Healthcare providers running on thin margins or just seeking new (and in the case of tax-exempt providers, permissible) revenue sources may jump at the chance when third party vendors offer to help them monetize their patient...more
7/22/2024
/ Business Associates ,
Data Privacy ,
Data Security ,
Data Selling ,
De-Identification ,
De-Identified Protected Health Information ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Monetization ,
Penalties ,
PHI ,
Privacy Laws ,
Statutory Violations
A recent federal court decision is a victory for Health Insurance Portability and Accountability Act (HIPAA) covered entities using third-party tracking tools on unauthenticated webpages. These are websites available to the...more
6/26/2024
/ American Hospital Association et al v Becerra Secretary Of Health And Human Services et al ,
Business Associates ,
Covered Entities ,
Federal Trade Commission (FTC) ,
Final Judgment ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Privacy Rule ,
IP Addresses ,
Judicial Review ,
OCR ,
PHI ,
Regulatory Authority ,
Warning Letters ,
Web Tracking ,
Websites
After months of uncertainty and multiple letters from industry associations advocating on behalf of the healthcare industry with the U.S. Department of Health and Human Service (HHS) Office for Civil Rights (OCR), covered...more
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has, as part of its mandate, the responsibility to enforce the Health Insurance Portability and Accountability Act (HIPAA) Security Rule....more
5/14/2024
/ Audits ,
Business Associates ,
Compliance ,
Covered Entities ,
Data Privacy ,
Data Security ,
Department of Health and Human Services (HHS) ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Security Rule ,
HITECH Act ,
OCR ,
PHI ,
Popular ,
Ransomware ,
Risk Assessment ,
Web Tracking
In the midst of an industry reeling from the Change Healthcare cybersecurity incident, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has issued a series of final rules requiring...more
"Informed consent" has been described as "a bedrock principle of healthcare in a free society," and if a "patient is denied the ability to exercise or even consider informed consent, the patient's personal liberty suffers."1...more
The U.S. Department of Health and Human Services Office for Civil Rights (OCR) issued updated guidance on March 18, 2024 regarding the use of online tracking technologies by entities and business associates covered by the...more
3/19/2024
/ Business Associates ,
Covered Entities ,
Department of Health and Human Services (HHS) ,
Enforcement ,
Enforcement Priorities ,
Guidance Update ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HIPAA Privacy Rule ,
OCR ,
PHI ,
Tracking Systems ,
Web Tracking ,
Websites
Healthcare compliance risks exist even when a company takes steps to structure its business activities to follow the government's own statements. A recent decision by the U.S. District Court for the Eastern District of...more
The U.S. Department of Health and Human Services (HHS) and the Centers for Medicare & Medicaid Services (CMS) have started a new effort to educate the public about the Emergency Medical Treatment and Labor Act (EMTALA)....more
Hospitals care about patient privacy, but they also have to connect with the public. In the real world, people mostly connect online. Having a fully functional online presence often requires help from third parties. ...more
11/8/2023
/ American Hospital Association ,
Business Associates ,
Class Action ,
Covered Entities ,
Department of Health and Human Services (HHS) ,
Federal Trade Commission (FTC) ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Hospitals ,
OCR ,
PHI ,
Third-Party Service Provider ,
Tracking Systems ,
Web Tracking
In this episode of our “Florida Capital Conversations” podcast series, healthcare attorneys Mia McKown, Eddie Williams and Shannon Hartsfield discuss how privacy violations can put a healthcare practitioner's license at risk....more
In this episode of our “Florida Capital Conversations” podcast series, healthcare attorney Eddie Williams joins to discuss the dissemination of electronic health information and provisions regarding information blocking. He...more
In this episode of "Counsel That Cares," HIPAA and healthcare privacy attorneys Beth Pitman and Shannon Hartsfield dissect the highly publicized Dinerstein v. Google case. They address the implications and concerns of sharing...more
Providing care via electronic communication when patients and providers are in separate locations, known as telemedicine or telehealth, has been possible for decades. The exigent circumstances sparked by the COVID-19 pandemic...more
New Florida legislation, Senate Bill 768 (2023), amending the Patient Self-Referral Act of 1992 (the Act), also known as the Florida "mini-Stark law," has been signed by Gov. Ron DeSantis and is set to take effect on July 1,...more
The Federal Trade Commission (FTC) is on a roll in its efforts to signal to the digital health industry that data privacy must be a priority. The FTC announced a consent decree with BetterHelp on March 2, 2023, to settle...more
3/7/2023
/ Advertising ,
Consent Decrees ,
Consumer Privacy Rights ,
Cookies ,
Digital Health ,
Enforcement Actions ,
Federal Trade Commission (FTC) ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Marketing ,
Mental Health ,
Telehealth ,
Unfair or Deceptive Trade Practices
The COVID-19 public health emergency (PHE) is set to expire on May 11, 2023, and there seems to be a scramble to extend some of the pandemic-related flexibilities involving telehealth. On March 1, 2023, the Drug Enforcement...more
For the first time ever, the Federal Trade Commission (FTC) is seeking enforcement under the Health Breach Notification Rule. This regulation requires certain businesses not covered by the Health Insurance Portability and...more
2/3/2023
/ Breach Notification Rule ,
Consent ,
Corporate Counsel ,
Data Breach ,
Data-Sharing ,
Electronic Protected Health Information (ePHI) ,
Enforcement ,
Enforcement Actions ,
Federal Trade Commission (FTC) ,
Food and Drug Administration (FDA) ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Health Technology ,
HIPAA Breach ,
HIPAA Breach Notification Rule ,
Mobile Apps
For years, patients and healthcare companies have been wrestling with privacy issues relating to cookies, pixels and other tracking technologies. The U.S. Department of Health and Human Services' (HHS) Office of Civil Rights...more
12/5/2022
/ Data Breach ,
Data Privacy ,
Department of Health and Human Services (HHS) ,
Electronic Protected Health Information (ePHI) ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
New Guidance ,
OCR ,
Personally Identifiable Information ,
PHI ,
Popular ,
Tracking Systems ,
Web Tracking
Patient assistance programs (PAPs) that seek to subsidize patient co-payments for drugs covered by Medicare may involve compliance challenges. A recent U.S. Department of Health and Human Services (HHS) Office of Inspector...more
11/3/2022
/ Advisory Opinions ,
Anti-Kickback Statute ,
Cost-Sharing ,
Fraud and Abuse ,
Generic Drugs ,
Health Care Providers ,
Medicare ,
Medicare Part D ,
OIG ,
Out-of-Pocket Expenses ,
Patient Assistance Programs ,
Pharmaceutical Industry ,
Prescription Drugs ,
Subsidies
Telehealth has been around for decades, but restrictive reimbursement rules kept it out of widespread use for many treatment needs. Then along came the COVID-19 pandemic and everything changed rapidly. Suddenly, due to the...more
10/5/2022
/ Compliance ,
Coronavirus/COVID-19 ,
Data Privacy ,
Department of Health and Human Services (HHS) ,
GAO ,
Health Care Providers ,
Health Insurance Portability and Accountability Act (HIPAA) ,
Information Reports ,
Medical Reimbursement ,
OCR ,
Patient Privacy Rights ,
Telehealth ,
Telemedicine
If a Health Insurance Portability and Accountability Act (HIPAA)-covered entity experiences a data breach involving fewer than 500 individuals, the incident must be reported to the U.S. Department of Health and Human Services...more
New federal regulations have been proposed that will affect licensure of wholesale drug distributors and third-party logistics providers (3PLs). The Drug Supply Chain Security Act became law in 2013. The U.S. Food and Drug...more
Kathryn Isted In Harbor Healthcare System, L.P. v. United States, 5 F.4th 593 (5th Cir. 2021), the court of appeals ruled that the district court abused its discretion in refusing to exercise its equitable jurisdiction over a...more
10/18/2021
/ Abuse of Discretion ,
Anti-Kickback Statute ,
Appeals ,
Attorney-Client Privilege ,
Comment Period ,
Criminal Investigations ,
Discovery ,
Draft Guidance ,
Evidence ,
Failure To State A Claim ,
False Claims Act (FCA) ,
Food and Drug Administration (FDA) ,
Health Care Providers ,
Healthcare Facilities ,
Hospitals ,
Kickbacks ,
Managed Care Contracts ,
Medicaid ,
Medicare ,
Patient Referrals ,
Pharmaceutical Industry ,
Pharmacies ,
Prescription Drugs ,
Qui Tam ,
Scienter
The Federal Trade Commission (FTC) adopted a policy statement on Sept. 15, 2021, emphasizing that developers of digital health apps, connected devices and other health products have obligations under the Health Breach...more
9/27/2021
/ App Developers ,
Breach Notification Rule ,
Business Associates ,
Covered Entities ,
Federal Trade Commission (FTC) ,
Health Insurance Portability and Accountability Act (HIPAA) ,
HITECH Act ,
Mobile Apps ,
Mobile Health Apps ,
Notice Requirements ,
PHI