Latest HIPAA Settlement—Federal Trade Commission Loses Health Data Security Case: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Although the Office for Civil Rights (“OCR”) of the Department of Health and Human Services (“DHHS”) is the primary agency enforcing HIPAA, the Federal Trade .. read more
Latest HIPAA Violation Settlement–$850,000 for a Stolen Laptop: HIPAA & HITECH Act Blog by Jonathan P. Tomes
I don’t understand why, with all the high six-figure and seven-figure resolution agreements (basically, settlements), covered entities do not provide adequate security for laptops and .. read more
Latest HIPAA Settlement—a Lesson Still Not Learned: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Although most civil money penalties (“CMPs”) to date have involved risk analysis—that is, failure to do one, failure to do a complete one, or failure .. read more
EMR Legal Remains Undefeated against OCR: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Sometimes, we just need to toot our own horn. We are pleased to note that EMR Legal remains undefeated going up against the Department of .. read more
Keep Those Tracking Numbers! HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Legal Editor Alice M. McCart
Have you ever wondered whether the package that you had sent via FedEx, USPS, UPS, or otherwise had arrived and wished that you had kept .. read more
Phase II Audits: HIPAA Privacy, Security, and Breach Notification Heads Up: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Section 13411 of the HITECH Act requires the Department of Health and Human Services (“DHHS”) to audit covered entities and business associates to ensure that .. read more
Will HIPAA Let You Report a Suspected Ebola Case to Public Health Officials? HIPAA & HITECH Act Blog by Jonathan P. Tomes
If you encounter a patient that you suspect may have ebola, do you want to waste time wading through the HIPAA Privacy Rule to figure .. read more
Next Stage of DHHS Audits Coming: HIPAA & HITECH Act Blog by Jonathan P. Tomes
The U.S. Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”) has not yet published an audit protocol for this year’s Phase .. read more
You Don’t Just “Address” an Addressable Implementation Specification: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Recently, a HIPAA consultant answered a question about whether one had to implement an addressable implementation specification. His answer was basically “no.” He must have .. read more
New $4.8 Million OCR Settlement for HIPAA Violations: HIPAA & HITECH Act Blog by Jonathan P. Tomes with Guest Commentator Attorney and EMR Legal Consultant Alice M. McCart
According to a press release issued May 7, 2014, by the Department of Health and Human Services (“DHHS”) Office for Civil Rights (“OCR”), “Two health .. read more