From: Bradley Arant Boult Cummings LLP
Dinetia Newman, Amy S. Leopard and Judd A. Harwood
On December 5, 2013, the Office of Inspector General (OIG) reported on the Office for Civil Rights’ (OCR) compliance as of May 2011 with oversight and enforcement of the Security Rule and compliance with federal cybersecurity requirements. The Security Rule implements provisions of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH).
These agency audits and reports, which are statutorily mandated of U.S. Department of Health and Human Services (HHS) departments, examine agency activity and nudge agency departments to “toe the line” to improve agency efficiency and prevent waste, fraud, abuse, and mismanagement. Even though reports may not identify nefarious behavior, the audits serve as a reminder of the previous agency focus and warn of future agency activity based on the auditor’s recommendations. The OIG’s December 5 report follows suit.
Although a read of the audit accounts may imply that the OCR lacked diligence in carrying out its HIPAA and HITECH mandates as far as the Security Rule is concerned, such an interpretation would be only partially true. First, the report assesses the OCR’s activities between July 2009 and May 2011. And, as might be expected, the OCR’s plate has been full since HHS’ 2009 delegation of responsibility to the OCR for oversight and enforcement of the Security Rule. The OCR already had more than its share of responsibilities with civil rights and health information privacy obligations. While not minimizing the OIG’s concerns, this article does highlight some of the complexities in enforcing a rapidly evolving regulatory regime. And, query, how relevant is a report of activity occurring more than 30 months ago?
The specific responsibilities that the OCR assumed in July 2009 included ensuring that HIPAA-covered entities complied with the Security Rule, investigating and resolving potential HIPAA violations, periodically auditing covered entities, and complying with federal internal control and cybersecurity requirements. Federal regulations gave the OCR leeway either to resolve noncompliance informally or to impose civil monetary penalties. Prior to HHS delegating Security Rule oversight to the OCR, CMS conducted no audits of the rule’s compliance, but rather allowed self-initiated compliance audits of covered entities.
What are the OIG’s Concerns, and What Federal Requirements Did the OCR Fail to Meet?
HITECH-Required Audits
The OIG states that the OCR did not perform a risk assessment, establish priorities, implement controls for the audits to ensure Security Rule compliance (see OMB Circular A-123), or provide for periodic audits. Because of those failings, the OCR could not ensure covered-entity compliance and “missed opportunities” to encourage compliance.
The OIG has several concerns: (1) The OCR had not assessed by May 2011 which entities and what systems had the greatest risk of electronic protected health information (ePHI) exposure. (2) The OCR continued the joint CMS/OCR complaint-driven approach (as opposed to the required audit approach). (3) The OCR focused more on its civil rights and health privacy oversight and enforcement responsibilities rather than on its risk assessment, control development, and periodic audits for Security Rule compliance. (4) Instead of auditing, the OCR spent resources on Security Rule investigations originating from press reports, large individual volume breaches (i.e., more than 500 individuals), and public complaints.
In its defense, the OCR related its insufficient resources to expand its compliance efforts beyond event-driven compliance investigations (versus audit-driven investigations) and its lack of expertise to carry out Security Rule and HITECH responsibilities. In other words, the Office did not have the capacity or capabilities to audit systems that store PHI and their security controls.
Leave a Reply