Hospital Patients Targeted in Scam: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Identity thieves have been conducting a telephone phishing (originally defined as the fraudulent practice of sending emails purporting to be from reputable companies in order .. read more
First HIPAA Penalty for Failure to Comply with the HIPAA Breach Notification Rule: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The U.S. Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) last week announced the first HIPAA settlement in lieu of a .. read more
New California Breach Notification Law: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Governor Jerry Brown recently signed into law a California bill regarding breach notification, A.B. 2828, amending California Civil Code §§ 1798.29(a) and 1798.82(a) so that, .. read more
New Sample BAA to Consider: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Because I have a number of current California clients and past ones who may be Premium Members, I have revised my sample Business Associate Agreement .. read more
Illinois Joins California in Affording More Protection to Personal Information: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In May, the Governor of Illinois, Bruce Rauner, signed amendments to the Illinois Personal Information Protection Act (“PIPA”), 815 ILCS 530/1 et seq., expanding the .. read more
$1.55 Million Settlement Stresses Importance of Business Associate Agreements: HIPAA & HITECH Act Blog by Jonathan P. Tomes
A recent settlement in lieu of a civil money penalty underscores the importance of having business associate agreements in place with entities that perform a .. read more
Latest HIPAA Settlement 2—a Lesson Still Not Yet Learned about Risk Analysis: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In its press release, the Department of Health and Human Services (“DHHS”) once again pointed out the importance of an organization-wide risk analysis. The press .. read more
Latest HIPAA Violation Settlement–$850,000 for a Stolen Laptop: HIPAA & HITECH Act Blog by Jonathan P. Tomes
I don’t understand why, with all the high six-figure and seven-figure resolution agreements (basically, settlements), covered entities do not provide adequate security for laptops and .. read more
Risk Analysis and Risk Assessment: Are They Different? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Quite often, my HIPAA clients and those who read my blog ask what the difference is between a risk analysis and a risk assessment. In .. read more
California News re Health Information Privacy and Security and HIPAA Breach Notification Rule: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In October 2014, Kamala D. Harris, Attorney General, California Department of Justice, released the California Data Breach Report. The report noted that, in the health .. read more