News & Analysis as of

Health Care Providers Health Insurance Portability and Accountability Act (HIPAA) Office of Civil Rights

Health Care Compliance Association (HCCA)

2nd Settlement Triggered by 2017 Ransomware Attack Costs WA Practice $100K; ‘Not a Breach’

Let’s review for a moment. It’s not a HIPAA violation to be a victim of ransomware. It’s not a HIPAA violation to pay a ransom. It’s up to the covered entity (CE) to determine if a security or privacy incident is a...more

Baker Donelson

The Office for Civil Rights Recently Settled Two Ransomware Related Investigations

Baker Donelson on

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) recently settled two ransomware cases with covered entities. These cases signal the government's growing concern with health care...more

Bass, Berry & Sims PLC

How Can Healthcare Providers Respond to Online Patient Reviews Without Violating HIPAA?

Bass, Berry & Sims PLC on

Current and potential patients are taking to the internet to share opinions and make decisions about healthcare providers. Good reviews can convert prospective healthcare consumers into patients, while bad reviews,...more

Saul Ewing LLP

Medical Practice Agrees to Pay $250,000 HIPAA Settlement Following Ransomware Attack

Saul Ewing LLP on

In late September 2024, the U.S. Department of Health and Human Services (“HHS”), Office for Civil Rights (“OCR”) announced a settlement with Cascade Eye and Skin Centers, P.C., a health care provider in the state of...more

Epstein Becker & Green

OCR Withdraws Appeal of District Court Order Declaring Unlawful and Vacating the “Proscribed Combination” Portion of Its HIPAA...

Epstein Becker & Green on

On March 18, 2024, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued updated guidance regarding the use of online tracking technologies by entities and business associates subject to...more

Robinson+Cole Data Privacy + Security Insider

OCR Settles Fourth Ransomware Investigation

The Office for Civil Rights of the Department of Health and Human Services (OCR) announced on September 26, 2024, that it had entered a settlement with Cascade Eye and Skin Centers (together, Cascade) for $250,000 following...more

Stevens & Lee

Pennsylvania Health System Settles HIPAA Violations Amid Rising Ransomware Threats

Stevens & Lee on

On July 1, 2024, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced a significant settlement with Western Pennsylvania’s Heritage Valley Health System following potential HIPAA...more

Jackson Lewis P.C.

Key Takeaways for Healthcare Providers Following HHS OCR’s Most Recent Ransomware Investigation

Jackson Lewis P.C. on

Announcing its fourth ransomware cybersecurity investigation and settlement, the Office for Civil Rights (OCR) also observed there has been a 264% increase in large ransomware breaches since 2018....more

Jackson Lewis P.C.

Investigation of AI Training by Australian Radiology Provider Provides Important Reminder for U.S. Healthcare Providers

Jackson Lewis P.C. on

If there is one thing artificial intelligence (AI) systems need is data and lots of it as training AI is essential for achieving success for a given use case. A recent investigation by Australia’s privacy regulator into the...more

Nelson Mullins Riley & Scarborough LLP

Providers Must Comply With Reproductive Health Amendment HIPAA Privacy Final Rule Soon

On April 22, the United States Department of Health and Human Services (HHS) Office for Civil Rights (OCR) released a Final Rule prohibiting the use and disclosure of protected health information (PHI) related to lawful...more

Health Care Compliance Association (HCCA)

HHS Abandons Appeal in Public Website Pixel Case, But CEs and BAs Should Expect Continued Scrutiny

The HHS Office for Civil Rights (OCR) has abandoned its appeal of a federal judge’s ruling overturning OCR’s guidance prohibiting covered entities (CEs) and business associates (BAs) from using the web-tracking technologies...more

Robinson+Cole Data Privacy + Security Insider

HHS Drops Appeal of Tracking Technology Case

Last year, the American Hospital Association (AHA) sued the U.S. Department of Health and Human Services (HHS) in the U.S. District Court of the Northern District of Texas, requesting that HHS be barred from enforcing a new...more

BakerHostetler

Let’s Get Physical - OCR Issues Reminder that HIPAA Security Isn’t Just Technical

BakerHostetler on

While most entities that are subject to the HIPAA Security Rule spend considerable time and effort ensuring that they have implemented appropriate administrate and technical safeguards to protect the health information that...more

Holland & Knight LLP

Business Associate Agreements Matter: Demystifying the Perceived Simplicity of HIPAA Agreements

Holland & Knight LLP on

For most healthcare providers and businesses, signing a Business Associate Agreement (BAA) is a standard practice. When contracting to provide services with an entity governed by the Health Insurance Portability and...more

ArentFox Schiff

Federal Court Scales Back HIPAA Online Tracking Technology Guidance

ArentFox Schiff on

On June 20, a federal district court in Texas ruled that the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) exceeded its authority under the Health Insurance Portability and Accountability Act...more

Rivkin Radler LLP

Medical Provider to Pay $115,200 Penalty for HIPAA Right of Access Violation

Rivkin Radler LLP on

The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) recently announced that it ordered American Medical Response (AMR) to pay a civil monetary penalty of $115,200 for failing to comply with the...more

Saul Ewing LLP

OCR Imposes $115,200 CMP Against HIPAA-Covered Entity

Saul Ewing LLP on

On August 1, 2024, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced a civil monetary penalty of $115,200 against American Medical Response (“AMR”) based on a complaint that...more

Arnall Golden Gregory LLP

OCR Announces Latest in Right of Access Enforcement Actions With Imposition of Civil Monetary Penalty

On August 1, 2024, the U.S. Department of Health and Human Services, Office for Civil Rights (“OCR”) announced the imposition of a civil monetary penalty (“CMP”) of $115,200 collected against American Medical Response...more

Kilpatrick

HIPAA Privacy Rule Model Attestation for Reproductive Health Information

Kilpatrick on

Earlier we discussed the Office for Civil Rights (“OCR”) of the US Department of Health and Human Services final rules relating to reproductive health care information (the “Final Rules”). In our prior blog we discussed that...more

Health Care Compliance Association (HCCA)

[Virtual Event] Healthcare Privacy Compliance Conference - October 10th, 8:00 am - 5:00 pm CT

Address the latest updates & emerging trends in privacy - Join us this October for HCCA's virtual event dedicated to privacy compliance. This virtual event provides first-hand insights from government agencies regarding...more

Rivkin Radler LLP

OCR Announces Third Ransomware Settlement as Threats Continue to Rise

Rivkin Radler LLP on

On July 1, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced that Heritage Valley Health System, a provider in Pennsylvania, Ohio and West Virginia, agreed to pay $950,000 to resolve...more

Kilpatrick

Changes to the HIPAA Privacy Rules – A Primer for Self-Insured Group Health Plans

Kilpatrick on

The Office for Civil Rights (“OCR”) of the US Department of Health and Human Services recently released a final rule (“Final Rule”) to update the HIPAA Privacy Rules for reproductive health care information. The Final Rule...more

Saul Ewing LLP

HIPAA Security Rule Settlement Results in $950,000 Payment by a Mid-Atlantic Health System

Saul Ewing LLP on

On July 1, 2024, the U.S. Department of Health and Human Services (“HHS”) Office For Civil Rights (“OCR”) announced a $950,000 settlement with Heritage Valley Health System (“Heritage Valley”) and a three-year Corrective...more

Greenbaum, Rowe, Smith & Davis LLP

HIPAA Privacy Rule to Support Reproductive Healthcare Privacy is Now Effective

On June 25, 2024, the Final Rule issued by the Office of Civil Rights (OCR) that amended the Privacy Rule of the Health Insurance Portability and Accountability Act (HIPAA) became effective as a means of further protecting...more

Polsinelli

HHS HIPAA Web-Tracking Guidance Takes a Step Back, While Providers Grapple with Latest Challenges

Polsinelli on

In a narrow but significant ruling in American Hospital Association et al. v. Xavier Becerra, et al., No. 4:23-cv-01110-P, the U.S. District Court for the Northern District of Texas (Hon. Mark T. Pittman) ruled that one...more

857 Results
 / 
View per page
Page: of 35

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide