HIPAA and Compliance News

SAMHSA Revises Privacy Rule 42 CFR Part 2 for Substance Use Patients

by

The Department of Health and Human Services’ Substance Abuse and Mental Health Services (SAMHSA) announced the agency has revised the Confidentiality of...

$185K Proposed Settlement Reached in Grays Harbor Data Breach Lawsuit

by

Grays Harbor Community Hospital and Harbor Medical Group has reached a proposed $185,000 settlement with the 88,000 patients impacted by a June 2019 ransomware attack, which drove...

Inadequate Security, Policies Led to LifeLabs Data Breach of 15M Patients

by

Ontario and British Columbia Information and Privacy Commissioners have concluded LifeLabs failed to protect the personal health information of the 15 million patients impacted by its...

UnityPoint Health Reaches $2.8M Settlement Over 2018 Data Breach

by

Iowa Health System, doing business as UnityPoint Health, has reached a proposed $2.8 million settlement with the millions of patients impacted by two phishing-related data breaches in 2017 and...

Judge Sends Episcopal Health Data Breach Lawsuit Back to State Court

by

A federal judge of the U.S. District Court for the Eastern District of New York has sent a data breach lawsuit against Episcopal Health Services back to state level courts, saying it lacked the grounds...

OCR Shares COVID-19 Guide on Contacting Patients for Blood Donations

by

The Office for Civil Rights released guidance for healthcare covered entities on the HIPAA-permitted ways providers can contact patients recovering from COVID-19 to inform them of blood and plasma...

Community Care Patients Sue Accounting Firm Over Data Breach

by

A class-action lawsuit has been filed against accounting firm BST and Co. CPAs, over a ransomware attack that breached the data of 170,000 patients from Community Care Physicians in New York, first...

Aveanna Healthcare Faces Lawsuit Over Monthlong Data Breach

by

Georgia-based Aveanna Healthcare is facing a class-action lawsuit filed by more than 100 patients impacted by a monthlong data breach from 2019. Over 166,000 patients were affected by the security...

Crafting Successful Business Associate Agreements, Breach Response

by

The healthcare sector relies heavily upon its relationships with third-party vendors and business associates, which are critical to ensuring uninterrupted patient care. However, given the vast number...

Zoom Settles with NY AG Over COVID-19-Related Privacy, Security Issues

by

Zoom settled with New York Attorney General Letitia James on May 7, following a state-led investigation into the videoconferencing platform. James launched an investigation after a number of privacy...

COVID-19: OCR Reminds Providers of Media Access Restrictions to PHI

by

The Office for Civil Rights issued a reminder to healthcare providers that even amid the COVID-19 crisis, the HIPAA Privacy Rule does not permit them to give site access to media and other film...

LabCorp Hit with Shareholder Lawsuit Over 2 Separate Data Breaches

by

LabCorp shareholder Raymond Eugenio recently filed suit against the lab testing giant, as well as its 12 directors and executives, to recoup share value losses caused by two data breaches, first...

Ciitizen: ‘Significant Improvement’ in HIPAA Right of Access Compliance

by

Ciitizen released its third Patient Record Scorecard, which found significant improvements in the number of providers in compliance with the HIPAA Right of Access rule. In fact, the number of...

OCR Lifts HIPAA Penalties for COVID-19 Community-Based Testing Sites

by

The Office for Civil Rights announced yet another enforcement discretion during the Coronavirus pandemic, lifting potential HIPAA penalties related to noncompliance for covered entities and business...

Sens. Probe Privacy, Cybersecurity of Apple COVID-19 Screening Tools

by

Apple recently announced the launch of a new COVID-19 screening app and website based on guidance from the Centers for Disease Control and Prevention. In response, a group of Senators are looking into...

OCR Permits Business Associates to Share Patient Data During COVID-19

by

The Office for Civil Rights will waive penalties for HIPAA noncompliance against providers or business associates over the good faith use and disclosure of protected health information during the...

OCR Shares COVID-19 PHI, Data Sharing Guidance for First Responders

by

The Office for Civil Rights released guidance for how protected health information on patients exposed or infected with COVID-19 can be shared with first responders, such as law enforcement,...

OCR Clarifies HIPAA Liability on Telehealth Use During COVID-19

by

The Department of Health and Human Services’ Office for Civil Rights released a list of frequently asked questions to common concerns raised about its recent move to lift certain HIPAA penalties...

OCR Lifts HIPAA Penalties for Telehealth Use During COVID-19

by

The Department of Health and Human Services’ Office for Civil Rights announced it will not impose penalties for noncompliance with HIPAA regulations against providers leveraging telehealth...

HHS Issues Limited Waiver of HIPAA Sanctions Due to Coronavirus

by

Following President Donald Trump’s declaration of a nationwide emergency over the Coronavirus, or COVID-19, the Department of Health and Human Service Secretary Alex Azar issued a limited waiver...