HIPAA Compliance – Using The Right Tool For The Job

When I was young, I remember my father working on the family station wagon (for our younger readers, think SUV). In those days, engine compartments were big enough to sit in, and even a big block V8 left plenty of room for wrenching. Now my father wasn’t exactly mechanically inclined. Don’t get me wrong, he was a great fix it man and could repair just about anything inside or around our house, but when it came to an automobile, he was just out of his element. On this particular day, he was changing spark plugs – I know, you used to be able to do that yourself. I remember sitting on the front fender, feet resting on the engine with my dad leaning in from the other side. I heard a clunk, and then a thunk, followed by a series of words I’d rather not repeat, certainly uncharacteristic of my father (at least in front of his 8 year old). My dad looked up at me, shaking his hand with a couple of bloody knuckles  and said – son, if you don’t have the right tool for the job, either get it, or let someone else who does do the job for you. I’ve never forgotten those words, and neither should you.

We all have a tendency to stick with what we know, vendors we’re already working with, by asking them to step beyond their area of expertise to tackle a new task or project for us. While in many cases the consequences of “using the wrong tool for the job” may not result in much more than bruised knuckles, where your HIPAA compliance is concerned, the results can prove much more dire.

New HIPAA laws raise the stakes for medical practices and their vendors. The “domain” of HIPAA compliance is now considered to be its own area of expertise, requiring specialized skills and knowledge beyond just IT security. While your IT company may be an excellent Managed Service Provider (MSP), unless they’ve done the heavy lifting HIPAA requires, and passed the acid test of multiple CMS audits, then hiring them to handle your Risk Assessment is simply using the wrong tool for the job.

