One of the many challenges you probably face as a business owner is dealing with the vague requirements present in HIPAA and PCI-DSS legislation. Due to the unclear regulatory messaging, “assuming” rather than “knowing” can land your organization in hot water with regulators. Are you taking a risk? Do you know if you are non-compliant?
The Health and Human Services (HSS) Office for Civil Rights receives over 1,000 complaints and notifications of HIPAA violations every year.1 When it comes to PCI-DSS, close to 70% of businesses are non-compliant.2 While you might assume it’s okay if your business does not comply with HIPAA or PCI-DSS since many other companies are non-compliant as well, we can assure you it’s not. Keep in mind that being non-compliant puts you and your business at risk of being audited and fined.
Never take compliance lightly because non-compliance can lead to:
HIPAA violations can draw fines ranging from $100 to $50,000 perviolation, with a maximum fine of $1.5 million per calendar year of non-compliance.1 PCI-DSS can squeeze your budget too, with fines ranging from $5,000 to $100,000 per month.3
Non-compliance can lead to unpleasant inspections and audits that can result in fines.
You must be extra careful while selecting solutions for your business. Using a single non-compliant solution can cause your insurance provider to deny a liability insurance claim.
It takes years to build a reputation and just minutes to ruin it. Don’t let your business fall into the pit of non-compliance.
In cases of severe non-compliance, regulatory bodies can sanction the arrest of top executives or even close the business.
If you are unsure where to start, assessing your business tools — cloud, VoIP, email service, electronic file-sharing service, applications, etc. — is a good place to start. Here are a few ways to check your existing business tools for compliance:
These lists are not comprehensive and only scratch the surface. Also, none of the points mentioned above ensure the tool is HIPAA or PCI-DSS compliant. Just consider it a starting point.
If you’re confused about what your next steps should be, don’t worry. We’re here to help.
Use our expertise in compliance matters to conduct a comprehensive assessment of your business’s current state of compliance.
Sources:
1. National Library of Medicine
2. Help Net Security Magazine
3. Security Boulevard
619 Main St
Vincennes, IN 47591
812.726.4500