On June 18, 2025, a Texas court issued a ruling that vacated, on a nationwide basis, the HIPAA Privacy Rule to Support Reproductive Health Care Privacy (the “Reproductive Health Rule”), just one year after the rule went into...more
2023 marked 20 years since the first compliance deadline under the Health Insurance Portability and Accountability Act’s (“HIPAA”) privacy rule. Despite the two decades of experience with HIPAA, compliance continues to remain...more
1/4/2024
/ Business Associates ,
Compliance ,
Corrective Action Plans (CAPs) ,
Covered Entities ,
Cybersecurity ,
Data Security ,
Data-Sharing ,
Electronic Protected Health Information (ePHI) ,
Enforcement Actions ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Privacy Rule ,
Hospitals ,
OCR ,
PHI ,
Phishing Scams ,
Popular ,
Regulatory Oversight ,
Settlement ,
Telehealth ,
Tracking Systems ,
Websites
Over the past decade, the number of health care data breaches reported to the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) has increased dramatically. From 2009 to 2022, over 5,000 data...more
5/22/2023
/ Business Associates ,
Covered Entities ,
Data Breach ,
Department of Health and Human Services (HHS) ,
Enforcement Actions ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Breach ,
OCR ,
PHI ,
Settlement
The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) has been actively enforcing HIPAA regulations this year, including a series of seven settlements under OCR’s Right of Access...more
10/15/2020
/ Civil Monetary Penalty ,
Department of Health and Human Services (HHS) ,
Enforcement Actions ,
Health Care Providers ,
Health Insurance ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Medical Records ,
OCR ,
PHI ,
Right of Access ,
Settlement Agreements
This post provides an update on a number of HIPAA waivers that have just been made available to health care providers: (1) Waivers for hospitals in the initial 72 hours of enacting a disaster protocol; and (2) Waivers for all...more