First HIPAA Penalty for Failure to Comply with the HIPAA Breach Notification Rule: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The U.S. Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) last week announced the first HIPAA settlement in lieu of a .. read more
HIPAA and Texting: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Alice M. McCart
You may wonder whether HIPAA allows your organization to engage in texting with your patients/clients and/or within your organization. HIPAA, of course, does not mention .. read more
Children’s Health Records and You: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Parents who have minor children have legitimate concerns about their children’s health records as used, disclosed, and maintained by their health care providers, insurers, and .. read more
Acting without Accurate Data Is Just Guessing: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Alice M. McCart
For those of you who are still reluctant to perform your first Risk Analysis or to update one from perhaps a few years ago, as .. read more
$1.55 Million Settlement Stresses Importance of Business Associate Agreements: HIPAA & HITECH Act Blog by Jonathan P. Tomes
A recent settlement in lieu of a civil money penalty underscores the importance of having business associate agreements in place with entities that perform a .. read more
California Determines What Is Reasonable and Appropriate for Securing Health Information: HIPAA & HITECH Act Blog by Jonathan P. Tomes
HIPAA requires covered entities and business associates to implement reasonable and appropriate security measures in § 164.308(a)(1)(ii)(B), the risk management Administrative safeguards, but although it does .. read more
It was the Best of Breach Responses, it was the Worst of Breach Responses: HIPAA & HITECH Act Blog by Jonathan P. Tomes
It was the best of times, it was the worst of times, it was the age of wisdom, it was the age of foolishness, it .. read more
Latest HIPAA Settlement 2—a Lesson Still Not Yet Learned about Risk Analysis: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In its press release, the Department of Health and Human Services (“DHHS”) once again pointed out the importance of an organization-wide risk analysis. The press .. read more
Latest HIPAA Violation Settlement–$850,000 for a Stolen Laptop: HIPAA & HITECH Act Blog by Jonathan P. Tomes
I don’t understand why, with all the high six-figure and seven-figure resolution agreements (basically, settlements), covered entities do not provide adequate security for laptops and .. read more
Latest HIPAA Settlement—a Lesson Still Not Learned: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Although most civil money penalties (“CMPs”) to date have involved risk analysis—that is, failure to do one, failure to do a complete one, or failure .. read more