On July 1, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced that Heritage Valley Health System, a provider in Pennsylvania, Ohio and West Virginia, agreed to pay $950,000 to resolve potential violations of the HIPAA Security Rule. Heritage Valley’s alleged violations included failure to conduct a risk analysis to
HIPAA
Conducting HIPAA Breach Assessments and Disclosures: Requirements and Tips for Success
On Thursday, June 13, in the next installment of Rivkin Radler’s Healthcare Compliance Lunch & Learn series, Rivkin Radler partner Ashley Algazi will present ”Conducting HIPAA Breach Assessments and Disclosures: Requirements and Tips for Success.” The program will take place from 12:00 noon to 1:00 PM Eastern time via Zoom.
Some of the topics covered…
NY Joins List of States Prohibiting Geofencing Near Healthcare Facilities
Rivkin Radler’s Frank Izzo and Jeff Ehrhardt authored an article in the Spring 2024 issue of USLAW magazine, “New York Joins List of States Prohibiting Geofencing Near Healthcare Facilities.” The article discussed geofencing laws, enacted partly in response to the Supreme Court Dobbs decision, in depth by state.
Sign up to receive Rivkin Rounds at
Montefiore Medical Center Settles HIPAA Breach for $4.75 Million
On February 6, the U.S. Department of Health and Human Services (HHS) announced a $4.75 million settlement with Montefiore Medical Center (MMC) for a breach of unsecured electronic protected health information (ePHI). The settlement stems from an internal investigation that found that an employee of the New York hospital system sold patient information to an…
OCR Releases Resource Documents on Telehealth Risks
The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) recently released two resource documents to help healthcare providers explain the privacy and security risks of telehealth to their patients.
The first document, entitled “Educating Patients about Privacy and Security Risks to Protected Health Information when Using Remote Communication Technologies…
FTC Issues Guidance on HIPAA, FTC Act, and Health Breaches
The Federal Trade Commission (FTC) recently issued guidance entitled “Collecting, Using, or Sharing Consumer Health Information? Look to HIPAA, the FTC Act, and the Health Breach Notification Rule.” The guidance points out that while businesses that collect, use, or share consumer health information are (or should be) accustomed to complying with HIPAA and its Privacy…
NJ Psychiatric Practice Fined for HIPAA Privacy Rule Violation
The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) recently announced that Manasa Health Center in Kendall Park, New Jersey entered into a Resolution Agreement and Corrective Action Plan to resolve a HIPAA Privacy Rule violation. The psychiatric practice, owned by Dr. Nidagalle Gowda, inexplicably disclosed four patients’ protected health information…
PA Therapist Fined for HIPAA Right of Access Violation
The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced on May 8 that David Mente, a Pittsburgh psychotherapist, has paid $15,000 to settle a violation of the HIPAA Privacy Rule. OCR has been pursuing its so-called Right of Access Initiative since 2019, as previously discussed here.
Incredibly, some healthcare…
PHE HIPAA Enforcement Discretion to Expire, Restoring Compliance Obligations
The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced on April 11 that the Notifications of Enforcement Discretion issued under HIPAA and the HITECH Act during the federal COVID-19 public health emergency (PHE) will expire when the PHE ends on May 11.
The four Notifications of Enforcement Discretion that will…
Arizona Hospital Pays $1.25 Million in HIPAA Settlement After Cyber Attack
The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) announced on February 2 that Banner Health, a not-for-profit hospital system based in Arizona, has paid $1.25 million in order to settle alleged HIPAA violations in connection with a cyber attack.
The incident occurred in 2016 when a hacker gained access to…
