Below are some general points to note when answering your Assessment Questions:
- If you do not understand the question or do not presently have a practice in place to address what the question is asking of you, answer No.
- If you have procedures but no formal policy in place, answer No.
- For questions about Policies, if you have a Policy over 3 years old, or if a lawyer has not reviewed it, answer No.
- If you have Procedures in place, a formal Policy, and the Policy has been reviewed by a lawyer, answer Yes. Please document in the notes section how your Organization has implemented the Policy or Procedure.
- If you do not have the ability to answer the question with a Yes or No, answer No to create a gap and task.
- The technical Assessments do not require a third party to complete, but many Organizations outsource their IT and security Assessments to a third party.
- Regarding the Privacy, Security, and HITECH policy Assessments, these gaps were created because you did not have the proper Policy and Procedure in place. The Policies, when followed, will cover you for all aspects of the rule. However, you are responsible for implementing the Policies within your Organization.
- For example: time outs on your workstations, encryption of Devices that connect to or store ePHI, security systems, locks on server rooms, etc. This can be done at your discretion, and may take time to implement in some situations, which is why the government requires Assessments be done yearly.
note* for Organizations that have multiple Locations, you must complete the Physical Site Assessment for each Site you have. All other Assessments must be completed Organization-wide.
Additional Documentation, like Work From Home, Bring Your Own Device, or additional Regulatory Acts (OSHA, HB 300), may be required, confirm with your coach or support@compliancygroup.com
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article