The Office of the National Coordinator for Health Information Technology (ONC) and the Office for Civil Rights released version 3.1 of the HHS Security Risk Assessment (SRA) Tool, designed to help healthcare providers conduct security risk assessments.
Kalispell Regional Healthcare (KRH) in Montana recently announced an email data breach that may have exposed the protected heath information of nearly 130,000 of its patients.
In an interview with Briefings on HIPAA, Tim Noonan, deputy director for the Division of Health Information Privacy at OCR, discussed cybersecurity and trends in reports of unsecured PHI to OCR. This article includes the highlights.
OCR meant what it said in February of this year about patients’ right of access to their medical records. The HIPAA Privacy and Security Rule enforcer issued its first enforcement action under its “Right of Access Initiative” in September.