Also In the News - Data, Privacy, & Security Practice Report - May 2016

King & Spalding
Contact

OCR Releases Guidance On Data Security Incident Preparedness—On May 3, 2016, the Office for Civil Rights (“OCR”) within the U.S. Department of Health & Human Services released its cyber-awareness monthly update on the topic of data security incident preparedness by covered entities and business associates regulated under the Health Insurance Portability and Accountability Act of 1996, as amended (“HIPAA”).  OCR, which enforces the HIPAA rules, notes in the update that “[d]espite the requirements of HIPAA, not only do a large percentage of covered entities believe they will not be notified of security breaches or cyberattacks by their business associates, they also think it is difficult to manage security incidents involving business associates, and impossible to determine if data safeguards and security policies and procedures at their business associates are adequate to respond effectively to a data breach.”  Accordingly, OCR provides guidance relating to managing data breaches at business associates and subcontractors, including defining timeframes for business associates and subcontractors to report data breaches and identifying the type of information that must be provided in data breach reports.  OCR further encourages covered entities and business associates to conduct training on breach incident reporting.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© King & Spalding | Attorney Advertising

Written by:

King & Spalding
Contact
more
less

King & Spalding on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide