DHHS OIG Finds Deficiencies in FDA Policies and Procedures to Address Cybersecurity Risk in Postmarket Medical Devices: HIPAA & HITECH Act Blog by Jonathan P. Tomes
As a follow-on to the previous three blog posts addressing the mIoT—that is, the medical Internet of Things―an Office of the Inspector General (“OIG”) audit .. read more
Reducing mIoT Risks: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In two recent blogs, we have discussed how the Internet of Things (“IoT”) has become the mIoT—that is, the medical Internet of Things―and what this .. read more
Another State Fine for a HIPAA Security Breach: HIPAA & HITECH Act Blog by Jonathan P. Tomes
As we’ve previously noted in this blog, the Office for Civil Rights (“OCR”) of the Department of Health and Human Services (“DHHS”), the Federal Trade .. read more
Must You Audit Your Business Associates for HIPAA Compliance? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Now that the HITECH Act and the Omnibus Rule have made covered entities potentially liable for breaches by their business associate, see Compliance Hit: Expanded .. read more
Hospital Patients Targeted in Scam: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Identity thieves have been conducting a telephone phishing (originally defined as the fraudulent practice of sending emails purporting to be from reputable companies in order .. read more
First HIPAA Penalty for Failure to Comply with the HIPAA Breach Notification Rule: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The U.S. Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) last week announced the first HIPAA settlement in lieu of a .. read more
Watch Out for a Fake OCR Audit Phishing Email: HIPAA & HITECH Act Blog by Jonathan P. Tomes
On November 28, the Department of Health and Human Services (“DHHS”) warned that a marketing campaign has been circulating a fake OCR audit phishing email .. read more
OCR Issues Revised Audit Protocol: HIPAA & HITECH Blog by Jonathan P. Tomes
In April 2016, the U.S. Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) issued its updated Phase 2 Audit Protocol. Its .. read more
Another HIPAA Breach Settlement for Not Having Had a Business Associate Agreement in Place: HIPAA & HITECH Act Blog by Jonathan P. Tomes
My Vice President and editor, Alice M. McCart, always says that she hates it when I’m always right. I always mess with her by saying, .. read more
Acting without Accurate Data Is Just Guessing: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Alice M. McCart
For those of you who are still reluctant to perform your first Risk Analysis or to update one from perhaps a few years ago, as .. read more