Completing Your Annual HIPAA Risk Assessment Before the Deadline

You must complete a HIPAA risk assessment each year, and now is the time to do so. Conducting an annual HIPAA risk assessment is an important part of compliance, as well being integral to protecting your business against breaches. This is because risk assessments reveal vulnerabilities, threats, and risks to protected health information (PHI) thus uncovering deficiencies in your current security practices. [...]

2022-05-06T17:03:50-04:00November 19th, 2021|

Why You Need Dental IT Support

Dental office administrative staff are often overburdened with a multitude of tasks, especially as of late with staffing shortages across the country. These staff members are often required to wear many hats and are therefore more likely to fall victim to burnout. With their focus divided across several tasks, it is difficult to fully address the security needs of the modern dental practice. This is where dental IT [...]

2022-05-06T14:38:09-04:00September 1st, 2021|

NIST Seeks Public Comment on Cybersecurity Resource Guide

In 2008, the National Institute of Standards and Technology (NIST) organization published guidance as to how covered entities and business associates were expected to implement HIPAA Security Rule requirements. At the end of April of 2021, the NIST organization announced that it is planning to update this cybersecurity guide. The NIST organization is seeking public comment as to what should be included in the new cybersecurity guide. The [...]

2022-05-06T14:38:11-04:00May 20th, 2021|

5 Tips on How to Complete a Risk Assessment

Are you worried about completing your HIPAA risk assessment? Many organizations are. To provide you with guidance, 5 tips on how to complete a risk assessment are discussed. Educate yourself on the HIPAA Security Rule Identify risks and vulnerabilities Create and implement remediation plans Use a risk assessment tool Repeat annually How to Complete a Risk Assessment Completing your [...]

2022-05-06T13:36:52-04:00April 15th, 2021|

OCR 2020 and HIPAA Security Rule Violations

In 2020, the Department of Health and Human Services’ (HHS) Office for Civil Rights issued a record 19 fines for failure to comply with the HIPAA regulations. Six of the fines announced in 2020 were principally issued for failure to comply with the HIPAA Security Rule’s requirement to conduct a security risk assessment and to track and inventory network devices. The message of OCR 2020: Keep patient records [...]

2022-05-06T14:44:10-04:00January 19th, 2021|

$5.1 Million Fine Announced for HIPAA Data Breach

The Department of Health and Human Services (HHS) Office for Civil Rights has entered into a settlement with the Excellus Health Plan, under which Excellus has agreed to pay $5.1 million and to enter into a corrective action plan. The settlement was prompted by an OCR investigation that found widespread noncompliance with provisions of the HIPAA Privacy and Security Rules. As a result of the noncompliance, the data [...]

2022-05-06T14:44:10-04:00January 15th, 2021|

September OCR Fines Reach $10.7 Million

The OCR seems to be on a fines spree, with a record number of fines issued in September. There were eight September OCR fines issued, amounting to $10,736,500. More details on September OCR fines are discussed below. September OCR Fines: Violating HIPAA Right of Access The HIPAA Right of Access gives patients the right to request copies of their medical records from their healthcare provider. Requested records must [...]

2020-11-16T09:02:38-05:00October 1st, 2020|

Healthcare Hack Leads to $2.3 Million OCR Settlement

In April of 2014, CHSPSC’s information system was hacked. The healthcare hack ended up affecting 6.1 million individuals, exposing their protected health information. As a result, CHSPSC has agreed to settle numerous HIPAA Security Rule violations with OCR. More details are discussed below. CHSPSC, LLC (“CHSPSC”) provides business associate services, including IT and health information management, to hospitals and physician clinics affiliated [...]

2022-05-06T13:55:34-04:00September 24th, 2020|

What are HIPAA Policies and Procedures Templates?

HIPAA Policies and Procedures Templates are form documents that relate to a particular area of HIPAA compliance. HIPAA Policies and Procedures templates provide information on what an organization must do to be compliant in that area. As an example, HIPAA Policies and Procedures Templates include a Policy and Procedure Template for Breach Notification. The template contains general language about how to detect and report a breach.  [...]

2021-04-01T10:44:49-04:00June 3rd, 2020|

What are HIPAA Experts?

HIPAA experts include individuals who provide expert consulting services to healthcare providers. One common form of consulting services is expert witness testimony. HIPAA experts can serve as expert witnesses in court cases where the issues consist of whether a party did or did not comply with HIPAA law and regulations. Why are HIPAA Experts Needed? HIPAA itself does not contain a “private right of action.” This means that an [...]

2021-08-02T17:02:39-04:00June 2nd, 2020|