HIPAA Compliance

OCR Issues HIPAA Guidance Surrounding Extreme Risk Protection Orders

by Jill McKeon

HHS’s Office for Civil Rights (OCR) released new guidance to clarify how HIPAA permits covered healthcare providers to disclose protected health information (PHI) without a patient’s...

Former NY Hospital Employee Charged with HIPAA Violation

by Jill McKeon

New York-based Huntington Hospital began notifying 13,000 patients of a data breach that exposed protected health information (PHI) and resulted in a former employee being charged with a HIPAA...

Millions of Patients Receive Healthcare Data Breach Notifications

by Jill McKeon

Under the HIPAA Breach Notification Rule, HIPAA covered entities are required to provide notification of a healthcare data breach to impacted individuals whose protected health information (PHI) was...

2 NJ Printing Companies Fined for HIPAA Violations, PHI Exposure

by Jill McKeon

Two New Jersey-based printing companies agreed to pay a fine of $130,000 for potentially committing HIPAA violations and New Jersey Consumer Fraud Act (CFA) violations through protected health...

De-Identification of PHI According to the HIPAA Privacy Rule

by Jill McKeon

De-identification of protected health information (PHI) can help researchers glean valuable insights about population health, aid in healthcare policymaking, and bolster other research ventures. Once PHI is de-identified and can no longer...

OCR Clarifies HIPAA Rules Surrounding Vaccination Status

by Jill McKeon

The COVID-19 pandemic and vaccine rollout have brought HIPAA into the spotlight, but many Americans continue to misunderstand how HIPAA relates and does not relate to vaccination status. As a result,...

CA Extends Telehealth HIPAA Penalty Exemption Until End of PHE

by Jill McKeon

California Governor Gavin Newsom renewed most of Executive Order N-43-20, which provides certain HIPAA penalty exemptions surrounding the release of patient information for providers who deliver...

OCR Settles 20th HIPAA Right of Access Case With Nebraska Hospital

by Jill McKeon

The HHS Office for Civil Rights (OCR) settled its twentieth case under the HIPAA Right of Access Initiative, marked by an $80,000 civil monetary penalty paid by Nebraska-based Children’s Hospital...

15 Years Later, Walgreens’ HIPAA Violation Case Raises Questions

by Jill McKeon

Following a 2006 HIPAA violation investigation by Indianapolis news station WTHR, CVS and Rite Aid reached settlements with HHS’ Office for Civil Rights (OCR) and paid a combined $3.25 million in...

How Do New Patient Right of Access Policies Impact HIPAA?

by Jill McKeon

It’s been 25 years since HIPAA was signed into law, but new patient right of access policies have experts questioning the future of HIPAA and third-party data sharing, according to a recent op-ed...

NY Law Shows Reasonable Cybersecurity Standards For Health Providers

by Lisa Gentes-Hunt

The pandemic has brought about an increase in healthcare-related electronic information and an increased need for health information regulations, according to...

Report: Privacy Concerns With Apps Used For Opioid Addiction Treatment

by Lisa Gentes-Hunt

A reported released by the ExpressVPN Digital Security Lab on July 7 revealed privacy concerns with ten smart phone apps used in...

Phishing Attack on Five Rivers Health Impacts Data of 156K Patients

by Jessica Davis

Ohio-based Five Rivers Health Centers recently notified 155,748 patients that their personally identifiable and health information was breached after a two-month long email compromise last year,...

Humana, Cotiviti Sued After Insider-Related Healthcare Data Breach

by Jessica Davis

A proposed class action lawsuit has been filed against insurance giant Humana and its vendor Cotiviti following a healthcare data breach impacting 65,000 patients, which was caused by an...

OCR Settles With West Virginia-Based DELC for HIPAA Right of Access Failure

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it reached a settlement with West Virginia specialist Diabetes, Endocrinology & Lipidology Center (DELC) for $5,000, to...

207K Rehoboth McKinley Patients Tied to Conti Ransomware, Data Leak

by Jessica Davis

Two months after the Conti ransomware hacking group leaked data they claim to have stolen from Rehoboth McKinley Christian Health Care Services (RMCHCS), 207,195 patients are being notified of the...

OCR Settles with AEON Clinical for $25K Over Multiple HIPAA Failures

by Jessica Davis

Peachstate Health Management, doing business as AEON Clinical Laboratories, has settled with the Department of Health and Human Services Office for Civil Rights for $25,000 and agreed to a...