California Exempts HIPAA Covered Entities from Its New Consumer Privacy Act: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In June 2018, the California legislature passed the California Consumer Privacy Act (“CCPA”), which was intended to change state law to better protect the privacy .. read more
Must You Audit Your Business Associates for HIPAA Compliance? HIPAA & HITECH Act Blog by Jonathan P. Tomes
Now that the HITECH Act and the Omnibus Rule have made covered entities potentially liable for breaches by their business associate, see Compliance Hit: Expanded .. read more
Phase II Audits: HIPAA Privacy, Security, and Breach Notification Heads Up: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Section 13411 of the HITECH Act requires the Department of Health and Human Services (“DHHS”) to audit covered entities and business associates to ensure that .. read more
Hands-on HIPAA Compliance Workshop: HIPAA & HITECH Act Blog by Jonathan P. Tomes
Is your organization’s HIPAA compliance lost at sea? As you may know, EMR Legal, Inc., is offering our 2-day Hands-on HIPAA Workshop October 16-17 aboard .. read more
Business Associates? How Low Can You Go? HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Omnibus Rule effectively made “downstream” business associates—that is, subcontractors—into business associates and thus effectively into covered entities. They are now effectively if not by .. read more
Potential Business Associate Screening Questionnaire Now Available on Premium Member Section: HIPAA & HITECH Act Blog by Jonathan P. Tomes
You do not necessarily have to ask a potential business associate to complete all or portions of the questionnaire that I have developed and made .. read more
Possible Defenses to an OCR Investigation into an Alleged HIPAA Violation Now on Premium Member Section: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In my How to Handle HIPAA and HITECH Act Breaches, Complaints, and Investigations: Everything You Need to Know, Overland Park, KS: Veterans Press (2011), with .. read more
Unintended Financial Consequences? Well, Maybe It’s Job Security: HIPAA & HITECH Act Blog by Jonathan P. Tomes
In my recent article for the Journal of Healthcare Finance, “The Law of Unintended (Financial) Consequences: The Expansion of HIPAA Business Associate Liability,” which is .. read more
Omnibus Rule Compliance Date 10 Days Away—Are You Ready? HIPAA & HITECH Act Blog by Jonathan P. Tomes
The Omnibus Rule compliance date is September 23, 2013. You may be feeling overwhelmed and thinking that you cannot possibly get your organization completely HIPAA .. read more
When You Update Your Notice of Privacy Practices by September 23, 2013, to Comply with the Omnibus Rule, Must You Mail Copies to Your Patients? HIPAA & HITECH Act Blog by Jonathan P. Tomes
I have been asked repeatedly whether a covered health care provider must mail a copy of its new Omnibus Rule compliant notice of privacy practices .. read more