Hayes Review: Summer 2009
Red Flag Rules
By Anita Johnson
As of June 1, 2010, the Federal Trade Commission (FTC) will require healthcare organizations defined as “creditors” to develop and implement an identity theft prevention program. This complements existing HIPAA rules.
How do I know if my organization is affected by the Red Flag Rules?
- Are you a provider who creates patient accounts that allow multiple payments? If so, you are considered a creditor offering a covered account and are subject to the Red Flag Rules.
- Do you use consumer credit reports? If yes, you come under the Address Discrepancy Rule, which is part of the Red Flag Rules.
How can Hayes assist our organization?
Hayes can help your organization develop a Red Flag Program. We can:
- Review your current privacy and security practices
- Perform a risk assessment of security checks to minimize data breaches
- Assist with forms, materials and information required for annual reporting
- Train your staff on how to detect suspicious activity
- Recommend a protocol for staff when potential identity theft is identified
If you would like more information, please call us at 617-559-0404.
About the Author
Anita directs Hayes Business Services' western region team. She brings 28 years of practice management, project management, system implementation and information systems experience to Hayes.
|