Important Government Warnings about Ransomware: HIPAA & HITECH Act Blog by Jonathan P. Tomes
You may think that I am going overboard with all my recent blogs about ransomware. But I’m not. It is that much of a problem. .. read more
Being a Small Practice Won’t Save You from a HIPAA Penalty: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In the first enforcement action announced in 2020, the Department of Health and Human Services (“HHS”) has settled with Dr. Stephen A. Porter for $100,000 .. read more
Jon Tomes Will Be Presenting an All-Day, Live, and In-Person HIPAA Seminar in San Francisco in 3 Weeks: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Alice M. McCart, J.D.
If you will be in San Francisco about 3 weeks from now and need HIPAA compliance training, go to https://www.compliancekey.us/seminar-details?industryId=3&seminarid=36&speakerid=124 to sign up. The HIPAA .. read more
Are You Encrypting Your Laptops and Other Portable Devices? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Although encrypting portable devices is not absolutely required by the Security Rule—that is, it is an addressable, not a required, implementation specification—another seven-figure penalty demonstrates .. read more
OCR Reveals Its Right of Access Enforcement Priorities: HIPAA & HITECH Act Blog by Jonathan P. Tomes
At a major annual HIPAA conference, Roger Severino, Director of the Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”), revealed its .. read more
Deny Me My Records? Pay $85,000 under the HIPAA Right of Access! HIPAA & HITECH Act Blog by Jonathan P. Tomes
I have previously written about one of the easiest ways to get a civil money penalty (or a state sanction (see California)—that is, failing to .. read more
DHHS Clarifies When OCR Can Sanction BAs with a CMP: HIPAA & HITECH Act Blog by Jonathan P. Tomes
To clear up confusion about business associate liability for HIPAA violations, on May 24, 2019, the Department of Health and Human Services (“DHHS”) Office for .. read more
The State Attorney General Won’t Sue You for a HIPAA Violation, So You Won’t Be Sued, Right? Wrong: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The initial conventional wisdom when HIPAA first came out was that a covered entity could not be sued for a HIPAA violation because it was .. read more
Changed HIPAA and HITECH Penalties—a Boon or a Trap for the Unwary: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Department of Health and Human Services (“HHS”) has announced a new penalty structure for the civil money penalties (“CMPs”) for HIPAA violations that apparently .. read more
A Masochist’s Guide to Getting a Huge, Painful HIPAA Penalty: HIPAA & HITECH Act Blog by Jonathan P. Tomes
A cynic might wonder whether some covered entities, and now business associates, want to become famous (perhaps infamous would be a better word) and break .. read more