HHS

With A New Leader, OCR to Focus on Risk Analysis, HIPAA Enforcement

by Jill McKeon

HHS’ Office for Civil Rights (OCR) recently announced the appointment of a new director, Lisa J. Pino, who will take over the office’s oversight of civil rights enforcement, HIPAA...

HC3 Warns Health Sector Against LockBit Ransomware Variant

by Jill McKeon

HHS’ Health Sector Cybersecurity Coordination Center (HC3) released a threat brief warning the heath sector of LockBit Ransomware, a hacking group that orchestrated an attack on Ireland-based...

HHS Announces Former DHS Official Lisa J. Pino as New OCR Director

by Jill McKeon

HHS has appointed Lisa J. Pino as director of the Office for Civil Rights (OCR). OCR oversees civil rights enforcements, HIPAA regulations, security, privacy, and breach notification rules. Most...

BlackMatter Ransomware Attacks Threaten Healthcare, HC3 Says

by Jill McKeon

The Health Sector Cybersecurity Coordination Center (HC3) recently released a detailed threat brief on BlackMatter ransomware, a group that first surfaced in July 2021 shortly after the notorious...

GAO: HHS Must Collaborate to Ensure Healthcare Cybersecurity

by Jill McKeon

HHS clearly defined roles and responsibilities within its security departments, but a lack of collaboration between these entities is preventing adequate healthcare cybersecurity, according to a study...

OCR Settles With West Virginia-Based DELC for HIPAA Right of Access Failure

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it reached a settlement with West Virginia specialist Diabetes, Endocrinology & Lipidology Center (DELC) for $5,000, to...

OCR Settles with AEON Clinical for $25K Over Multiple HIPAA Failures

by Jessica Davis

Peachstate Health Management, doing business as AEON Clinical Laboratories, has settled with the Department of Health and Human Services Office for Civil Rights for $25,000 and agreed to a...

HHS’ Proposed HIPAA Right of Access Changes: CHIME, ABHW Weigh in

by Jessica Davis

CHIME and the Association for Behavioral Health and Wellness sent letters to the Department of Health and Human Services, in response to proposed changes to HIPAA. Among a range of concerns are...

GAO Audit Finds HHS Information Security Program “Not Effective”

by Jessica Davis

An evaluation of the Department of Health and Human Services against Federal Information Security Modernization Act of 2014 (FISMA) principles found the agency’s information security program...

OCR Settles With NJ Specialist for Over HIPAA Right of Access Failure

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it reached a settlement with Village Plastic Surgery (VPS) to resolve potential violations of the HIPAA right of access...

Arbour Hospital Pays OCR $65K Over HIPAA Right of Access Violation

by Jessica Davis

The Department of Health and Human Services announced it reached a $65,000 settlement with Massachusetts-based Arbour Hospital, which resolved potential violations of the HIPAA right of access...

HHS Extends Comment Period for HIPAA Privacy Rule Changes

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights announced it has extended the comment period for proposed changes to the HIPAA Privacy Rule. Proposed in December 2020, the changes...

$70K OCR Penalty for Sharp Health Over HIPAA Right of Access Failures

by Jessica Davis

California-based Sharp HealthCare, doing business as Sharp Rees-Stealy Medical Centers (SRMC), has agreed to a corrective action plan and to pay the Office for Civil Rights a $70,000 civil monetary...

Renown Health Pays OCR $75K for HIPAA Right of Access Failure

by Jessica Davis

The Office for Civil Rights reached a $75,000 civil monetary penalty and corrective action plan with Nevada-based Renown Health, to settle a potential violation of the HIPAA right of access...

Insurer Pays $5.1M OCR Penalty for Data Breach Involving 9.3M Patients

by Jessica Davis

New York-based Excellus Health Plan, doing business as Excellus BlueCross BlueShield and Univera Healthcare, agreed to a $5.1 million civil monetary penalty and a corrective action plan with the...

Banner Health to Pay OCR $200K for HIPAA Right of Access Failures

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights reached a $200,000 civil monetary penalty and a corrective action plan with Banner Health, to resolve potential violations of the...

HIPAA Safe Harbor Bill Becomes Law; Requires HHS to Incentivize Security

by Jessica Davis

President Donald Trump officially signed HR 7898 into law on January 5. The HIPAA Safe Harbor bill amends the HITECH act to require the Department of Health and Human Services to incentivize best...

FBI, HHS Alert to COVID-19 Vaccine Fraud Schemes Aimed at Data Theft

by Jessica Davis

All private sector organizations should be on the alert for fraud schemes tied to the COVID-19 vaccine, as multiple complaints have been received by the Department of Health and Human Services Office...

Elite Primary Care Pays OCR $36K for HIPAA Right of Access Violation

by Jessica Davis

Elite Primary Care in Georgia has agreed to a $36,000 settlement with the Office for Civil Rights to resolve a potential violation of the HIPAA Privacy Rule's right of access...

Health IT Groups Laud Proposed Bill Incentivizing Best Practice Security

by Jessica Davis

Several health IT industry stakeholder groups have issued support of legislation recently passed by the House Energy and Commerce Committee. The proposed HR 7898 bill would require the Department...