Business Continuity and HIPAA: Business Continuity Management in the Health Care Environment
This book will examine business continuity planning as adapted to encompass the requirements of The Health Care Portability and Accountability Act of 1996, or HIPAA. We will examine the typical business continuity planning model and highlight how the special requirements of HIPAA have shifted the emphasis. The layout of this book was designed to afford assistance, hints, and templates to the person or team charged with the task of implementing business continuity planning into a healthcare organization.You will notice that this book does not address Emergency Management (building evacuations and other immediate response procedures), which is outside the scope of the HIPAA regulations.Upon reading and re-reading the HIPAA regulations and the ?Comments and Responses? in the federal register, it becomes quite evident that the ?Contingency Plan? (read Business Continuity Plan) requirements were written by those looking to protect health information data. That being said, many of the examples that I use in this book relate to information technology and disaster recovery (recovery of computer capabilities). What is also important, and that I try to emphasize throughout the book, is that recovering the computer systems of a health care organization will not necessarily get it operational again after a disaster; a multitude of other production and operational components must be present in order to deliver services and products to customers/patients. Where appropriate, I have identified procedures and strategies that are unique to healthcare provider organizations. If not so indicated, it can be assumed that I am referring to healthcare organizations in general.The audience for whom I have designed this book are the people who are responsible for implementing a business continuity plan in a healthcare organization that comes under the scope of the HIPAA regulations. At first reading, the book may appear to be an exact template to be used to design a business continuity plan. What I hope that you will get out of the book (perhaps on a reread once you are into the planning project) is that this is a pencil outline on a canvas and that your insights and knowledge of your healthcare organization will add the color that will make it a masterpiece.What you will notice in this book is that we present an approach that is similar to traditional business continuity planning. This is done purposefully. The basic business continuity planning model looks to protect and/or recover all critical components of production. This model assumes an industry-specific nature not by changing the model itself, but by placing greater emphasis on the protection and recovery of those production resources that characterize that industry. In our view, ?thinking outside the box? is only required if the box was ill-conceived in the first place. Accordingly, this book can also be appropriate for many non-healthcare organizations.This book will include the special precautions and procedures that address the unique concerns of HIPAA, but it will present them along with the other business components in order to emphasis the need to take a holistic approach when constructing and maintaining a business continuity plan.
What people are saying - Write a review
We haven't found any reviews in the usual places.
ABCD Action Plan alternate backup tapes Barnes TASK Business Continuity Institute Business Continuity Management business continuity planning Business Impact Analysis business processes business unit Compaq components Compterville configuration Contact Name Coordinator customers Damage Assessment determine developed disaster declaration Disaster Recovery disk document electrical electronic Emergency Management Team employees entity Environment TASK Ethernet event files hardware HCPCS Health Care Environment health information healthcare organization healthcare organization's HIPAA hot-site identify installation Insurance James maintained maintenance Mitigation off-site operations outage parallel port personnel Phone procedures production protect recover recovery facility recovery plan Recovery Point Objective Recovery Time Objective Resource Item responsible restoration SCSI servers SERVICE LEVEL AGREEMENTS specific standards storage strategy Task Force team members Total Votes transactions Vendor Name Telephone