Lack of Business Associate Agreement Costs $500,000! HIPAA & HITECH Act Blog by Jonathan P. Tomes
Advanced Care Hospitalists PL (“ACH”) recently settled a Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) enforcement action for $500,000 for .. read more
New Guidance on Mobile Device Security: The New Standard of Care? HIPAA & HITECH Act Blog by Jonathan P. Tomes
The National Cybersecurity Center of Excellence (“NCCoE”), in conjunction with the National Institute of Standards and Technology (“NIST”), has released its final guidance on the .. read more
EHR Vendor Settles False Claims Act Violation Case for $57.25 Million: HIPAA & HITECH Act Blog by Jonathan P. Tomes
So what does HIPAA have do to with the Federal False Claims Act? As simply stated as possible, the Meaningful Use criteria for getting government .. read more
DHHS Issues New Cybersecurity Best Practices: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The U.S. Department of Health and Human Services (“DHHS”) recently issued voluntary cybersecurity best practices for health care organizations and guidelines for managing cyber threats .. read more
Is Honey Trapping a Risk for Health Information? HIPAA & HITECH Act Blog by Jonathan P. Tomes
In the past few years, I have written a series of short stories about Womble, known among his colleagues in the CIA as the god .. read more
DHHS Seeks Your Comments: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Office for Civil Rights (“OCR”) of the Department of Health and Human Services (“DHHS”) has issued a Request for Information (“RFI”), seeking public comments .. read more
20 Plus Years of HIPAA and What Have We Got?: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Alice M. McCart, J.D.
The Quinnipiac Health Law Journal, vol. 22, no. 1 (2018), of Quinnipiac School of Law, just published Jon’s most recent scholarly article. This article is .. read more
$125,000 for Talking to a Reporter? HIPAA & HITECH Act Blog by Jonathan P. Tomes
After the last three technically orientated blog posts on the medical Internet of Things (“mIoT”), perhaps it’s time to remember that there is a higher .. read more
DHHS OIG Finds Deficiencies in FDA Policies and Procedures to Address Cybersecurity Risk in Postmarket Medical Devices: HIPAA & HITECH Act Blog by Jonathan P. Tomes
As a follow-on to the previous three blog posts addressing the mIoT—that is, the medical Internet of Things―an Office of the Inspector General (“OIG”) audit .. read more
Reducing mIoT Risks: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In two recent blogs, we have discussed how the Internet of Things (“IoT”) has become the mIoT—that is, the medical Internet of Things―and what this .. read more