Latest Posts › Health Care Providers

Share:

New Year, New HIPAA Security Rules Headed Your Way

What better way to welcome the new year than with proposed new HIPAA Security Rules? As 2024 came to an end, the U.S. Department of Health and Human Services announced new proposed regulations to strengthen cybersecurity and...more

Confidentiality of Substance Use Disorder Records Now More Closely Aligned With HIPAA

Today the U.S. Department of Health & Human Services (HHS) finalized rules published in December of 2022 changing the requirements for handling SUD patient information governed by 45 CFR part 2 (Part 2)....more

Are We There Yet? New HIPAA Privacy Protections for Reproductive Health Data May Be Just Ahead

As states enact and enforce various laws restricting, prohibiting, and even criminalizing abortion and other reproductive health care services, HIPAA rules that allow disclosure of patient information become potential privacy...more

Data Privacy Day: 15 Tips to Keep in Mind for the Coming Year

Data Privacy Day is this weekend. Here are some tips and pointers individuals and businesses should keep in mind going forward. 1. Transparency is front and center for regulators in the United States and Europe, so if...more

Updated OCR Guidance On Contacting Recovered COVID-19 Patients

The Office for Civil Rights within the Department of Health and Human Services (OCR) provided guidance in June that reassured covered entity health care providers and that it is generally OK to use or disclose protected...more

“I Have An App For That”: ONC’s Information Blocking Rule And HIPAA Access Rights

A patient asks her doctor to send her test results to an app the patient has downloaded on her phone. The doctor worries that the app is not secure and that the patient might not understand the security risks. What should...more

OCR Webinar On HIPAA And COVID-19: Key Points For Covered Entities And Business Associates

Fox Rothschild LLP partner Beth Larkin listened to the HHS Office for Civil Rights 4/24/20 webinar (which should be posted on its website at some point) regarding HIPAA and COVID-19 and took notes. Here’s my summary of key...more

Does the HIPAA Concept Of De-identification Serve To Adequately Protect The Privacy Of All Personal Health Information?

Some twenty-three years ago, the first well-publicized incident of the re-identification of de-identified personal health data was brought to the attention of the American public. It involved the then governor of...more

Tell Me Again: What Can Covered Entities (Or Their Business Associates) Charge For Medical Records Requests?

The answer to this question has changed yet again. I’ve blogged on this topic several times in the past, and described the question as a wriggling worm. Plaintiff Ciox Health, LLC has finally managed to catch that worm and...more

Clear Message From OCR: Don’t Ignore (Or Overcharge For) Patient Requests For Records

Last week, the Office for Civil Rights (OCR) announced its second enforcement action and settlement with a provider for failing to comply with HIPAA’s patient access requirements. Korunda Medical, LLC, a primary care and...more

How The Grinch Steals Health Care Data: OCR Warnings And Tips In Time For The Holidays

More and more often, health care data is stolen or made inaccessible by targeted ransomware attacks. The Office for Civil Rights (OCR) published a newsletter this week that provides warnings for HIPAA covered entities and...more

One Of Three $3 Million Lessons: Encrypt Mobile Devices

A large New York hospital system learned this lesson the expensive way. According to a U.S. Department of Health and Human Services (HHS) press release issued earlier this week, the Office for Civil Rights (OCR) investigated...more

Back To School And Back To BAAs: OCR Guidance Provides Reason To Review BAA Provisions

Last May, around the time many schools let out for the summer, the Office for Civil Rights (“OCR”) published guidance entitled “Direct Liability of Business Associates” (the “Guidance”), which focuses, not surprisingly, on...more

Too Much (Protected Health) Information Exposed + Too Little Response = $3M And Corrective Action Plan For Medical Imaging Company

“TMI” usually means “too much information”, but it was used aptly by the Office for Civil Rights (OCR) as an acronym for a covered entity that exposed protected health information (PHI) of more than 300,000 patients through...more

Feeling Lucky? You Could Be One Of The Nine Covered Entities Selected For HIPAA Compliance Review This Month

If you are a covered entity health plan or clearinghouse, you may be among the nine (un)lucky entities randomly chosen this month for review into compliance with HIPAA’s Administrative Simplification rules governing...more

HIPAA Security And “Zero Day” Exploits: How To Stay Ahead Of The Hack

HHS Office for Civil Rights (OCR)’s April 3, 2019 cybersecurity newsletter highlights one of the more challenging cybersecurity vulnerabilities faced by covered entities and business associates. OCR reminds covered entities...more

Don’t Miss Your Opportunity To Tell HHS How To Improve HIPAA

The U.S. Department of Human Services’ Office for Civil Rights has set a Feb. 12 deadline for stakeholders to comment on how it should modify HIPAA, especially the Privacy Rule, to promote coordinated, value-based health...more

The Heavy Hit Of HIPAA: Violations May Send You To Jail

The recent criminal conviction of a Massachusetts physician provides a stark reminder that violating HIPAA can result in more than civil monetary penalties and the financial and reputational fall-out that results from a...more

The President Can Tweet, But Can A Doctor Text?

Text messaging is a convenient way for busy doctors to communicate, but for years, the question has remained: are doctors allowed to convey sensitive health information with other members of their provider team over SMS? The...more

Top 5 Common HIPAA Mistakes To Avoid In 2018

Heading into its 22nd year, HIPAA continues to be misunderstood and misapplied by many, including health care industry professionals who strive for (or at least claim the mantle of) HIPAA compliance. Here is my “top 5” list...more

“Getting Receipts” – The Millennial Disconnect Between Short-Term Social Media Posts And HIPAA

Long gone are the days when social media consisted solely of Myspace® and Facebook®, accessible only by logging in through a desktop computer at home or personal laptop. With every single social media platform readily...more

Electronic Health Records And HIPAA Security: A Design Problem Fixable With Blockchain Technology?

In some respects, HIPAA has had a design problem from its inception. HIPAA is well known today as the federal law that requires protection of individually identifiable health information (and, though lesser-known, individual...more

23 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide