ensure HIPAA Security compliance. We provide a set of policy templates for a variety of business associate types including Cloud Vendors, Third Party Administrators, and Information Technology companies. - [HIPAA Business Associate](https://eagleconsultingpartners.com/topic/hipaa-business-associate/) - HIPAA Business Associates, in general terms, are companies or other organizations who contract with HIPAA “Covered Entities” (Health payers, health providers and clearinghouses) and create, use, transmit or maintain confidential patient information (Protected Health Information or PHI). Beginning in 2013, HIPAA Business Associates are themselves regulated by the HIPAA regulations and are subject to both civil and criminal penalties for violations of the rules. Eagle works with clients in healthcare and healthcare business associates to ensure HIPAA Security compliance. We provide a set of HIPAA Policy Templates for a variety of business associate types including Cloud Vendors, Third Party Administrators, and Information Technology companies. - [HIT Threat Intelligence](https://eagleconsultingpartners.com/topic/hit-threat-intelligence/) - HIT Threat Intelligence includes details regarding IT threats such as recently discovered vulnerabilities, current exploits, statistics and analysis regarding security issues and similar actionable information. - [Ransomware](https://eagleconsultingpartners.com/topic/ransomware/) - Ransomware is a type of malicious software (malware) that systematically encrypts files accessible to the user. The malware then demands a ransom, frequently payable in Bitcoin, in exchange for the encryption key to decrypt the files. While ransomware is not new, during 2016, there was a dramatic increase in the number of attacks against healthcare organizations. In the spring of 2016, the FBI issued an alert and requested that organizations do not pay ransomware demands. Eagle Consulting Partners recommends multiple security controls to prevent these attacks including employee security awareness training, web filtering technology, a robust patching program and others. Critical controls to mitigate this exploit should it occur are robust incident response capability, isolated and redundant data backup and data recovery capability. - [MACRA](https://eagleconsultingpartners.com/topic/macra/) - MACRA, the Medicare Access and CHIP Re-Authorization Act, is sweeping legislation enacted in April 2015. MACRA repeals the Sustainable Growth Rate (SGR) formula originally enacted in 1997. To control the growth of Medicare costs, SGR is replaced by value-based reimbursement programs. These value-based reimbursement programs include Alternative Payment Models (APMs) such as Accountable Care Organizations (ACOs), Patient Centered Medical Homes (PCMHs) and others. For physicians and other providers who do not participate in an APM, the Merit-Based Incentive Payment System (MIPS) will reward providers who deliver high-value care while penalizing those who provide low-value care. - [MIPS](https://eagleconsultingpartners.com/topic/mips/) - Eagle Consulting, a healthcare HIPPA security and compliance group, has prepared a series of articles on MIPS and successful ways for physician practices to maximize bonuses and avoid penalties. Learn about common mistakes to avoid and how to win thousands of dollars in reimbursements for your practice. We work through the ever changing CMS landscape so you can chart the best course forward. Eagle Consulting has worked with healthcare providers for decades to help meet government regulations, boost HIPAA related security, and comply with MIPS/MACRA requirements so that you end up benefiting. Read more about our related MIPS/MACRA services here. - [Meaningful Use](https://eagleconsultingpartners.com/topic/meaningful-use/) - (Download PDF). Eagle provides regular articles about Meaningful use and updates from the Centers for Medicare & Medicaid Services (CMS). We also provide analysis, recommendations, and links to supporting documents to help our clients stay up on rules and requirements, including the Objectives and Measures for Meaningful Use — 2015-2017 — you can download at right (PDF). The Meaningful Use program will fragment on 1/1/2017. Physicians who participate in the Medicare version of Meaningful Use will instead participate in the “Advancing Care Information” component of the MIPS Program. The existing Meaningful Use rules and programs will continue for hospitals and physician practices who participate under the Medicaid Meaningful Use program. - [PQRS](https://eagleconsultingpartners.com/topic/pqrs/) - PQRS, the CMS Physician Quality Reporting System, is an physician incentive program which requires physicians to report quality statistics. PQRS will become the “Quality” performance category under the new Merit-Based Incentive Payment System (MIPS) established by CMS. - [Eagle Services](https://eagleconsultingpartners.com/topic/eagle-services/) - Eagle Consulting Partners offers a wide range of services including HIPAA Privacy and Security consulting, Electronic Health Records Implementation, Compliance support for Developmental Disability Boards, support for CMS Quality Programs including MIPS, Meaningful Use, PQRS & Value Modifier and other information technology related services. Eagle serves physicians, hospitals and other health providers; HIPAA Business Associates; government agencies and other clients. - [Case Studies](https://eagleconsultingpartners.com/topic/case-studies-hipaa-ehr/) - HIPAA and EHR Case Studies: Read our case studies which deal with a wide variety of issues detailing the work of Eagle Consulting Partners with its clients, including HIPAA Privacy & Security; MIPS MACRA Support; EHR Implementation and Support. Case study topics are included to demonstrate best practices, to detail a scope of work performed by Eagle Consulting Partners, or to highlight another subject that would be of interest to others. - [Electronic Health Records](https://eagleconsultingpartners.com/topic/electronic-health-records/) - [Encryption and Cryptography](https://eagleconsultingpartners.com/topic/encryption-cryptography/) - Topics and guidance regarding best practices in encryption and cryptography, including risk assessment, best practices, implementation guidance, news regarding available tools, and related information. - [HIPAA Security Risk Analysis](https://eagleconsultingpartners.com/topic/hipaa-security-risk-analysis/) - The HIPAA Security Risk Analysis, also known as a security risk assessment, is a fundamental process required by the HIPAA Security Rule. Health care providers, payers, clearinghouses and Business Associates are all required to conduct a HIPAA SRA. A limited-scope SRA is also required by the Meaningful Use (Advancing Care Information) program. For Meaningful Use, the SRA is required on an annual basis. - [Accountable Care Organization](https://eagleconsultingpartners.com/topic/aco/) - Accountable Care Organizations (ACOs) are one of several Alternative Payment Models (APMs) established by CMS. Many private payers have adopted the ACO as an option for providers. Consequently, health providers can align incentives for both Medicare and private payers. - [FQHC](https://eagleconsultingpartners.com/topic/fqhc/) - [Value Modifier](https://eagleconsultingpartners.com/topic/value-modifier/) - The CMS Value-Based Payment Modifier, aka Value Modifier, is a Medicare Incentive program designed to reward physicians (and other providers who are reimbursed under the Medicare Physician Fee Schedule) who deliver high-value care. This is a revenue-neutral program in which payments are reduced for providers who deliver low-value care, and these monies are given as bonuses to providers who provide high-value care. - [Advancing Care Information](https://eagleconsultingpartners.com/topic/advancing-care-information/) - [Improvement Activities](https://eagleconsultingpartners.com/topic/improvement-activities/) - [mean](https://eagleconsultingpartners.com/topic/mean/) - [Meltdown](https://eagleconsultingpartners.com/topic/meltdown/) - [Spectre](https://eagleconsultingpartners.com/topic/spectre/) - [Vulnerability](https://eagleconsultingpartners.com/topic/vulnerability/) - [Computer Security](https://eagleconsultingpartners.com/topic/computer-security/) - [Malware](https://eagleconsultingpartners.com/topic/malware/) - [Creepware](https://eagleconsultingpartners.com/topic/creepware/) - [Confidentiality](https://eagleconsultingpartners.com/topic/confidentiality/) - [42 CFR Part 2](https://eagleconsultingpartners.com/topic/42-cfr-part-2/) - [Policies and procedures](https://eagleconsultingpartners.com/topic/policies-and-procedures/) - [Regulation](https://eagleconsultingpartners.com/topic/regulation/) - [News](https://eagleconsultingpartners.com/topic/news/) - [Cybersecurity](https://eagleconsultingpartners.com/topic/cybersecurity/) - [OCR](https://eagleconsultingpartners.com/topic/ocr/) - [HHS](https://eagleconsultingpartners.com/topic/hhs/) - [Email](https://eagleconsultingpartners.com/topic/email/) - [Disability](https://eagleconsultingpartners.com/topic/disability/) - [PHI](https://eagleconsultingpartners.com/topic/phi/) - [Promoting Interoperability](https://eagleconsultingpartners.com/topic/promoting-interoperability/) - [Quality](https://eagleconsultingpartners.com/topic/quality/) - [Resource Use](https://eagleconsultingpartners.com/topic/resource-use/) - [GDPR](https://eagleconsultingpartners.com/topic/gdpr/) - [Compliance](https://eagleconsultingpartners.com/topic/compliance/) - [Social Media](https://eagleconsultingpartners.com/topic/social-media/) - [Security Awareness Training](https://eagleconsultingpartners.com/topic/security-awareness-training/) - [Risk Management](https://eagleconsultingpartners.com/topic/risk-management/) - [HIPAA](https://eagleconsultingpartners.com/topic/hipaa/) - Eagle is focused on HIPAA related compliance and security concerns and solutions for our healthcare and related business clients. We write regular articles covering these topics. Eagle works with clients in healthcare and healthcare to ensure HIPAA Security compliance. We provide a set of HIPAA Policy Templates for a variety of client types including Cloud Vendors, Medical Offices, Insured Employers, Government Agencies, Third Party Administrators, and Information Technology companies. - [ACOs](https://eagleconsultingpartners.com/topic/acos/) - [Medicare](https://eagleconsultingpartners.com/topic/medicare/) - [Vulnerabilitym HIPAA](https://eagleconsultingpartners.com/topic/vulnerabilitym-hipaa/) - [CMS](https://eagleconsultingpartners.com/topic/cms/) - [qpp](https://eagleconsultingpartners.com/topic/qpp/) - [proposed rule](https://eagleconsultingpartners.com/topic/proposed-rule/) - [2020](https://eagleconsultingpartners.com/topic/2020/) - [hospital](https://eagleconsultingpartners.com/topic/hospital/) - [physician led](https://eagleconsultingpartners.com/topic/physician-led/) - [SRA](https://eagleconsultingpartners.com/topic/sra/) - [security risk assessment](https://eagleconsultingpartners.com/topic/security-risk-assessment/) - [pcp](https://eagleconsultingpartners.com/topic/pcp/) - [primary care](https://eagleconsultingpartners.com/topic/primary-care/) - [economy](https://eagleconsultingpartners.com/topic/economy/) - [mssp](https://eagleconsultingpartners.com/topic/mssp/) - [shared savings](https://eagleconsultingpartners.com/topic/shared-savings/) - [specialist](https://eagleconsultingpartners.com/topic/specialist/) - [healthcare spending](https://eagleconsultingpartners.com/topic/healthcare-spending/) - [coronavirus](https://eagleconsultingpartners.com/topic/coronavirus/) - [COVID-19](https://eagleconsultingpartners.com/topic/covid-19/) - Resources to support our clients and friends during the COVID-19 pandemic, including topics such as securing remote work capabilities, changes in telehealth, and other operations and pandemic support resources. ## Download Categories - [Business Associates](https://eagleconsultingpartners.com/downloads/category/business-associates/) - [Physician's Practices](https://eagleconsultingpartners.com/downloads/category/physicians-practices/) - [Self Insured Employers](https://eagleconsultingpartners.com/downloads/category/self-insured-employers/) - [Public Health Dept.](https://eagleconsultingpartners.com/downloads/category/public-health-dept/) - [Ohio DD Boards](https://eagleconsultingpartners.com/downloads/category/ohio-dd-boards/) - [GPDR](https://eagleconsultingpartners.com/downloads/category/gdpr/) - [SaaS Vendors](https://eagleconsultingpartners.com/downloads/category/saas-vendors/) ## Download Tags - [billing](https://eagleconsultingpartners.com/downloads/tag/billing/) - [medical billing](https://eagleconsultingpartners.com/downloads/tag/medical-billing/) - [billing company hipaa](https://eagleconsultingpartners.com/downloads/tag/billing-company-hipaa/) - [medical billing company](https://eagleconsultingpartners.com/downloads/tag/medical-billing-company/) ## Categories - [HIPAA Omnibus Rule 1-25-2013](https://eagleconsultingpartners.com/HIPAA-Guide-category/hipaa-omnibus-rule-1-25-2013/) - [Part 160 – General](https://eagleconsultingpartners.com/HIPAA-Guide-category/part-160-general/) - [Subpart A](https://eagleconsultingpartners.com/HIPAA-Guide-category/subpart-a/) - Eagle’s HIPPA redlined version of the HIPAA Privacy and Security Rules (including Breach rule) includes update information and guidance. - [Part 164 – Security and Privacy](https://eagleconsultingpartners.com/HIPAA-Guide-category/part-164-security-and-privacy/) - [Subpart A – General Provisions](https://eagleconsultingpartners.com/HIPAA-Guide-category/subpart-a-general-provisions/) - [Subpart C – Security Standards](https://eagleconsultingpartners.com/HIPAA-Guide-category/subpart-c-security-standards-for-protection-of-electronic-protected-health-information/) - [Subpart D – Breach Notification](https://eagleconsultingpartners.com/HIPAA-Guide-category/subpart-d-notification-in-the-case-of-breach-of-unsecured-protected-health-information/) - [Subpart E – Privacy of Health Information](https://eagleconsultingpartners.com/HIPAA-Guide-category/subpart-e-privacy-of-individually-identifiable-health-information/) ## Tags - [Business Associate](https://eagleconsultingpartners.com/hipaa-guide-tag/business-associate/) - Review the Business Associate section of the HIPAA Privacy and Security Rules (including Breach rule). Eagle Consulting helps you achieve HIPAA compliance and offers HIPAA policy templates with live assistance as needed. Eagle has also created seven HIPAA policy templates based on our expertise and understanding of business processes for several types of organizations with HIPAA business obligations. Eagle consultants bring years of experience in HIPAA compliance and audit readiness at hospitals and for physician’s practices, business associates, and for government sector organizations in Ohio. - [Business Associate Contract](https://eagleconsultingpartners.com/hipaa-guide-tag/business-associate-contract/) - [Electronic Copy of Records](https://eagleconsultingpartners.com/hipaa-guide-tag/electronic-copy-of-records/) - [Fundraising](https://eagleconsultingpartners.com/hipaa-guide-tag/fundraising/) - [Group Health Plans](https://eagleconsultingpartners.com/hipaa-guide-tag/group-health-plans/) - [Notice of Privacy Practices](https://eagleconsultingpartners.com/hipaa-guide-tag/notice-of-privacy-practices/) - [Record Fees](https://eagleconsultingpartners.com/hipaa-guide-tag/record-fees/) - [Research](https://eagleconsultingpartners.com/hipaa-guide-tag/research/) - [Restrictions](https://eagleconsultingpartners.com/hipaa-guide-tag/restrictions/) - [Genetic](https://eagleconsultingpartners.com/hipaa-guide-tag/genetic/) - [Disclosure to School](https://eagleconsultingpartners.com/hipaa-guide-tag/disclosure-to-school/) - [PHI Sale](https://eagleconsultingpartners.com/hipaa-guide-tag/phi-sale/) - [Marketing](https://eagleconsultingpartners.com/hipaa-guide-tag/marketing/) - [Breach](https://eagleconsultingpartners.com/hipaa-guide-tag/breach/)