idbusiness red flag rules for dentists

42
Red Flag Compliance for Dental Practices May 17, 2009 1

Upload: steven-lane

Post on 29-Nov-2014

1.596 views

Category:

Health & Medicine


0 download

DESCRIPTION

In our rapidly changing healthcare environment, dentists need to understand not only what compliance requirements they need to meet, but how to use that compliance to strengthen their practice and build trust with patients.

TRANSCRIPT

Page 1: idBUSINESS Red Flag Rules For Dentists

Red Flag Compliance for Dental PracticesMay 17, 2009

1

Page 2: idBUSINESS Red Flag Rules For Dentists

Our goals today

2

Page 3: idBUSINESS Red Flag Rules For Dentists

Our goals today

‣ To give you the WHAT…

2

Page 4: idBUSINESS Red Flag Rules For Dentists

Our goals today

‣ To give you the WHAT…

‣ The FTC’s Red Flag Rules

2

Page 5: idBUSINESS Red Flag Rules For Dentists

Our goals today

‣ To give you the WHAT…

‣ The FTC’s Red Flag Rules

‣ ...review the HOW…

2

Page 6: idBUSINESS Red Flag Rules For Dentists

Our goals today

‣ To give you the WHAT…

‣ The FTC’s Red Flag Rules

‣ ...review the HOW…

‣ demo the idBUSINESS Red Flag Compliance Module

2

Page 7: idBUSINESS Red Flag Rules For Dentists

Our goals today

‣ To give you the WHAT…

‣ The FTC’s Red Flag Rules

‣ ...review the HOW…

‣ demo the idBUSINESS Red Flag Compliance Module

‣ but also give you the WHY

2

Page 8: idBUSINESS Red Flag Rules For Dentists

Our goals today

‣ To give you the WHAT…

‣ The FTC’s Red Flag Rules

‣ ...review the HOW…

‣ demo the idBUSINESS Red Flag Compliance Module

‣ but also give you the WHY

‣ Why information security should be a part of your business

2

Page 9: idBUSINESS Red Flag Rules For Dentists

An issue of PATIENT CARE

“The possibility for medical identity theft gives rises to a duty to monitor for the

potential that patients may be victims. The prudent provider will also monitor employee

and vendor access to patient data.”

- World Privacy Forum, 9/24/08

3

Page 10: idBUSINESS Red Flag Rules For Dentists

What this means

4

Page 11: idBUSINESS Red Flag Rules For Dentists

What this means

‣ Medical identity theft is on the rise

‣ Costs $192 per record to restore

‣ Often an inside job

‣ Organized crime is involved

4

Page 12: idBUSINESS Red Flag Rules For Dentists

What this means

‣ Medical identity theft is on the rise

‣ Costs $192 per record to restore

‣ Often an inside job

‣ Organized crime is involved

‣ Dental offices are unique

‣ Reliance on office manager to run operations

‣ No line between your brand and your name

4

Page 13: idBUSINESS Red Flag Rules For Dentists

The Opportunity

‣ There is a unique opportunity to grow a practice by leveraging strong information security policy and sharing it with patients

‣ Build trust with patients

‣ Strengthen employee relationships

‣ Tighten operations with vendors

5

Page 14: idBUSINESS Red Flag Rules For Dentists

The facts

• Since 2/15/05, over 251,000,000 Americans have had identities or other personal information compromised

40%

60%

Business has suffered breachBusiness has yet to incur a breach

30%

70%

Thief is employee or knows employeeThief is unknown

6

Page 15: idBUSINESS Red Flag Rules For Dentists

The facts

The average breach and its impact on customer confidence is growing.

Source: Ponemon Institute, 2008.

58% of customers willlose confidence in your business after a breach.

31% of your customers will immediately cease doing business with you following a breach.

7

Page 16: idBUSINESS Red Flag Rules For Dentists

The Red Flag Rules

8

Page 17: idBUSINESS Red Flag Rules For Dentists

The Red Flag Rules

‣ Sections 114 & 315 of the Fair and Accurate Credit Transactions Act

8

Page 18: idBUSINESS Red Flag Rules For Dentists

The Red Flag Rules

‣ Sections 114 & 315 of the Fair and Accurate Credit Transactions Act

‣ Applies to you if:

8

Page 19: idBUSINESS Red Flag Rules For Dentists

The Red Flag Rules

‣ Sections 114 & 315 of the Fair and Accurate Credit Transactions Act

‣ Applies to you if:

‣ you hold “covered accounts”

8

Page 20: idBUSINESS Red Flag Rules For Dentists

The Red Flag Rules

‣ Sections 114 & 315 of the Fair and Accurate Credit Transactions Act

‣ Applies to you if:

‣ you hold “covered accounts”

‣ your customer records present a “reasonably foreseeable risk of identity theft”

8

Page 21: idBUSINESS Red Flag Rules For Dentists

Why are dentistsCOVERED ENTITIES?‣ Accepting insurance

‣ Deferral of 100% of payment, you collect enough patient data to collect the remainder that insurance does not pay.

‣ Reasonably foreseeable risk

‣ Your patient files are a treasure trove

‣ Each record worth between $80-300 each*

* Source: Black Market Identity Auction attended by Net Reaction mole, 2008.

9

Page 22: idBUSINESS Red Flag Rules For Dentists

Red Flag REQUIREMENTS

10

Page 23: idBUSINESS Red Flag Rules For Dentists

Red Flag REQUIREMENTS1. A Written Information Security Program

10

Page 24: idBUSINESS Red Flag Rules For Dentists

Red Flag REQUIREMENTS1. A Written Information Security Program

2. Controls to prevent and mitigate the risks associated with identity theft

10

Page 25: idBUSINESS Red Flag Rules For Dentists

Red Flag REQUIREMENTS1. A Written Information Security Program

2. Controls to prevent and mitigate the risks associated with identity theft

3. Must be administered by a board of directors or a member of senior management

10

Page 26: idBUSINESS Red Flag Rules For Dentists

Red Flag REQUIREMENTS1. A Written Information Security Program

2. Controls to prevent and mitigate the risks associated with identity theft

3. Must be administered by a board of directors or a member of senior management

4. Must deliver compliance report on at least an annual basis

10

Page 27: idBUSINESS Red Flag Rules For Dentists

Red Flag REQUIREMENTS1. A Written Information Security Program

2. Controls to prevent and mitigate the risks associated with identity theft

3. Must be administered by a board of directors or a member of senior management

4. Must deliver compliance report on at least an annual basis

5. Must contain mechanism to train employees

10

Page 28: idBUSINESS Red Flag Rules For Dentists

Red Flag REQUIREMENTS1. A Written Information Security Program

2. Controls to prevent and mitigate the risks associated with identity theft

3. Must be administered by a board of directors or a member of senior management

4. Must deliver compliance report on at least an annual basis

5. Must contain mechanism to train employees

6. Must contain an incident response capability

10

Page 29: idBUSINESS Red Flag Rules For Dentists

Red Flag REQUIREMENTS1. A Written Information Security Program

2. Controls to prevent and mitigate the risks associated with identity theft

3. Must be administered by a board of directors or a member of senior management

4. Must deliver compliance report on at least an annual basis

5. Must contain mechanism to train employees

6. Must contain an incident response capability7. Must ensure that vendors and suppliers are also compliant

10

Page 30: idBUSINESS Red Flag Rules For Dentists

“What happens if I don’t comply?”• Noncompliance carries several penalties

– Civil Liability

– Class-Action Lawsuits

– Federal Fines

– State Fines

11

Page 31: idBUSINESS Red Flag Rules For Dentists

“Didn’t the ADA send me something?”• The ADA’s written template still leaves you

vulnerable:

– No vendor integrity assessment

– No employee training, just signature line

– No mitigation of damages in the event of an incident• Who will you call when you have a question?

• No context of how Red Flag Policy fits into your business

–What’s worth doing is worth doing right.

–Missing an opportunity to GROW your practice

12

Page 32: idBUSINESS Red Flag Rules For Dentists

The solution

‣ The idBUSINESS Red Flag Compliance Module‣ Built on real-world forensic fieldwork‣ Includes tools & benefits that actively involve

employees in your compliance efforts

‣ Transitions information security from a compliance issue into a competitive advantage

13

Page 33: idBUSINESS Red Flag Rules For Dentists

The Red Flag Compliance Module

‣ Secure online interface

14

Page 34: idBUSINESS Red Flag Rules For Dentists

The Red Flag Compliance Module

‣ Learning tools available as text or video webinar

15

Page 35: idBUSINESS Red Flag Rules For Dentists

The Red Flag Compliance Module

‣ Risk Assessment tool provides ranking of your company in 12 key focus areas

16

Page 36: idBUSINESS Red Flag Rules For Dentists

The Red Flag Compliance Module

‣ Customizable checklist of 26 Red Flags to meet requirements of FACT Act

17

Page 37: idBUSINESS Red Flag Rules For Dentists

The Red Flag Compliance Module

‣ Employee training automated & easy, integrates automatically with your compliance report

18

Page 38: idBUSINESS Red Flag Rules For Dentists

The Red Flag Compliance Module

‣ Ability to evaluate supplier compliance practices using 19

Page 39: idBUSINESS Red Flag Rules For Dentists

The Red Flag Compliance Module

‣ Access individual identity recovery protection using FraudStop and Restore from ID Experts

‣ Available as employee benefit, cafeteria-style add-on, customer blanket, or new revenue stream

‣ In the event of a breach, one-click access to best-in-breed data breach services and forensic services

20

Page 40: idBUSINESS Red Flag Rules For Dentists

So I’m compliant...

‣ NOW WHAT?

‣ Don’t let it sit on a shelf

‣ Talk to your employees

‣ Talk to your patients

‣ Use your policy as a practice-building tool

21

Page 41: idBUSINESS Red Flag Rules For Dentists

A final word‣ “I understand the mindset of other dentists in practice for themselves, and that it is easy

to minimize identity theft as a business threat or a patient care issue. It is low on their

list of priorities, which is unfortunate because if and when a patient data breach occurs,

we are by law responsible. I personally would recommend that dentists act with a sense

of urgency to become compliant with the FTC ‘Red Flag Rules’ both to avoid penalty

and to protect your patients from a life-wrenching identity theft experience. You’ll be

protecting yourself as well, and as a result, will sleep better at night.”

Dr. Miles Collett, DDS

22

Page 42: idBUSINESS Red Flag Rules For Dentists

Thank you!

‣ To learn more, please visit idBUSINESS.com

‣ Discounts are available for some dental associations - check with your association or call Carla Adams, 303-810-3091

23