HIPAA Compliance

OCR Settles with Small Provider for $25K Over Multiple HIPAA Violations

by Jessica Davis

The Department of Health and Human Services Office for Civil Rights has reached a settlement with North Carolina-based Metropolitan Community Health Services, DBA Agape Health Services, over...

SAMHSA Revises Privacy Rule 42 CFR Part 2 for Substance Use Patients

by Jessica Davis

The Department of Health and Human Services’ Substance Abuse and Mental Health Services (SAMHSA) announced the agency has revised the Confidentiality of...

$185K Proposed Settlement Reached in Grays Harbor Data Breach Lawsuit

by Jessica Davis

Grays Harbor Community Hospital and Harbor Medical Group has reached a proposed $185,000 settlement with the 88,000 patients impacted by a June 2019 ransomware attack, which drove...

UnityPoint Health Reaches $2.8M Settlement Over 2018 Data Breach

by Jessica Davis

Iowa Health System, doing business as UnityPoint Health, has reached a proposed $2.8 million settlement with the millions of patients impacted by two phishing-related data breaches in 2017 and...

Judge Sends Episcopal Health Data Breach Lawsuit Back to State Court

by Jessica Davis

A federal judge of the U.S. District Court for the Eastern District of New York has sent a data breach lawsuit against Episcopal Health Services back to state level courts, saying it lacked the grounds...

OCR Shares COVID-19 Guide on Contacting Patients for Blood Donations

by Jessica Davis

The Office for Civil Rights released guidance for healthcare covered entities on the HIPAA-permitted ways providers can contact patients recovering from COVID-19 to inform them of blood and plasma...

Aveanna Healthcare Faces Lawsuit Over Monthlong Data Breach

by Jessica Davis

Georgia-based Aveanna Healthcare is facing a class-action lawsuit filed by more than 100 patients impacted by a monthlong data breach from 2019. Over 166,000 patients were affected by the security...

Crafting Successful Business Associate Agreements, Breach Response

by Jessica Davis

The healthcare sector relies heavily upon its relationships with third-party vendors and business associates, which are critical to ensuring uninterrupted patient care. However, given the vast number...

30K Patients Impacted in Ohio Business Associate Breach from 2019

by Jessica Davis

Ohio-based Management and Network Services (MNS) recently began notifying 30,132 patients that their data was potentially compromised after several employee email accounts were hacked for several...

AMA Shares Privacy Principles for Non-HIPAA Covered Entities, Data

by Jessica Davis

The American Medical Association unveiled a set of privacy principles for non-HIPAA covered entities, designed to empower consumers with more control over the health data collected about them. AMA will...

Insights into HHS COVID-19 HIPAA Waivers and Lasting Implications

by Jessica Davis

The nationwide public health emergency brought on by the COVID-19 outbreak has led to several Good Faith HIPAA waivers from the Department of Health and Human Services and the Office for Civil Rights. The waivers aim to fuel data sharing...

COVID-19: OCR Reminds Providers of Media Access Restrictions to PHI

by Jessica Davis

The Office for Civil Rights issued a reminder to healthcare providers that even amid the COVID-19 crisis, the HIPAA Privacy Rule does not permit them to give site access to media and other film...

LabCorp Hit with Shareholder Lawsuit Over 2 Separate Data Breaches

by Jessica Davis

LabCorp shareholder Raymond Eugenio recently filed suit against the lab testing giant, as well as its 12 directors and executives, to recoup share value losses caused by two data breaches, first...

Ciitizen: ‘Significant Improvement’ in HIPAA Right of Access Compliance

by Jessica Davis

Ciitizen released its third Patient Record Scorecard, which found significant improvements in the number of providers in compliance with the HIPAA Right of Access rule. In fact, the number of...

Ransomware Attack on Brandywine Urology Impacts 131K Patients

by Jessica Davis

About 131,825 patients of Brandywine Urology Consultants are being notified that their data was potentially compromised during a ransomware attack. The Delaware specialist is continuing to investigate...

OCR Lifts HIPAA Penalties for COVID-19 Community-Based Testing Sites

by Jessica Davis

The Office for Civil Rights announced yet another enforcement discretion during the Coronavirus pandemic, lifting potential HIPAA penalties related to noncompliance for covered entities and business...

OCR Permits Business Associates to Share Patient Data During COVID-19

by Jessica Davis

The Office for Civil Rights will waive penalties for HIPAA noncompliance against providers or business associates over the good faith use and disclosure of protected health information during the...

OCR Shares COVID-19 PHI, Data Sharing Guidance for First Responders

by Jessica Davis

The Office for Civil Rights released guidance for how protected health information on patients exposed or infected with COVID-19 can be shared with first responders, such as law enforcement,...

OCR Clarifies HIPAA Liability on Telehealth Use During COVID-19

by Jessica Davis

The Department of Health and Human Services’ Office for Civil Rights released a list of frequently asked questions to common concerns raised about its recent move to lift certain HIPAA penalties...

OCR Lifts HIPAA Penalties for Telehealth Use During COVID-19

by Jessica Davis

The Department of Health and Human Services’ Office for Civil Rights announced it will not impose penalties for noncompliance with HIPAA regulations against providers leveraging telehealth...