{"id":7370,"date":"2025-11-05T06:39:41","date_gmt":"2025-11-05T12:39:41","guid":{"rendered":"https:\/\/pmaworks.com\/observations\/?p=7370"},"modified":"2025-12-04T06:42:52","modified_gmt":"2025-12-04T12:42:52","slug":"ask-lisa-compliance-201-your-shield-against-bad-risk","status":"publish","type":"post","link":"https:\/\/pmaworks.com\/observations\/ask-lisa-compliance-201-your-shield-against-bad-risk\/","title":{"rendered":"Ask Lisa &#8211; Compliance 201:  Your Shield Against Bad Risk"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-7371 aligncenter\" src=\"https:\/\/pmaworks.com\/observations\/wp-content\/uploads\/2025\/11\/compliance.jpg\" alt=\"compliance in the health care field for chiropractors\" width=\"430\" height=\"290\" \/>As a follow-up to our previous compliance articles, I thought what I\u2019d do this month is put together a FAQ list for my dear readers and call it Compliance 201. Keep reading to learn about upcoming new requirements in the compliance\/cybersecurity world to keep you at least safe-guarded when you are hit with a cybersecurity incident. Special thanks and credit goes out to ChiroArmour and Dr. Scott Muensterman for his research and presenting at the Chiropractic Society of Wisconsin Fall Experience last month on some of the content in my FAQ.<\/p>\n<p><strong>Q:<\/strong> What is HIPAA and HITECH?<br \/>\n<strong>A:<\/strong> HIPAA is the acronym for Health Insurance Portability and Accountability Act of 1996, in which uniform standards and requirements for the electronic transmission of certain health information were put into place and made into law. HITECH is the acronym for Health Information Technology for Economic and Clinical Health Act of 2009, a countrywide adoption and standardization of information technology to securely support the sharing of clinical data.<\/p>\n<p><strong>Q:<\/strong> What is Cybersecurity?<br \/>\n<strong>A:<\/strong> Cybersecurity is the practice of protecting digital systems, networks, and data from malicious attacks, damage, and unauthorized access.<\/p>\n<p><strong>Q:<\/strong> Is there a checklist available to ensure we are in compliance?<br \/>\n<strong>A:<\/strong> Yes.\u00a0Current and Active PM&amp;A clients have access to our HIPAA\/HITECH compliance checklist, on the <a href=\"https:\/\/pmamembers.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-link-type=\"web\"><span style=\"color: #008080;\">PMA Members Site<\/span><\/a>, and compliance services are included upon request from the client.\u00a0\u00a0If you are currently inactive or not a client, we can provide you with the checklist for a nominal fee.\u00a0Please keep in mind your staff are already very busy, so ask yourself who is going to take on ensuring compliance at your office and going through the checklist?\u00a0We can help.<\/p>\n<p><strong>Q:<\/strong> Isn\u2019t it a matter of IF a cyberattack at my office occurs, not WHEN as you stated above?<br \/>\n<strong>A:<\/strong> On average there are 11 to 12 cyberattacks happening per minute in the US. So in today\u2019s world yes, it is a matter of when, not if. And after research, it has been found that small businesses are more of a target for an attack than large organizations mainly because large organizations can put more dollars into security measures.<\/p>\n<p><strong>Q:<\/strong> What does Windows 10 and Windows 11 have to do with compliance?<br \/>\n<strong>A:<\/strong> Windows 10 no longer supports the security patches it used to support, effective 10\/25\/2025, so all of your computers must be operating on Windows 11 at minimum by this time. You CAN extend your Windows 10 protection for 1, 2, or 3 years at a significant price, but your software vendor may not honor the upgrade.<\/p>\n<p><strong>Q:<\/strong> I heard that there is something called an OIG Exclusions report \u2013 what is this and does it affect me and my practice?<br \/>\n<strong>A:<\/strong> The OIG Exclusions database is a reporting site listing every individual who is prohibited from seeing Medicare\/Medicaid patients due to prosecution of a criminal activity, which can include being found guilty of fraud against Medicare\/Medicaid, non-compliance of court-ordered child support payments, and illegal drug convictions. It is and will be a requirement to run a report MONTHLY on every person in your office including owners, subcontractors, and upon a new hire.<\/p>\n<p>Here\u2019s the link to check names:<span style=\"color: #008080;\">\u00a0<a style=\"color: #008080;\" href=\"https:\/\/exclusions.oig.hhs.gov\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #008080;\">https:\/\/exclusions.oig.hhs.gov\/<\/span><\/a><\/span><br \/>\nIf you don\u2019t see your name, that\u2019s a good thing. Some of you are already running and checking this report due to insurance contract requirements. Save or print and file the results page.<\/p>\n<p><strong>Q:<\/strong> How can I confirm if my practice management program is fully compliant?<br \/>\n<strong>A:<\/strong> The website for verifying compliant healthcare software programs is down as of this writing, so for peace of mind if you are not 100% certain, call your software company or IT person.<\/p>\n<p><strong>Q:<\/strong> When do changes\/new requirements occur?<br \/>\n<strong>A:<\/strong> As of now, no date has been set by HHS, but if you are doing the above steps and have written policies in place, you should not worry, but watch for future communications. You can subscribe to HHS email notifications here: https:\/\/cloud.connect.hhs.gov\/subscriptioncenter<\/p>\n<p><strong>Q:<\/strong> What does Medicare documentation have to do with cybersecurity?<br \/>\n<strong>A:<\/strong> To avoid a documentation audit and subsequent potential visit from the OIG to further audits on compliance with HIPAA and your cybersecurity policies, keep your documentation and billing practices solid per Medicare chiropractic documentation standards, and make sure to securely send your notes to Medicare upon audit (and any other payer group who requests) to ensure you are staying HIPAA compliant.<\/p>\n<p><strong>Q:<\/strong> Can my staff be our Security officer?<br \/>\n<strong>A:<\/strong> By law, yes, but you as the doctor owner are always ultimately responsible for any attack or breaches, and payments to the government, so it is strongly recommended that the doctor owner be the compliance security officer for the business.<\/p>\n<p>That concludes our FAQ for now. I know you\u2019ll have additional questions. Feel free to reach out with those we\u2019ll respond within three calendar days!<\/p>\n<p>Stay Secure,<\/p>\n<p>Lisa<\/p>\n<p>References: <a href=\"https:\/\/chiroarmor.com\/\" target=\"_blank\" rel=\"noopener\"><span style=\"color: #008080;\">ChiroArmour<\/span><\/a><\/p>\n<p>&nbsp;<\/p>\n<div>\n<style>.pp-AHQWR7DDVKRJN{text-align:center;border:none;border-radius:1.5rem;min-width:11.625rem;padding:0 2rem;height:2.625rem;font-weight:bold;background-color:#EF5424;color:#000000;font-family:\"Helvetica Neue\",Arial,sans-serif;font-size:1rem;line-height:1.25rem;cursor:pointer;}<\/style>\n<form action=\"https:\/\/www.paypal.com\/ncp\/payment\/AHQWR7DDVKRJN\" method=\"post\" target=\"_blank\" style=\"display:inline-grid;justify-items:center;align-content:start;gap:0.5rem;\">\n    <input class=\"pp-AHQWR7DDVKRJN\" type=\"submit\" value=\"Buy Now\" \/><br \/>\n    <img src=https:\/\/www.paypalobjects.com\/images\/Debit_Credit_APM.svg alt=\"cards\" \/><\/p>\n<section style=\"font-size: 0.75rem;\"> Powered by <img decoding=\"async\" src=\"https:\/\/www.paypalobjects.com\/paypal-ui\/logos\/svg\/paypal-wordmark-color.svg\" alt=\"paypal\" style=\"height:0.875rem;vertical-align:middle;\"\/><\/section>\n<\/p><\/form>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>As a follow-up to our previous compliance articles, I thought what I\u2019d do this month is put together a FAQ list for my dear readers and call it Compliance 201. Keep reading to learn about upcoming new requirements in the &hellip; <a href=\"https:\/\/pmaworks.com\/observations\/ask-lisa-compliance-201-your-shield-against-bad-risk\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702,176,559,64,7],"tags":[404,361,770,771,482,359,377,367,104,772],"class_list":["post-7370","post","type-post","status-publish","format-standard","hentry","category-ask-lisa","category-chiropractic-2","category-medicare","category-medicare-audit","category-chiropractic-reimbursement-insurance","tag-barnett","tag-chiropractic","tag-cyber","tag-cyber-security","tag-goal-driven","tag-marketing","tag-michel","tag-petty","tag-practice-management-2","tag-security"],"_links":{"self":[{"href":"https:\/\/pmaworks.com\/observations\/wp-json\/wp\/v2\/posts\/7370","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pmaworks.com\/observations\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pmaworks.com\/observations\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pmaworks.com\/observations\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/pmaworks.com\/observations\/wp-json\/wp\/v2\/comments?post=7370"}],"version-history":[{"count":10,"href":"https:\/\/pmaworks.com\/observations\/wp-json\/wp\/v2\/posts\/7370\/revisions"}],"predecessor-version":[{"id":7387,"href":"https:\/\/pmaworks.com\/observations\/wp-json\/wp\/v2\/posts\/7370\/revisions\/7387"}],"wp:attachment":[{"href":"https:\/\/pmaworks.com\/observations\/wp-json\/wp\/v2\/media?parent=7370"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pmaworks.com\/observations\/wp-json\/wp\/v2\/categories?post=7370"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pmaworks.com\/observations\/wp-json\/wp\/v2\/tags?post=7370"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}