Articles and Blogs

HIPAA

Repeated Breaches of ePHI Result in a $3 Million Fine, Capping Off OCR’s “Record Year” of 2018 Enforcement Actions

[02/19/19]

Posted on February 19, 2019 in Health Information Technology

Published by: Hall Render

The Office for Civil Rights (“OCR”) announced that a health system in California (the “System”) was required to pay a $3 million fine and adopt an extensive corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). The System operates several hospitals, including a rehabilitation hospital... READ MORE

Tags: , , , , , , ,

This Week in Washington – December 14, 2018

[12/14/18]

Posted on December 14, 2018 in Health Law News

Published by: Hall Render

Congress Tackles Multiple Health Provisions This Week The standstill on progress over finalizing the remaining fiscal year 2019 spending bills has given Congress the opportunity to advance some outstanding health care measures. This week, the House of Representatives passed legislation including the ACE Kids Act to allow state Medicaid programs to use a home... READ MORE

Tags: , , , ,

OCR Announces Fine for Lack of BAA and Failure to Terminate Former Employee’s Access to PHI

[12/14/18]

Posted on December 14, 2018 in Health Law News

Published by: Hall Render

On December 11, 2018, the Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced that a critical access hospital in Colorado (the “Hospital”) will settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) by paying a civil penalty of $111,400 and adopting a corrective action... READ MORE

Tags: , , , , ,

Business Associate’s Data Breach Leads to $500,000 Fine for Hospitalist Group

[12/10/18]

Posted on December 10, 2018 in Health Information Technology

Published by: Hall Render

The Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced on December 4, 2018 that a hospitalist group (“Group”) that works with hospitals and nursing homes to provide internal medicine physicians has agreed to pay $500,000 and adopt a corrective action plan to settle alleged violations of the Health Insurance... READ MORE

Tags: , , , ,

Disclosing PHI to a Reporter Leads to $125,000 HIPAA Settlement

[11/29/18]

Posted on November 29, 2018 in Health Information Technology

Published by: Hall Render

The Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”), announced that a small professional association with three doctors and four locations (the “Practice”) has agreed to pay $125,000 and adopt a corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). The... READ MORE

Tags: , , , ,

Largest Health Data Breach = Largest OCR Settlement in History

[10/19/18]

Posted on October 19, 2018 in Health Information Technology

Published by: Hall Render

On October 15, 2018, the Department of Health and Human Services (“HHS”), Office for Civil Rights (“OCR”) announced that it had reached a record $16 million settlement with Anthem arising out of alleged violations of the Privacy and Security Rules under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). The settlement comes... READ MORE

Tags: , , , , , ,

Hospitals Fined for Allowing Documentary Film Crews to Film Patients Without Consent

[09/24/18]

Posted on September 24, 2018 in Health Information Technology

Published by: Hall Render

The Department of Health and Human Services Office for Civil Rights (“OCR”) fined three separate hospitals a cumulative total of $999,000 to settle potential violations of HIPAA arising from allowing film crews on premises to film a reality television show without first obtaining patient authorizations. The OCR Resolution Agreement can be found here. Generally, a... READ MORE

Tags: , , , ,

Don’t Forget! HIPAA Breaches Affecting Fewer Than 500 Must Be Reported to OCR by March 1, 2017

[02/21/17]

Posted on February 21, 2017 in Health Law News

Published by: Hall Render

Under the Breach Notification Rule, HIPAA covered entities are required to submit reports of certain breaches of unsecured protected health information (“PHI”) affecting fewer than 500 individuals to the Office for Civil Rights (“OCR”) on an annual basis. Covered entities must submit their breaches electronically through OCR’s breach notification web page, which can be... READ MORE

Tags: , , , ,

OCR Announces Largest Single-Entity Settlement to Date

[08/18/16]

Posted on August 18, 2016 in Health Law News

Published by: Hall Render

On August 4, the Office for Civil Rights (“OCR”) announced a $5.55 million settlement with the largest fully integrated health care system in Illinois. The settlement is the largest HIPAA settlement ever by a single entity and follows two recent settlements with university health systems in Oregon and Mississippi that were $2.7 million and... READ MORE

Tags:

Did You Get an OCR HIPAA Audit Letter or a Golden Pass?

[07/19/16]

Posted on July 19, 2016 in Health Law News

Published by: Hall Render

The Office for Civil Rights (“OCR”), Department of Health and Human Services (“HHS”), emailed notices to 167 covered entities on July 11, 2016 informing them they were selected for a HIPAA Phase II audit. Health care providers, health plans and health care clearinghouses were randomly selected by OCR from the audit pool. If your organization... READ MORE

Tags: