Close

Articles Posted in HIPAA

Updated:

Court Strikes Down HHS “Guidance” Regarding Online Tracking Technologies and HIPAA: Implications for Healthcare Providers

In a recent landmark decision, the United States District Court for the Northern District of Texas issued an opinion and order with significant implications for healthcare providers and their use of online technologies. The case, filed by the American Hospital Association, Texas Hospital Association, Texas Health Resources, and United Regional…

Updated:

Newly Released FTC Health Breach Notification Rule: A Guide for Non-HIPAA Health Apps and Technologies

As healthcare regulatory attorneys, we’ve seen firsthand the confusion and challenges that arise when health-related entities fall outside the purview of the Health Insurance Portability and Accountability Act (HIPAA). One crucial, newly released, regulation that often gets overlooked is the Federal Trade Commission’s (FTC) Health Breach Notification Rule (HBN Rule).…

Updated:

Rise in HIPAA Class Action Suits: Partnership HealthPlan of California

HIPAA itself does not contain a private right of action for individuals following unauthorized disclosures of medical information. Yet, HIPAA does not prohibit individuals from seeking remedies through state or other law. Each U.S. state’s tort law system can potentially allow individuals to pursue reparations when they are harmed by…

Updated:

Evolving HIPAA Regulations Will Shape the Future of OCR’s Enforcement Regime

On April 6th, 2022, a HIPAA-regulatory Request for Information (RFI) was released by the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) soliciting feedback from the public for future rulemaking. The RFI seeks information on how the industry views “recognized security practices,” and on OCR’s compensating…

Updated:

Alarming Rate of Ransomware Data Breaches Calls for Increased Protection in Healthcare Industry

Participants in the healthcare industry have seen a multi-front threat related to their information security practices/healthcare data – increased enforcement and fines by the Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR); increased scrutiny from plaintiffs’ attorneys and State Attorneys General; and increased threats from malicious…

Updated:

OCR Issues Notification of Enforcement Discretion for Telehealth Remote Communications During COVID-19 Nationwide Public Health Emergency

On March 17, 2020, the Office for Civil Rights (“OCR”) issued a notification regarding enforcement discretion for telehealth remote communications that may not fully comply with applicable HIPAA Rules (the “Notification”). The Notification provides that OCR will not impose penalties on covered health care providers for noncompliance with regulatory requirements…

Updated:

February 29, 2020, Deadline for Reporting Small Health Care Data Breaches Approaches

Small health care data breaches – those affecting fewer than 500 patients – that occurred in the 2019 calendar year must be reported to the Department of Health and Human Services’ Office for Civil Rights (OCR) by February 29, 2020. The HIPAA Breach Notification Rule requires HIPAA-covered entities to report…

Updated:

HHS Caps Maximum HIPAA Penalty Fines

As of April 30, 2019, the maximum penalties for violations of the Health Insurance Portability and Accountability Act (HIPAA) have new annual limits. These updated penalties will be based on the level of culpability associated with the violation, according to the Department of Health and Human Services (HHS). Organizations that…

Updated:

OCR Sets New Enforcement Activity Record with 2018 Settlements Totaling $28.7 Million

Maintaining compliance with all HIPAA Rules has never been more important for a health care business’s success than it is now. Last year, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) concluded an all-time record in Health Insurance Portability and Accountability Act…

Updated:

March 1st Deadline for Reporting Small Health Care Data Breaches Approaches

Tomorrow, March 1, 2019, is the deadline for reporting small data breaches (<500) that occurred in calendar year 2018 to the Department of Health and Human Services’ Office for Civil Rights (OCR). Any HIPAA-covered entities and their business associates are required by the HIPAA Breach Notification Rule to, at least…