
MACRA gives you the ability to report your measures for any 90-day consecutive period. If you wait until December you will be bound to report your measures for the last quarter of the year or miss your numbers altogether. Considering that the SRA should be your first step in the category of Advancing Care Information, then you shouldn’t report your measures until the next calendar year.
From the standpoint of the meaning of the law, a Security Risk Assessment (SRA) should be conducted at the beginning of the year as a means to establish a baseline and decide upon a plan of action to implement for the rest of the year.
Last but not least, HIPAA Security Risk Assessments (SRA) have become the cornerstone of every Government audit and inspection. Worst of all, each agency we worked with emphasizes a different area of the SRA, which means that these SRAs, at the very least, must be able to address these areas to the satisfaction of the auditing agency. Another point to consider, most of these audits are desk audits so they are cheap and easy to conduct which makes it for an increase of the same regardless of your location. In summary, conduct your SRA as soon as possible and do not cut yourself short by doing it yourself or with the cheapest source as this will not end well.About Dr. Jose Delgado
Dr. Jose I. Delgado is the founder and CEO of Taino Consultants, a veteran-owned, 8(a) graduate healthcare IT consulting firm based in St. Augustine, Florida. With over 30 years of experience in healthcare compliance and government contracting, Dr. Delgado has helped organizations navigate HIPAA, MACRA/MIPS, and federal IT security requirements.
Need help with healthcare compliance?
Taino Consultants provides HIPAA compliance consulting, MACRA/MIPS compliance support, and healthcare IT modernization services for government and private healthcare organizations.
Schedule a consultation
