C427 WGU Technology Applications in Healthcare Task 1.
A. Create a planning, organizing, directing, controlling (PODC) HIPAA training model by doing
the following:
1. Describe how you would teach the hospital employees the rules and regulations
regarding HIPAA.
P-I would require all hospital employees to complete training on the healthcare facility’s
policies and procedures for protecting the patient’s health information.
O-All employees will receive an email with a web link to the hospital’s learning
management system. The employees will have 3 weeks to register and complete the
hour long training video.
D-The training is an interactive presentation that is done by healthcare professionals
from across the country with years of experience dealing with HIPPA.
C-The hour long training video will have questions after each section that you must
answer correctly to move on to the next section in the video. At the end of the video,
there is a test that all employees must complete with a passing score of 85% or higher.
This training course will become an annual requirement, and become part of the new-
hire orientation process. The employees must then sign a form saying they understand
the content and passed the HIPPA training, which will be put into the employees file.
a. Identify three appropriate types of PHI that can be shared between staff.
Staff can share PHI such as the patients name, social security number, and
Medical Record Number.
i. Identify where in the facility the information sharing should take place.
PHI can only be shared at the reception desk when other patients are not
around, the billing office when the accountant is on the phone with an
insurance company, and in the nurse station when out of earshot of visitors
and other patients.
ii. Identify three individuals who can use and disclose this information.
Clinic receptionists can provide a patients name when a patient comes in for an
appointment, hospital billing department can send a patients social security
number to an insurance company for payment, and nurses can share the
patient’s medical record number with doctors so the doctors can look up the
patient’s record.
b. Describe two penalties associated with breaching patient information.
If an employee unknowingly violated HIPPA, the employee could face a minimum
fine of $100 and a maximum up to $50, 000 per violation. Jail time for the
employee could be up to 1 year. If the same employee knowingly violates HIPPA,
but attempts to correct the issue, the minimum fine is $10, 000, going up to a
maximum of $50,000. The employee could face up to 10 years in jail.
, c. Identify two appropriate ways to secure data from one working shift to another
using HIPAA guidelines.
Staff can make efforts to protecting PHI by keeping a password on their
computer, and locking their computer when they get up and leave so no prying
eyes can log on and get into any patient health information. The staff can also
shred any files containing sensitive information when they are through discussing
the patients file with other staff members.
2. Complete an internal audit plan of all security measures meant to protect
health information by doing the following:
a. Identify which department will oversee the audit.
The information Technology department would be the best department to
perform the audit since IT is the ones who keep the computers protected with
passwords, and keeping the computers up to date with the latest antivirus
software.
b. Explain three security practices the audit will review (e.g., PHI sign-out sheets,
secured storage/location of records).
The IT department will perform the audit by verifying each computer is password
protected, and no two computers have the same password. They will verify each
computer is updated with the latest antivirus software to protect the server from
unwanted viruses. The department can then send out a fake phishing email,
addressed from an unknown source that will ask the employees to log on using
their hospital credentials.
c. Describe three potential changes that can be made within the organization to
address the results of the audit (e.g., additional employee education).
To address the results of the audit, the IT department can require every
employee to change their passwords every 90 days, to prevent anyone from
using someone else’s password. IT will then have the hospital server
automatically update each computer with the latest software so the computers
are always up-to-date, and protected from malware and viruses. Additional online
training will be assigned to every employee on how to identify phishing emails
and how to avoid giving out their logon credentials.
d. Create a risk assessment plan to identify the potential for any future security breaches.
Risk Assessment Report
Vulnerability Risk Impact Risk Recommended Best Organizational
Name Description Severity Level Practice Control Owner
A. Create a planning, organizing, directing, controlling (PODC) HIPAA training model by doing
the following:
1. Describe how you would teach the hospital employees the rules and regulations
regarding HIPAA.
P-I would require all hospital employees to complete training on the healthcare facility’s
policies and procedures for protecting the patient’s health information.
O-All employees will receive an email with a web link to the hospital’s learning
management system. The employees will have 3 weeks to register and complete the
hour long training video.
D-The training is an interactive presentation that is done by healthcare professionals
from across the country with years of experience dealing with HIPPA.
C-The hour long training video will have questions after each section that you must
answer correctly to move on to the next section in the video. At the end of the video,
there is a test that all employees must complete with a passing score of 85% or higher.
This training course will become an annual requirement, and become part of the new-
hire orientation process. The employees must then sign a form saying they understand
the content and passed the HIPPA training, which will be put into the employees file.
a. Identify three appropriate types of PHI that can be shared between staff.
Staff can share PHI such as the patients name, social security number, and
Medical Record Number.
i. Identify where in the facility the information sharing should take place.
PHI can only be shared at the reception desk when other patients are not
around, the billing office when the accountant is on the phone with an
insurance company, and in the nurse station when out of earshot of visitors
and other patients.
ii. Identify three individuals who can use and disclose this information.
Clinic receptionists can provide a patients name when a patient comes in for an
appointment, hospital billing department can send a patients social security
number to an insurance company for payment, and nurses can share the
patient’s medical record number with doctors so the doctors can look up the
patient’s record.
b. Describe two penalties associated with breaching patient information.
If an employee unknowingly violated HIPPA, the employee could face a minimum
fine of $100 and a maximum up to $50, 000 per violation. Jail time for the
employee could be up to 1 year. If the same employee knowingly violates HIPPA,
but attempts to correct the issue, the minimum fine is $10, 000, going up to a
maximum of $50,000. The employee could face up to 10 years in jail.
, c. Identify two appropriate ways to secure data from one working shift to another
using HIPAA guidelines.
Staff can make efforts to protecting PHI by keeping a password on their
computer, and locking their computer when they get up and leave so no prying
eyes can log on and get into any patient health information. The staff can also
shred any files containing sensitive information when they are through discussing
the patients file with other staff members.
2. Complete an internal audit plan of all security measures meant to protect
health information by doing the following:
a. Identify which department will oversee the audit.
The information Technology department would be the best department to
perform the audit since IT is the ones who keep the computers protected with
passwords, and keeping the computers up to date with the latest antivirus
software.
b. Explain three security practices the audit will review (e.g., PHI sign-out sheets,
secured storage/location of records).
The IT department will perform the audit by verifying each computer is password
protected, and no two computers have the same password. They will verify each
computer is updated with the latest antivirus software to protect the server from
unwanted viruses. The department can then send out a fake phishing email,
addressed from an unknown source that will ask the employees to log on using
their hospital credentials.
c. Describe three potential changes that can be made within the organization to
address the results of the audit (e.g., additional employee education).
To address the results of the audit, the IT department can require every
employee to change their passwords every 90 days, to prevent anyone from
using someone else’s password. IT will then have the hospital server
automatically update each computer with the latest software so the computers
are always up-to-date, and protected from malware and viruses. Additional online
training will be assigned to every employee on how to identify phishing emails
and how to avoid giving out their logon credentials.
d. Create a risk assessment plan to identify the potential for any future security breaches.
Risk Assessment Report
Vulnerability Risk Impact Risk Recommended Best Organizational
Name Description Severity Level Practice Control Owner