Compliance for Healthcare Companies
Healthcare companies which include, health care providers, insurers and their business associates have received some considerable and definitive guidance over the requirements on how they should handle and communicate patient information. Under HIPAA in 1996 and revisions to HIPAA made in 2009’s HITECH Act, healthcare companies are limited in the types of PHI (personal health information) they can collect from individuals, share with other organizations or use in marketing communications.
Increased demand for security, privacy and regulatory compliance has escalated the need for healthcare companies to obtain a third-party assurance over the controls that are in place to protect PHI. Compliance attestations and reviews play an important role for healthcare companies by establishing credibility and trust with their customers and have been used as a marketing tool to enter new markets or expand existing market share.
There are many compliance attestations or reviews available to the healthcare industry today. Some of the options that are governed by the AICPA are: the System and Organization Controls (SOC) for Service Organizations (SOC 2®) Attestation, Agreed-Upon Procedures Review or Compliance Attestation. If a healthcare company is in the market for an attestation that provides customers and other relevant parties with assurance about controls relevant to security, availability, processing integrity, confidentiality and/or privacy that do not affect their customers’ internal controls over financial reporting, a SOC 2® report is the logical choice for examining internal controls. Whereas the Agreed-Upon Procedures Review and Compliance Attestation are usually driven by a specific customer or customers that require the healthcare company abide by a defined set of requirements or standards.
Healthcare Company’s SOC 2® attestation involves the following critical areas:
- Security: the system is protected against unauthorized access (both physical and logical).
- Availability: the system is available for operation and use as committed or agreed.
- Processing Integrity: system processing is complete, accurate, timely and authorized.
- Confidentiality: information designated as confidential is protected as committed or agreed.
- Privacy: personal information is collected, used, retained, disclosed and destroyed in conformity with commitments in the organization’s privacy notice and with criteria set forth in generally accepted privacy principle issued by the AICPA and CICA.
Healthcare company’s Agreed-Upon Procedures Review is a specific set of controls that are defined by a customer. The Compliance Attestation’s scope is defined by the complete set of controls in a specific standard or regulation (such as HIPAA, HITECH or DEA 1311.120 Electronic Prescriptions for Controlled Substances Act).
The scope of these attestations and reviews are determined by the healthcare company and their customers. Accordingly, a well scoped attestation can clearly demonstrate your organization’s quality of service and ensure that sufficient information is provided to your user organizations to communicate your stringent controls over physical security, environmental security, authorized access and continuous availability of services.
Compliance Process
We tailor every attestation engagement to our client’s requirements. However, we have a fundamental four phase process that normally meets our clients’ needs and creates an efficient, unobtrusive attestation that enables you to focus on your business while we focus on your compliance.
Project Timeline: Four Phase Audit
For More Information Speak to a Service Auditor at Roosa CPA, LLC (877) 410-8516