Reducing mIoT Risks: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In two recent blogs, we have discussed how the Internet of Things (“IoT”) has become the mIoT—that is, the medical Internet of Things―and what this .. read more
Securing EHRs on Mobile Devices—New NIST Guidance: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The single biggest category of DHHS civil money penalties involves loss or theft of EHRs on mobile devices. The only guidance in the Security Rule .. read more
Must You Audit Your Business Associates for HIPAA Compliance? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Now that the HITECH Act and the Omnibus Rule have made covered entities potentially liable for breaches by their business associate, see Compliance Hit: Expanded .. read more
OCR Encourages Covered Entities to Perform a Gap Analysis: HIPAA & HITECH Act Blog by Jonathan P. Tomes
We at EMR Legal and Veterans Press have been encouraging our clients and customers to perform a gap analysis since shortly after HIPAA became law .. read more
California Determines What Is Reasonable and Appropriate for Securing Health Information: HIPAA & HITECH Act Blog by Jonathan P. Tomes
HIPAA requires covered entities and business associates to implement reasonable and appropriate security measures in § 164.308(a)(1)(ii)(B), the risk management Administrative safeguards, but although it does .. read more
Data Destruction and HIPAA Competence as Related to IT Support Companies: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Michael B. O’Hara, CISSP
Michael B. O’Hara’s narrative, part 1: Recently, my company, KB Computing, LLC, lost a managed services client. The reason, as it so often is, was .. read more
Some Good News and an Apology: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The good news is that I purchased Richard Dvorak’s half interest in Veterans Press and its wholly owned subsidiary, EMR Legal (the consulting arm of .. read more
New Electronic Medical Records Article Now Posted in Premium Member Section: HIPAA & HITECH Act Blog by Jonathan P. Tomes
James G. Meyer, an attorney in the law firm of Ialongo & Meyer in Chicago, and Lee Neubecker, a computer forensics expert and president of .. read more
Risk Analysis Change for Breach Notification: HIPAA & HITECH Act Blog by Jonathan P. Tomes
On January 17, 2013, the Department of Health and Human Services (“DHHS’”) released its draft long-anticipated Omnibus Rule amending the HIPAA Privacy, Security, Breach Notification .. read more
Addressable Implementation Specification Matrix Posted on Premium Member Section
Under the Department of Health and Human Services (“DHHS”) regulations implementing the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), a covered entity must .. read more