[06/07/19]
Posted on June 7, 2019 in Health Information Technology
Published by: Hall Render
American Medical Collection Agency (“AMCA”), a collection agency that works primarily with health care companies, recently announced a breach of protected health information (“PHI”) and personally identifiable information (“PII”) affecting over 19.6 million patients. Quest Diagnostics and LabCorp, both clients of AMCA, have reported that their patients have been impacted by the incident. AMCA... READ MORE
Tags: AMCA, American Medical Collection Agency, HIPAA, PHI, PII, Protected Health Information
[06/04/19]
Posted on June 4, 2019 in Health Information Technology
Published by: Hall Render
The Office for Civil Rights (“OCR”) issued a factsheet detailing ten ways a business associate can be held directly liable for violations of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as provided by the Health Information Technology for Economic Clinical Health (“HITECH”) Act of 2009. Although covered entities are ultimately responsible... READ MORE
Tags: HIPAA, HITECH, OCR, PHI, Protected Health Information
[02/19/19]
Posted on February 19, 2019 in Health Information Technology
Published by: Hall Render
The Office for Civil Rights (“OCR”) announced that a health system in California (the “System”) was required to pay a $3 million fine and adopt an extensive corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). The System operates several hospitals, including a rehabilitation hospital... READ MORE
Tags: Cottage Health, ePHI, health it, HIPAA, HIPAA Breach, OCR, OCR enforcement, PHI
[12/14/18]
Posted on December 14, 2018 in Health Law News
Published by: Hall Render
On December 11, 2018, the Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced that a critical access hospital in Colorado (the “Hospital”) will settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) by paying a civil penalty of $111,400 and adopting a corrective action... READ MORE
Tags: BAA, hhs, HIPAA, Office for Civil Rights, Pagosa Springs Medical Center, PHI
[12/10/18]
Posted on December 10, 2018 in Health Information Technology
Published by: Hall Render
The Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced on December 4, 2018 that a hospitalist group (“Group”) that works with hospitals and nursing homes to provide internal medicine physicians has agreed to pay $500,000 and adopt a corrective action plan to settle alleged violations of the Health Insurance... READ MORE
Tags: Data Breach, HIPAA, HIPAA Security Rule, PHI, Privacy and Security Compliance
[11/29/18]
Posted on November 29, 2018 in Health Information Technology
Published by: Hall Render
The Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”), announced that a small professional association with three doctors and four locations (the “Practice”) has agreed to pay $125,000 and adopt a corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). The... READ MORE
Tags: HHS Office for Civil Rights, HIPAA, HIPAA Settlement, OCR, PHI
[09/24/18]
Posted on September 24, 2018 in Health Information Technology
Published by: Hall Render
The Department of Health and Human Services Office for Civil Rights (“OCR”) fined three separate hospitals a cumulative total of $999,000 to settle potential violations of HIPAA arising from allowing film crews on premises to film a reality television show without first obtaining patient authorizations. The OCR Resolution Agreement can be found here. Generally, a... READ MORE
Tags: Business Associate Agreement, HIPAA, HIPAA Authorization, PHI, Protected Health Information
[02/21/17]
Posted on February 21, 2017 in Health Law News
Published by: Hall Render
Under the Breach Notification Rule, HIPAA covered entities are required to submit reports of certain breaches of unsecured protected health information (“PHI”) affecting fewer than 500 individuals to the Office for Civil Rights (“OCR”) on an annual basis. Covered entities must submit their breaches electronically through OCR’s breach notification web page, which can be... READ MORE
Tags: Breach Notification Rule, HIPAA, PHI, Protected Health Information, Security Rule