Latest Publications

Share:

D’oh! OCR Confirms that Medical Records Should Not be Left in the Driveway

The most recent Office for Civil Rights (“OCR”) HIPAA enforcement action serves as an important reminder to health care providers of the security risks associated with a mishandled medical records custody transfer and the...more

Five Lessons from OCR’s Report to Congress on Breaches and HIPAA Rules Compliance

Last week, the HHS Office of Civil Rights (OCR) released two reports required by the Health Information Technology for Economic and Clinical Health (HITECH) Act: (i) the Annual Report to Congress on Breaches of Unsecured...more

SAMHSA to Hold Part 2 “Listening Session”

The Substance Abuse and Mental Health Services Administration (“SAMHSA”) has scheduled a “public listening session” on Wednesday, June 11, 2014, to seek input on potential changes to the federal Confidentiality of Alcohol and...more

State Data Security Breach Notification Laws

The general definition of “personal information” or “PI” used in the majority of statutes is: An individual’s first name or first initial and last name plus one or more of following data elements: (i) Social Security number,...more

Is Your HIPAA Compliance Program Going Out the Window with XP?

April 8, 2014 marks the end of Microsoft’s support for the Windows XP operating system, which means the end of security updates from Microsoft and the beginning of new vulnerability to hackers and other intruders into systems...more

Compliance is No Joke: OCR Releases Security Risk Assessment Tool

On March 28, 2014, the Office of Civil Rights (OCR) announced the release of an online and iPad app-based security risk assessment (SRA) tool. The tool is intended to help health care providers in small to medium sized...more

En Español: HHS Agencies Issue Model Notices of Privacy Practices in Spanish

Last week, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) and Office for the National Coordinator for Health Information Technology (ONC) issued model Notices of Privacy Practices (NPPs) in...more

CMS Finalizes HIPAA and CLIA Amendments Intended to Increase Patient Access to Test Results

Yesterday the Centers for Medicare & Medicaid Services (CMS) finally published the long-awaited final rule amending the Clinical Laboratory Improvement Amendments of 1988 (CLIA) and the Health Insurance Portability and...more

A New Year’s Resolution (And Corrective Action Plan) From OCR: Physician Practice Cited For HIPAA Violations

The Office for Civil Rights (OCR) is closing out 2013 with a reminder of the importance of an effective HIPAA compliance program. On December 26, 2013, OCR announced a resolution agreement with a Massachusetts physician...more

On the First Day of Privacy, The OCR Gave to Me...

Welcome to our series, “The 12 Days of Privacy” as we look to “gifts” that may be received this season and some of the big issues ahead …. Day One – - HIPAA 2014 – Where will the Audit Trail Lead? The year 2013...more

OCR Clarifies Scope of HIPAA Prescription Refill Reminder Exception

In response to recent litigation as well as concerns from the health care industry and privacy advocates, the Office for Civil Rights (OCR) has published guidance regarding the scope of the refill reminder exception under the...more

9/23/2013

OCR Guidance to Address HIPAA Marketing Turmoil

In response to a recent lawsuit and outcry from a variety of players in the health care market, the Department of Health and Human Services (“HHS”) has committed to issuing guidance by September 23rd (the compliance date for...more

HIPAA Marketing Rules Prompt First Amendment Challenge

In what is believed to be the first legal challenge to the HIPAA Omnibus Rule (the “Rule”), a vendor of prescription drug adherence services is seeking an injunction to block certain provisions of the Rule related to drug...more

Seven-Figure HIPAA Settlement Prompted by Photocopier Breach

The Office for Civil Rights’ (OCR) latest seven-figure fine for HIPAA violations resulted from a failure to remove protected health information or “PHI” from the hard drive of a leased photocopier. The $1,215,780 settlement...more

Privacy Monday – July 22, 2013

Privacy gaffes and tidbits to start your week. Keeping up with Kardashians is NOT a defense under HIPAA - The LA Times recently reported the firing of six workers at Cedars-Sinai Medical Center in connection...more

Keeping Up With the Kardashians Is NOT a Defense Under HIPAA

The LA Times recently reported the firing of six workers at Cedars-Sinai Medical Center in connection with the unauthorized access to patient medical records. The firings occurred in the days following the birth of reality...more

Highlights of the Joint NIST and OCR Safeguarding Health Information Conference

Earlier this week we attended the National Institute of Standards and Technology (NIST) and HHS Office for Civil Rights (OCR) 6th Annual Safeguarding Health Information Conference in Washington, D.C. (the NIST-OCR...more

Final Medical Marijuana Regulations Approved in Massachusetts

The Massachusetts Department of Public Health Public Health Council approved, by unanimous vote, final regulations for the implementation of the medical marijuana ballot initiative law that will allow qualifying patients with...more

5/10/2013  /  Final Rules , Medical Marijuana

Firearms Debate Triggers OCR Request for Comments

Gun violence is a hot topic in the wake of the Newtown shootings and the aftermath of last week’s Boston Marathon bombings, and now health privacy has joined the debate....more

Medical Marijuana – Massachusetts Department of Public Health Posts Proposed Regulations

Today, the Massachusetts Department of Public Health issued proposed regulations regarding the medical use of marijuana. The proposed regulations, formally called Proposed Regulations at 105 CMR 725.000: Implementation of An...more

Countdown Begins for HIPAA Omnibus Rule Compliance

The HIPAA Omnibus Rule goes into effect today, which officially starts the clock for covered entities, business associates, and their subcontractors to begin updating their agreements, forms, policies, procedures, and...more

OCR Wants Feedback From Audited Covered Entities

The Office for Civil Rights (OCR) is preparing to conduct an online survey of the 115 covered entities it audited in 2012 as part of the HITECH-mandated, pilot audit program. OCR hopes to use the survey results to evaluate...more

The New HIPAA Omnibus Rule & Your Liability — A Detailed Review

As we have reported in this blog, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) recently released final regulations containing modifications to the HIPAA Privacy, Security, Enforcement, and...more

HIPAA Omnibus Rule Reference Chart

Mintz Levin is pleased to provide this section-by-section analysis of the HIPAA Omnibus Rule. The chart lists provisions of the proposed privacy, security and enforcement rules mandated by the Health Information...more

Finally! HHS Office of Civil Rights Releases HIPAA Omnibus Rule With Sweeping Changes to Compliance Requirements and Enforcement

The final regulations from Department of Health and Human Services Office of Civil Rights (OCR) containing modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules (Omnibus Rule) have finally...more

75 Results
 / 
View per page
Page: of 3

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide