Latest Posts › Department of Health and Human Services (HHS)

Share:

HIPAA Attestation Requirement Is No More

On June 18, 2025, in Purl v. U.S. Dep't of Health and Human Services, the U.S. District Court for the Northern District of Texas vacated the 2024 amendments to the HIPAA Privacy Rule that enhanced certain privacy protections...more

HIPAA Security Rule Resolves To Hit the Gym and Bulk Up

For more than 20 years, the HIPAA Security Rule has been virtually unchanged other than extending its scope beyond covered entities to also include business associates. During that time, technology has changed, cybersecurity...more

Whether Naughty or Nice, Compliance Deadline for HIPAA Reproductive Care Privacy Is Coming to Town

We just want to provide a friendly reminder that, before key staff depart for the holidays, HIPAA covered entities and business associates should finalize their compliance with the 2024 HIPAA amendments related to...more

Federal District Court Casts Doubt on HHS HIPAA Tracking Technology Guidance

The U.S. District Court for the Northern District of Texas ruled that HHS's December 1, 2022, guidance applying HIPAA to online tracking technologies is unlawful with respect to its treatment of certain combinations of...more

HHS Amends HIPAA To Further Protect Privacy of Reproductive Health Care Information

The U.S. Department of Health and Human Services (HHS) this week released final amendments to the HIPAA Privacy Rule to further protect the privacy of protected health information (PHI) related to reproductive health care....more

OCR Updates Guidance on HIPAA and Online Tracking, But New Examples Lead to New Questions

Changes to guidance are unlikely to mitigate widespread concerns - On March 18, 2024, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) revised its controversial guidance on how HIPAA applies...more

LEAP, Don't Run, to Make this YEAR's Deadline: HIPAA Small Breach Notifications Due February 29

February 29, 2024, is the date by which HIPAA-covered entities must notify the U.S. Department of Health and Human Services Office for Civil Rights (OCR) of all "small" breaches of unsecured protected health information that...more

Information Blocking Enforcement Is Here – Are You Ready?

The U.S. Department of Health and Human Services (HHS) Office of Inspector General (OIG) announced its final rule (the Enforcement Rule) implementing the information blocking penalties created by the 21st Century Cures Act...more

HHS Publishes Guidance on Using Online Tracking Technologies Under HIPAA

The U.S. Department of Health and Human Services Office for Civil Rights (OCR) issued a bulletin on December 1, 2022, clarifying that "regulated entities are not permitted to use tracking technologies in a manner that would...more

OCR Issues New Guidance Applying Security Rule to Digital Voice Transmissions and Storage

On June 13, 2022, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) announced new guidance on using remote communication technologies to provide audio-only telehealth services in compliance with...more

Politics and PHI, Bad Online Reviews, and the Right of Access

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced four enforcement resolutions at the end of March 2022, with issues ranging from the misuse of protected health information (PHI)...more

Some Things Are Inevitable … Death, Taxes, and Rising HIPAA Penalties

It used to be easy to calculate HIPAA penalties in your head—$50,000 per violation and up to $1.5 million per calendar year for multiple violations of the same HIPAA provision. But those days of easy math are long gone since...more

More Time for Filing Comments on Proposed HIPAA Changes

The U.S. Department of Health and Human Services (HHS) recently announced a 45-day extension of the comment period for proposed changes to the HIPAA Privacy Rule. The deadline for submitting comments now has been pushed from...more

Will the Biden Administration Complete the "Regulatory Sprint" With HHS' Proposed HIPAA Amendments?

On January 21, 2021, the Department of Health and Human Services (HHS) published proposed changes to the privacy rule (Privacy Rule) of the Health Insurance Portability and Accountability Act (HIPAA). This Notice of Proposed...more

HHS Reinterprets (and Significantly Lowers) Annual Penalty Caps for HIPAA Violations

The Department of Health and Human Services Office for Civil Rights (OCR) today announced that it is lowering the maximum total penalties it may assess against covered entities and business associates for multiple violations...more

Where Is the HIPAA Right to Defend One’s Self?

When a patient publicly disparages a health care provider, HIPAA leaves the health care provider in a seemingly impossible situation. If the health care provider does not respond and dispute the allegation, then its...more

Is OCR Moving the Goal Posts on Vendor Management?

Recent statements at the 27th National HIPAA Summit suggest that the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) may be changing its position and expecting a greater level of vendor due...more

ACA’s Nondiscrimination Taglines and Notices Require Updating Your Notice of Privacy Practices

There has been confusion as to whether the Affordable Care Act’s nondiscrimination provision (“ACA”) affects a covered entity’s notice of privacy practices (“NPP”) or data breach notifications. OCR has issued guidance...more

Tick Tock Tick Tock, When a Breach Occurs, You’re on the Clock!

As a reminder that state attorneys general have enforcement authority over breach notifications, the New York Attorney General recently announced a $130,000 settlement for a failing to provide breach notification in a...more

Public Still Must be Kept Private under HIPAA

A not-for-profit health care system recently agreed to pay the Department of Health and Human Services (HHS) $2.4 million as part of a settlement over potential Health Insurance Portability and Accountability Act (HIPAA)...more

HIPAA Small Breach Notification Due March 1: “In Like a Lion, Out Like a Lamb” if You Submit Timely

March 1, 2017 is the date by which HIPAA covered entities must notify the U.S. Department of Health and Human Services Office for Civil Rights (OCR) of “small” breaches of unsecured protected health information that were...more

The Price of PHI – A $2.2 Million USB Drive

A stolen unencrypted USB drive led to a $2.2 million settlement and a Resolution Agreement. The Department of Health and Human Services Office for Civil Rights (OCR) announced on January 18th a settlement with MAPFRE Life...more

No Phishing: OCR Warns of Phishing Attempts Disguised as Official HIPAA Audit Program Emails

What’s worse than receiving an email indicating that you have been selected for an audit by your favorite government regulator? Clicking on a link in the email and discovering that it is a phishing attack that has just...more

45 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide