{"id":366,"date":"2019-03-19T19:34:04","date_gmt":"2019-03-19T23:34:04","guid":{"rendered":"https:\/\/eagleassociates.net\/news\/?p=366"},"modified":"2019-03-19T19:35:11","modified_gmt":"2019-03-19T23:35:11","slug":"hipaa-workforce-sanctions","status":"publish","type":"post","link":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/","title":{"rendered":"HIPAA Workforce Sanctions"},"content":{"rendered":"\n<p>Sanctions, also known as penalties or disciplinary actions, are a common requirement when implementing regulatory requirements.&nbsp; HIPAA Rules specifically state that a Covered Entity (i.e., a medical or dental practice) must implement policies to prevent, detect, contain, and correct privacy and security violations and apply appropriate sanctions against members of their workforce who fail to comply with policies and procedures.<\/p>\n\n\n\n<p>The HIPAA definition of <em>workforce<\/em> meansemployees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity, is under the direct control of such entity, whether or not they are paid by the covered entity.<\/p>\n\n\n\n<p>A recent Eagle Associates News page article <em>Preventing HIPPA Violations<\/em> referenced a practice that was fined $125,000 for unauthorized disclosures of PHI.&nbsp; Another reason for the civil monetary penalty was that the practice did not sanction the provider that made the disclosures.&nbsp; This draws attention to the fact that no member of the practices\u2019 workforce is exempt from sanctions when they are involved in a HIPAA-related violation<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Sanction Policy and Types<\/h3>\n\n\n\n<p>Covered entities must maintain a written policy establishing a set of disciplinary actions that may be imposed when a workforce member violates its Privacy or Security policies. The policy should explain that sanctions will be applied equally to any workforce member that is at fault regardless of title or length of employment (including management and officers).&nbsp; The policy should further outline that the actual sanction that is imposed for a given violation will be based on the risk to the patient\u2019s PHI, repeat offenses, intent, and actual impact on PHI.&nbsp; The authority for imposing sanctions lies with the practice\u2019s Privacy Manager, Security Officer, and management personnel.&nbsp; Having multiple persons involved ensures an appropriate review of circumstances and determination of the appropriate sanction to be imposed.<\/p>\n\n\n\n<p>Workforce members must be provided notice of possible sanctions for violations.&nbsp; This can be easily communicated in a confidentiality agreement that outlines the workforce member\u2019s responsibilities, and consequences for failing to comply with practice policies.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><em>HIPAA Sanction Examples<\/em><\/h4>\n\n\n\n<p>The Security Officer, Privacy Manager and\/or Compliance Committee should impose the sanction(s) that they determine to be appropriate, considering the severity of the incident, the intent of the workforce member, and the number of prior incidents in which the individual has been involved. Following are examples of possible sanctions that may be imposed:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>A verbal reprimand should be imposed for incidents that are deemed to be minor, and for first occurrence of an incident by an individual.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>A written reprimand should be imposed for incidents that are a repetition of an incident, or a different incident that involves the same individual.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>A staff member may be temporarily suspended from work to prevent him\/her from accessing protected health information, for a length of time to be determined by the Security Officer or Privacy Manager. The length of the suspension will be dependent upon the type and the severity of the incident and\/or the repetition of offenses by the individual.<\/li><\/ul>\n\n\n\n<ul class=\"wp-block-list\"><li>A staff member may be terminated from the practice for malicious or other serious failure to follow HIPAA policies and procedures implemented by the practice.<\/li><\/ul>\n\n\n\n<p>The written policy and sample sanctions should enable a practice to determine an appropriate sanction for the incident being addressed.&nbsp; Again, sanctions need to be applied to all workforce members that violate HIPAA policies and procedures.&nbsp; Perhaps the most difficult sanctions are those that need to be applied to providers and management personnel.&nbsp; Due to the sensitivity and possible resistance to sanctions for providers and management personnel, it is recommended to have a discussion with compliance officers and management before violations occur.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Recommended Actions for Sanctions Compliance<\/strong><\/h3>\n\n\n\n<ol class=\"wp-block-list\"><li>Ensure that your practice has written sanction policies.&nbsp; Practices with Eagle\u2019s HIPAA policy manuals should review Sections 1.14 and 1.14a and either:<ol><li>Implement those policies or;<\/li><li>Implement existing HR or other practice policies intended to address HIPAA violations.<\/li><\/ol><\/li><li>Ensure that workforce members are aware of possible sanctions for HIPAA violations.&nbsp; We recommend using a confidentiality agreement (Form 7.10 from the Eagle Associates HIPAA policy manual) for all workforce members to inform them of sanctions and possible actions.<\/li><li>Ensure that sanctions are imposed and documented in the workforce member\u2019s personnel file.<\/li><li>Provide workforce member training for Privacy, Security, and Breach Notification Rule requirements.&nbsp; Using Eagle Associates\u2019 Compliance Training modules for HIPAA (occurring in April, May, and June issues of the <em>Advisor<\/em>) will document that the practice has met requirements for training and awareness.<\/li><\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Sanctions, also known as penalties or disciplinary actions, are a common requirement when implementing regulatory requirements.&nbsp; HIPAA Rules specifically state that a Covered Entity (i.e., a medical or dental practice) must implement policies to prevent, detect, contain, and correct privacy and security violations and apply appropriate sanctions against members of their workforce who fail to&#8230; <span class=\"more\"><a class=\"more-link\" href=\"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/\">Continue reading <span class=\"meta-nav\">&#8594;<\/span><\/a><\/span><\/p>\n","protected":false},"author":2,"featured_media":367,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[35],"tags":[23],"class_list":["post-366","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-eagle-staff","tag-hipaa"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>HIPAA Workforce Sanctions | Eagle Associates News<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HIPAA Workforce Sanctions | Eagle Associates News\" \/>\n<meta property=\"og:description\" content=\"Sanctions, also known as penalties or disciplinary actions, are a common requirement when implementing regulatory requirements.&nbsp; HIPAA Rules specifically state that a Covered Entity (i.e., a medical or dental practice) must implement policies to prevent, detect, contain, and correct privacy and security violations and apply appropriate sanctions against members of their workforce who fail to... Continue reading &#8594;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/\" \/>\n<meta property=\"og:site_name\" content=\"Eagle Associates News\" \/>\n<meta property=\"article:published_time\" content=\"2019-03-19T23:34:04+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-03-19T23:35:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/eagleassociates.net\/news\/wp-content\/uploads\/2019\/03\/HIPAA-Workforce-Sanctions.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"684\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Eagle Staff\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Eagle Staff\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/\"},\"author\":{\"name\":\"Eagle Staff\",\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/#\\\/schema\\\/person\\\/ed0338105c6f7bd7e7014934db2b97f9\"},\"headline\":\"HIPAA Workforce Sanctions\",\"datePublished\":\"2019-03-19T23:34:04+00:00\",\"dateModified\":\"2019-03-19T23:35:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/\"},\"wordCount\":760,\"image\":{\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/wp-content\\\/uploads\\\/2019\\\/03\\\/HIPAA-Workforce-Sanctions.jpg\",\"keywords\":[\"hipaa\"],\"articleSection\":[\"eagle associates staff\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/\",\"url\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/\",\"name\":\"HIPAA Workforce Sanctions | Eagle Associates News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/wp-content\\\/uploads\\\/2019\\\/03\\\/HIPAA-Workforce-Sanctions.jpg\",\"datePublished\":\"2019-03-19T23:34:04+00:00\",\"dateModified\":\"2019-03-19T23:35:11+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/#\\\/schema\\\/person\\\/ed0338105c6f7bd7e7014934db2b97f9\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/#primaryimage\",\"url\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/wp-content\\\/uploads\\\/2019\\\/03\\\/HIPAA-Workforce-Sanctions.jpg\",\"contentUrl\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/wp-content\\\/uploads\\\/2019\\\/03\\\/HIPAA-Workforce-Sanctions.jpg\",\"width\":1000,\"height\":684},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/2019\\\/03\\\/hipaa-workforce-sanctions\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HIPAA Workforce Sanctions\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/#website\",\"url\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/\",\"name\":\"Eagle Associates News\",\"description\":\"News and More from Eagle Associates, Inc.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/eagleassociates.net\\\/news\\\/#\\\/schema\\\/person\\\/ed0338105c6f7bd7e7014934db2b97f9\",\"name\":\"Eagle Staff\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f46663bd04e8c76f12d55caa7ba167ba1e86492b7c8b4bb878cad266fde91a5b?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f46663bd04e8c76f12d55caa7ba167ba1e86492b7c8b4bb878cad266fde91a5b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f46663bd04e8c76f12d55caa7ba167ba1e86492b7c8b4bb878cad266fde91a5b?s=96&d=mm&r=g\",\"caption\":\"Eagle Staff\"},\"sameAs\":[\"http:\\\/\\\/www.eagleassociates.net\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"HIPAA Workforce Sanctions | Eagle Associates News","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/","og_locale":"en_US","og_type":"article","og_title":"HIPAA Workforce Sanctions | Eagle Associates News","og_description":"Sanctions, also known as penalties or disciplinary actions, are a common requirement when implementing regulatory requirements.&nbsp; HIPAA Rules specifically state that a Covered Entity (i.e., a medical or dental practice) must implement policies to prevent, detect, contain, and correct privacy and security violations and apply appropriate sanctions against members of their workforce who fail to... Continue reading &#8594;","og_url":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/","og_site_name":"Eagle Associates News","article_published_time":"2019-03-19T23:34:04+00:00","article_modified_time":"2019-03-19T23:35:11+00:00","og_image":[{"width":1000,"height":684,"url":"https:\/\/eagleassociates.net\/news\/wp-content\/uploads\/2019\/03\/HIPAA-Workforce-Sanctions.jpg","type":"image\/jpeg"}],"author":"Eagle Staff","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Eagle Staff","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/#article","isPartOf":{"@id":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/"},"author":{"name":"Eagle Staff","@id":"https:\/\/eagleassociates.net\/news\/#\/schema\/person\/ed0338105c6f7bd7e7014934db2b97f9"},"headline":"HIPAA Workforce Sanctions","datePublished":"2019-03-19T23:34:04+00:00","dateModified":"2019-03-19T23:35:11+00:00","mainEntityOfPage":{"@id":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/"},"wordCount":760,"image":{"@id":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/#primaryimage"},"thumbnailUrl":"https:\/\/eagleassociates.net\/news\/wp-content\/uploads\/2019\/03\/HIPAA-Workforce-Sanctions.jpg","keywords":["hipaa"],"articleSection":["eagle associates staff"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/","url":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/","name":"HIPAA Workforce Sanctions | Eagle Associates News","isPartOf":{"@id":"https:\/\/eagleassociates.net\/news\/#website"},"primaryImageOfPage":{"@id":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/#primaryimage"},"image":{"@id":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/#primaryimage"},"thumbnailUrl":"https:\/\/eagleassociates.net\/news\/wp-content\/uploads\/2019\/03\/HIPAA-Workforce-Sanctions.jpg","datePublished":"2019-03-19T23:34:04+00:00","dateModified":"2019-03-19T23:35:11+00:00","author":{"@id":"https:\/\/eagleassociates.net\/news\/#\/schema\/person\/ed0338105c6f7bd7e7014934db2b97f9"},"breadcrumb":{"@id":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/#primaryimage","url":"https:\/\/eagleassociates.net\/news\/wp-content\/uploads\/2019\/03\/HIPAA-Workforce-Sanctions.jpg","contentUrl":"https:\/\/eagleassociates.net\/news\/wp-content\/uploads\/2019\/03\/HIPAA-Workforce-Sanctions.jpg","width":1000,"height":684},{"@type":"BreadcrumbList","@id":"https:\/\/eagleassociates.net\/news\/2019\/03\/hipaa-workforce-sanctions\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/eagleassociates.net\/news\/"},{"@type":"ListItem","position":2,"name":"HIPAA Workforce Sanctions"}]},{"@type":"WebSite","@id":"https:\/\/eagleassociates.net\/news\/#website","url":"https:\/\/eagleassociates.net\/news\/","name":"Eagle Associates News","description":"News and More from Eagle Associates, Inc.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/eagleassociates.net\/news\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/eagleassociates.net\/news\/#\/schema\/person\/ed0338105c6f7bd7e7014934db2b97f9","name":"Eagle Staff","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f46663bd04e8c76f12d55caa7ba167ba1e86492b7c8b4bb878cad266fde91a5b?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f46663bd04e8c76f12d55caa7ba167ba1e86492b7c8b4bb878cad266fde91a5b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f46663bd04e8c76f12d55caa7ba167ba1e86492b7c8b4bb878cad266fde91a5b?s=96&d=mm&r=g","caption":"Eagle Staff"},"sameAs":["http:\/\/www.eagleassociates.net"]}]}},"_links":{"self":[{"href":"https:\/\/eagleassociates.net\/news\/wp-json\/wp\/v2\/posts\/366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/eagleassociates.net\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eagleassociates.net\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eagleassociates.net\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/eagleassociates.net\/news\/wp-json\/wp\/v2\/comments?post=366"}],"version-history":[{"count":2,"href":"https:\/\/eagleassociates.net\/news\/wp-json\/wp\/v2\/posts\/366\/revisions"}],"predecessor-version":[{"id":369,"href":"https:\/\/eagleassociates.net\/news\/wp-json\/wp\/v2\/posts\/366\/revisions\/369"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/eagleassociates.net\/news\/wp-json\/wp\/v2\/media\/367"}],"wp:attachment":[{"href":"https:\/\/eagleassociates.net\/news\/wp-json\/wp\/v2\/media?parent=366"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eagleassociates.net\/news\/wp-json\/wp\/v2\/categories?post=366"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eagleassociates.net\/news\/wp-json\/wp\/v2\/tags?post=366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}