WellPoint, Inc., Reports Breach to DHHS, Settles for $1.7 Million: HIPAA & HITECH Act Blog by Jonathan P. Tomes
WellPoint, Inc., an Indiana managed care organization, reported under the requirements of the HITECH Act Breach Notification Rule a breach of the electronic protected health .. read more
Did You Know That You Were a Torturer if You Breached Patient Confidentiality? HIPAA & HITECH Act Blog by Jonathan P. Tomes
As if it were not bad enough facing HIPAA’s criminal penalties—a doctor was sentenced to four months in federal prison for accessing celebrity charts just .. read more
Can You Encrypt an iPad? HIPAA & HITECH Act Blog by Jonathan P. Tomes
A client recently asked me whether her organization could encrypt iPads that contained PHI. The answer is yes. Encryption, of course, is an addressable implementation .. read more
HIPAA Compliance and the FTC: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Richard D. Dvorak
On June 6–7, 2012, I attended the NIST/OCR HIPAA Security Rule Conference at the Ronald Reagan Center, Washington, DC. The Federal Trade Commission’s Division of .. read more
You’d Better Not Control Your Business Associate’s Performance! HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Omnibus Rule, fleshing out the HIPAA changes in the HITECH Act, clarified when covered entities and business associates would be liable for breaches of .. read more
Compliance Hit: Expanded Liability for Business Associates’ Breaches: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The HITECH Act expanded the liability of business associates in a number of ways, primarily by making them face the same civil and criminal liability .. read more
Risk Analysis Change for Breach Notification: HIPAA & HITECH Act Blog by Jonathan P. Tomes
On January 17, 2013, the Department of Health and Human Services (“DHHS’”) released its draft long-anticipated Omnibus Rule amending the HIPAA Privacy, Security, Breach Notification .. read more
Addressable Implementation Specification Matrix Posted on Premium Member Section
Under the Department of Health and Human Services (“DHHS”) regulations implementing the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), a covered entity must .. read more
New Resource Posted for Premium Members
The $1 million settlement by Massachusetts General for what has come to be known as the “Million Dollar Subway Ride,” for the loss of paper .. read more
New Sample Business Associate Policy Posted in Premium Member Section: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Now that the HITECH Act has effectively (if not legally—business associates were not added to the list of covered entities) made business associates covered entities .. read more