Volume 14, Issue 3
fall 2017
Security Shredding News Serving the Security Shredding & Records Storage Markets
Visit us online at www.SecurityShreddingNews.com
ATTN: READERS !
Shredding Equipment , The Basics
Are you looking for Products, Equipment or Services for your business? If so, please check out these leading companies advertised in this issue:
Collection & Storage Containers Bomac Carts – pg 7
Equipment Financing TransLease Inc – pg 2
Lock & Locking Systems Lock America Intl. – pg 3
Mobile Truck Shredders
Alpine Shredders Ltd – pg 4 Shred-Tech Limited – pg 9 Vecoplan, LLC – pg 6
Moving Floor System Keith Manufacturing – pg 11
Stationary Shredders & Grinders Shred-Tech Limited – pg 9 Vecoplan, LLC – pg 6
Trade Associations NAID/Shred School – pg 12
(National Association of Information Destruction)
RIOS – pg 5
Website design Chachka – pg 8
For most operations, the shredder is the heart of the operation.By choosing the right type of machine and knowing how to customize it, shredding performance can be maximized further. An industry shredding expert describes some of the key aspects to realizing the maximum performance from a shredding asset.
By Rafael Reveles
T
he choices available in the security s h re d d i n g e q u i p m e n t m a rke t have never been more diverse and numerous. Most manufacturers have seen just about every application and have a solution for it. Understanding the types of shredders available and criteria for evaluating the best choice is a good practice before making such a large purchase. Many manufacturers are willing to facilitate a test as buyers perform their due diligence to ensure they make the best selection for their exact material. The shredders highlighted here are not an exhaustive list, but the most common ones used for paper and confidential hardware destruction. Likewise, there is not one “correct” way to shred. Selecting a shredder is a very business-specific choice depending on many factors and not one choice will fit every business.
Types of Common Shredders
T
here are a multitude of shredders available but they generally fall into two categories of either slow or high-speed machines. High-
speed machines cut or fractionate faster due to the higher RPM of their rotors or shafts, which also leads to higher heat generated by more friction in some cases as well as higher dust generation. They are often times the right machines when heavy items need to be broken apart because extreme liberation is needed, or particle sizes need to be small. Slow-speed machines rely on high torque shear cutting and generally run cooler, produce less fines and are quieter. Whether slow or fast, the shredder chosen will need to have the right umbilical systems including provisions for noise, dust, fire and maintenance depending on what is being shredded.
Mills
F
or the high-speed machines, mills, whether hammer or ring type, are a longtime staple of size reduction and best apply to hard drives or heavy confidential metallic or bulky materials. These mills use high speeds to spin rings or hammers that fractionate the product on impact until small enough to fall through a sizing Continued on page 3
®
Specialist in Mobile Shred Truck Financing • LOW INITIAL INVESTMENT • LEASE OR LOAN FINANCING • FINANCING NEW OR PRE-OWNED EQUIPMENT
• SIMPLE APPLICATION PROCESS • SERVING THE U.S. & CANADA • COMPETITIVE RATE STRUCTURE
We Provide a Convenient and Cost-Effective Solution!
Financing The World Of Transportation For a Quote or More Information Contact: Eastern States Western States Terry Lee Cassie Bergo Direct: 303-301-7651 | Cell: 937-620-9400 Direct: 303-301-7685 | Cell: 303-324-8340 tlee@transleaseinc.com cbergo@transleaseinc.com
www.transleaseinc.com WWW.TRANSLEASEINC.COM 2 Security Shredding News Fall 2017
Security Shredding News
Shredding Equipment , The Basics Continued from page 1
grate. Rings are a suitable choice when better liberation and less fines are desired. The rings internal diameter is about 2.5 times larger than the diameter of the rings retaining shaft which allows for deflection and rotation of the ring. In the case of hammers, multiple types are available including chisel types, notched, and plain bars. The hammers are especially useful in reducing heavy or hard-to-shred items. The geometry of these mills adds to the shredding mechanism by means of the sweep of the hammers/rings. As the hammer passes the screen or grate, the distance between the two progressively gets closer to encourage more grinding action and further reduction. There are also some variations on mills where the rotors and shafts are vertical. The material is ground against bars and textured wear plates as it falls towards the bottom of the mill. Some vertical machines have several stages of size reduction implements such as pre-breaker bars followed by rings below. Rather than a sizing screen, an adjustable orifice at the bottom of the mill’s tub controls the volume of the exit and how long the material recirculates inside the vessel. Other types of vertical mills use large chains to fractionate materials where a coarse shred is needed or where large tolerance is required for a very large piece to be introduced. Maintenance and wear can be higher for mills in certain cases requiring owners to keep removable wear plates and surfaces in stock. These mills are not good candidates for applications involving paper or easily flammable materials due to the heat and friction developed.
Single-Rotor Shredders
T
here are two main types of single-rotor shredders on the market that either accept whole product, or are designed to be secondary for use on pre-shredded materials. These machines are high speed and rotate from 125-250 rpm depending on design. To be efficient they rely on momentum (the flywheel effect), and use solid, heavy rotors to enable more efficient shredding. Multiple blades affixed to the rotor shaft shear against stationary blades or anvils attached to the granulator frame. A sizing screen allows the material to recirculate until small enough to pass and meet security requirements. Maintaining the correct manufacturer’s specification on shear gap (distance between rotor blade and stationary blade interface) is a key aspect to enabling proper and efficient cutting. Most machines allow for a blade flip where the cutter can be unbolted and turned over to use an unworn face. Many anvils can be sharpened as they wear making these machines very serviceable over time. Some machines have a hydraulic ram and a large hopper that takes on whole product and pushes it into the rotor cutters horizontally. A PLC (programmable
logic controller) monitors the demand on the drive motor and can modulate how much the ram feeds material into the cutting area, which is especially helpful for paper applications. Other machines are designed for smaller pieces including pre-shredded materials and rely on gravity for feeding into the rotor chamber and seen in applications requiring high volume (two stage shredding). Similar to mills, these machines offer high quality liberation and throughput. They are challenged when dealing with steel and non-ferrous metals and shine when processing batches of plastics, circuit boards and paper.
Now Even More Options for Customers Who Want Their Own Key Codes! Lock America Adds More New Key Codes for Padlocks and Console Locks. • Give your drivers and customers a single key that fits all the locks at a site. • Ask your console or bin supplier for new available key codes, or contact Lock America directly.
One Key Can Now Operate All Your Locks!
Tel: (951) 277-5180 Fax: (951) 277-5170 www.laigroup.com
800-422-2866
9168 Stellar Court Corona, CA 92883 sales@laigroup.com
Shear Shredders
hear-type, slow-speed, high-torque S shredders are the most common shredders in the secure shredding industry and fairly economical to operate. The interlocking cutters are disk-like and have hooks integrated into their circumference. They size reduce on the principal of shear cutting against cutters on the opposing rotating shaft that have an interference gap of 0.010”-0.030”. They are offered in two, three or four shaft models with either electric or hydraulic driven options. For units with more than two shafts, sizing screens are placed under the shredder cutters to produce a defined particle size. For two shaft models, cleaning fingers are used for stripping off the shredded materials from the cutter stack and prevent shaft deflection or damage. The two shaft shredder models are affordable, but are limited to produce mostly a long strip cut based on the width of the cutters. For those wishing to produce a tighter particle size, multi-shaft shredders deliver a defined piece and reasonable throughput based on the screen opening size. Care must be used when choosing the cutter thickness and screen size since throughput can be reduced by excessive re-circulation. Having about a 10 percent larger hole versus cutter width can be a winning approach for using a four shaft shredder.
Shear Shredder Customizing
ll the shredders mentioned above have A their own ways of customizing based on application, but we will focus on specific ways to optimize shear shredders specifically. The cutter is one of the most influential ways to define shredder performance. The overall radius or diameter of the cutter directly affects the available cutting force since force = torque / distance. Based on this simple physics equation, one can see that reducing distance, in this case the radius of the cutter, improves the amount of force developed. There is of course a limit to how much this trick can work since the Continued on page 4
PUBLICATION STAFF Publisher / Editor Rick Downing Contributing Editors / Writers Rafael Reveles • Sandy Woodthorpe Production / Layout Barb Fontanelle • Christine Mantush Advertising Sales Rick Downing Subscription / Circulation Donna Downing Editorial, Circulation & Advertising Office 6075 Hopkins Rd., Mentor, OH 44060 Ph: 440-257-6453 • Fax: 440-257-6459 Email: downassoc2@oh.rr.com www.securityshreddingnews.com For subscription information, please call 440-257-6453 Security Shredding News (ISSN #15498654) is published bimonthly by Downing & Associates. Reproductions or transmission of Security Shredding News, in whole or in part, without written permission of the publisher is prohibited. Annual subscription rate U.S. is $19.95. Outside of the U.S. add $10.00 ($29.95). Contact our main office, or mail-in the subscription form with payment.
©Copyright 2017 by Downing & Associates Printed on Post-Consumer Recycled Paper
Security Shredding News Fall 2017
3
Security Shredding News
Shredding Equipment , The Basics Continued from page 3
cutter overall size has to be large enough to geometrically grab whatever is being shredded. Now consider how the height of the hook plays a role in cutting ability since force is also proportional to surface area and pressure. A smaller surface area as seen in a cutter with a shorter hook will exhibit more pressure that enables better shearing. Whatever cutter configuration is chosen, the quantities and patterns of cutters placed in the shredder chamber is also significant. The total number of hooks engaging together at the same time will all equally draw on the available cutting force, so only having one hook engaging at a time is always going to be the strongest option. For higher throughput, more hooks need to engage at once and spiral or chevron patterns of the cutter hooks are often seen on most manufacturer’s offerings. The cutter alloy is also a key variable and can influence operational costs due to cutter wear rates. Common cutter
materials include D2 tool steel, 4140 heat treated and hardox variants such as 600. The brittleness of the cutter must be balanced with the difficulty of the materials to shred to ensure cutter cracking and failure is not likely. Lastly, if it is not possible to make a cutter change and the shredder does have a planetary or similar gearbox, the gear ratio can be changed to adjust the shredder shaft speed with slower speeds yielding more torque. On occasion, just an internal section of the planetary can be switched out at small expense to make the ratio change.
Shredder Drive Systems
here are either hydraulic or electric drives usually offered with most T types of shredders and both have a role to play with their applications. Hydraulic systems are mainly used for heavy duty stationary plant processing or situations requiring frequent reversal. Hydraulic systems are also found on shredder trucks often and use a PTO driven pump to reduce weight. Hydraulic-mechanical systems have a compound drive where a hydraulic motor turns a planetary gearbox to achieve a desired torque with a lower-cost motor in some cases. Many hydraulic pump systems allow the volume the pump displaces to be adjusted to control the speed of the shredder shafts, while others only allow for one fixed speed and are less expensive. Hydraulics are a proven technique, but do require by-the-book maintenance to keep them running well to avoid replacement of expensive pumps prematurely. Electric motor directly driven shredders are popular due to their efficiency and simpler to maintain nature. A dry clutch or belt system is common to reduce gearbox damage caused by hard jams and reversals. The planetary gearbox however will require frequent oil changes and monitoring since that is the most likely failure point in these types of drives. When using an electric drive, external options can allow for more shredder customization such as a variable frequency drive (VFD). VFD’s allow the motor and shredder speed to be decreased and adjusted on the fly by reducing the frequency of the power. They can also be used to speed up shafts as well, but do lose motor torque in those scenarios once the motor frequency rises above the standard 60 hertz. Using the shredder’s drive motor amperage, a special controls routine can be developed to run a shredder at speeds above normal motor speed and then slow down once more shredding amperage load is detected to ensure peak torque is realized when truly needed. Such a setup can drastically increase throughput for various types of materials.
Conclusions
here has never been so many great choices in shredding equipment, and T customizing your shredder to meet the exact needs of your job pays dividends. Selecting the right cutter or hammer materials and configuration, design, screen size and drive system play key roles in performance. Selecting a shredder style and platform that can be easily re-configured and adjusted for changing business needs is a good investment. Step one in the search for a shredder should always be to arrange a test with the manufacturers to shred your material, and also speak with a number of manufaturers before making your decision. Rafael Reveles is an engineer and president of Converge Engineering and has 18 years of experience designing and building shredding systems. He can be contacted at rafael.reveles@convergeengineering.com or visit www.convergeengineering.com. This article was adapted by Rafael Reveles from an article he wrote in the March 2017 edition of E-scrap News. Visit www.e-scrapnews.com. Photos courtesy of Rafael Reveles
4 Security Shredding News Fall 2017
www.certifymerecycling.org info@certifymerecycling.org
Security Shredding News Fall 2017
5
Security Shredding News
Patient Privacy: Be Careful with What You Say and Where You Say It The trial court dismissed the defamation claim, as well, noting that, as a matter of law, the hospital could not have defamed Hereford by speaking the truth that the nurse was terminated for a HIPAA violation. In their blog post, attorneys David McKinney and Cynthia Bremer emphasize that covered entities should make sure employees take patient privacy seriously. “Employees should be trained and retrained on how to properly handle HIPAA-related information in various contexts and situations. Here, the nurse may have been trying to be helpful by informing her colleagues to wear gloves, but she went too far when she verbally and publicly broadcast the patient’s condition within earshot of others. Even if no one actually heard Hereford, the patient believed a violation had occurred and the conduct itself yielded unnecessary risks,” they wrote. McKinney and Bremer also suggest that employers avoid disclosing the reasons for an employee’s termination of employment except under certain limited circumstances in consultation with counsel. Norton Audubon Hospital is a 480-bed acute care facility specializing in cardiac, surgical, pulmonary, neurologic, orthopedic, emergency and diagnostic care.
266.6mm h] [10 1/2inc
Shreds Everything!
533.4mm [21inch]
m 1108.6m nch] [43 21/32i
rail
800mm h] [31 1/2inc
L
ouisville, KY – A registered nurse who Hereford first sued Norton in Jefferson claimed she was fired for “incidental Circuit Court, arguing that the termination of disclosure” of protected patient her employment had been in violation of public information lost her suit, according to a blog policy because the termination had occurred in post on Ogletree.com. spite of her complying with HIPAA regulations. The Kentucky Appeals Court decision She maintained that, at most, she was engaged in (Hereford v. Norton Healthcare, Inc. D/B/A “incidental disclosure,” which is not actionable Norton Audubon Hospital and Phyllis Vissman) under HIPAA. Hereford also asserted that the has sent a clear message to medical providers hospital and one of its employees had defamed that probable (not actual) disclosure may be her by informing others that she had been disenough to constitute a HIPAA violation—or at missed for violating HIPAA regulations. least serve as a basis for discharging an employee The trial court dismissed Hereford’s claims, who makes an alleged disclosure. holding that the circumstances did not implicate Dianna Hereford, a registered nurse, was asa public policy concern that would alter the atsisting with a type of echocardiogram procedure will employment relationship. Further, the trial at Norton Audubon Hospital (Norton) when she court held that Hereford’s disclosure was untold her colleagues to wear gloves because the necessary because, as a matter of law, “a physipatient receiving the procedure had Hepatitis C. cian should not require being told that a patient Following the incident, which occurred in has an infectious disease as a reminder to wear 2013, the patient filed a HIPAA complaint with personal protective equipment such as gloves.” Norton, alleging that confidential health inforOn appeal, the higher court upheld the mation was improperly disclosed. Hereford’s lower court’s dismissal of Hereford’s claims. voice was loud enough to be heard by other The hospital did not terminate Hereford’s empatients and medical personnel in the patient’s ployment for her engaging in conduct that fell Security Shredding Storage Mobile page, “immediate presence,”&the patientNews, claimed. The - 1/2 within the4C public policy exception to the at-will hospital placed Hereford on administrative employment doctrine, the Kentucky Court of leave and conducted an investigation, deciding Appeals held. Because Hereford did not refuse to terminate her employment for unnecessarily to do anything that would violate the law and disclosing confidential health information in did not exercise a statutorily-conferred right, the violation of HIPAA. trial court’s ruling was upheld.
Shreds Everything!
SHSHRREECDD S S U CKK TRU TR new & USed Single-Shaft RotaRy ShReddeRS PieRce & teaR ShReddeRS cdl & non-cdl
WITH
W
ba c fa ge ked Pa ctoRnUin by Rt S & y diRe Se ec RV t ice
IT H
(336) 285-0021 www.VecoPlanllc.com 5708 UwhaRRie Road • aRchdale, nc 27263
6 Security Shredding News Fall 2017
26' - 1"
Shreds Everything!
rail 8' - 7"
Yep, That Too! 35' - 4" Truck Curb Side Vie
w
17 Body (Tail End)
1,200 Cubic Feet Shredded Materia Storage Capacity
Security Shredding News
Former City Council Member Faces E-Waste Violations
HIPAA Rules and Law Enforcement Investigations
S
A
ioux City, IA – The Iowa state Attorney General’s office will be reviewing allegations of improper e-waste disposal, storage and contamination made by the state Environmental Commission against a former Sioux City council member. Earlier this year, environmental inspectors from the State Department of Natural Resources found piles of computer monitors and other hazardous materials outdoors at a recycling center owned by ex-Sioux City council member, Aaron Rochester. Rochester’s business, Recycletronics, had collected payments from businesses and the public to properly recycle electronics including CRTs. Since 2011, the company had been operating under a permit that allows recyclable materials to be removed from e-waste and sold as scrap. Materials which are not recycled must be handled according to government requirements for solid waste and hazardous materials. According to the Iowa State Environmental Protection Commission’s September meeting minutes, the DNR had been working with Rochester to bring the recycling center’s operations into compliance beginning in 2014. In January of this year, the DNR issued Rochester a final warning that if he didn’t come into compliance he would face revocation of the site’s permit. In March, the agency revoked the permit and cited Rochester for noncompliance of solid waste and hazardous waste regulations. In April, DNR investigators learned that Rochester had disposed of hazardous materials at other sites -- three in the Sioux City area and two additional sites in Nebraska. The estimated weight of material disposed of at these sites in Iowa alone – 1.2 million pounds – is approximately eleven times the amount by weight that was still sitting at the formerly-permitted site. In addition, nearly 11 million pounds of waste were illegally disposed at the other three other sites in Iowa, and more at illegal disposal sites in Nebraska, according to a transcription of investigator comments made to the Commission. Recycletronics originally hired disabled U.S. military veterans who worked part-time at the recycling facility. Rochester explained to the DNR that he had sought federal funding for the venture, but the assistance never came through. He has stated that the other sites were for storage and he believed they did not require permits. Rochester had planned to sell the CRT glass stored at those sites to a construction company that was to combine it with concrete to make landscaping blocks. That plan did not work out because the EPA got involved when a complaint was filed about the hazardous glass, he said. Rochester has told the DNR that he has been operating in the red since he took over the facility from a franchise in 2011. He said that stockpiling the waste offsite was common in the recycling trade. The DNR reports Recycletronics owes back payments of $75,000 on a state loan. Rochester had assumed the loan when he took over the facility to finance the company’s recycling equipment. DNR officials reported that the equipment is in poor condition and not recoverable. In September, state Environmental Protection Commissioners voted to turn the Recycletronics case over to the state attorney general’s office, which can seek higher penalties than the DNR. State law caps the Department’s fines at $10,000.
ccording to HealthITSecurity.com article, the widely distributed video of a Salt Lake City, Utah nurse refusing to draw blood from an unconscious patient and give it to a detective has raised awareness of how the HIPAA Privacy Rule applies in law enforcement investigations. Covered entities may disclose PHI under certain circumstances in relation to law enforcement investigations. In this case, because the patient was alive, but had not been formally arrested, and no warrant or court order had been issued and there was no evidence or suspected involvement in a crime, the nurse was following hospital regulations in her refusal to cooperate with the police detective. The Privacy Rule states, “Covered entities may disclose protected health information in a judicial or administrative proceeding if the request for the information is through an order from a court or administrative tribunal. Such information may also be disclosed in response to a subpoena or other lawful process if certain assurances regarding notice to the individual or a protective order are provided.” In some states, such as North Carolina, a covered entity must comply with law enforcement request for a blood draw from an unconscious patient, so long as it can be done safely. A court issued warrant is not required. It’s left to the lawyers to work out any technicalities during the discovery process or in court. HIPAA-covered entities and their business associates do well to review their policies and staff training for PHI, along with applicable state and federal laws, the article suggests.
www.bomaccarts.com
sales@bomaccarts.com
Advertise in SSN and reach over 3,000 businesses involved in ... Document & Product Destruction • Records & Media Storage Medical / Pharmaceutical Waste Transporting For more information, contact Rick at 440-257-6453 or email rickdowning@oh.rr.com.
Security Shredding News Fall 2017
7
Security Shredding News
HIPAA Compliance Audits – Here to Stay?
A
ccording to an InfroRiskToday article, the ways in which the Department of Health and Human Services HIPAA will administer compliance audits under the Trump administration remains unclear. For now, phase two of the on-site audit compliance program slated by HHS’ Office for Civil Rights (OCR) remains up in the air. An OCR official speaking in September at an annual HIPAA conference co-hosted by National Institute of Standards and Technology (NIST) and OCR revealed little in the way of how the agency will proceed with HHS Secretary Tom Price at the helm. Under the Obama administration, OCR announced plans to complete a total of about 250 desk and on-site audits in phase two. In a pilot program, or phase one, conducted in 2011 and 2012, OCR conducted 115 onsite audits. In April 2016, OCR issued an updated protocol for phase two, reflecting the HIPAA Omnibus Rule, which went into effect in 2013. A revamped pilot audit program launched in 2012 focused on covered entities, but not business associates, examining compliance with the HIPAA privacy, security and breach notification rules. In phase two, remote “desk audits” were to be conducted by OCR, followed by an undisclosed number of on-site audits of randomly chosen covered entities and business associates. These audits were slated to begin the first quarter of 2017. Earlier this year, however, an OCR official acknowledged that the onsite audits might not start until 2018. This would allow time for Secretary Price to provide his input.
Preliminary Findings:
O
CR has completed its preliminary analysis of findings from 166 remote “desk” compliance audits of covered entities conducted thus far. The agency is currently conducting desk audits of 41 business associates,
according to OCR. Speaking at the September conference the OCR official emphasized that the program’s emphasis was never on enforcement details, but rather to assist covered entities with compliance practices. Under the initial phase two audits, OCR focused on smaller providers or health plans, mainly looking at compliance with selected provisions of the HIPAA privacy and breach notification rules, and certain provisions of the HIPAA Security Rule. Business associates were audited for compliance with provisions of the HIPAA security and breach notification rules. The OCR official noted “room for improvement,” because many of those audited were not being diligent enough with HIPAA security risk analyses and documentation.
HHS’ Improved HIPAA Breach Reporting Tool Launched
W
ashington, D.C. – In July, the U.S. Department of Health and Human Services (HHS) unveiled an enhanced version of its web tool for breach reporting. The HIPAA Breach Reporting Tool (HBRT) features improved navigation for both those looking for information on breaches and easeof-use for organizations reporting incidents. The tool also helps educate industry on the types of breaches that are occurring, industry-wide or within particular sectors, and how breaches are commonly resolved following investigations launched by OCR, which can help industry improve the security posture of their organizations. “HHS heard from the public that we needed to focus more on the most recent breaches and clarify when entities have taken action to resolve the issues that might have led to their breaches,” said HHS Secretary Tom Price, M.D. in a statement. The website, which features only larger breaches, is intended to be a more positive, relevant source of information for concerned consumers can be accessed at https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf. HHS OCR originally released the HBRT in 2009, as required by the Health Information Technology for Economic and Clinical Health (HITECH) Act. The HRBT makes available to the public information that entities covered by the Health Insurance Portability and Accountability Act (HIPAA) report to OCR when they are involved in breaches of unsecured protected health information of 500 or more individuals. Searchable fields include: the name of the entity; state where the entity is located; number of individuals affected by the breach; the date of the breach; type of breach (e.g., hacking/IT incident, theft, loss, unauthorized access/disclosure); and location of the breached information (e.g., email, network server, laptop, paper records, desktop computer). Although HIPAA requires the covered entity to promptly notify affected individuals of a breach, and, in some cases, notify the media, the HBRT puts the information at consumers’ fingertips. • • • •
New features of the HBRT include: Enhanced functionality that highlights breaches currently under investigation and reported within the last 24 months; New archive that includes all older breaches and information about how breaches were resolved; Improved navigation to additional breach information; and Tips for consumers.
HHS plans on expanding and improving the site over time to add functionality and features based on feedback. The HBRT provides transparency to the public and organizations covered by HIPAA and helps highlight the importance of safeguards to protect the privacy and security of sensitive health care information.
www.chachkagroup.com chachka@chachkagroup.com
8 Security Shredding News Fall 2017
Visit us online at www.SecurityShreddingNews.com
Security Shredding News
OCR Sends Message with 2017 HIPAA Enforcement
A
ccording to a MedCityNews.com report, 2017 is shaping up to be a bigger year than 2016 in terms of HIPAA enforcement. Last year the U.S. Department of Health and Human Services, Office for Civil Rights (OCR) tallied 13 total settlements and nearly a 300 percent increase in total collected fines over 2015. As of this past June, OCR has settled nine cases with settlements totaling more than $16.6 million in fines. Writing in a National Law Review article, Foley Lardner Law Firm attorneys offer the following tips for reducing risk of violations: 1. Conduct Regular Risk Analyses. Although the Security Rule does not lay out specific risk analysis methodology, covered entities must comply with available OCR guidance, including the Guidance on Risk Analysis Requirements. 2. Implement a Risk Management Plan and Reasonable Safeguards. OCR wants to see not just a risk management plan that treats identified risks or vulnerabilities seriously, but also documentation of follow-through. 3. Report Breaches in Timely Manner. In January OCR announced the first HIPAA settlement to be based on the untimely reporting or notification of a breach under the HIPAA Breach Notification Rule. OCR found that a healthcare network had failed, with unreasonable delay, to notify OCR, the affected individuals, and the media within the required 60-day timeframe. Notifications were made more than 100 days after discovery of the breach. This settlement highlights the importance of having clear policies and procedures in place and ensuring that workforce members are trained to respond within HIPAA’s breach notification timeframes. The National Law Review article was written by Foley Lardner attorneys Jennifer L. Rathburn, Jennifer J. Hennessy and Julia K. Kadish.
HIPAA Omnibus Rule Enforcement and Increased Security Threats
F
rom the time the U.S. Health and Human Services Office of Civil Rights (OCR) began enforcing the HIPAA Omnibus Rule in September of 2014, covered entities trying to manage risk have been grappling with a surge in cyber-attacks, InfoRiskToday.com reports. The number of breaches impacting more than 500 individuals has more than tripled in four years. The number of individuals impacted by breaches has grown more than six-fold, to nearly 176 million individuals. The size of breaches keeps getting bigger. Four years ago, lost and unencrypted devices were to blame for the largest breaches posted on the Health and Human Services HIPAA “wall of shame” web page. So far in 2017, 247 breaches impacting about 4.3 million individuals have been added to that page. Of those, 109 were reported as hacking incidents, which in total, affected about 3 million individuals. The trend toward massive hacker attacks is significant and cause for concern throughout the security industry. Of the 378 hacker breaches that impacted 132 million individuals since September 2009, the year OCR began keeping a tally, 75 percent involved health data. Extending patient privacy and security compliance requirements to business associates has resulted in a greater number of breach reports. Since 2009, business associates have reported 324 breaches impacting a total of nearly 29 million individuals. The number of cases where business associates are penalized is far below that of covered entities – 180 breaches impacting 13.1 million individuals and one financial settlement. One industry observer told InfoRiskToday that, despite guidance issued by HHS, confusion over what constitutes a reportable breach may account to some overreporting.
www.shred-tech.com
Security Shredding News Fall 2017
9
Security Shredding News
Waivers of HIPAA Sanctions and Penalties Help Disaster Relief Efforts
I
n response to destructive tropical storms in August and September, Secretary of Health and Human Services, Tom Price, M.D., followed President Trump’s emergency declarations by declaring public health emergencies in four states – Texas, Louisiana, Florida and Georgia, as well as Puerto Rico and U.S. Virgin Islands. The action, which temporarily waived certain HIPAA regulations, was taken to allow healthcare providers to be more expedient in emergency situations. A bulletin posted on the HHS.gov website explains that, while the HIPAA Privacy Rule is not suspended during a public health or other emergency, the Secretary of HHS may waive certain provisions under applicable sections of the Project Bioshield Act of 2004 and the Social Security Act. In effect, the declaration allows HHS to waive sanctions and penalties against a covered hospital that does not comply with the following provisions of the HIPAA Privacy Rule, including: • the requirements to obtain a patient’s agreement to speak with family members or friends involved in the patient’s care • the requirement to honor a request to opt out of the facility directory • the requirement to distribute a notice of privacy practices • the patient’s right to request privacy restrictions • the patient’s right to request confidential communications. Such a waiver only applies in the emergency area and for the emergency period identified in the public health emergency declaration. The waiver covers hospitals that have instituted a disaster protocol and is in effect for up to 72 hours from the time the hospital implements its disaster protocol. Once the President or HHS Secretary issues a declaration to terminate the waiver, a hospital must then comply with all the requirements of the Privacy Rule for any patient still under its care, even if 72 hours has not elapsed since implementation of its disaster protocol.
HIPAA Privacy & Disclosures in Emergency Situations
E
ven without a waiver, the HIPAA Privacy Rule always allows patient information to be shared for the following purposes and under the following conditions. Treatment Under the Privacy Rule – covered entities may disclose, without a patient’s authorization, protected health information about the patient as necessary to treat the patient or to treat another person (who might be, for example, affected by the same emergency situation). Treatment includes the coordination or management of health care and related services by one or more health care providers and others, consultation between providers, and the referral of patients for treatment. Public Health Activities – The HIPAA Privacy Rule recognizes the legitimate need for public health authorities and others responsible for ensuring public health and safety to have access to protected health information that is necessary to carry out their public health mission. This provision covers disclosures to Centers for Disease Control and Prevention (CDC) or a state or local health department, and in some cases, a foreign government agency, for the purpose of preventing or controlling disease, injury or disability; reporting births or deaths; and conducting public health surveillance, investigations, or interventions. Notifications – The rule provides for notification of family members, relatives, friends, or other persons identified by the patient as involved in the patient’s care. A covered entity also may share information about a patient as necessary to identify, locate, and notify family members, guardians, or anyone else responsible for the patient’s care, of the patient’s location, general condition, or death. This may include, where necessary to notify family members and others, the police, the press, or the public at large. In addition, a provider may determine that it is in the best interests of an incapacitated patient to share relevant information with the patient’s adult child, but generally could not share unrelated information about the patient’s medical history without permission. Disaster Relief – A covered entity may share protected health information with disaster relief organizations that, like the American Red Cross, are authorized by law or by their charters to assist in disaster relief efforts, for the purpose of coordinating the notification of family members or other persons involved in the patient’s care, of the patient’s location,
10 Security Shredding News Fall 2017
general condition, or death. It is unnecessary to obtain a patient’s permission to share the information in this situation if doing so would interfere with the organization’s ability to respond to the emergency. Imminent Danger – Health care providers may share patient information with anyone as necessary to prevent or lessen a serious and imminent threat to the health and safety of a person or the public – consistent with applicable law (such as state statutes, regulations, or case law) and the provider’s standards of ethical conduct. This includes family, friends, caregivers, and law enforcement, without a patient’s permission. HIPAA expressly defers to the professional judgment of health professionals in making determinations about the nature and severity of the threat to health or safety. Disclosures to the Media or Others Not Involved in the Care of the Patient/Notification – Upon request for information about a particular patient by name, a hospital or other health care facility may release limited facility directory information to acknowledge that an individual is a patient at the facility and provide basic information about the patient’s condition in general terms (e.g., critical or stable, deceased, or treated and released) if the patient has not objected to or restricted the release of such information or, if the patient is incapacitated, if the disclosure is believed to be in the best interest of the patient and is consistent with any prior expressed preferences of the patient. However, disclosure to the public or media of specific information about treatment of an identifiable patient, such as specific tests, test results or details of a patient’s illness, may not be done without the patient’s written authorization (or the written authorization of a personal representative who is a person legally authorized to make health care decisions for the patient). Minimum Necessary – For most disclosures, a covered entity must make reasonable efforts to limit the information disclosed to that which is the “minimum necessary” to accomplish the purpose. (Minimum necessary requirements do not apply to disclosures to health care providers for treatment purposes.) Covered entities may rely on representations from a public health authority or other public official that the requested information is the minimum necessary for the purpose. Internally, covered entities should continue to apply their role-based access policies to limit access to protected health information to only those workforce members who need it to carry out their duties. Business Associates – A business associate of a covered entity (including a business associate that is a subcontractor) may make disclosures permitted by the Privacy Rule, such as to a public health authority, on behalf of a covered entity or another business associate to the extent authorized by its business associate agreement. Safeguarding Patient Information – In an emergency situation, covered entities must continue to implement reasonable safeguards to protect patient information against intentional or unintentional impermissible uses and disclosures. Further, covered entities (and their business associates) must apply the administrative, physical, and technical safeguards of the HIPAA Security Rule to electronic protected health information.
HIPAA Applies Only to Covered Entities and Business Associates
T
he HIPAA Privacy Rule applies to disclosures made by employees, volunteers, and other members of a covered entity’s or business associate’s workforce. Covered entities are health plans, health care clearinghouses, and those health care providers that conduct one or more covered health care transactions electronically, such as transmitting health care claims to a health plan. Business associates are defined as “persons or entities (other than members of the workforce of a covered entity) that perform functions or activities on behalf of, or provide certain services to, a covered entity that involve creating, receiving, maintaining, or transmitting protected health information.” Also under this category are subcontractors that create, receive, maintain, or transmit protected health information on behalf of another business associate. The Privacy Rule does not apply to disclosures made by entities or other persons who are not covered entities or business associates (although such persons or entities are free to follow the standards on a voluntary basis if desired).
Security Shredding News
www.youtube.com/user/KeithMfgCo
www.keithwalkingfloor.com
Security Shredding News Fall 2017 11
PRSRT STD U.S. Postage
PAID
Cleveland, OH Permit #1737
6075 Hopkins Rd • Mentor, OH 44060 • Ph: 440-257-6453 • Fx: 440-257-6459 • Email: downassoc2@oh.rr.com
Inside This Issue
VOL. 14 NO. 3
FALL 2017
Shredding Equipment, The Basics PAGE 1 Patient Privacy: Be Careful with What You Say and Where You Say It PAGE 6 HHS’ Improved HIPAA Breach Reporting Tool Launched PAGE 8 OCR Sends Message with 2017 HIPAA Enforcement PAGE 9 Waivers of HIPAA Sanctions and Penalties Help Disaster Relief Efforts PAGE10
Data Destruction by the Book Finally, a book that tells the customer what reputable data destruction service providers have always wanted to say. • • • • •
How to pick a service provider What do regulations require Risk management best practices What to include in an RFP or contract Includes forms, policies & templates
Order your copy today! www.naidonline.org Disposition halfpg ShreddingNews317.indd 1
This is the book your customers will soon be reading. 3/17/17 10:22 AM