
ANSWER THE FOLLOWING QUESTIONS:
⊛ Have you performed a Security Risk Assessment?
⊛ Do you have an appointed a compliance officer for your practice?
⊛ Have your Business Associates signed Business Associate Agreements?
⊛ Do you have disaster recovery policies and procedures in place?
⊛ Do you have emergency operation procedures in place?
⊛ Are procedures in place to facilitate proper ePHI access being granted?
⊛ Do you have a policy in place for terminating a staff members access to ePHI?
⊛ Are all staff members required to go through security training?
⊛ Can you provide an OIG manual if Medicare came knocking on your door?
⊛ Do you have procedures for disposal of electronic media that stores ePHI?
⊛ Does your practice encrypt email to protect ePHI and important information sent through email?