OCR Issues Revised Audit Protocol: HIPAA & HITECH Blog by Jonathan P. Tomes
In April 2016, the U.S. Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) issued its updated Phase 2 Audit Protocol. Its .. read more
Acting without Accurate Data Is Just Guessing: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Alice M. McCart
For those of you who are still reluctant to perform your first Risk Analysis or to update one from perhaps a few years ago, as .. read more
Data Destruction and HIPAA Competence as Related to IT Support Companies: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Michael B. O’Hara, CISSP
Michael B. O’Hara’s narrative, part 1: Recently, my company, KB Computing, LLC, lost a managed services client. The reason, as it so often is, was .. read more
MA AG Settles Cross-border HIPAA and Breach Notification Enforcement Suit: HIPAA & HITECH Act Blog by Jonathan P. Tomes
So only the state attorney general in the state in which you do business can file a lawsuit against you? Right? No, wrong. A Rhode .. read more
Next Stage of DHHS Audits Coming: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The U.S. Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) has not yet published an audit protocol for this year’s Phase .. read more
OIG Slams DHHS Again for Not Enforcing HIPAA Adequately! HIPAA & HITECH Act Blog by Jonathan P. Tomes
On November 21, 2013, the Department of Health and Human Services (“DHHS”) Office of the Inspector General (“OIG”) issued another scathing report about the DHHS .. read more
Gap Analysis Is Key to Effective Risk Analysis: HIPAA & HITECH Blog by Jonathan P. Tomes
An effective Risk Analysis is the absolute key to HIPAA compliance, and an effective Gap Analysis is the absolute key to an effective Risk Analysis. .. read more
Still Not Convinced That You Need HIPAA Policies, Procedures, and Training? HIPAA & HITECH Act Blog by Jonathan P. Tomes
I hope that you have read my previous blog posts, particularly those recounting that the Department of Health and Human Services (“DHHS”) Office for Civil .. read more
KPMG Audits
I was fortunate enough to have a seminar attendee at my Dallas, Texas, Cross Country HIPAA seminar on August 23 whose hospital had been audited .. read more
Boston’s Hospital’s Security Breach Results in $750,000 Settlement | HIPAA
Boston’s South Shore Hospital has agreed to pay $750,000 to resolve allegations that it failed to protect the confidential health information of more than 800,000 .. read more