Acting without Accurate Data Is Just Guessing: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Alice M. McCart
For those of you who are still reluctant to perform your first Risk Analysis or to update one from perhaps a few years ago, as .. read more
California Determines What Is Reasonable and Appropriate for Securing Health Information: HIPAA & HITECH Act Blog by Jonathan P. Tomes
HIPAA requires covered entities and business associates to implement reasonable and appropriate security measures in § 164.308(a)(1)(ii)(B), the risk management Administrative safeguards, but although it does .. read more
It was the Best of Breach Responses, it was the Worst of Breach Responses: HIPAA & HITECH Act Blog by Jonathan P. Tomes
It was the best of times, it was the worst of times, it was the age of wisdom, it was the age of foolishness, it .. read more
Latest HIPAA Settlement 2—a Lesson Still Not Yet Learned about Risk Analysis: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In its press release, the Department of Health and Human Services (“DHHS”) once again pointed out the importance of an organization-wide risk analysis. The press .. read more
Latest HIPAA Violation Settlement–$850,000 for a Stolen Laptop: HIPAA & HITECH Act Blog by Jonathan P. Tomes
I don’t understand why, with all the high six-figure and seven-figure resolution agreements (basically, settlements), covered entities do not provide adequate security for laptops and .. read more
Latest HIPAA Settlement—a Lesson Still Not Learned: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Although most civil money penalties (“CMPs”) to date have involved risk analysis—that is, failure to do one, failure to do a complete one, or failure .. read more
Is That Security Incident a Reportable Breach? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Several times a month, on average, I get a question from a Premium Member or others who get a free question, such as our seminar .. read more
The Bigger You Are, the Harder You’re Hacked: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Anthem, previously known as WellPoint, Inc., the nation’s second-largest health insurance company, recently suffered a sophisticated external cyberattack. Reportedly, 80 million of Anthem’s insureds had .. read more
California News re Health Information Privacy and Security and HIPAA Breach Notification Rule: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In October 2014, Kamala D. Harris, Attorney General, California Department of Justice, released the California Data Breach Report. The report noted that, in the health .. read more
MA AG Settles Cross-border HIPAA and Breach Notification Enforcement Suit: HIPAA & HITECH Act Blog by Jonathan P. Tomes
So only the state attorney general in the state in which you do business can file a lawsuit against you? Right? No, wrong. A Rhode .. read more