December 28, 2016
Briefings on HIPAA

Breaches and audits brought much needed attention to HIPAA

December 26, 2016
Briefings on HIPAA

Q. Are we required to use encryption on all email, or only email that contains PHI?

December 12, 2016
Briefings on HIPAA

Information security officers often have their hands full with HIPAA. But as high-deductible health plans have patients paying more out of pocket, it’s time organizations took a closer look at another set of cybersecurity guidance: the Payment Card Industry Data Security Standard (PCI DSS).

December 1, 2016
Briefings on HIPAA

It’s been a challenging year for HIPAA compliance. OCR levied more than $20 million in breach settlement fines. Ransomware rocked the healthcare industry.

December 2, 2016
News & Insights

The second round of desk audits in the HIPAA audit program began this week, the Office for Civil Rights (OCR) announced in a November 30 email alert.

November 29, 2016
News & Insights

A new phishing scam targeting covered entities (CE) and business associates (BA) is disguised as an official communication from the Office for Civil Rights (OCR). In an alert released November 28, OCR advised CEs and BAs that a phishing email is being circulated on fake HHS letterhead with the signature of Jocelyn Samuels, OCR’s director.

November 28, 2016
News & Insights

The University of Massachusetts Amherst (UMass) agreed to a $650,000 HIPAA settlement fine after a breach investigation revealed the university failed to implement basic security measures.

December 9, 2016
News & Insights

An information security blogger stumbled across vulnerable protected health information stored by a billing service.

November 14, 2016
News & Insights

Data breaches spiked dramatically in the second half of the year but some experts at AHIMA’s 2016 national convention in Baltimore suggest the apparent surge might be caused in part by improved reporting.

October 1, 2016
Briefings on HIPAA

Q: In our pharmacy dispensing system, we can enter free-form notes for certain records such as a patient record, prescription records, and physician records. This field is used to enter notes that are customer service?focused and not treatment- or payment-related in nature. Would these notes be considered PHI, and would record retention requirements apply to these notes?

Pages