Do Not Create Your Policies without First Doing a Risk Analysis! HIPAA & HITECH Act Blog by Jonathan P. Tomes
Although I love it when people buy my sample policies to adapt to their situation, we sometimes get asked to comment on policies from our .. read more
Can You Talk to the News Media? HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Janet Wray
“A reporter’s on the phone!” What to do? What to say? How to say it? Talking to a reporter can be stressful, but the following .. read more
Insurance for HIPAA Violations? HIPAA & HITECH Act Blog by Jonathan P. Tomes
A Premium Member asked me what I recommended for the policy limits for insurance for HIPAA violations. Without obtaining a lot more information, such as .. read more
Unintended Financial Consequences? Well, Maybe It’s Job Security: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In my recent article for the Journal of Healthcare Finance, “The Law of Unintended (Financial) Consequences: The Expansion of HIPAA Business Associate Liability,” which is .. read more
Refill Reminder Exception under HIPAA: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Richard D. Dvorak
The Privacy Rule gives individuals important controls over whether and how their health information is used and disclosed for marketing purposes. With some exceptions, the .. read more
HIPAA Compliance Enforcement Delay Regarding CLIA Labs: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Richard D. Dvorak
The Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) on September 19, 2013, announced a delay until further notice in its .. read more
Omnibus Rule Compliance Date 10 Days Away—Are You Ready? HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Omnibus Rule compliance date is September 23, 2013. You may be feeling overwhelmed and thinking that you cannot possibly get your organization completely HIPAA .. read more
Gap Analysis Is Key to Effective Risk Analysis: HIPAA & HITECH Blog by Jonathan P. Tomes
An effective Risk Analysis is the absolute key to HIPAA compliance, and an effective Gap Analysis is the absolute key to an effective Risk Analysis. .. read more
When You Update Your Notice of Privacy Practices by September 23, 2013, to Comply with the Omnibus Rule, Must You Mail Copies to Your Patients? HIPAA & HITECH Act Blog by Jonathan P. Tomes
I have been asked repeatedly whether a covered health care provider must mail a copy of its new Omnibus Rule compliant notice of privacy practices .. read more
Still Not Convinced That You Need HIPAA Policies, Procedures, and Training? HIPAA & HITECH Act Blog by Jonathan P. Tomes
I hope that you have read my previous blog posts, particularly those recounting that the Department of Health and Human Services (“DHHS”) Office for Civil .. read more