HIPAA and Compliance News

New Haven Pays OCR $202K for PHI Breach of 498 Patients, HIPAA Failure

by

The Office for Civil Rights reached a settlement with the city of New Haven, Connecticut, including a $202,400 civil monetary penalty and a corrective action plan, following a...

Aetna to Pay OCR $1M Over 3 Patient Data Breaches, HIPAA Violations

by

The Department of Health and Human Services Office for Civil Rights announced it reached a $1 million settlement with Aetna to resolve potential HIPAA violations stemming from three...

Ensuring Transparency: Language to Avoid in HIPAA Breach Notifications

by

HIPAA-required breach notifications in the wake of a security incident continue to be an Achille’s heel for the healthcare sector. Many notices appear laden with flowery...

3 Compliance Considerations for HIPAA-Required Breach Response

by

In the wake of a breach, navigating a response to quickly eradicate the hackers from the network and reduce the impact of an attack is no easy feat. But in the healthcare sector, ensuring a...

NY Spine Settles with OCR for $100K Over HIPAA Right of Access Violation

by

The Office for Civil Rights announced yet another settlement under the 2019 HIPAA Right of Access Initiative. NY Spine Medicine will pay the agency $100,000 and agreed to a corrective...

Dignity Health to Pay OCR $160K for HIPAA Right of Access Failure

by

Arizona-based Dignity Health, doing business as St. Joseph’s Hospital and Medical Center (SJHMC), has agreed to corrective actions and a $160,000 enforcement action with the...

Treasury Dept: Ransomware Payment Facilitation Could Be Sanction Risk

by

The US Department of Treasury’s Office of Foreign Assets Control (OFAC) issued an advisory on the potential sanction risks associated with companies that facilitate ransomware...

Anthem Settles with 44 States for $40M Over 2014 Breach of 78.8M

by

A multi-state coalition made up of 44 states and Washington, D.C reached a $39.5 million settlement with Anthem, to resolve breach claims stemming from the...

Blackbaud Confirms Hackers Stole Some SSNs, as Lawsuits Increase

by

The ransomware hackers behind the massive Blackbaud ransomware attack and subsequent data breach likely had access to more unencrypted data than previously disclosed, including bank account...

Premera Pays OCR $6.85M to Settle HIPAA Violations, Breach of 10.4M

by

The Department of Health and Human Services Office for Civil Rights settled with Premera Blue Cross for $6.85 million and a corrective action plan, after an audit into the insurer’s...

OCR Settles With Business Associate CHSPSC for $2.3 Over Breach of 6M

by

The Department of Health and Human Services Office for Civil Rights reached a $2.3 million settlement with CHSPSC, which provides services to hospitals and...

Athens Orthopedic Pays OCR $1.5M Over Systemic HIPAA Noncompliance

by

The Office for Civil Rights reached a settlement with the Athens Orthopedic Clinic for $1.5 million over a 2016 data breach caused by the notorious hacking group...

Patient Breach Victims File Lawsuits Against Assured Imaging, BJC Health

by

The patients impacted by two separate data breaches of Assured Imaging and BJC Healthcare have filed lawsuits against the providers, alleging security failings were behind...

HIPAA Compliance: ONC Updates Security Risk Assessment Tool

by

The Office of the National Coordinator (ONC) in collaboration with the Office of Civil Rights released an update to the Department of Health and Human Services Security Risk Assessment Tool designed to...

OCR Settles with 5 Providers Over HIPAA Right of Access Violations

by

The Office for Civil Rights closed investigations and announced settlements with five providers over separate HIPAA right of access violations, which brings the total number of...

Patient Data Privacy Lawsuit Against Google, UChicago Dismissed

by

The patient data privacy lawsuit brought against Google and the University of Chicago Medical Center was dismissed by a federal judge in Illinois on September 4, ruling that patient who filed the...

OCR: IT Asset Inventory Can Improve HIPAA-Required Risk Analysis

by

The Office for Civil Rights recently shared a detailed list of IT asset inventory steps, which can help covered entities and their business associates better fulfill the HIPAA Security Rule...

Lifespan to Pay OCR $1.04M HIPAA Penalty For Unencrypted Laptop Theft

by

The Office for Civil Rights reached a settlement with Lifespan Health System Affiliated Covered Entity over the theft of an unencrypted laptop in 2017. The Rhode...

OCR Settles with Small Provider for $25K Over Multiple HIPAA Violations

by

The Department of Health and Human Services Office for Civil Rights has reached a settlement with North Carolina-based Metropolitan Community Health Services, DBA Agape Health Services, over...

SAMHSA Revises Privacy Rule 42 CFR Part 2 for Substance Use Patients

by

The Department of Health and Human Services’ Substance Abuse and Mental Health Services (SAMHSA) announced the agency has revised the Confidentiality of...