Mind your compliance gaps to make sure you don’t take unnecessary risks

Image of GettyImages-1274989544.jpg

From our partners

This blog post is sponsored by NACo partner, Buck.

Buck is supporting HIPAA compliance which may be even more critical for county governments given their standing in the communities they serve and the sensitivity of the information being stored.

We take chances every day, in the firm hope of a payoff, no matter how small.  

But a breach of protected health information (PHI) or electronic protected health information (ePHI) could place your county at risk for fines for failing to comply with the Health Insurance Portability and Accountability Act (HIPAA).

Unlike some compliance requirements that only apply to the private sector, all public sector organizations are required to comply with HIPAA’s rules. In fact, HIPAA compliance may be even more critical for county governments given your standing in the communities you serve and the sensitivity of the information you store. With the increase in the number of remote workers, the ever-present threat of cybersecurity breaches, and, more recently, the privacy concerns around reproductive health, there are multiple reasons that reinforce the need for strong HIPAA compliance. 

Three steps to creating a comprehensive HIPAA compliance program

1) Document your HIPAA policies and procedures

Your HIPAA policies and procedures act as the playbook for how your group health plan will comply with HIPAA’s requirements and, as such, will be one of the first things checked if audited by the Health and Human Services Office of Civil Rights.

These documents are highly customized to the way your county operates.  Privacy policies and procedures address when, how, and to whom disclosures of PHI are permitted and how to obtain authorizations to release protected health information. They also identify your team members with access to PHI and prescribe who should be trained. 

The security policies and procedures describe how your county will protect PHI and e-PHI from a workplace and system security perspective. They incorporate physical, technical, and administrative safeguards accounting for the measures your employees will take to secure the HIPAA data you collect, store, and disseminate while administering the group health plan.

Individual rights, business associate agreements, forms, and templates such as the Notice of Privacy Practices, Uses and Disclosures Tracking Form, and Breach Incident Reporting Forms, are all typical components of a thoroughly documented privacy policy and procedure.

2) Assess your risks – HIPAA’s required risk threat analysis

A risk analysis considers a range of threats but also provides a range of possible solutions.

It’s important to note that health plans and their business associate vendors with access to protected health information have a responsibility to conduct a thorough risk assessment.

To conduct a risk analysis, your county must identify and inventory the locations where PHI and ePHI are stored. For example, there may be PHI in HRIS systems, email, various benefits administration systems, applications, physical storage locations, cloud servers, networks, and websites, to name a few.

Once inventoried, your team must weigh the likelihood/frequency, cost/impact, vulnerability, and mitigating controls of various types of natural, human, and environmental threats that may apply.  High-risk threats should be mitigated through safeguards until the risk is lowered to an acceptable level. The risk analysis itself must be well documented and shared with all involved parties responsible for protecting PHI/ePHI.

3) Train your workforce – HIPAA’s training requirement

For sponsors of group health plans, HIPAA training is a requirement. Lack of training for employees exposed to PHI was identified as a primary area of concern in audit reviews conducted by the Office of Civil Rights. It’s critical to include HIPAA training during the onboarding of new employees with access to PHI.  Attendance at all HIPAA training sessions should be documented, as these records can be requested during audits and investigations.

Training content must include “HIPAA basics” for those unfamiliar with the law, an overview of the privacy and security rules, including leading practices, and what steps to take in the event of a breach (including identification, notification, and additional tasks that may be necessary after a confirmed breach).

Of equal importance is to emphasize specific areas of concern within an organization and to update the content regularly to address new issues and threats along with leading practices to mitigate risk. Training should also capture when HHS issues new guidelines or rules and when there are changes in policies and procedures. 

Keep diligent

In today’s environment, it’s crucial to develop sound policies and procedures, perform systems assessments, document the necessary risk/threat analysis, and train your workforce to fulfill the responsibilities associated with handling PHI. 

Diligence is defined as a steady, earnest, and energetic effort, which is precisely what is called for when it comes to HIPAA compliance.  Although not a small undertaking, following these steps will result in your county being better prepared to address any of the challenges to the privacy and security of group health plan data that may lie ahead. 

To learn more about the compliance challenges facing county governments, register HERE for Buck’s September 28th webinar “Compliance challenges and best practices for public sector health and retirement plans.”

 

 

Post Sponsor

Image of Buck-GallagherCo_logo.png
Buck

Stories from our partners

NACo partners with the private sector on solutions.

Together, we are highlighting innovative solutions for counties, as we work with our federal, state, local and private sector partners to build healthy, safe and vibrant communities.

View all stories

Freight Train
News

Counties and Railroads: Shared Priorities for the Next Surface Transportation Bill

County leaders from across the country have a vital opportunity to ensure their infrastructure priorities are front and center.

Woman reading on a laptop
News

Unlocking AI Starts With Strong Data Governance

Strong data governance is the foundation of trustworthy AI in government. When Agencies inventory, clean, unify and steward their data, they unlock better decisions, improved services and stronger public trust.

Woman Typing on a computer
News

How County Governments Thrive with Cloud-Based Solutions

Modern cloud infrastructure enables agencies to better meet residents and workforce needs. Agencies report increased efficiencies as well as reduction of technical and operational debt as they replace aging, fragmented systems.

man pointing at a cybersecurity shield with a checkmark and then a checklist is next to it
News

The Cybersecurity Health Check List: Ensure Your Cybersecurity Program is Healthy and Resilient

Many organizations neglect their cybersecurity "health," leaving them vulnerable to sudden, catastrophic cyberattacks. By following a simple cybersecurity health checklist, you can ensure your organization's cybersecurity program is healthy and resilient. 

Yellow Hazard sign that says relief
News

APS Expands Heat Relief Efforts in Maricopa County, Arizona

APS supports and partners with community organizations and nonprofits to provide heat relief.

Are Your Ready Street Sign
News

Prepared to respond: How counties can strengthen readiness amid federal emergency management policy changes

As local leaders, you are often the first call - and the final line of defense - when disaster strikes. From hurricanes and wildfires to floods and winter storms, natural disasters are growing in both frequency and intensity nationwide.

Light a Path Image
News

#LightAPath for Amazon Deliveries This Winter

During reduced daylight hours, Amazon is encouraging customers to help drivers when they are delivering their packages in the dark.

HIPAA compliant
News

New in 2025: Counties Should Prepare Now for the Upcoming HIPAA Security Rule Update

Counties across the country are leveraging the Sectri platform to achieve HIPAA Security Rule compliance and to proactively prepare for the updated requirements set to be finalized in 2025.

Opioid crisis
News

America's Opioid Crisis: Counties as Frontline Forces in the Fight

Counties serve as the first line of defense, providing essential services in public health, mental health, law enforcement and social services - supporting communities in crisis and driving lasting recovery.

Prevent
News

Empowering Communities: How County Leaders are Tackling the Opioid Crisis Head-On

Forward-thinking county leaders are implementing year-round strategies to prevent overdoses, educate communities about the importance of proper drug disposal and connect residents with local resources for support.

Tech
News

County collaboration is key to overcoming the cybersecurity talent shortage

In the United States, citizens depend on county governments to deliver many of the nation’s most critical services. These organizations play a crucial role in ensuring overall community well-being by managing essential services such as law enforcement, public health, infrastructure maintenance, and emergency response.

AGA
News

DTE Energy bringing natural gas, opportunity to Tri-County Region in Northern Michigan

Residents of Benzie, Manistee and Wexford counties in Michigan can breathe a sigh of relief this winter as natural gas becomes available in the region for the first time leading to significant savings, increased comfort and improved reliability.

Windmill
News

Building Resilience Against Climate Change – Insights from Tidal Basin

Carlos J. Castillo, President of Federal Services at Tidal Basin, emphasized the critical role of emergency management in local climate resilience at the 2024 NACo Legislative Conference and Annual Conference.

Telecommunications
News

Investing Over $100 Billion in American Infrastructure

AT&T has invested over $140 billion in the past five years to enhance American connectivity, focusing on expanding its role as the nation's largest fiber internet provider and improving its reliable 5G network, which now serves nearly 290 million people.

Computer servers
News

Building Networks for the Next Century, Not the Last One

AT&T emphasizes its nearly 150-year history of innovation and connectivity as it transitions from traditional copper landlines to modern fiber and wireless technologies, highlighting the importance of adapting to current consumer demands and technological advancements.

Home construction
News

Travis County Develops 2,000 Units of Housing to Address Homelessness

This post is sponsored by our partners at Guidehouse. Through Guidehouse's comprehensive support, Travis County is on track to successfully create over 2,000 units of affordable, supportive housing by 2027.

Picnic
News

Feeding kids during the summer requires county officials

The introduction of the Summer Electronic Benefit Transfer program marks a pivotal shift in addressing childhood hunger, especially during the summer when school meals are unavailable. This nationwide initiative, offering substantial grocery benefits, promises transformative support for over 29 million children, with a significant impact on communities facing systemic inequalities.

Programmers
News

Why customer-centric strategy is vital for digital service adoption

The importance of a customer-centric strategy in digital service adoption for county governments is emphasized, highlighting the need for thoughtful design, clear communication, and multi-channel engagement to meet user expectations and improve customer experience.

EMS
News

Fighting opioid addiction – one life at a time

The opioid crisis, a major national issue, saw a 55% increase in drug overdose deaths from 2019 to 2022, with 75% involving opioids. Effective strategies to combat this include integrated care, policy enhancement, and technology, focusing on whole-person care and intervention opportunities to save lives.

Building facade
News

Planning for the post-American Rescue Plan Act future

Guidehouse outlines strategies for state and local governments to sustain programs after the end of American Rescue Plan Act (ARPA) State and Local Fiscal Recovery Funds (SLFRF) funding. It emphasizes the need for reassessing constituent needs, measuring program impact, and considering fiscal implications to ensure long-term viability and effective resource allocation for programs initially funded by SLFRF.

Group with hands in
News

How voluntary benefits can help improve your employee benefit package

Voluntary benefits, tailored to diverse employee needs and often at reduced costs, are proving essential in enhancing employer benefit packages, attracting, and retaining talent, and addressing specific wellbeing issues across different age and income groups.

Deterra
News

A countywide opioid misuse prevention campaign is easier to implement than you think

The Deterra Household Mailing Campaign delivers educational tools and deactivation pouches directly to homes. To save lives by tackling the opioid crisis.

Fire danger sign
News

From prevention to resilience: Strategies in wildfire mitigation

Explore a multifaceted approach to wildfire mitigation with Tidal Basin. From creating defensible spaces to early detection systems, discover strategies fostering resilient communities, protecting lives & property. Urgent action is crucial amidst rising wildfire risks. Learn more at TidalBasinGroup.com. 

Related News

bike
Press Release

NACo launches 2026 Public Health Leadership Academy Cohort to Strengthen County Health

The National Association of Counties (NACo) announces the launch of the inaugural 2026 Public Health Leadership Academy. 

1501185765
Advocacy

CMS announces new funding opportunity to promote holistic health innovation

On March 13, the Centers for Medicare & Medicaid Services (CMS) released a Notice of Funding Opportunity (NOFO) for the Make America Healthy Again – Enhancing Lifestyle and Evaluating Value-based Approaches Through Evidence (MAHA ELEVATE) Model.

NACIO President Schuyler Harding discusses the importance of storytelling at a NACo-NACIO workshop on the topic. Photo by Denny Henry
County News

County officials urged to use storytelling to strengthen advocacy, public trust

“People experience these services every day, but they don’t always see the county’s role behind them.”