{"id":10018,"date":"2021-02-02T15:21:00","date_gmt":"2021-02-02T20:21:00","guid":{"rendered":"https:\/\/www.sage.com\/en-us\/blog\/?p=10018"},"modified":"2024-08-21T15:10:56","modified_gmt":"2024-08-21T19:10:56","slug":"healthcare-understand-risks-benefits-hipaa-phi-2021","status":"publish","type":"post","link":"https:\/\/www.sage.com\/en-us\/blog\/healthcare-understand-risks-benefits-hipaa-phi-2021\/","title":{"rendered":"Healthcare finance leaders: understand the risks &#038; benefits of HIPAA and PHI in 2021"},"content":{"rendered":"<header class=\"entry-header has-dark-background-color entry-header--has-illustration entry-header--has-illustration--generic\">\n\t<div class=\"container\">\n\t\t<div class=\"entry-header__row row align-center\">\n\t\t\t<div class=\"col col-lg-7 col-xlg-6 entry-header__content\">\n\t\t\t\t\t\t\t<div class=\"component component-single-header\">\n\t\t\t\t\t\t\t\t\t\t<div class=\"entry-header__misc text--subtitle text--uppercase text--small\">\n\t\t\t\t\t\t\t<a href=\"https:\/\/www.sage.com\/en-us\/blog\/category\/people-leadership\/\" class=\"entry-header__link\">People &amp; Leadership<\/a>\t\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t<div class=\"entry-title-wrapper\">\n\t\t\t\t\t<h1 class=\"entry-title\">\n\t\t\t\t\t\tHealthcare finance leaders: understand the risks &#038; benefits of HIPAA and PHI in 2021\t\t\t\t\t<\/h1>\n\t\t\t\t<\/div>\n\n\t\t\t\t\t\t\t\t\t<p class=\"entry-header__description\">\n\t\t\t\t\t\t\t\t\t\t\t<\/p>\n\t\t\t\t\n\t\t\t\t\n\t\t\t\t\n\t\t\t<\/div>\n\n\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/div>\n\t<div class=\"single-post-details container\">\n\t\t<div class=\"col\">\n\t\t\t<span class=\"posted-on \"><time class=\"entry-date published\" datetime=\"2021-02-02T15:21:00-05:00\">February 2, 2021<\/time><\/span><span class=\"reading-time\"> min read<\/span>\n\t\t<button\n\t\t\ttype=\"button\"\n\t\t\tclass=\"social-share-button button button--icon button--secondary js-social-share-button\"\n\t\t\tdata-share-title=\"Healthcare finance leaders: understand the risks &#038; benefits of HIPAA and PHI in 2021\"\n\t\t\tdata-share-url=\"https:\/\/www.sage.com\/en-us\/blog\/healthcare-understand-risks-benefits-hipaa-phi-2021\/\"\n\t\t\tdata-share-text=\"Please read this interesting article\"\n\t\t>\n\t\t\t<span class=\"social-share-button__share-label\">Share<\/span>\n\t\t\t<span class=\"social-share-button__copy-label\" hidden>Copy Link<\/span>\n\t\t\t<span class=\"social-share-button__copy-tooltip\" aria-hidden=\"true\" hidden>Copied<\/span>\n\t\t<\/button>\n\n\t\t\t\t<\/div>\n\t<\/div>\n<\/header>\n\n\n<div class=\"wp-block-post-author has-dark-background-color alignfull\">\n\t<div class=\"container\">\n\t\t<div class=\"col\">\n\t\t\t\t\t\t\t<div class=\"co-authors\">\n\t\t\t\t\t\n\t\t<div class=\"entry-author-wrapper\">\n\t\t\t<a class=\"entry-author\" href=\"https:\/\/www.sage.com\/en-us\/blog\/author\/melissa-odowd\/\">\n\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"40\" height=\"40\" src=\"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/09\/Mel-ODowd_Headshot_Square-350x350.jpg\" class=\"entry-author__image\" alt=\"\" srcset=\"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/09\/Mel-ODowd_Headshot_Square-350x350.jpg 350w, https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/09\/Mel-ODowd_Headshot_Square-768x768.jpg 768w, https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/09\/Mel-ODowd_Headshot_Square-810x810.jpg 810w, https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/09\/Mel-ODowd_Headshot_Square-1536x1536.jpg 1536w, https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/09\/Mel-ODowd_Headshot_Square.jpg 1994w\" sizes=\"auto, (max-width: 40px) 100vw, 40px\" \/>\t\t\t\t<span class=\"entry-author__name\">Melissa O&#039;Dowd<\/span>\n\t\t\t<\/a>\n\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t<\/div>\n<\/div>\n\n\n\n<p>More and more finance teams are integrating PHI into their financial systems and <a href=\"https:\/\/www.sage.com\/en-us\/industry\/healthcare\/\">hipaa compliant accounting solutions <\/a>to facilitate activities including patient collections, new products and services and insight into performance-based reimbursement programs. As a result, financial and business leaders can no longer assume the risk of a potential breach is limited to clinical software and must become more aware of the changing dynamics and risks associated with protecting their patients\u2019 PHI in the financial suite.<\/p>\n\n\n\n<p>If we use 2020 as an example, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued a record 19 resolution agreements for the Health Insurance Portability and Accountability Act (HIPAA) and the HIPAA Privacy Rule despite the ongoing pandemic.<sup>1<\/sup> This shows that OCR did not lose sight of the continuing need for provider organizations to secure protected health information (PHI) from potential breaches. All signs point to OCR and HHS continuing to enhance HIPAA regulations in response to the continuing pandemic, as provider organizations expand their use of PHI and participate in new business models like value-based reimbursement and more.<sup>2<\/sup><\/p>\n\n\n\n<p>Simply rolling back the use of PHI is not an option either, as the \u201ctoothpaste is already out of the tube,\u201d and PHI now plays a critical role in understanding the financial performance of the business. Financial leaders must instead employ strategies to ensure their policies, procedures and financial management systems are HIPAA-compliant.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-understanding-phi-and-hipaa\">Understanding PHI and HIPAA<\/h2>\n\n\n\n<p>PHI is defined as \u201chealth information that relates to the past, present, or future physical or mental health or condition of an individual; the provision of health care to an individual; or the past, present, or future payment for the provision of health care to an individual.\u201d<sup>3<\/sup> In addition to information contained within medical records, correspondence, billing information or virtually any patient-identifiable information is considered PHI and must be protected from potential breach. That means something as simple as a patient name can be considered PHI.<\/p>\n\n\n\n<p>Healthcare organizations, including health plans, providers and clearinghouses must follow HIPAA guidelines and the HIPAA Privacy Rule, and must also have contracts in place (called <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/covered-entities\/sample-business-associate-agreement-provisions\/index.html\" target=\"_blank\" rel=\"noopener\">Business Associate Agreements<\/a>) with many of their contractors and subcontractors, to safeguard the use of PHI to ensure it is not disclosed in violation of HIPAA. Organizations that fail to protect PHI or experience a breach put themselves at risk of a <span style=\"background-color: transparent;\">HIPAA violation.<\/span><\/p>\n\n\n\n<p>And the impact can be significant, with healthcare data breaches costing an average of 60% more \u2013 or $6.45 million \u2013 than cross-industry averages to remedy. That equates to an average of $429 spent per lost or stolen record to implement breach detection and response, notification of affected patients, lost business due to downtime, reputational damage, and impact to patient trust.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-text-align-left\"><strong>Sage Intacct is certified as HIPAA- and HITECH-compliant by Avertium (formerly Sword &amp; Shield) and enters into Business Associate Agreements with eligible healthcare clients.<\/strong><\/p>\n<\/blockquote>\n\n\n<div class=\"single-simple-button__container\"><a class=\"single-simple-button button button--primary\" role=\"button\" href=\"https:\/\/www.sage.com\/en-us\/sage-business-cloud\/intacct\/industry\/healthcare\/\">Read more about how Sage Intacct works with healthcare organizations<\/a><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-practical-strategies-for-managing-phi-in-a-financial-setting\">Practical strategies for managing PHI in a financial setting<\/h2>\n\n\n\n<p>To help finance leaders better manage and protect PHI in their own teams and across the organization, Sage Intacct recently retained market research firm Porter Research to assess finance leaders\u2019 awareness and understanding of the risks associated with PHI and HIPAA violations.<\/p>\n\n\n\n<p>The resulting whitepaper, \u201cNew Research: Finance Professionals &amp; PHI,\u201d reviews five key findings including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>How to use PHI to understand your business<\/li>\n\n\n\n<li>Why PHI and HIPAA are misunderstood by financial teams<\/li>\n\n\n\n<li>Being prepared for and understanding of the consequences of HIPAA violations<\/li>\n<\/ul>\n\n\n\n<div class=\"single-cta gated-content\">\n\t<div class=\"single-cta__positioner\">\n\t\t<div class=\"single-cta__wrapper has-dark-background-color\">\n\t\t\t<div class=\"single-cta__content\">\n\t\t\t\t\t\t\t\t<h2 class=\"single-cta__title h3\">New Research: Finance Professionals and PHI <\/h2>\n\n\t\t\t\t\t\t\t\t\t<div class=\"single-cta__description\">\n\t\t\t\t\t\t<p><!-- wp:paragraph --><\/p>\n<p class=\"\">Financial systems may be putting non-acute providers at risk for HIPAA violations.<\/p>\n<p><!-- \/wp:paragraph --><\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a\n\t\t\t\t\t\thref=\"#gate-cf5884ca-0209-4b4b-b841-4ac385b8a1c7\"\n\t\t\t\t\t\tclass=\"single-cta__button button button--primary\"\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t>Read the White Paper<\/a>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<img decoding=\"async\" width=\"1440\" height=\"810\" src=\"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/04\/GettyImages-1227349947-1440x810.jpg\" class=\"single-cta__image\" alt=\"Female scientist working in a laboratory\" loading=\"lazy\" srcset=\"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/04\/GettyImages-1227349947-1440x810.jpg 1440w\" sizes=\"auto, (min-width: 48em) 33vw, 100vw\" \/>\t\t\t<\/div>\n<\/div>\n\n\n\n\n<p>As you hit the ground running in 2021 and use PHI to understand the financial performance of your organization, be ready for the next change to HIPAA and the HIPAA Privacy Rule and what it might mean for your business.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-sources\">Sources<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/compliance-enforcement\/agreements\/index.html\" target=\"_blank\" rel=\"noopener\">\u201cResolution Agreements and Civil Money Penalties\u201d<\/a> US. Department of Health &amp; Human Services<\/li>\n\n\n\n<li><a href=\"https:\/\/www.hipaajournal.com\/hipaa-updates-hipaa-changes\/\" target=\"_blank\" rel=\"noopener\">\u201cPossible HIPAA Updates and HIPAA Changes in 2021\u201d<\/a> HIPAA Journal<\/li>\n\n\n\n<li><a href=\"https:\/\/www.law.cornell.edu\/cfr\/text\/45\/160.103\" target=\"_blank\" rel=\"noopener\">HIPAA Definitions<\/a>, Legal Information Institute, Cornell Laws School<\/li>\n\n\n\n<li>Landi, Heather, <a href=\"https:\/\/www.fiercehealthcare.com\/tech\/healthcare-data-breach-costs-average-6-45m-60-higher-than-other-industries-report\" target=\"_blank\" rel=\"noopener\">\u201cHealthcare data breaches cost an average $6.5 M: report\u201d<\/a> Fierce Healthcare, July 23, 2019<\/li>\n<\/ol>\n\n\n\n<p><\/p>\n\n\n<div class=\"single-cta\">\n\t<div class=\"single-cta__positioner\">\n\t\t<div class=\"single-cta__wrapper has-dark-background-color\">\n\t\t\t<div class=\"single-cta__content\">\n\t\t\t\t\t\t\t\t<h2 class=\"single-cta__title h3\">Subscribe to our Sage Advice Newsletter<\/h2>\n\n\t\t\t\t\t\t\t\t\t<div class=\"single-cta__description\">\n\t\t\t\t\t\t<p>Get our latest business advice delivered directly to your inbox.<\/p>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a\n\t\t\t\t\t\thref=\"#gate-ab515c6e-7e90-4c2f-a67e-113872516e8b\"\n\t\t\t\t\t\tclass=\"single-cta__button button button--primary\"\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t>Subscribe<\/a>\n\t\t\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<\/div>\n\n\t\t\t\t\t<img decoding=\"async\" width=\"1440\" height=\"810\" src=\"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/04\/GettyImages-1073797282-1440x810.jpg\" class=\"single-cta__image\" alt=\"Working from home with tea in hand\" loading=\"lazy\" srcset=\"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/04\/GettyImages-1073797282-1440x810.jpg 1440w\" sizes=\"auto, (min-width: 48em) 33vw, 100vw\" \/>\t\t\t<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>More and more finance teams are integrating PHI into their financial systems and hipaa compliant accounting solutions to facilitate activities including patient collections, new products and services and insight into performance-based reimbursement programs. As a result, financial and business leaders can no longer assume the risk of a potential breach is limited to clinical software [&hellip;]<\/p>\n","protected":false},"author":1442,"featured_media":8965,"menu_order":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sage_video":false,"post_featured_image_hide":false,"footnotes":""},"categories":[348,47],"tags":[420,128,154],"business_type":[40,41],"lilypad":[],"context":[418,429],"industry":[453,451,450,204],"persona":[98,96,97],"imagine_tag":[209,436],"coauthors":[845],"class_list":["post-10018","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-free-guides-templates","category-people-leadership","tag-cloud-financial-management","tag-customer-acquisition","tag-technology","business_type-small-business","business_type-growing-business","industry-biotech","industry-healthcare","industry-software-saas","industry-technology"],"sage_meta":{"region":"en-us","author_name":"Melissa O'Dowd","featured_image":"https:\/\/www.sage.com\/en-us\/blog\/wp-content\/uploads\/sites\/2\/2022\/04\/GettyImages-1145276299.jpg","imagine_tags":{"209":"Accounting","436":"Intacct Accounting"}},"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"Sage Advice US","distributor_original_site_url":"https:\/\/www.sage.com\/en-us\/blog","push-errors":false,"_links":{"self":[{"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/posts\/10018","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/users\/1442"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/comments?post=10018"}],"version-history":[{"count":0,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/posts\/10018\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/media\/8965"}],"wp:attachment":[{"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/media?parent=10018"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/categories?post=10018"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/tags?post=10018"},{"taxonomy":"business_type","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/business_type?post=10018"},{"taxonomy":"lilypad","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/lilypad?post=10018"},{"taxonomy":"context","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/context?post=10018"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/industry?post=10018"},{"taxonomy":"persona","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/persona?post=10018"},{"taxonomy":"imagine_tag","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/imagine_tag?post=10018"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.sage.com\/en-us\/blog\/api\/wp\/v2\/coauthors?post=10018"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}