Office for Civil Rights

HHS Appoints Melanie Fontes Rainer as New OCR Director

by Sarai Rodriguez

Department of Health and Human Services (HHS) Secretary Xavier Becerra has officially sworn in Melanie Fontes Rainer as director of the Office for Civil Rights (OCR).  Since assuming the role...

US Orgs Have Suffered 5,000 Healthcare Data Breaches Since 2009

by Jill McKeon

From 2009 to June 2022, organizations reported nearly 5,000 healthcare data breaches to the HHS Office for Civil Rights (OCR) data breach portal, researchers at Comparitech found. The breaches impacted...

OCR Settles Improper PHI Disposal Case, Resolves Potential HIPAA Violation

by Jill McKeon

The HHS Office for Civil Rights (OCR) settled a case with New England Dermatology and Laser Center (NEDLC) to resolve a potential HIPAA violation involving improper protected health information (PHI)...

OCR Settles 11 HIPAA Right of Access Cases

by Jill McKeon

The HHS Office for Civil Rights (OCR) announced 11 HIPAA Right of Access resolutions. OCR created the HIPAA Right of Access Initiative in 2019 to support patients' right to timely and...

Oklahoma State University Agrees to $875K OCR Data Breach Settlement

by Jill McKeon

Oklahoma State University – Center for Health Sciences (OSU-CHS) agreed to pay the HHS Office for Civil Rights (OCR) $875,000 in a data breach settlement. OSU-CHS also agreed to implement a...

OCR Issues Patient Privacy, HIPAA Privacy Rule Guidance After Roe v. Wade Ruling

by Jill McKeon

The HHS Office for Civil Rights (OCR) issued guidance on patient privacy and rights under the HIPAA Privacy Rule that can help patients maintain security and privacy in light of the recent Roe v. Wade...

GAO Calls on HHS to Improve Healthcare Data Breach Reporting Process

by Jill McKeon

In its latest report, the US Government Accountability Office (GAO) called on HHS to improve the healthcare data breach reporting process. Specifically, GAO urged HHS to create a mechanism for entities...

ONC, OCR Release Updated Version of HHS Security Risk Assessment (SRA) Tool

by Jill McKeon

The Office for Civil Rights (OCR) and the Office of the National Coordinator for Health Information Technology (ONC) released version 3.3 of the HHS Security Risk Assessment (SRA) Tool. ONC and OCR...

OCR to Release Video on HITECH Recognized Security Practices

by Jill McKeon

The HHS Office for Civil Rights (OCR) announced plans to produce a pre-recorded video presentation on the Health Information Technology for Economic and Clinical Health Act (HITECH) recognized security...

Aesto Health, Aon PLC, Alameda Health System Suffer Healthcare Data Breaches

by Jill McKeon

Three organizations suffered healthcare data breaches and reported them to HHS recently. All three incidents described below involved unauthorized access to certain systems or email accounts. In...

CHI, MGMA Respond to OCR’s RFI On Recognized Security Practices Under HITECH

by Jill McKeon

The Connected Health Initiative (CHI) and the Medical Group Management Association (MGMA) both responded to the HHS Office for Civil Rights’ (OCR) request for information (RFI) surrounding...

8 More Orgs Added to Eye Care Leaders EMR Data Breach Tally

by Jill McKeon

Eye Care Leaders, which offers an ophthalmology-specific EMR solution, experienced unauthorized access to its myCare Integrity system in December 2021. Since notifying impacted eye care practices on...

OCR Seeks Public Input on Penalties, Security Measures Under HITECH

by Jill McKeon

HHS’ Office for Civil Rights (OCR) issued a request for information (RFI) seeking feedback on two requirements under the Health Information Technology for Economic and Clinical Health Act...

OCR Announces Four HIPAA Enforcement Actions

by Jill McKeon

The HHS Office for Civil Rights (OCR) announced four HIPAA enforcement actions to hold healthcare providers accountable for potential HIPAA violations. Two of the actions stemmed from OCR’s HIPAA...

OCR Provides Tips for Fending Off Common Healthcare Cyberattacks

by Jill McKeon

The Office for Civil Rights (OCR) issued its quarter one newsletter, containing tips for defending against some of the most common healthcare cyberattacks. The newsletter stated that healthcare...

OCR Director Urges Healthcare to Prioritize Cybersecurity This Year

by Jill McKeon

Office for Civil Rights (OCR) director Lisa J. Pino urged healthcare organizations to prioritize cybersecurity in 2022 in a recent blog post on HHS’s website. Healthcare data breaches are still...

OCR Settles 5 HIPAA Right of Access Cases

by Jill McKeon

The Office for Civil Rights (OCR) announced the resolution of five cases under the HIPAA Right of Access Initiative. OCR created the initiative in 2019 in order to support patients' right to timely...

Ohio Hospital Faces Sixth Day of EHR Downtime After Cyberattack

by Jill McKeon

Healthcare cyberattacks continue to overwhelm the sector as the end of the year approaches. At the time of publication, one Ohio hospital is facing ongoing EHR downtime and appointment cancelations as...

With A New Leader, OCR to Focus on Risk Analysis, HIPAA Enforcement

by Jill McKeon

HHS’ Office for Civil Rights (OCR) recently announced the appointment of a new director, Lisa J. Pino, who will take over the office’s oversight of civil rights enforcement, HIPAA...

OCR Clarifies HIPAA Rules Surrounding Vaccination Status

by Jill McKeon

The COVID-19 pandemic and vaccine rollout have brought HIPAA into the spotlight, but many Americans continue to misunderstand how HIPAA relates and does not relate to vaccination status. As a result,...