An OCR data request answered in nine business days.
A specialty physician group received a data request following a business associate’s breach. The request had a thirty-day clock on it.
- 9 days
- To a complete response, against a 30-day clock
- 0
- Penalties assessed
- 0
- Artifacts created after the request arrived
What was asked for
Eleven categories of document. The current risk analysis and the methodology behind it. The risk management plan with evidence of completed remediation. The asset inventory and the ePHI data-flow map. Workforce training records with dates and role assignments. The business associate register with executed agreements. Access review and termination records. Audit log samples. The incident response plan and evidence it had been tested. Encryption status. Policies with version history. Prior incident history.
This is a fairly standard list. It is also, more or less exactly, the contents of the evidence file.
What we did
Assembled the response. That is the entire description of the work, and it is the point. Every one of the eleven categories already existed as a maintained, dated artifact. Nothing was produced after the request arrived, which matters enormously: an investigator reading a risk analysis dated two weeks after the data request understands exactly what happened.
The bulk of the nine days was the group’s counsel reviewing the package and the vCISO writing the cover narrative that explained how the artifacts related to one another. The evidence-gathering itself took under two days.
The Recognized Security Practices claim
The response included a Recognized Security Practices attestation covering twelve rolling months of enterprise-wide implementation, submitted under the HITECH amendment signed January 5, 2021. Where a regulated entity can demonstrate Recognized Security Practices were in place for the previous twelve months, OCR must consider that as a mitigating factor.
This is a statutory discount that costs nothing but disciplined recordkeeping, and almost no organization this size has the twelve months of documentation required to claim it. Making it claimable is a design goal of the evidence file, not a happy accident.
Outcome
The matter was closed without penalty and without a corrective action plan. We have supported four OCR data requests and investigations since founding. Zero penalties have been assessed against a Chartline client.
The whole result, in one table.
Including the figures that are less flattering than the headline. A case study that only contains good numbers is an advertisement.
Two more, also with numbers.
An 11-location dental group, encrypted on a Thursday night.
Practice management server, imaging server, and the backup share, all encrypted. Chairs were seeing patients again in 31 hours.
Read it DSO integrationTwelve acquired practices, three PM systems, one standard.
A dental support organization had grown by acquisition for four years and inherited twelve environments nobody had ever standardized.
Read it