Over the past few years, and particularly during the COVID-19 pandemic, the Department of Health and Human Services Office for Civil Rights in Action (OCR) has made countless efforts to enhance its Health Insurance Portability and Accountability Act (HIPAA) guidance and other related resources on its website. Last week, the OCR launched a new feature
Office of Civil Rights
Prepare For Increased HIPAA Fines
Since mid-2013, the Department of Health and Human Services has recovered more than $10 million from numerous entities in connection with alleged violations of the Health Insurance Portability and Accountability Act (“HIPAA”). However, during a recent American Bar Association conference, Jerome B. Meites, a chief regional civil rights counsel at the Department of Health and…
HHS to Conduct Survey About Which HIPAA Covered Entities and Business Associates Should Be Audited
The Department of Health and Human Services announced on February 24 that it is seeking information about conducting a pre-audit survey. That is, it plans to conduct a “survey of up to 1200 [HIPAA] covered entities (health plans, health care clearinghouses, and certain health care providers) and business associates (entities that provider certain services to…
OCR Issues Protocol For HIPAA Privacy, Security and Breach Notification Audit Program
As we previously discussed, the Office of Civil Rights (“OCR”) continues to push forward with the HIPAA audits required by the HITECH Act. To this end, the OCR recently posted the protocol which is used to conduct the HIPAA audits on its website.
The HITECH Act requires HHS to provide for periodic audits to…
New Director of Office of Civil Rights Speaks About HIPAA Enforcement
New director of the Department of Health and Human Services’ Office for Civil Rights, Leon Rodriguez, says, “enforcement promotes compliance.”…
Continue Reading New Director of Office of Civil Rights Speaks About HIPAA Enforcement
HHS Announces Proposed Changes to HIPAA Privacy Rule
The U.S. Department of Health and Human Services’ (HHS) announced proposed changes to the HIPAA Privacy Rule to implement new requirements concerning individuals’ rights to access reports and accountings of disclosures of their protected health information. The announcement seeks comments from the public as the agency hopes to craft the law so as to provide the greatest transparency for individuals with respect to access to and disclosures of their PHI, while minimizing the burden on covered entities and business associates.
Continue Reading HHS Announces Proposed Changes to HIPAA Privacy Rule
Inter-agency Cooperation Nabs HIPAA Violator for HHS
Any illusion an organization may hold that it is operating “under the radar” of regulators should be shattered in the current compliance environment. Governmental agencies are increasingly able to efficiently coordinate with one another in matters of enforcement, and this post is a good example of that.
Continue Reading Inter-agency Cooperation Nabs HIPAA Violator for HHS
HHS Posts On Its Website Covered Entities Reporting HIPAA Data Breaches
On February 22, 2010, the Office of Civil Rights (OCR) posted on its website its first list of covered entities that have reported breaches of unsecured protected health information affecting more than 500 individuals. OCR acknowledged the HITECH Act requires HHS to make this information public by posting it on an HHS website.
The breach notification rule became effective on…