News & Analysis as of

Health Care Providers Corrective Action Plans (CAPs)

Health Care Compliance Association (HCCA)

Seven Years After Worldwide NotPetya Attacks, OCR Singles Out PA System, Collects Nearly $1M

Unleashed on June 27, 2017, NotPetya caused an estimated $10 billion in damages globally, among the costliest ransomware attacks in history. In 2018, the Trump administration—in tandem with the British government—blamed...more

Saul Ewing LLP

HIPAA Security Rule Settlement Results in $950,000 Payment by a Mid-Atlantic Health System

Saul Ewing LLP on

On July 1, 2024, the U.S. Department of Health and Human Services (“HHS”) Office For Civil Rights (“OCR”) announced a $950,000 settlement with Heritage Valley Health System (“Heritage Valley”) and a three-year Corrective...more

Society of Corporate Compliance and Ethics...

[Event] Higher Education & Healthcare Research Compliance Conference - June 10th - 12th, New Orleans, LA

Don’t miss our annual conference devoted to higher education and research compliance - Attend the Higher Education & Healthcare Research Compliance Conference June 10–12, 2024 and hear from experienced professionals on a...more

Saul Ewing LLP

HHS OCR Issues Its Most Recent HIPAA Annual Report and a Second Ransomware Settlement

Saul Ewing LLP on

On February 14, 2024, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) issued two reports to Congress as required by the Health Information Technology for Economic and Clinical Health...more

Health Care Compliance Association (HCCA)

OCR Ends Year With Settlements That Tread Old Ground, Says New Rules Are Coming—Someday

If the penultimate enforcement settlement of 2023 issued by the HHS Office for Civil Rights (OCR) sounds familiar, that’s with good reason. And the last one of the year should ring some bells, too....more

Hall Benefits Law

HHS Issues First Settlement for HIPAA Violations Related to a Ransomware Attack

Hall Benefits Law on

In late October, the U.S. Department of Health and Human Services (HHS) reached a settlement agreement with a medical management company based in Massachusetts over alleged HIPAA violations. Under the settlement terms, the...more

Dorsey & Whitney LLP

HIPAA on the Horizon in the New Year: Important Lessons from an Active 2023 and Regulatory Initiatives to Watch for in 2024

Dorsey & Whitney LLP on

2023 marked 20 years since the first compliance deadline under the Health Insurance Portability and Accountability Act’s (“HIPAA”) privacy rule. Despite the two decades of experience with HIPAA, compliance continues to remain...more

Saul Ewing LLP

News Article Results in $80,000 HIPAA Settlement by New York State Hospital

Saul Ewing LLP on

On November 20, 2023, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) announced an $80,000 HIPAA settlement with Saint Joseph’s Medical Center (“SJMC”) in New York State. The...more

Health Care Compliance Association (HCCA)

Dramatic Portrayal of Care During Early COVID-19 Costs Hospital $80K; OCR: No Prior Authorization

Report on Patient Privacy 23, no. 12 (December, 2023) Spring 2020 was a terrifying period in the annals of COVID-19, and New York was at the epicenter. COVID-19 cases, and deaths, already the highest in the nation, were...more

Health Care Compliance Association (HCCA)

BA Depicted by OCR as Example of Ransomware Dangers Recovered Quickly, Didn’t Expect Fine

Report on Patient Privacy 23, no. 11 (November, 2023) Tim DiBona clearly remembers Christmas Eve 2018 when the staff of his small firm—Doctors’ Management Service (DMS)—arrived at their West Bridgewater, Mass., office to...more

Fox Rothschild LLP

L.A. Care to Pay $1.3 Million Settlement Over HIPAA Violations: What You Need to Know

Fox Rothschild LLP on

A recent settlement entered into by the nation’s largest publicly operated health plan serves as a stark warning to all entities and business associates subject to the Health Insurance Portability and Accountability Act:...more

Arnall Golden Gregory LLP

A Midsummer’s Review – Cybersecurity Is the Word: HIPAA Enforcement and Guidance Trends

Summer is in full swing, but the U.S. Department of Health and Human Services Office for Civil Rights (“OCR”) is doing anything but taking a vacation from HIPAA. In May and June, OCR issued five resolution agreements...more

WilmerHale

HHS OCR Settles with iHealth Solutions Over Alleged HIPAA Violations

WilmerHale on

On June 28, the US Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a settlement (resolution agreement and corrective action plan) with iHealth Solutions (also known as Advantum Health)...more

Sheppard Mullin Richter & Hampton LLP

CMS Releases Updates to Hospital Pricing Transparency Rule

On April 26, 2023, the Centers for Medicare and Medicaid Services (“CMS”) released a fact sheet on Hospital Price Transparency Enforcement Updates (the “Fact Sheet”) under the Hospital Price Transparency Rule (the “Rule”)....more

Jackson Lewis P.C.

NJ Mental Health Provider’s Response to Negative Online Reviews Costs Practice $30,000 in OCR Penalty

Jackson Lewis P.C. on

Unhappy consumers, including patients, are free to express dissatisfaction with services they receive from providers on popular social media or online review platforms, such as Yelp and Google. At least in the healthcare...more

WilmerHale

HHS OCR Brings Enforcement Against Banner Health for HIPAA Security Rule Violations

WilmerHale on

On February 2, 2023, the US Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) reached a settlement with Banner Health Affiliated Covered Entities (“Banner Health”) for a 2016 data breach that...more

Mintz - Health Care Viewpoints

OCR Warns Providers Against Disclosing PHI on Social Media Platforms in Response to Negative Reviews in Settlement with Dental...

As illustrated by a recent Office for Civil Rights (OCR) settlement with a dental practice, health care entities continue to struggle with how to respond to negative online reviews while maintaining compliance with the HIPAA...more

Health Care Compliance Association (HCCA)

OCR Announces Trio of Access Cases; Already Stung, One Dental Chain Eliminates All Fees

Report on Patient Privacy 22, no. 10 (October, 2022) - How about free? Patients daily face the machinations of getting records from their providers, and health care practices, hospitals and even dentists struggle with...more

BakerHostetler

What’s Old Is New Again: OCR Announces $300,000 Settlement Related to Improper Disposal of Physical PHI

BakerHostetler on

​​​​​​​After a long stretch of breach enforcement actions and settlements arising out of alleged technology gaps, the U.S. Department of Health & Human Services Office for Civil Rights (OCR) announced that it settled a case...more

Health Care Compliance Association (HCCA)

One Security Guard, One Container: Find Unravels Derm Practice's Disposal Failure

Report on Patient Privacy 22, no. 9 (September, 2022) - When recommending best practices, federal privacy and security officials stress that organizations need to follow their protected health information (PHI) wherever...more

Rivkin Radler LLP

Dermatology Practice Settles Alleged HIPAA Violations

Rivkin Radler LLP on

On August 23, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced that Massachusetts-based New England Dermatology, P.C., d/b/a New England Dermatology and Laser Center (NEDLC), agreed to...more

BakerHostetler

OCR Announces Four Enforcement Actions

BakerHostetler on

On March 28, 2022, Health and Human Services, Office for Civil Rights (OCR) announced the resolution of four enforcement actions, three resolved in 2021 and one resolved in 2022. There are some interesting aspects of this...more

Health Care Compliance Association (HCCA)

Report on Medicare Compliance Volume 30, Number 28. News Briefs: August 2021

Report on Medicare Compliance 30, no. 28 (August 2, 2021) - CMS has not fined any hospitals yet for noncompliance with price transparency requirements, a spokesperson tells RMC. “In April 2021, CMS began issuing warning...more

Oberheiden P.C.

Seven Points to be Aware of for Durable Medical Equipment Company Compliance

Oberheiden P.C. on

Durable medical equipment (DME) is particularly important for many Medicare beneficiaries. However, companies that manufacture and sell DME need to be careful because there are strict federal regulations outlining almost...more

Rivkin Radler LLP

OCR’s HIPAA Right Of Access Initiative Continues

Rivkin Radler LLP on

The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) has pursued its HIPAA Right of Access Initiative since 2019. OCR’s 19th settlement under the initiative, with The Diabetes, Endocrinology &...more

44 Results
 / 
View per page
Page: of 2

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide