Business Associates Face the Same HIPAA Penalties as Covered Entities: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Attorney General of New Jersey recently announced a $200,000 settlement for a HIPAA violation with a business associate, one of the classic examples of .. read more
HHS Civil Money Penalties (“CMPs”) Aren’t the Only Ones! And Do You Need Insurance? HIPAA & HITECH Act Blog by Jonathan P. Tomes
UCLA Health recently settled a class action lawsuit against it for $7.5 million. The plaintiffs were victims of a hack attack on UCLA’s network that .. read more
Who Knew HIPAA Could Harm Data Security? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Earlier this month, in response to a request by Congress, the College of Healthcare Information Management Executives (“CHIME”) reported that complying with HIPAA is not .. read more
New Guidance on Mobile Device Security: The New Standard of Care? HIPAA & HITECH Act Blog by Jonathan P. Tomes
The National Cybersecurity Center of Excellence (“NCCoE”), in conjunction with the National Institute of Standards and Technology (“NIST”), has released its final guidance on the .. read more
DHHS Issues New Cybersecurity Best Practices: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The U.S. Department of Health and Human Services (“DHHS”) recently issued voluntary cybersecurity best practices for health care organizations and guidelines for managing cyber threats .. read more
20 Plus Years of HIPAA and What Have We Got?: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Alice M. McCart, J.D.
The Quinnipiac Health Law Journal, vol. 22, no. 1 (2018), of Quinnipiac School of Law, just published Jon’s most recent scholarly article. This article is .. read more
DHHS OIG Finds Deficiencies in FDA Policies and Procedures to Address Cybersecurity Risk in Postmarket Medical Devices: HIPAA & HITECH Act Blog by Jonathan P. Tomes
As a follow-on to the previous three blog posts addressing the mIoT—that is, the medical Internet of Things―an Office of the Inspector General (“OIG”) audit .. read more
Reducing mIoT Risks: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In two recent blogs, we have discussed how the Internet of Things (“IoT”) has become the mIoT—that is, the medical Internet of Things―and what this .. read more
More about Medical Internet of Things (“MIoT”) Risks: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In my previous blog post, I discussed the need to evaluate the risks of the Internet of Things (“IoT”) for HIPAA compliance generally. In this .. read more
Risk and the Internet of Things (“IoT”): HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Internet of Things (“IoT”) is a concept that is becoming more and more important in HIPAA compliance. The Internet of Things generally is the .. read more