Articles and Blogs

Health Information Technology

Provider Penalized for Failure to Properly Dispose of Patient Information

[08/29/22]

Posted on August 29, 2022 in Health Information Technology, Health Law News

Published by: Hall Render

The United States Department of Health and Human Services Office for Civil Rights (“OCR”) announced a $300,640 settlement and corrective action plan with a dermatology provider over the improper disposal of protected health information (“PHI”). Background In May of 2021, the dermatology provider reported a breach to OCR when empty specimen containers with PHI on... READ MORE

Tags: , , ,

Unauthorized Access to ePHI on Web Server Leads to $875,000 Settlement

[08/08/22]

Posted on August 8, 2022 in Health Information Technology, Health Law News

Published by: Hall Render

The United States Department of Health and Human Services Office for Civil Rights (“OCR”) announced a settlement with a research university (“University”) which has agreed to pay $875,000 to settle potential violations of the HIPAA Privacy, Security and Breach Notification Rules, as well as to take corrective action after an unauthorized third party gained... READ MORE

Tags: , , ,

Impermissible Disclosures of PHI Leads to Settlement for Dental Practice

[04/28/22]

Posted on April 28, 2022 in Health Information Technology, Health Law News

Published by: Hall Render

The United States Department of Health and Human Services Office for Civil Rights (“OCR”) announced a settlement with a dental practice (“Practice”) which has agreed to pay $62,500 to settle potential violations of the HIPAA Privacy Rule, as well as to take corrective action after impermissibly disclosing patient PHI to a political campaign manager... READ MORE

Tags: , , ,

Dentist Disclosing PHI in Response to Negative Online Review Leads to $50,000 Civil Monetary Penalty

[04/28/22]

Posted on April 28, 2022 in Health Information Technology, Health Law News

Published by: Hall Render

A North Carolina dental practice (“Practice”) has been fined $50,000 following a Notice of Final Determination regarding a violation of the HIPAA Privacy Rule. In the Notice of Proposed Determination, the United States Department of Health and Human Services Office for Civil Rights (“OCR”) stated that a patient visited the Practice in 2013 and... READ MORE

Tags: , ,

New Cyber Incident Reporting Requirements

[03/18/22]

Posted on March 18, 2022 in Health Information Technology

Published by: Hall Render

New cyber incident reporting requirements are forthcoming from the Cybersecurity and Infrastructure Security Agency. Part of the just-signed Consolidated Appropriations Act of 2022 (H.R. 2471) that we wrote about here, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (“Act”) gives covered entities 72 hours to report to the Agency that a covered... READ MORE

Tags: , ,

Information Un-Blocked: Increased Access Can Reveal Compliance Risks

[05/05/21]

Posted on May 5, 2021 in Health Information Technology

Published by: Hall Render

The Information Blocking Rule (45 CFR part 171) is only a month into effect, and improved access to medical records, particularly concurrent delivery of lab results to the provider and patient and increased access to provider notes through patient portals, already has led to scrutiny of accurate encounter notes and complicated patient satisfaction issues... READ MORE

Tags: , , , ,

Notice of Enforcement Discretion Issued for Scheduling Technology for COVID-19 Vaccination Appointments

[01/22/21]

Posted on January 22, 2021 in Health Information Technology

Published by: Hall Render

On January 19, 2021, OCR announced that it will exercise its discretion in enforcing the HIPAA Privacy, Security and Breach Notification Rules by not imposing penalties for noncompliance with those requirements against covered entities who are health care providers or their business associates in connection with the use of online or web-based scheduling applications... READ MORE

Tags: , , ,

OCR Issues Guidance on Health Information Exchanges to Disclose PHI for Public Health Authority Activities

[12/30/20]

Posted on December 30, 2020 in Health Information Technology

Published by: Hall Render

Following a Notice of Enforcement Discretion (“NED”) issued earlier this year (discussed in our previous article here), the Office for Civil Rights (“OCR”) has issued detailed guidance addressing the sharing of protected health information (“PHI”) through health information exchanges (“HIEs”) for public health activities of a public health authority (“PHA”). An HIE enables participants... READ MORE

Tags: , , ,

Updates to EHR Donation Rules and New Cybersecurity Donation Rules Published by HHS, CMS

[12/16/20]

Posted on December 16, 2020 in Health Information Technology

Published by: Hall Render

On December 2, 2020, both the Health and Human Services Office of Inspector General (“OIG”) and Centers for Medicare & Medicaid Services (“CMS”) issued final rules amending the Anti‑Kickback Statute safe harbor and Physician Self-Referral Law (Stark) exception for EHR donations (“EHR Donation Rules”), as well as a new safe harbor and exception for... READ MORE

Tags: ,

Federal Agencies Warn of Significant and Imminent Cyber Security Threat Targeting the Health Care and Public Health Sectors

[10/29/20]

Posted on October 29, 2020 in Health Information Technology

Published by: Hall Render

On October 28, 2020, the Cybersecurity and Infrastructure Security Agency (“CISA”), the Federal Bureau of Investigation (“FBI”) and the Department of Health and Human Services (“HHS”) coauthored an urgent cybersecurity advisory (the “CISA Alert”) describing the tactics, techniques and procedures (“TTPs”) used by cybercriminals against targets in the Healthcare and Public Health Sector (“HPH”)... READ MORE

Tags: , , ,