On December 1, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) issued a Bulletin entitled ”Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates“ that addresses the responsibilities of HIPAA covered entities and business associates (“regulated entities”) when using online tracking technologies. Regulated entities need
Electronic Health Records
Dental Care Alliance Settles Cyberattack Lawsuit for $3 Million
Dental Care Alliance, LLC (DCA) agreed to settle a class action lawsuit that arose out of a 2020 cyberattack. A hearing to approve the $3 million settlement was held on September 1.
DCA, based in Sarasota, Fla., is a dental services organization that provides practice support to over 390 affiliated dental practices across the U.S.…
Conducting HIPAA Breach Assessments and Disclosures: Requirements and Tips for Success
In the next installment of Rivkin Radler’s Healthcare Compliance Lunch & Learn series, Ashley Algazi will discuss requirements and tips for success in conducting HIPAA breach assessments and making required disclosures. The program will:
• Review HIPAA breach definition
• Discuss the analysis and investigation process to determine whether a breach has occurred
• Review…
University Health Center Pays $875,000 in HIPAA Fines after Cyber Hack
Oklahoma State University’s Center for Health Services recently paid $875,000 to settle potential HIPAA violations after a cyberattack resulted in the unauthorized access of its patients’ protected health information. A hacker installed malware on the Center’s web server which contained electronic protected health information. More than 275,000 individuals were affected by the breach, which resulted…
FTC Appears Ready to Begin Enforcing Its Health Breach Notification Rule
Rivkin Radler’s Shari Claire Lewis wrote an article, “FTC Appears Ready to Begin Enforcing Its Health Breach Notification Rule,” that was published in the New York Law Journal on April 18. The article discusses the Federal Trade Commission’s rule that requires manufacturers of connected medical devices, fitness trackers and other wearables, and health…
HHS Issues Guidance Clarifying Obligations of HIPAA Covered Entities
On March 22, the U.S. Department of Health and Human Services (HHS) issued guidance clarifying the obligations of covered entities to require their business associates to comply with HIPAA Administrative Simplification requirements related to standards for electronic health care transactions, code sets, unique identifiers, and operating rules.
While these requirements apply only to covered entities,…
OCR Announces Four HIPAA Enforcement Actions
On March 28, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced four new enforcement actions against healthcare providers for HIPAA violations. Two of the actions were part of OCR’s HIPAA Right of Access Initiative which has been ongoing since 2019.
Three of the actions were against dental…
HHS Report Warns of EMR and EHR Security Risks
The U.S. Department of Health and Human Services’ Health Sector Cybersecurity Coordination Center (HC3) recently issued a report entitled “Electronic Medical Records in Healthcare” that discussed security risks applicable to electronic medical records (EMRs) and electronic health records (EHRs). EHRs and EMRs are prime targets for cyber attackers because protected health information (PHI)…
HIPAA Changes Coming in 2022 Might Require Policy Revisions
An article in the December issue of HIPAA Regulatory Alert, “HIPAA Changes Coming in 2022 Might Require Policy Revisions,” discussed how proposed changes to HIPAA and the HITECH Act may affect covered entities and business associates. Rivkin Radler’s Eric Fader was quoted in the article.
Eric pointed out that the proposed changes…
Recent Developments in Telehealth: For the Pandemic and Beyond
On Thursday, November 18, in the next installment of Rivkin Radler’s Healthcare Compliance Lunch & Learn series, Rivkin Radler Partner Eric D. Fader will present an overview of changes in the provision of telehealth services, and federal and state regulation of them, since the beginning of the COVID-19 pandemic. New rules and waivers that are…