January 22, 2018
Briefings on HIPAA

Everyone is familiar with the words “privacy” and “security,” but what do these terms mean to the experts, and what is the relationship between privacy and security?

January 15, 2018
Briefings on HIPAA

With massive data breaches rocking industries and the public, and policymakers scrutinizing how organizations respond, it’s time to dust off policies and ensure organizations have meaningful, compliant reporting and response plans.

January 8, 2018
Briefings on HIPAA

HIPAA compliance and enforcement saw its share of highs and lows in 2017. As the year comes to a close, it’s a good time to look back on what your organization has learned—in terms of personal growth and lessons gleaned from other organizations.

December 14, 2017
News & Insights

Q: We see many assertions that encryption at the right level meets the National Institute of Standards and Technology (NIST)/HIPAA safe harbor provision with no explanation of what is necessary to prove the breached electronic protected health information (PHI) was actually encrypted at the moment of breach. How can a covered entity prove the PHI was actually encrypted at the time of the breach?

December 8, 2017
News & Insights

Intentionally concealing a data breach could lead to jail time for C-suite executives under a bill introduced in the Senate November 30.

December 6, 2017
HIM Briefings

OCR’s 2016 guidance on patient access opened up a debate in the industry and brought questions about fulfilling patient access requests to the foreground.

December 25, 2017
Briefings on HIPAA

This month's security Q&A answers readers' questions on incidental disclosures, sending protected health information in the mail, and addressing vulnerabilities identified in a risk analysis.

December 18, 2017
Briefings on HIPAA

The general rules for security, risk analysis, and risk management implementation specifications, and evaluation standards are key directives for ongoing compliance assurance. Although risk analysis concepts guidance appears in the Security Rule, many organizations use it for auditing Privacy Rule processes as well.

December 11, 2017
Briefings on HIPAA

Handling requests for information from law enforcement can throw staff for a loop. Most staff are aware of their organization’s policies and the basic HIPAA requirements for disclosing patient information to family members, friends, and other individuals such as legal guardians. But handling requests from law enforcement officials can be a different matter.

December 4, 2017
Briefings on HIPAA

Changes to the Office for Civil Rights' HIPAA Audit Program and enforcement focus highlight compliance areas organizations should review.

Pages