A Court Order Isn’t Necessarily a Court Order. What is necessary and sufficient? HIPAA &HITECH Act Blog by Jonathan P. Tomes
HIPAA is hard to understand, even for lawyers. One of the hardest HIPAA concepts to understand and apply is the difference between necessary and sufficient .. read more
Sample Release of PHI to Clergy Policy Posted in Premium Member Section: HIPAA & HITECH Act Blog by Jonathan P. Tomes
As I discussed in my December 21, 2017, blog post, which included a new Sample Media Policy, and my November 28, 2017, post regarding the .. read more
Hospital Patients Targeted in Scam: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Identity thieves have been conducting a telephone phishing (originally defined as the fraudulent practice of sending emails purporting to be from reputable companies in order .. read more
First HIPAA Penalty for Failure to Comply with the HIPAA Breach Notification Rule: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The U.S. Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) last week announced the first HIPAA settlement in lieu of a .. read more
Children’s Health Records and You: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Parents who have minor children have legitimate concerns about their children’s health records as used, disclosed, and maintained by their health care providers, insurers, and .. read more
Illinois Joins California in Affording More Protection to Personal Information: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In May, the Governor of Illinois, Bruce Rauner, signed amendments to the Illinois Personal Information Protection Act (“PIPA”), 815 ILCS 530/1 et seq., expanding the .. read more
Neglect is Enough to Get One a HIPAA Civil Money Penalty! HIPAA & HITECH Blog by Jonathan P. Tomes
Under the terms of a resolution agreement, Anchorage Community Mental Health Services (“ACMHS”) had to pay $150,000 as a civil money penalty settlement and integrate .. read more
Are You Protected from Ransomware? HIPAA & HITECH Act Blog by Jonathan P. Tomes
I have been planning to write a blog post on ransomware since spring 2015 when I was a victim of ransomware. I got a message .. read more
Another HIPAA Breach Settlement for Not Having Had a Business Associate Agreement in Place: HIPAA & HITECH Act Blog by Jonathan P. Tomes
My Vice President and editor, Alice M. McCart, always says that she hates it when I’m always right. I always mess with her by saying, .. read more
California Determines What Is Reasonable and Appropriate for Securing Health Information: HIPAA & HITECH Act Blog by Jonathan P. Tomes
HIPAA requires covered entities and business associates to implement reasonable and appropriate security measures in § 164.308(a)(1)(ii)(B), the risk management Administrative safeguards, but although it does .. read more