News & Analysis

May 1, 2012
Briefings on HIPAA

If healthcare organizations take a lesson from Blue Cross Blue Shield of Tennessee's (BCBST) $1.5 million settlement for its 2009 HIPAA breach, it's that they should wake up and pay attention to where their ePHI is contained and stored, says Ali Pabrai, MSEE, CISSP, CSCS.

May 1, 2012
Briefings on HIPAA

With 20 initial "trial" audits completed, OCR ­expects to move forward with another 95 audits to ­measure HIPAA compliance before year's end, said ­Susan ­McAndrew, JD, OCR's deputy director for health ­information privacy. This represents a reduction in the number of audits (150) that were originally planned for 2012.

April 1, 2012
Briefings on HIPAA

Q. Please explain in an understandable way for nontechnical individuals what level of encryption is needed for e-mail to be considered secure as defined in the interim final breach notification rule.

April 1, 2012
Briefings on HIPAA

Navigating the new world of social media is challenging for many professions, but perhaps none more so than the medical profession, where physicians and other healthcare professionals must balance a tell-all online culture with the HIPAA Privacy Rule's mandate to protect patient privacy.

April 1, 2012
Briefings on HIPAA

Mac McMillan, CISSM, has an insider’s look at what it’s like to undergo a HIPAA compliance audit.

April 1, 2012
Briefings on HIPAA

All covered entities (CE) face the question, “Will the data be there when I need it?”

Pages