On April 22, 2024, the federal Department of Health and Human Services’ Office for Civil Rights (OCR) announced a final rule enhancing privacy protections relating to reproductive health care. Specifically, the final rule amends the Privacy Rule under the Health Insurance Portability and Accountability Act (HIPAA) to, among other things, establish new limits on the
Privacy
Sanction Policies Can Help Drive Cybersecurity and HIPAA Compliance, OCR Says
Many HIPAA covered entities and business associates struggle with developing and implementing a sanctions policy. What should it say, is zero-tolerance required, do we have to impose discipline in every case, etc. These are examples of frequent and thorny questions that arise in connection with the development and implementation of these policies. But they are…
OCR Official Speaks About Compliance Concerns for HIPAA Covered Entities and Business Associates
What do ransomware, Yelp, and website tracking technologies all have in common? They are troubling areas of concern for HIPAA covered entities and business associates, according to one official from the federal Office for Civil Rights (OCR) which enforces the HIPAA privacy and security rules. Recently, the Executive Editor of Information Security Media Group’s (ISMG’s)…
Getting Healthcare in 2023 and Beyond…Virtually…and Securely
Much is being written about “remote work” – is it productive, will demand for it continue or be curtailed in a recession, is cybersecurity compromised, does it inhibit workplace culture, collaboration, etc. Lots of questions, few clear answers. Read more at our Workplace Privacy, Data Management & Security Report.
Is your e-PHI Secure? ONC and OCR Update HIPAA Security Risk Assessment Tool
October 2018 marks the 15th annual National Cyber Security Awareness Month. In honor of this occasion, the Office of the National Coordinator for Health Information Technology (ONC) and the HHS Office for Civil Rights (OCR) have jointly launched an updated HIPAA Security Risk Assessment (SRA) Tool to help covered entities and business associates comply…
“Your Own Cybersecurity Is Not Enough”: NJ Physician Practice Fined Over $400,000 for Data Breach Caused By Vendor
New Jersey’s Attorney General Gurbir S. Grewal and the New Jersey Division of Consumer Affairs (“Division”) recently announced that a physician group affiliated with more than 50 South Jersey medical and surgical practices agreed to pay $417,816 and improve data security practices to settle allegations it failed to properly protect the privacy of more than…
Health Apps: Convenience vs. Security Risks
The pace of innovation in healthcare today has produced an amazing increase in the number of available mobile apps for health-related information. More than 300,000 healthcare apps are available online. Our colleagues in the Workplace Privacy, Data Management & Security practice group discusses whether healthcare providers can tap into the available technology of “connectivity” and…
Cybercriminals Often Target Healthcare Providers with Ransomware Attacks
The U.S. Department of Health and Human Services had issued guidance on ransomware attack prevention and recovery from a healthcare sector perspective in July 2016. The importance of these measures was highlighted by the recent worldwide ransomware, “WannaCry,” attack that caused major disruption to the United Kingdom’s National Health Service and cancellation of operations. Learn…
Enterovirus D-68 and Ebola Cases Raise Privacy Concerns for Healthcare Providers and their Workers
The following posting from our colleagues on the Jackson Lewis P.C. website, as part of the Workplace Privacy, Data Management & Security Report, regarding privacy concerns related to Enterovirus and Ebola may be of particular interest to healthcare employers. Click here to be transferred directly to the link.
Data Breach Notification Deadline Extended 10 Days for Certain Healthcare Providers in California
The following posting from our colleagues on the Jackson Lewis P.C. website, as part of the Workplace Privacy, Data Management & Security Report, regarding data breach notification requirements for healthcare providers in California may be of particular interest. Click here to be transferred directly to the link.