While years of lax enforcement may have lulled many HIPAA covered entities and business associates to not take HIPAA seriously, recent activities by HHS, including the recently announced nationwide enforcement training program for State Attorneys General should spur renewed efforts toward compliance.
Continue Reading HHS to Help Train State Attorneys General to Enforce HIPAA
Joseph J. Lazzarotti
Joseph J. Lazzarotti is a principal in the Tampa, Florida, office of Jackson Lewis P.C. He founded and currently co-leads the firm's Privacy, Data and Cybersecurity practice group, edits the firm’s Privacy Blog, and is a Certified Information Privacy Professional (CIPP) with the International Association of Privacy Professionals. Trained as an employee benefits lawyer, focused on compliance, Joe also is a member of the firm’s Employee Benefits practice group.
In short, his practice focuses on the matrix of laws governing the privacy, security, and management of data, as well as the impact and regulation of social media. He also counsels companies on compliance, fiduciary, taxation, and administrative matters with respect to employee benefit plans.
Florida, Michigan, and Montana Follow National Trend and Consider Banning the Use of Applicant Credit History Background Checks in Hiring Decisions
In the face of increasing unemployment, in March 2011, Florida, Michigan, and Montana joined the ranks of approximately fifteen other states that are considering bills limiting employers’ ability to use credit checks for employment purposes.
Florida. Florida’s Senate Bill 1562, introduced on March 3, would prohibit employers from using an applicant’s personal credit history…
Jumping on the e-Application, Electronic On-Boarding Bandwagon?
In an effort to go “green” or “paperless,” employers have been rapidly moving to electronic employment application and on-boarding systems. These systems can be significantly beneficial, but care should be taken when making the switch. This post provides some key questions/considerations for employers.
Continue Reading Jumping on the e-Application, Electronic On-Boarding Bandwagon?
HHS’ First Civil Penalty Under HIPAA is $4.3 Million
The U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) has imposed its first civil monetary penalty since the Privacy Rule of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) became effective in April 2003. HHS issued a Notice of Final Determination finding that Cignet Health of Prince George’s County…
Deleting E-mails Can Constitute a “Damage” Under the Computer Fraud and Abuse Act
What is a company’s recourse when a former employee deletes e-mails and other company electronic information before he leaves? A case from Indiana provides a lesson.
When Meridian Financial Advisors began serving as Receiver for bankrupted OCMC, Inc., it took possession of a number of OCMC computers, including one belonging to Joseph A. Pence, OCMC’s President…
FTC Issues Guidance Addressing Medical Identity Theft
Last month, the Federal Trade Commission’s Bureau of Consumer Protection posted FAQs on its website to guide health care providers and health plans when their patients and subscribers are affected by medical identity theft.
When most people hear about an identity theft or a data breach, they typically think about credit card data or Social Security…
Employers Beware: Aggrieved Employee Commits Data Breach Affecting 2400 Individuals
As employees become more savvy with electronic communications and employers face increasing challenges with controlling vast amounts of data, the circumstances in this recent San Francisco Examiner story are likely being repeated all over the country – employee takes company information to support her wrongful termination case.
Continue Reading Employers Beware: Aggrieved Employee Commits Data Breach Affecting 2400 Individuals
The Army Embraces Social Media
Our adversaries are trolling social networks, blogs and forums, trying to find sensitive information they can use about our military goals and objectives. Therefore, it is imperative that all Soldiers and Family members understand the importance of practicing good operations security measures.
-Sgt. Maj. of the Army Kenneth O. Preston
The above quote is contained…
Data Breach Insurance Growing In Popularity for Health Care Providers, Others
The demand for "data breach" insurance appears to be growing based on our experiences, as well as commentary such as a recent article by Pamela Lewis Dolan of American Medical News.
As we’ve reported, data breach coverage is something quite different than traditional "cyber-risk" coverage which tends to address "hazards such as unauthorized Web site access, online…
Congress Has The Sense It Should Enact A Comprehensive Data Security Law
“sense of Congress” S.21…
Continue Reading Congress Has The Sense It Should Enact A Comprehensive Data Security Law