On June 20, 2024, a Texas federal court vacated the Office for Civil Rights’ (OCR's) controversial guidance concerning Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates, available here....more
The HIPAA Privacy, Security, and Breach Notification Rules apply to healthcare providers who engage in certain electronic transactions, healthcare clearinghouses, and health plans, including employee group health plans with...more
5/30/2024
/ Affirmative Defenses ,
Breach Notification Rule ,
Cause of Action Accrual ,
Civil Monetary Penalty ,
Covered Entities ,
Department of Health and Human Services (HHS) ,
Disclosure Requirements ,
Employee Training ,
Federal Trade Commission (FTC) ,
FTC Act ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Breach ,
HIPAA Privacy Rule ,
HIPAA Security Rule ,
OCR ,
Penalties ,
PHI ,
Popular
On May 6, 2024, the Department of Health and Human Services (HHS) published its final rule revamping the non-discrimination regulations issued under § 1557 of the Affordable Care Act. The revised rules apply to all...more
5/22/2024
/ Affordable Care Act ,
Americans with Disabilities Act (ADA) ,
Civil Rights Act ,
Compliance ,
Department of Health and Human Services (HHS) ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Healthcare ,
Non-Discrimination Rules ,
Notice Requirements ,
OCR ,
Policies and Procedures ,
Popular ,
Telehealth ,
Title VI
HIPAA applies to both covered entities (e.g., healthcare providers and health plans) and their business associates. A “business associate” is generally a person or entity that “creates, receives, maintains or transmits”...more
10/25/2023
/ Business Associates ,
Business Associates Agreement (BAA) ,
Covered Entities ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Security Rule ,
OCR ,
Patient Confidentiality Breaches ,
PHI ,
Security Risk Assessments ,
Software ,
Subcontractors
The HIPAA Privacy and Security Rules generally require covered entities (including most healthcare providers) to execute written agreements (“business associate agreements” or “BAAs”) with their business associates before...more
10/20/2023
/ Business Associates ,
Business Associates Agreement (BAA) ,
Civil Monetary Penalty ,
Covered Entities ,
Data Breach ,
Disclosure Requirements ,
Electronic Protected Health Information (ePHI) ,
Federal Trade Commission (FTC) ,
Health Care Providers ,
HIPAA Privacy Rule ,
HIPAA Security Rule ,
HIPAA Violations ,
OCR ,
Penalties ,
PHI ,
Settlement ,
Subcontractors ,
Termination ,
Written Agreements
Given the COVID-19 vaccine mandates, employers—including healthcare entities—will need to confirm their employees’ vaccination status. Employers and healthcare providers must ensure they comply with privacy rules relating to...more
9/24/2021
/ Americans with Disabilities Act (ADA) ,
Coronavirus/COVID-19 ,
Disclosure Requirements ,
Employer Mandates ,
Equal Employment Opportunity Commission (EEOC) ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
OCR ,
PHI ,
Vaccinations ,
Virus Testing
With limited exceptions, HIPAA generally gives individuals the right to access or obtain copies of their protected health information ("PHI") from covered entities. (45 CFR § 164.524(a)). But the right of access does not...more
The OCR has announced a surprising number of HIPAA settlements in the past few months with penalties ranging from $10,000 to $6.5 million. Here are some of the key takeaways for healthcare providers:
1. Protect against...more
10/27/2020
/ Centers for Medicare & Medicaid Services (CMS) ,
Cyber Attacks ,
Data Breach ,
Data Protection ,
Department of Health and Human Services (HHS) ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
OCR ,
Personal Information ,
Phishing Scams ,
Settlement
In an era of decreasing reimbursement and rapidly expanding opportunities associated with “big data”, healthcare entities may be looking for ways to monetize protected health information (“PHI”) for their own, non-patient...more
2/20/2020
/ Business Associates ,
Business Associates Agreement (BAA) ,
Consent ,
Consumer Privacy Rights ,
Covered Entities ,
Data Collection ,
Data Privacy ,
Data Sellers ,
Data Use Policies ,
De-Identified Protected Health Information ,
Department of Health and Human Services (HHS) ,
Disclosure Requirements ,
Electronic Protected Health Information (ePHI) ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Privacy Rule ,
Information Sharing ,
Medical Records ,
Notice Requirements ,
OCR ,
PHI ,
Privacy Policy
Thanks to a federal judge, the Office for Civil Rights has modified its rules for sending records to third parties. Covered entities are no longer required by HIPAA to send non-electronic protected health information (“PHI”)...more
2/10/2020
/ Business Associates ,
Covered Entities ,
Data Protection ,
Data Transfers ,
Department of Health and Human Services (HHS) ,
Electronic Protected Health Information (ePHI) ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Omnibus Rule ,
HITECH Act ,
Medical Records ,
OCR ,
Patient Privacy Rights ,
PHI ,
Records Request ,
Right of Access
The HIPAA privacy rules give special protection to “psychotherapy notes,” but providers often misunderstand what are and are not covered and how they differ from other mental health records.
I. “Psychotherapy Notes”...more
1/29/2020
/ Department of Health and Human Services (HHS) ,
Electronic Protected Health Information (ePHI) ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Healthcare Facilities ,
HIPAA Privacy Rule ,
Medical Records ,
Mental Health ,
NPRM ,
OCR ,
Professional Disciplinary Actions
This week, the Office for Civil Rights (“OCR”) announced a $3,000,000 HIPAA settlement arising from a medical center’s loss of an unencrypted laptop and flash drive. This is simply the latest of many HIPAA settlements based...more
11/8/2019
/ Business Associates ,
Covered Entities ,
Department of Health and Human Services (HHS) ,
Electronic Protected Health Information (ePHI) ,
Encryption ,
Enforcement Actions ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Breach Notification Rule ,
HIPAA Security Rule ,
HITECH Act ,
Laptop Computers ,
Mobile Devices ,
OCR ,
Penalties ,
Settlement
Business associates may want to use a covered entity’s protected health information (“PHI”) for the business associates’ own purposes, e.g., for their own product development, data aggregation, marketing, etc. However, with...more
9/6/2019
/ Business Associates ,
Covered Entities ,
Cybersecurity ,
Data Protection ,
Department of Health and Human Services (HHS) ,
Electronic Protected Health Information (ePHI) ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Privacy Rule ,
OCR ,
PHI
Question: May I share records with another healthcare provider without the patient’s authorization?
Answer: It depends on the purpose. If the disclosure is for purposes of the patient’s treatment, including continuation of...more
The HITECH Act extended certain HIPAA obligations to business associates, including those entities that create, receive, maintain or transmit protected health information (“PHI”) on behalf of covered entities. Business...more
Failing to have HIPAA business associate agreements (“BAAs”) can result in significant penalties for healthcare providers and business associates. Last month, the OCR imposed a $500,000 settlement and robust corrective action...more
Under the Health Information Privacy and Portability Act (HIPAA), “covered entities” (generally speaking health care providers and their business associates) must all complete a risk assessment to identify and mitigate...more
HIPAA privacy and security violations can result in fines of $110 to $55,100 to covered entities (including healthcare providers and health plans) and their business associates. (45 CFR 160.404). If the violation resulted...more
10/22/2018
/ Cyber Attacks ,
Cybersecurity ,
Department of Health and Human Services (HHS) ,
Electronic Medical Records ,
Hackers ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Breach ,
Notice Requirements ,
OCR ,
Personally Identifiable Information ,
PHI
There is a common misunderstanding that healthcare providers may not or should not produce medical records that were created by another healthcare provider.
Under HIPAA, patients have a right to access all records that a...more