The ECRI Institute recently published an excellent summary of key issues for hospitals concerning social media (registration required), a valuable read for any hospital administrator, risk manager or human resources director. ECRI reports that approximately 4,000 U.S. hospitals own social media sites and that number is sure to grow significantly. One of the reasons for this growth will likely be due in significant
Joseph J. Lazzarotti
Joseph J. Lazzarotti is a principal in the Tampa, Florida, office of Jackson Lewis P.C. He founded and currently co-leads the firm's Privacy, Data and Cybersecurity practice group, edits the firm’s Privacy Blog, and is a Certified Information Privacy Professional (CIPP) with the International Association of Privacy Professionals. Trained as an employee benefits lawyer, focused on compliance, Joe also is a member of the firm’s Employee Benefits practice group.
In short, his practice focuses on the matrix of laws governing the privacy, security, and management of data, as well as the impact and regulation of social media. He also counsels companies on compliance, fiduciary, taxation, and administrative matters with respect to employee benefit plans.
School Kids’ Data at Risk
Note to parents and school districts – data thieves are targeting cash-strapped school distrists to steal unprotected personal information of students who happen to have pristine credit histories.
Continue Reading School Kids’ Data at Risk
Wall Street Journal Article Is Reminder to Employers Concerning NLRB Focus On Social Media
A Wall Street Journal article on December 2 discusses the National Labor Relations Board’s emergence into social media and non-union workplaces. For employers that have not looked at their policies and practices concerning employee activity in social media, this article serves as a good reminder.
Record Retention and Notice Requirements Go Into Effect for New Jersey Employers
New Jersey notice and records maintenance requirements concerning records that must be maintained by employers under the wage and hour laws, prevailing wage act, unemployment law, temporary disability benefits law, family leave insurance benefits law, workers compensation law, and gross income tax law.
Continue Reading Record Retention and Notice Requirements Go Into Effect for New Jersey Employers
Automating HIPAA Compliance Tracking and Audit Preparation
HIPAA covered entities and business associates need to consider how to practically and efficiently track and illustrate compliance should they find an OCR investigator knocking at the door.
Continue Reading Automating HIPAA Compliance Tracking and Audit Preparation
OCR Announces HIPAA Audit Program
Today, the Office for Civil Rights formally announced its HIPAA audit plan, with audits commencing in November 2011. A new page on OCR’s website answers some helpful questions for covered entities and business associates, which are summarized in this report.
Continue Reading OCR Announces HIPAA Audit Program
Provide Feedback to Government on Exchanging Health Information on Mobile Communications Devices
If you have an interest in the role the growing use of mobile communications devices (smartphones, iPads, iPhones, etc.) will play in how personal health information is exchanged in the health care industry, the Office of the National Coordinator for Health Information Technology (ONC) is seeking your input. According to a notice published Nov. 1, 2011 (76 Fed. Reg. 67455), comments are due Dec. 31.
Continue Reading Provide Feedback to Government on Exchanging Health Information on Mobile Communications Devices
Unauthorized Employee Recommendations, References on Social Media May Put Employers at Risk
Employers are beginning to realize that their employees are sending or receiving recommendations on social media sites that are inconsistent with the employer’s policies, or worse, are false or fraudulent. They need to do something about it.
Continue Reading Unauthorized Employee Recommendations, References on Social Media May Put Employers at Risk
SEC Guidance Related to Reporting Cyber Risks and Incidents
SEC issues guidance clarifying reporting obligations for public companies relating to cybersecurity and cyber incidents.
Continue Reading SEC Guidance Related to Reporting Cyber Risks and Incidents
Federal Contractors Required to Conduct Privacy Training Under Proposed Regulations
A proposed regulation would require federal contractors to conduct privacy training on at least 7 key areas before being given access to government records or handling personally identifiable information. Failing to provide the training potentially would put a halt to the contractor’s government work.
Continue Reading Federal Contractors Required to Conduct Privacy Training Under Proposed Regulations