|
Q: I just did HIPAA two years ago - why do I have to do it again?
A: The work you did in 2003 was phase one of HIPAA compliance. It focused on the Privacy Rule of HIPAA. Come April 20, 2005, phase two takes effect -- the HIPAA Security Rule -- requiring its own unique set of policies and procedures (and different from the ones you put in place to deal with Privacy concerns). These policies and procedures deal with confidential patient information in electronic form.
Q: Can I just do the training -- will that be enough to comply?
A: Not by itself. Like many compliance regulations, documentation is a critical component of overall compliance. While your internal operating practices may be okay, if you don't have them formally documented, then there is no way for an auditor to validate compliance. Policies and procedures are an important ingredient. Our templates do most of this work for you.
Q: This is an awful lot of work for a small practice like mine -- isn't there an easier way?
A: Our manuals have simplified the process as much as possible and provide easy-to-use instructions and the policies and forms you'll need. Be wary of solutions that promise "Get compliant in minutes!" These "bare bones" programs can easily miss potential areas of risk that could lead to trouble down the line.
Q: I trained everyone in my office last year (or the year before that). Do I have to train them again?
A: If the training you've already done included Security Training, then nothing further needs to be done. However, it's more likely that prior training did not include Security training so you'll need to complete this specific training and maintain documentation.
Q: I have some existing employees that already took Privacy training and only need the Security training. I also have new staff that need both Privacy and Security training. Which option is best for me?
A: Assuming you already have all the necessary Privacy policies & procedures, then the Security Package (Option 2) is the best fit. You'll get the Security Manual (with policies & procedures) plus 4 licenses for training. The users can register for either Security only training or Privacy & Security training -- it's the same price for either course. |