Risk and the Internet of Things (“IoT”): HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Internet of Things (“IoT”) is a concept that is becoming more and more important in HIPAA compliance. The Internet of Things generally is the .. read more
How Does a $16 Million HIPAA Violation Settlement Grab You? HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) has announced the biggest HIPAA violation settlement yet—that is, $16 million, smashing .. read more
Securing EHRs on Mobile Devices—New NIST Guidance: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The single biggest category of DHHS civil money penalties involves loss or theft of EHRs on mobile devices. The only guidance in the Security Rule .. read more
Must You Audit Your Business Associates for HIPAA Compliance? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Now that the HITECH Act and the Omnibus Rule have made covered entities potentially liable for breaches by their business associate, see Compliance Hit: Expanded .. read more
DHHS Finally to Draft Rule for Sharing HIPAA Civil Money Penalties with Victims: HIPAA & HITECH Act Blog by Jonathan P. Tomes
DHHS has announced that it will issue the advance notice for receiving comments on proposed rules for sharing a percentage of HIPAA civil money penalties, .. read more
Biggest HIPAA Civil Money Penalty Yet—How Does $5.5 Million Sound? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Memorial Healthcare System (“MHS”) settled with the U.S. Department of Health and Human Services (“DHHS”) for $5.5 million for potential violations of the Health Insurance .. read more
New Sample BAA to Consider: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Because I have a number of current California clients and past ones who may be Premium Members, I have revised my sample Business Associate Agreement .. read more
Not-for-Profit Business Associate—No Risk Analysis: $650,000 Settlement: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Catholic Health Care Services of the Archdiocese of Philadelphia (“CHCS”), a not-for-profit business associate, was the corporate owner of six nursing homes and provided .. read more
Neglect is Enough to Get One a HIPAA Civil Money Penalty! HIPAA & HITECH Blog by Jonathan P. Tomes
Under the terms of a resolution agreement, Anchorage Community Mental Health Services (“ACMHS”) had to pay $150,000 as a civil money penalty settlement and integrate .. read more
Another HIPAA Breach Settlement for Not Having Had a Business Associate Agreement in Place: HIPAA & HITECH Act Blog by Jonathan P. Tomes
My Vice President and editor, Alice M. McCart, always says that she hates it when I’m always right. I always mess with her by saying, .. read more