HIPAA Violations Are Still Mostly People, Not Technology: HIPAA & HITECH Act Blog by Jonathan P. Tomes
I learned a long time ago, when I served in that contradiction of terms, military intelligence, that the big risk, at that time to defense .. read more
HHS Office for Civil Rights and the Department of Education Issue Updated Guidance on Sharing Student Health Records under HIPAA and FERPA: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Having had the good fortune to be a HIPAA consultant for several universities, I am quite aware of the confusion that could result from possibly .. read more
OCR Reveals Its Right of Access Enforcement Priorities: HIPAA & HITECH Act Blog by Jonathan P. Tomes
At a major annual HIPAA conference, Roger Severino, Director of the Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”), revealed its .. read more
Deny Me My Records? Pay $85,000 under the HIPAA Right of Access! HIPAA & HITECH Act Blog by Jonathan P. Tomes
I have previously written about one of the easiest ways to get a civil money penalty (or a state sanction (see California)—that is, failing to .. read more
Security Breaches Aren’t the Only Compliance Risks! So Are Privacy Rights Violations: HIPAA & HITECH Act Blog by Jonathan P. Tomes
A recent announcement by the Dental Board of California has reinforced the notion that having a breach of security, such as a hacker’s gaining access .. read more
EHR Vendor Settles False Claims Act Violation Case for $57.25 Million: HIPAA & HITECH Act Blog by Jonathan P. Tomes
So what does HIPAA have do to with the Federal False Claims Act? As simply stated as possible, the Meaningful Use criteria for getting government .. read more
DHHS Seeks Your Comments: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Office for Civil Rights (“OCR”) of the Department of Health and Human Services (“DHHS”) has issued a Request for Information (“RFI”), seeking public comments .. read more
Patient Right of Access to Their Charts—Still a Problem Area: HIPAA & HITECH Act Blog by Jonathan P. Tomes
According to a recent study by Yale University School of Medicine, published in JAMA Network Open, covered entities are not providing to patients copies of .. read more
Does the European Union’s General Data Protection Regulation (“GDPR”) Affect You? HIPAA & HITECH Act Blog by Jonathan P. Tomes
The European Union’s General Data Protection Regulation (“GDPR”) protects personal data for European Union (“EU”) residents around the world. Under it, any business or organization, .. read more
DHHS Issues New Guidance on HIPAA and Individual Authorization of Uses and Disclosures of PHI for Research: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The U.S. Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) has issued new guidance for HIPAA-covered entities to streamline HIPAA authorizations .. read more