Office for Civil Rights

HHS Proposes HIPAA Privacy Rule Changes, Improving Right of Access

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights released a set of proposed changes to the HIPAA Privacy Rule, which take aim at Right of Access rules and are designed to reduce...

Ohio Medical Center Pays OCR $65K for HIPAA Right of Access Failure

by Jessica Davis

The University of Cincinnati Medical Center in Ohio has agreed to a $65,000 settlement and a corrective action penalty with the Office for Civil Rights to resolve a potential violation of the...

NY Specialist Pays OCR $15K for HIPAA Right of Access Failures

by Jessica Davis

The Office for Civil Rights announced it reached a settlement with Rajendra Bhayani, MD, a private practice otolaryngology specialist based in Regal Park, New York for $15,000 and a corrective action...

OCR Settles with Psychiatric Provider for HIPAA Right of Access Violation

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it reached a $25,000 settlement with California-based Riverside Psychiatric Medical Group...

New Haven Pays OCR $202K for PHI Breach of 498 Patients, HIPAA Failure

by Jessica Davis

The Office for Civil Rights reached a settlement with the city of New Haven, Connecticut, including a $202,400 civil monetary penalty and a corrective action plan, following a...

Aetna to Pay OCR $1M Over 3 Patient Data Breaches, HIPAA Violations

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it reached a $1 million settlement with Aetna to resolve potential HIPAA violations stemming from three...

NY Spine Settles with OCR for $100K Over HIPAA Right of Access Violation

by Jessica Davis

The Office for Civil Rights announced yet another settlement under the 2019 HIPAA Right of Access Initiative. NY Spine Medicine will pay the agency $100,000 and agreed to a corrective...

Dignity Health to Pay OCR $160K for HIPAA Right of Access Failure

by Jessica Davis

Arizona-based Dignity Health, doing business as St. Joseph’s Hospital and Medical Center (SJHMC), has agreed to corrective actions and a $160,000 enforcement action with the...

Premera Pays OCR $6.85M to Settle HIPAA Violations, Breach of 10.4M

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights settled with Premera Blue Cross for $6.85 million and a corrective action plan, after an audit into the insurer’s...

Top Healthcare Cybersecurity Resources from NIST, HHS, OCR, HSCC

by Jessica Davis

Many healthcare providers struggle with finding and retaining security staff, as well as budget constraints, which make it difficult to properly secure the enterprise. In...

OCR Settles With Business Associate CHSPSC for $2.3 Over Breach of 6M

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights reached a $2.3 million settlement with CHSPSC, which provides services to hospitals and...

Athens Orthopedic Pays OCR $1.5M Over Systemic HIPAA Noncompliance

by Jessica Davis

The Office for Civil Rights reached a settlement with the Athens Orthopedic Clinic for $1.5 million over a 2016 data breach caused by the notorious hacking group...

HIPAA Compliance: ONC Updates Security Risk Assessment Tool

by Jessica Davis

The Office of the National Coordinator (ONC) in collaboration with the Office of Civil Rights released an update to the Department of Health and Human Services Security Risk Assessment Tool designed to...

OCR Settles with 5 Providers Over HIPAA Right of Access Violations

by Jessica Davis

The Office for Civil Rights closed investigations and announced settlements with five providers over separate HIPAA right of access violations, which brings the total number of...

OCR Updates HIPAA Resource for mHealth Apps, Cloud Computing

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights updated and renamed its former Health App Developer Portal as a HIPAA resource page for mobile health apps, APIs, and...

OCR: IT Asset Inventory Can Improve HIPAA-Required Risk Analysis

by Jessica Davis

The Office for Civil Rights recently shared a detailed list of IT asset inventory steps, which can help covered entities and their business associates better fulfill the HIPAA Security Rule...

Lifespan to Pay OCR $1.04M HIPAA Penalty For Unencrypted Laptop Theft

by Jessica Davis

The Office for Civil Rights reached a settlement with Lifespan Health System Affiliated Covered Entity over the theft of an unencrypted laptop in 2017. The Rhode...

OCR Settles with Small Provider for $25K Over Multiple HIPAA Violations

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights has reached a settlement with North Carolina-based Metropolitan Community Health Services, DBA Agape Health Services, over...

OCR Shares COVID-19 Guide on Contacting Patients for Blood Donations

by Jessica Davis

The Office for Civil Rights released guidance for healthcare covered entities on the HIPAA-permitted ways providers can contact patients recovering from COVID-19 to inform them of blood and plasma...

OCR Shares COVID-19 Privacy and Security Threat Resources

by Jessica Davis

The Office for Civil Rights issued a list of COVID-19-related cyber threat resources for covered healthcare providers to help the sector best prevent, detect, respond, and recover from privacy and...