ie8 fix

Should HIPAA compliance be outsourced?

By | January 10, 2008, 9:59am PST

Summary: What if PWC has to audit one of its own clients? The government says the company will recuse themselves. Does that mean the audit is then off? Better call PWC, then.

HIPAA imageCynergisTek, a computing and security consultant, reported on its blog recently that HIPAA compliance audits will be increased this year, thanks to a contract the government signed with PriceWaterhouseCoopers.

I admit that the significance of this went right by me at first. Then I went, “whaah?”

The government’s enforcement process has just been privatized.

Admittedly there is a huge backlog of audits. CynergisTek reports that the government has a list of over 100 active complaints concerning lax HIPAA compliance, which have to be checked out before anyone knocks on your door.

According to iHealthBeat, PWC is going to review 10-20 organizations under the one-year contract, so unless someone has an outstanding complaint against you you’re probably safe.

But the knock will come, CynergisTek promises. Oh, they work in that area and will be glad to hear from you.

Perhaps you think nothing of this. Nothing gets done on law enforcement until the government hires some private firm to do it. The assumption is the private firm will do it efficiently.

But I know how much a good PWC auditor costs, and I know how much the average civil service auditor makes. I guarantee the latter costs less, unless PWC itself is outsourcing this work to India or someplace.

And would it be too much to ask for the public, or at least the industry, to get a gander at that contract? On what basis is PWC being paid? What is their incentive? Is it a fixed price per audit, is it hourly, or is it based on the fines they collect?

The folks at iHealthBeat have another concern. What if PWC has to audit one of its own clients? The government says the company will recuse themselves. Does that mean the audit is then off? Better call PWC, then.

Given the excitement which occurs here whenever I mention the word HIPAA, chances are you have your own questions.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Disclosure

Dana Blankenhorn

Dana Blankenhorn has been a journalist, writer and part-time futurist for over 30 years. At the present moment I run only a personal blog in addition to my ZDNet open source blog. DanaBlankenhorn.Com has the subtitle The War Against Oil. In the past I have used it to write about political history, e-commerce, personal matters, some ideas related to open source, and The World of Always On, which is the idea of using sensors, motes and RFID to turn WiFi links into platforms for applications which live in the air. My IRA account at Schwab holds a few tech shares, most notably some Intel and Applied Materials, but there are no open source companies in it. I don’t even own any CBS stock.

Biography

Dana Blankenhorn

Dana Blankenhorn has been a business journalist since 1978, and has covered technology since 1982. He launched the Interactive Age Daily, the first daily coverage of the Internet to launch with a magazine, in September 1994.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
7
Comments

Join the conversation!

Just In

basics
Darrell Pruitt DDS 13th Jan 2008
Will PWC employees know the difference between an autoclave and a microwave? The first OSHA inspectors had no clue. Darrell Pruitt DDS
0 Votes
+ -
Why is the sky blue?????
D T Schmitz 10th Jan 2008
Let's wait and see Dana...everything is in a state of flux and ALOT could change in the next year (hopefully for the better)!

8+ Years of damage isn't going to change over night.
0 Votes
+ -
RE: Should HIPAA compliance be outsourced?
Darrell Pruitt DDS 10th Jan 2008
Will they confiscate office computers as a part of their investigations? Darrell Pruitt
0 Votes
+ -
RE: Should HIPAA compliance be outsourced?
queenofkeyboards@... 11th Jan 2008
Yes, If it saves thetax payers money. But I think that HIPAA should be worried about the medical transcription companies in India that receive outsourced work to type from American hospitals, doctors, and medical transcription companies? HIPAA should be just as worried about our health information being over there as well as here.
0 Votes
+ -
Tax collection used to be outsourced
John L. Ries 11th Jan 2008
The way it used to work was that governments sold tax collection franchises to the highest bidder; the franchisee then got to keep whatever he could collect. Seems that these privatized tax collectors (the Romans called them "publicans") were enormously unpopular and often accused of squeezing people for whatever they could get. First century Jews (who were Roman subjects) appear to have used the terms "publican" and "sinner" synonymously.

Be careful what you wish for...
0 Votes
+ -
PWC and similar groups already do financial statement attestations - it's fairly similar.
0 Votes
+ -
basics
Darrell Pruitt DDS 13th Jan 2008
Will PWC employees know the difference between an autoclave and a microwave? The first OSHA inspectors had no clue. Darrell Pruitt DDS

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix