Office of Civil Rights Dept. of Health and Human Services

News & Analysis as of

Health Update - July 2016

The Vulnerability of Healthcare Information - According to a report the Brookings Institute issued in May 2016, 23% of all data breaches occur in the healthcare industry. Nearly 90% of healthcare organizations had some...more

HHS Releases Guidance On Ransomware And HIPAA

On July 11, 2016, the U.S. Department of Health and Human Services Office for Civil Rights (“OCR”) published new guidance on the how HIPAA applies to ransomware prevention and attacks. Specifically, the guidance lays out...more

HHS: Ransomware Attacks Can Trigger Reporting Requirements

On July 11, 2016, the HHS Office for Civil Rights (OCR) released new HIPAA guidance regarding ransomware. The Fact Sheet, issued by OCR on July 11, covers various issues relating to ransomware, including reporting...more

HHS OCR Guidance on Ransomware Attacks: They Constitute a “Security Incident” and Are Likely a Data Breach

On July 11, 2016, the HHS Office of Civil Rights (OCR) released guidance on HIPAA covered entities’ responsibilities in a ransomware attack, a type of cyber-attack that has targeted the health care sector extensively in...more

New Materials Help Covered Entities Comply with Nondiscrimination Rules

Last week, the Department of Health and Human Services (“HHS”) released new materials for covered entities to use to comply with Section 1557, the nondiscrimination provision of the Affordable Care Act. Section 1557...more

Ransomware Attack is a Breach – Unless You Can Prove Otherwise

Ransomware is the fastest growing malware threat in the United States, targeting simple home computers to elaborate corporate IT networks. The Federal Bureau of Investigation recently reported an increase in ransomware...more

Regulatory Authorities Launch The Second Phase Of The HIPAA Compliance Audit Program

As a part of its continued efforts to assess compliance with the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules, the Health and Human Services (HHS) Office for...more

The Long Anticipated HIPAA Audits Are Here!

Phase 2 HIPAA Audits, which the Department of Health and Human Services' Office of Civil Rights ("OCR") announced had "launched" back in March of this year, have now officially begun. On Monday, July 11, 2016, the first round...more

Ransomware Attacks on ePHI May Be a Data Breach Under HIPAA

On July 11, 2016, the Office of Civil Rights (“OCR”) at the Department of Health and Human Services issued new HIPAA guidance regarding the growing epidemic of malicious computer software known as “ransomware”....more

OCR Issues New Guidance on Ransomware and HIPAA

In response to a rising number of ransomware attacks on healthcare systems, the Department of Health and Human Services (HHS) Office of Civil Rights (OCR) has issued new ransomware guidance on the HIPAA obligations of...more

OCR Begins HIPAA Phase 2 Audits

What covered entities and business associates can do to prepare for the next round of audits. On July 11, the HIPAA Phase 2 audits commenced when 167 covered entities received notice of a desk audit from the Department...more

BYOD Risks under HIPAA – Does Your HIPAA Compliance Program Adequately Address the Ever Increasing Use of Portable Electronic...

Many U.S. employers are now allowing employees to use their own personal handheld devices and laptop computers for work-related purposes. As the age of employer-provided devices is coming to an end and “bring your own device”...more

OCR Releases Guidance on Ransomware & HIPAA

On July 11, 2016, the U.S. Department of Health and Human Services, Office for Civil Rights (“OCR”) issued guidance (the “Guidance”) for health care entities relating to ransomware and the Health Insurance Portability and...more

OCR Announces New HIPAA Guidance on Ransomware

In response to the increasing prevalence of ransomware cyber-attacks by hackers on electronic health information systems in hospitals and medical practices, the Department of Health and Human Services (HHS) Office for Civil...more

Entity Fined $650,000 in First HIPAA Settlement with a Business Associate

The possibility of business associates potentially being audited, investigated, and ultimately fined is now a reality. On June 24, 2016, the United States Department of Health and Human Services’ Office of Civil Rights...more

[Event] HIPAA Compliance: The Current Audit and Enforcement Environment - August 4th, Richmond, VA

Featuring Iliana L. Peters, J.D., LL.M., Senior Advisor for HIPAA Compliance and Enforcement at the HHS Office for Civil Rights, and Members of Williams Mullen’s Health Care Practice...more

Business Associates of HIPAA Covered Entities Beware!

If your organization is a business associate of a HIPAA covered entity (such as a health care provider or employee health benefit plan), you should know that the Department of Health and Human Services' Office of Civil Rights...more

Business Associates Beware: First HIPAA Settlement with Business Associate

For the first time, the U.S. Department of Health & Human Services Office for Civil Rights (OCR) has entered into a Resolution Agreement with a business associate over allegations that it potentially violated the Health...more

HHS Office of Civil Rights Releases Guidance for Long-Term Care Facilities Using the Minimum Data Set to Facilitate Opportunities...

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has issued new guidance to help long-term care facilities comply with anti-discrimination obligations when they administer the Minimum Data...more

Business Associate Enters Into Mid Six-Figure HIPAA Settlement

On June 30, 2016, the U.S. Department of Health and Human Services, Office for Civil Rights (“OCR”) announced that a business associate providing management services to nursing homes in the Philadelphia, Pa. region agreed to...more

Bad News for HIPAA Business Associates: HHS OCR Announces $650,000 Settlement for BA Breach

Catholic Health Care Services of the Archdiocese of Philadelphia (“CHCS”), a HIPAA business associate, has agreed to pay the Department of Health and Human Services Office of Civil Rights (“OCR”) $650,000 in connection with a...more

Major Changes To Nondiscrimination Requirements Under ACA Effective Soon: Are Covered Entities Ready?

The HHS Office of Civil Rights (“OCR”) published a final rule May 18, 2016, broadening the nondiscrimination requirements applicable to all health programs and activities receiving federal financial assistance from HHS, those...more

HIPAA Enforcement Actions by the Numbers

Protecting patient information is a central duty for both covered entities and business associates under the Health Insurance Portability and Accountability Act (HIPAA). Should a HIPAA-subject entity ever fail to protect...more

HHS Issues Final Rule On Nondiscrimination In Health Programs And Activities

On May 18, 2016, the United States Department of Health and Human Services ("HHS") Office for Civil Rights ("OCR") issued a Final Rule implementing Section 1557 of the Affordable Care Act ("ACA"), which prohibits...more

HIPAA Enforcement on the Rise

After a number of years of little HIPAA enforcement activity, the tides appear to be turning. From September 2015 through April 2016, HIPAA settlements have averaged more than one a month. The dollar amounts involved are...more

261 Results
|
View per page
Page: of 11
JD Supra Readers' Choice 2016 Awards

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:

Sign up to create your digest using LinkedIn*

*By using the service, you signify your acceptance of JD Supra's Privacy Policy.

Already signed up? Log in here

*With LinkedIn, you don't need to create a separate login to manage your free JD Supra account, and we can make suggestions based on your needs and interests. We will not post anything on LinkedIn in your name. Or, sign up using your email address.
×