HHS

HHS Proposes HIPAA Privacy Rule Changes, Improving Right of Access

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights released a set of proposed changes to the HIPAA Privacy Rule, which take aim at Right of Access rules and are designed to reduce...

Final HHS Rules Provide Safe Harbor for Cybersecurity Tech Donations

by Jessica Davis

The Department of Health and Human Services published two final rules on Friday designed to reduce regulatory barriers and improve care coordination, which both contain safe harbor provisions that will...

Ransomware Wave Hits Healthcare, as 3 Providers Report EHR Downtime

by Jessica Davis

The FBI is investigating an ongoing wave of cyberattacks, including Ryuk ransomware, trouncing US hospitals, health systems, and other providers. At least three systems...

Aetna to Pay OCR $1M Over 3 Patient Data Breaches, HIPAA Violations

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it reached a $1 million settlement with Aetna to resolve potential HIPAA violations stemming from three...

NY Spine Settles with OCR for $100K Over HIPAA Right of Access Violation

by Jessica Davis

The Office for Civil Rights announced yet another settlement under the 2019 HIPAA Right of Access Initiative. NY Spine Medicine will pay the agency $100,000 and agreed to a corrective...

Premera Pays OCR $6.85M to Settle HIPAA Violations, Breach of 10.4M

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights settled with Premera Blue Cross for $6.85 million and a corrective action plan, after an audit into the insurer’s...

Top Healthcare Cybersecurity Resources from NIST, HHS, OCR, HSCC

by Jessica Davis

Many healthcare providers struggle with finding and retaining security staff, as well as budget constraints, which make it difficult to properly secure the enterprise. In...

Lifespan to Pay OCR $1.04M HIPAA Penalty For Unencrypted Laptop Theft

by Jessica Davis

The Office for Civil Rights reached a settlement with Lifespan Health System Affiliated Covered Entity over the theft of an unencrypted laptop in 2017. The Rhode...

Ciitizen: ‘Significant Improvement’ in HIPAA Right of Access Compliance

by Jessica Davis

Ciitizen released its third Patient Record Scorecard, which found significant improvements in the number of providers in compliance with the HIPAA Right of Access rule. In fact, the number of...

OCR Clarifies HIPAA Liability on Telehealth Use During COVID-19

by Jessica Davis

The Department of Health and Human Services’ Office for Civil Rights released a list of frequently asked questions to common concerns raised about its recent move to lift certain HIPAA penalties...

OCR Lifts HIPAA Penalties for Telehealth Use During COVID-19

by Jessica Davis

The Department of Health and Human Services’ Office for Civil Rights announced it will not impose penalties for noncompliance with HIPAA regulations against providers leveraging telehealth...

HHS Issues Limited Waiver of HIPAA Sanctions Due to Coronavirus

by Jessica Davis

Following President Donald Trump’s declaration of a nationwide emergency over the Coronavirus, or COVID-19, the Department of Health and Human Service Secretary Alex Azar issued a limited waiver...

As HHS Responds to Coronavirus, Network Targeted by Cyberattack

by Jessica Davis

The Department of Health and Human Services faced a targeted cyberattack on its network Sunday night. Hackers launched a disruptive disinformation campaign designed to impede the agency’s...

OCR Settles with Utah Provider for $100K Over HIPAA Security Failures

by Jessica Davis

The provider office of Steven Porter, MD in Ogden, Utah has settled with the Department of Health and Human Services Office for Civil Rights after failing to implement certain HIPAA security...

OIG Finds NIH Security Practices Potentially Put EHR Data at Risk

by Jessica Davis

The security policies and practices around the electronic health system of the National Institutes of Health may have potentially put the security, confidentiality, integrity, and availability of its...

OIG Finds Serious Misuse of Medicare Data Transactions by Pharmacies

by Jessica Davis

The Department of Health and Human Service Office of the Inspector General recently discovered widespread inappropriate access and use of Medicare beneficiary data by pharmacies and other healthcare...

AHIP: CMS Price Transparency Proposal Poses Patient Privacy Risk

by Jessica Davis

In November, the Trump Administration rolled out broad transparency rules designed to provide consumers with more insights into how much hospitals charge health insurers for both out-of- and in-network...

Judge Rules Against HHS Over HIPAA Right of Access Third-Party Fees

by Jessica Davis

Washington, DC US District Court Judge Amit Mehta issued a blow to the Department of Health and Human Services for its 2013 HIPAA Right of Access rule around third-party requests for patient records,...

ONC Draft Federal Health IT Strategy Puts Privacy, Security in Focus

by Jessica Davis

The Department of Health and Human Services released its proposed Federal Health IT Strategy for 2020 to 2025, developed with the Office of the National Coordinator for Health Information Technology....

HSCC Tells HHS: Include Patching in Stark Law Cybersecurity Donations

by Jessica Davis

The Department of Health and Human Services’ proposed changes to the Physician Self-Referral Law (Stark Law) and the Federal Anti-Kickback Statute should include patching and update language in...