OCR enforces the HIPAA Privacy, Security, and Breach Notification rules. Failing to properly manage and oversee remote access to and the protection of health information can be costly, as the following three cases demonstrate.
Jackson Health System was fined $2.15 million for HIPAA violations that included an employee selling patient information for years, an incident in which an NFL player's PHI was shared with an ESPN reporter, and more.
Q: Can a cloud provider like Amazon Web Services or Microsoft Azure, when considered a business associate (BA), be held liable for breach notification requirements?
New York Gov. Andrew Cuomo signed legislation on October 7 that prohibits ambulance and first response service providers from selling patient information to third parties for marketing purposes.