MA AG Settles Cross-border HIPAA and Breach Notification Enforcement Suit: HIPAA & HITECH Act Blog by Jonathan P. Tomes
So only the state attorney general in the state in which you do business can file a lawsuit against you? Right? No, wrong. A Rhode .. read more
Next Stage of DHHS Audits Coming: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The U.S. Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) has not yet published an audit protocol for this year’s Phase .. read more
First HIPAA Enforcement Action against a County Government: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Richard D. Dvorak
Last week, the Department of Health and Human Services (“DHHS”) announced in a press release its first HIPAA enforcement action against a county government and .. read more
Report HIPAA Breaches Involving Fewer Than 500 Individuals by February 28! HIPAA & HITECH Act Blog by Jonathan P. Tomes
45 C.F.R. § 164.408 requires covered entities that discover a breach of unsecured protected health information (“PHI”) to notify the Secretary of Health and Human Services .. read more
Not-for-profit to Settle Copier HIPAA Breach with DHHS: HIPAA & HITECH Act Blog by Jonathan P. Tomes
According to a press release from the U.S. Department of Health and Human Services (“DHHS”), Affinity Health Plan, Inc., a not-for-profit managed care plan in .. read more
WellPoint, Inc., Reports Breach to DHHS, Settles for $1.7 Million: HIPAA & HITECH Act Blog by Jonathan P. Tomes
WellPoint, Inc., an Indiana managed care organization, reported under the requirements of the HITECH Act Breach Notification Rule a breach of the electronic protected health .. read more
HIPAA Reportable Breach or Not? HIPAA & HITECH Act Blog by Jonathan P. Tomes
According to Health Data Management, the Michigan Department of Community Health notified more than 49,000 individuals that a server of the Michigan Cancer Consortium holding .. read more
Risk Analysis Change for Breach Notification: HIPAA & HITECH Act Blog by Jonathan P. Tomes
On January 17, 2013, the Department of Health and Human Services (“DHHS’”) released its draft long-anticipated Omnibus Rule amending the HIPAA Privacy, Security, Breach Notification .. read more
New Resource Posted for Premium Members
The $1 million settlement by Massachusetts General for what has come to be known as the “Million Dollar Subway Ride,” for the loss of paper .. read more
Updated Portable Computer Policy Posted in the Premium Member Section
As my blog post of September 17, 2012, noted, the Massachusetts Eye and Ear Infirmary (“MEEI”) and Massachusetts Eye and Ear Associates, Inc. (“MEEA”), entered .. read more