January 19, 2021
News & Insights

South County Health Alliance (SCHA), a health plan based out of Owatonna, Minnesota, reported a security breach on December 31 affecting 66,874 individuals, according to the Office for Civil Rights (OCR) breach report.

January 21, 2021
News & Insights

Q: If a patient writes his or her email address in an illegible fashion and the provider misreads it and then inadvertently sends appointment reminders and other communication to the wrong email address, is the provider at fault? What steps can be taken to avoid such a situation?

January 20, 2021
News & Insights

Q: Telemedicine may not be the best fit for all patients. How can case managers help facilitate in-person visits for those patients that cannot engage in telemedicine visits?

January 18, 2021
Briefings on HIPAA

Ever run into a vendor who claims to be a conduit versus a business associate (BA)? It happens all too often, in my experience. Here’s the problem: The conduit exception is a narrow one. If you’re storing protected health information (PHI), even encrypted PHI where you don’t have the encryption key, you’re a BA. Once you sign the business associate agreement (BAA), it applies to you.

January 14, 2021
News & Insights

Q: What type of activity must be audited to comply with the HIPAA requirement to audit electronic medical record (EMR) activity? Does this include every action a user takes within a record and the length of time a user spends in a record?

January 12, 2021
News & Insights

President Donald Trump signed H.R. 7898 into law on January 5, amending the Health Information Technology for Economic and Clinical Health Act (HITECH Act) to require the Health and Human Services secretary to consider certain recognized security practices of covered entities (CE) and business associates (BA) when taking enforcement actions.

January 11, 2021
Briefings on HIPAA

As many anticipated, the Department of Health and Human Services (HHS) has pushed out a flurry of proposed rules in the months leading up to the Trump administration’s departure. Among them is a Notice of Proposed Rulemaking (NPRM) that would make significant changes to the HIPAA Privacy Rule.

January 7, 2021
News & Insights

Q: If we end a contract with a business associate (BA), does the BA need to provide us with assurance that all protected health information (PHI) has been destroyed? Is this something that should be written into the initial contract? What are the steps to take if the BA does not respond to requests to confirm deletion of PHI?

January 5, 2021
News & Insights

GenRx Pharmacy, which is headquartered in Scottsdale, Arizona, reported a data security incident on December 18 affecting 137,110 individuals, according to the Office for Civil Rights (OCR) breach report.

January 4, 2021
Briefings on HIPAA

Your facility’s information security officer has ultimate responsibility for information security policies implemented at your facility. However, everyone has an important role to play in keeping information secure by following policies and procedures.

Pages