HIPAA and NIST: What’s the Connection? HIPAA & HITECH Act Blog by Jonathan P. Tomes
The National Institute for Standards and Technology [“NIST”] first became involved with HIPAA when it published “An Introductory Resource Guide for Implementing the Health Insurance .. read more
Does the European Union’s General Data Protection Regulation (“GDPR”) Affect You? HIPAA & HITECH Act Blog by Jonathan P. Tomes
The European Union’s General Data Protection Regulation (“GDPR”) protects personal data for European Union (“EU”) residents around the world. Under it, any business or organization, .. read more
California Exempts HIPAA Covered Entities from Its New Consumer Privacy Act: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In June 2018, the California legislature passed the California Consumer Privacy Act (“CCPA”), which was intended to change state law to better protect the privacy .. read more
Must You Audit Your Business Associates for HIPAA Compliance? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Now that the HITECH Act and the Omnibus Rule have made covered entities potentially liable for breaches by their business associate, see Compliance Hit: Expanded .. read more
DHHS Finally to Draft Rule for Sharing HIPAA Civil Money Penalties with Victims: HIPAA & HITECH Act Blog by Jonathan P. Tomes
DHHS has announced that it will issue the advance notice for receiving comments on proposed rules for sharing a percentage of HIPAA civil money penalties, .. read more
A Different Type of HIPAA Risk Analysis: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Long-time readers of my blog are probably sick of my preaching the importance of a HIPAA risk analysis in HIPAA compliance. And I’m not going .. read more
OCR Encourages Covered Entities to Perform a Gap Analysis: HIPAA & HITECH Act Blog by Jonathan P. Tomes
We at EMR Legal and Veterans Press have been encouraging our clients and customers to perform a gap analysis since shortly after HIPAA became law .. read more
Biggest HIPAA Civil Money Penalty Yet—How Does $5.5 Million Sound? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Memorial Healthcare System (“MHS”) settled with the U.S. Department of Health and Human Services (“DHHS”) for $5.5 million for potential violations of the Health Insurance .. read more
OCR Clarification on Aspects of Privacy Rule after Man-made Disasters: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The recent shooting attack in Las Vegas and other man-made disasters have prompted the Department of Health and Human Services (“DHHS”) Office for Civil Rights .. read more
Watch Out for a Fake OCR Audit Phishing Email: HIPAA & HITECH Act Blog by Jonathan P. Tomes
On November 28, the Department of Health and Human Services (“DHHS”) warned that a marketing campaign has been circulating a fake OCR audit phishing email .. read more