Report HIPAA Breaches Involving Fewer Than 500 Individuals by February 28! HIPAA & HITECH Act Blog by Jonathan P. Tomes
45 C.F.R. § 164.408 requires covered entities that discover a breach of unsecured protected health information (“PHI”) to notify the Secretary of Health and Human Services .. read more
New Wall of Shame Format: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Before discussing the new format, note that almost 800 covered entities are now memorialized, so to speak, on the Big Breacher website (my name for .. read more
Do You Have a Patient Portal for Your Practice? HIPAA & HITECH Act Blog by Jonathan P. Tomes
About the time that I signed up to go through a patient portal to set up an appointment with my bone and joint doctor about .. read more
OIG Slams DHHS Again for Not Enforcing HIPAA Adequately! HIPAA & HITECH Act Blog by Jonathan P. Tomes
On November 21, 2013, the Department of Health and Human Services (“DHHS”) Office of the Inspector General (“OIG”) issued another scathing report about the DHHS .. read more
Unintended Financial Consequences? Well, Maybe It’s Job Security: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In my recent article for the Journal of Healthcare Finance, “The Law of Unintended (Financial) Consequences: The Expansion of HIPAA Business Associate Liability,” which is .. read more
Refill Reminder Exception under HIPAA: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Richard D. Dvorak
The Privacy Rule gives individuals important controls over whether and how their health information is used and disclosed for marketing purposes. With some exceptions, the .. read more
HIPAA Compliance Enforcement Delay Regarding CLIA Labs: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Richard D. Dvorak
The Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) on September 19, 2013, announced a delay until further notice in its .. read more
Gap Analysis Is Key to Effective Risk Analysis: HIPAA & HITECH Blog by Jonathan P. Tomes
An effective Risk Analysis is the absolute key to HIPAA compliance, and an effective Gap Analysis is the absolute key to an effective Risk Analysis. .. read more
Still Not Convinced That You Need HIPAA Policies, Procedures, and Training? HIPAA & HITECH Act Blog by Jonathan P. Tomes
I hope that you have read my previous blog posts, particularly those recounting that the Department of Health and Human Services (“DHHS”) Office for Civil .. read more
Not-for-profit to Settle Copier HIPAA Breach with DHHS: HIPAA & HITECH Act Blog by Jonathan P. Tomes
According to a press release from the U.S. Department of Health and Human Services (“DHHS”), Affinity Health Plan, Inc., a not-for-profit managed care plan in .. read more