Looking for a Business Associate Agreement? Download our FREE starter template.
Total HIPAA Logo

HIPAA Enforcement: 2021 Predictions for Agents and Brokers

Jason Karn, Total HIPAA’s Chief Compliance Officer, recently spoke with David Smith, a nationally recognized healthcare benefits consultant, and regulatory expert, about HIPAA enforcement projections for agents and brokers in 2021. They spoke about HIPAA enforcement under the new administration and how to protect your business against breaches. You can listen to this episode of our podcast HIPAA Talk here or on your mobile device via Apple Podcasts. Or, read the summary below.

Broadening HIPAA Enforcement Expected

While the previous administration did take steps to limit HIPAA-related penalties and other federal regulations through executive orders, 2020 was a banner year for HIPAA enforcement. The Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) settled a whopping 19 HIPAA violation cases. The total amount of financial penalties issued in 2020 was more than HHS had issued in any previous year.

Although HIPAA-related penalties went up in 2020, most of them were large fines directed at big corporations, with few small offender fines. There were, however, a handful of small companies and providers that were met with significant penalties. 

We expect OCR to continue cracking down on HIPAA violations by smaller offenders. Instead of focusing on large, headline-generating fines, OCR will be increasing enforcement across the board. If you are a small insurance agent thinking, “They won’t come after me. They’re busy monitoring and penalizing large carriers,” think again. With enforcement efforts increasing, being noncompliant leaves you vulnerable to breaches and dangerous fines.

A large fine can do a lot of damage, leading to loss of business, employee trust, and client confidence, especially in the case of incidents that receive major media attention. Your company may also incur the cost of legal fees and client protection services, like credit monitoring.

OCR is projected to increase crackdowns on companies who experience breaches in 2021. This increase in enforcement may partially stem from a massive breach that occurred in December 2020. The cybersecurity incident occurred after SolarWinds, a third party vendor widely used across the federal government was found to be the victim of a sophisticated hacking campaign. This, along with the increased attention OCR is devoting to breaches of all sizes, is going to result in more stringent enforcement.1

State Level Enforcement

In the last several years, additional state regulations designed to strengthen the protection of consumer information have also become law. The California Consumer Privacy Act and the New York State Financial Services Department Regulation both introduced requirements for Covered Entities that are more stringent than HIPAA. Some of these regulations include requiring the use of multi-factor authentication and strengthening cybersecurity incident notification rules.

These states will continue to pursue HIPAA enforcement while also cracking down on entities that violate their even stricter state regulations. More states will follow by adopting similar laws. This trend is sure to continue over the next few years, so it’s best to adopt good security practices now so you’re prepared for the future.

HIPAA Enforcement in 2021: Conclusions

The new administration will likely be adding a renewed emphasis on HIPAA Privacy and Security. Under the Obama administration there were several key changes to the HIPAA law, including stricter breach notification requirements, harsher penalties for noncompliance, and required auditing. We expect the Biden administration to put a similar emphasis on breaches and their enforcement, taking an increasingly aggressive approach.2

For this reason, it is more important than ever to achieve and maintain HIPAA compliance. It’s not worth risking a breach and possibly your business. Be sure to implement good security practices that reflect the state of your business and current technology. These practices may include using an email encryption provider, or retiring old systems that Microsoft is no longer supporting

Remember, HIPAA compliance is not a choice. Ignoring these rules and regulations can jeopardize your business and your livelihood. Investing in HIPAA security practices like securing your network and business information will benefit you immensely in the long run. And once the process is implemented, maintaining compliance is a minimal cost and well worth the investment. Not to mention, it is required by law.

Our HIPAA compliance services help ensure that your business follows the basic HIPAA rules and guidelines to protect sensitive patient information. Our team of experts is dedicated to providing affordable rates and personalized solutions to help you become HIPAA compliant. We understand that navigating the complex requirements of HIPAA can be challenging, which is why we offer a comprehensive range of services to meet your unique needs. From risk assessments to employee training, we have the tools and expertise necessary to help your business achieve and maintain HIPAA compliance. Contact us today to learn more about how we can help you protect your patients, your employees, and your business.

Related Articles

  1. What We Know About the SolarWinds Breach
  2. Looking back at key HIPAA changes under 2009 law

Sharing is caring!

Documents

Looking for a Business Associate Agreement?

Download our free template to get started on your path toward HIPAA compliance.

Download Now

Let's keep in touch

Stay up to date on the latest HIPAA news, plus receive tons of free tools and info.

Navigating HIPAA Compliance in 2023

Watch the recording of this webinar to learn more about how you can become and stay HIPAA compliant!

Document

Related Posts

What is Access Control in terms of HIPAA?

What is Access Control in terms of HIPAA?

Access control, in terms of cybersecurity, refers to the practice of managing and regulating who can access specific resources, systems, or data within an organization's network or information...

Comparing HIPAA and NIST

Comparing HIPAA and NIST

In the ever-evolving landscape of data security and privacy, two key frameworks have emerged as significant players: HIPAA and NIST. Both emphasize the importance of safeguarding sensitive...

Save & Share Cart
Your Shopping Cart will be saved and you'll be given a link. You, or anyone with the link, can use it to retrieve your Cart at any time.
Back Save & Share Cart
Your Shopping Cart will be saved with Product pictures and information, and Cart Totals. Then send it to yourself, or a friend, with a link to retrieve it at any time.
Your cart email sent successfully :)