Client support portal Pay invoice Sales(615) 555-0110 Support(615) 555-0111
Chartline Health IT
OCR data request

An OCR data request answered in nine business days.

A specialty physician group received a data request following a business associate’s breach. The request had a thirty-day clock on it.

9 days
To a complete response, against a 30-day clock
0
Penalties assessed
0
Artifacts created after the request arrived
The organization
Organization Specialty physician group
Market East Tennessee
Locations 5
Users 73
Engagement Chartline Compliant, 2 years in

What was asked for

Eleven categories of document. The current risk analysis and the methodology behind it. The risk management plan with evidence of completed remediation. The asset inventory and the ePHI data-flow map. Workforce training records with dates and role assignments. The business associate register with executed agreements. Access review and termination records. Audit log samples. The incident response plan and evidence it had been tested. Encryption status. Policies with version history. Prior incident history.

This is a fairly standard list. It is also, more or less exactly, the contents of the evidence file.

What we did

Assembled the response. That is the entire description of the work, and it is the point. Every one of the eleven categories already existed as a maintained, dated artifact. Nothing was produced after the request arrived, which matters enormously: an investigator reading a risk analysis dated two weeks after the data request understands exactly what happened.

The bulk of the nine days was the group’s counsel reviewing the package and the vCISO writing the cover narrative that explained how the artifacts related to one another. The evidence-gathering itself took under two days.

The Recognized Security Practices claim

The response included a Recognized Security Practices attestation covering twelve rolling months of enterprise-wide implementation, submitted under the HITECH amendment signed January 5, 2021. Where a regulated entity can demonstrate Recognized Security Practices were in place for the previous twelve months, OCR must consider that as a mitigating factor.

This is a statutory discount that costs nothing but disciplined recordkeeping, and almost no organization this size has the twelve months of documentation required to claim it. Making it claimable is a design goal of the evidence file, not a happy accident.

Outcome

The matter was closed without penalty and without a corrective action plan. We have supported four OCR data requests and investigations since founding. Zero penalties have been assessed against a Chartline client.

Outcome

The whole result, in one table.

Including the figures that are less flattering than the headline. A case study that only contains good numbers is an advertisement.

Document categories requested 11
Categories already maintained as dated artifacts 11
Artifacts created after the request arrived 0
Time to complete response 9 business days
Clock allowed 30 days
Recognized Security Practices claim Submitted, 12 rolling months
Outcome Closed without penalty or corrective action plan
Your turn

Where would you land on the same questions?

The readiness check runs the fifteen questions we open every assessment with. It takes about eight minutes and it names the §164 citation behind every gap.

Under attack right now? (615) 555-0119

Our incident line is answered 24/7/365 by a security engineer, not a queue. Clients and non-clients both. If you are mid-incident, call before you email.