RyanCoyne

Ryan Coyne is a results-driven leader in the healthcare compliance industry, specializing in regulatory compliance, compliance training, and assisting healthcare organizations and business associates in achieving and maintaining compliance. With a deep knowledge of healthcare regulations and a keen understanding of the challenges faced by the industry, Ryan has developed a reputation as a trusted advisor and advocate for ethical and compliant practices in healthcare. Ryan has successfully advised and guided numerous healthcare organizations, business associates, and healthcare professionals on achieving and maintaining compliance with regulatory training requirements. Ryan's professional focus is using his in-depth expertise and leading a world class team of subject matter experts at ComplianceJunction in regulatory compliance to help organisations navigate the complex landscape of ensuring staff adhere to healthcare regulations. You can connect with Ryan via LinkedIn https://www.linkedin.com/in/ryancoyne/ and follow on Twitter https://twitter.com/ryancoyne

Potential Cyberattack on McLaren Health Care

Health system McLaren Health Care based in Grand Blanc, MI manages 13 hospitals in Michigan and several doctor offices, ambulatory surgery centers, and other patient care facilities in the state. It reported an investigation of an outage impacting its telephone and...

Phishing Attack on Nebraska Life Insurance Company

United of Omaha Life Insurance Company based in Nebraska has reported a phishing email that led to a protected health information (PHI) breach involving 107,894 individuals. The insurer discovered the breach on April 23, 2024 upon identification of anomalous activity...
23andMe to Settle Class Action Data Breach Lawsuit

23andMe to Settle Class Action Data Breach Lawsuit

23andMe based in San Francisco has proposed an agreement to resolve a class action lawsuit that was submitted because of a breach of consumer information in 2023. The breach happened in October 2023 and the attacker stole the data of around 6.9 million people, about...
Adventist Health Resolves HIPAA Violation

Adventist Health Resolves HIPAA Violation

California Attorney General Rob Bonta has reported reaching a settlement with Adventist Health Hanford concerning alleged violations of California’s Confidentiality of Medical Information Act (CMIA), the Health Insurance Portability and Accountability Act (HIPAA), the...
Cencora Cyberattack Affects Pharmaceutical Companies

Cencora Cyberattack Affects Pharmaceutical Companies

Cencora, Inc. (earlier known as AmerisourceBergen), and its Lash Group affiliate, were impacted by a cyberattack. Cencora reported the incident in a Securities and Exchange Commission (SEC) filing in February 2024. During that time, the scope of the data breach is not...
HITECH Act Explained

HITECH Act Explained

The HITECH Act (Health Information Technology for Economic and Clinical Health Act) was passed by Congress in 2009 as a part of the American Recovery and Reinvestment Act – an economic stimulus package intended to help the country recover from the Great Depression of...
UnitedHealth Group’s Financial Assistance Program and HIPAA Compliance Investigation of Change Healthcare

The Cost of Inaction in HIPAA Compliance

Inaction in HIPAA compliance can have several costs and consequences for healthcare organizations. Here are some of the key consequences: Data Breaches and Financial Costs A breach of patient data can lead to high financial costs. Expenses related to notifying...
What is Defined as PHI Under HIPAA?

What is Defined as PHI Under HIPAA?

Due to the complexity of the HIPAA Privacy Rule, it can sometimes be difficult to find an accurate answer to the question what is defined as PHI under HIPAA. This article explains not only what Protected Health Information (PHI) is, but why it is importantly to fully...
What are some Good PHI Examples?

What are some Good PHI Examples?

Good PHI examples include most aspects of a patient’s healthcare, including their comprehensive medical history, which encompasses past and current medical conditions, surgeries, allergies, and ongoing treatments, along with laboratory test results like blood...
Who Enforces HIPAA?

Who Enforces HIPAA?

Who enforces HIPAA depends on the section of HIPAA being enforced, the activities of the organization against which enforcement action is being taken, or whether an individual against whom enforcement action is being taken is a member of a covered entity’s or business...
Is HIPAA Training Required Annually?

Is HIPAA Training Required Annually?

Yes, HIPAA training is typically required annually for all staff members who have access to protected health information (PHI), and it is considered a best practice to conduct annual training sessions to ensure that employees stay up-to-date with the latest...
What is a Key to Success for HIPAA Compliance?

What is a Key to Success for HIPAA Compliance?

A key to success for HIPAA compliance is having a full HIPAA compliance program that includes comprehensive training. HIPAA training is an key element of HIPAA compliance because it ensures that all employees and relevant personnel understand the regulations, their...
What does HIPAA stand for?

What does HIPAA stand for?

HIPAA stands for the Health Insurance Portability and Accountability Act, a comprehensive federal law enacted in the United States in 1996, which is designed to safeguard the privacy and security of individuals’ protected health information (PHI) while also...
What is the Maximum Penalty for a HIPAA Violation?

What is the Maximum Penalty for a HIPAA Violation?

The maximum penalty for a HIPAA violation can range from $100 to $50,000 per violation, with a maximum annual penalty of $1.5 million for repeated violations of the same provision, and in cases involving willful neglect, the penalties can reach up to $1.5 million per...
What is a Key to Success for HIPAA Compliance?

What is HIPAA Certification?

The purpose of HIPAA certification for healthcare professionals is to demonstrate a level of competency and understanding of the Health Insurance Portability and Accountability Act (HIPAA). HIPAA certification can be beneficial because it establishes a standardized...
Employee Consequences of Violating HIPAA

Employee Consequences of Violating HIPAA

Employees who violate HIPAA may face severe consequences, including disciplinary actions, termination of employment, legal penalties, fines, and even imprisonment, as their actions can compromise the privacy and security of patient information and breach the trust...
HIPAA Training for Student Nurses

HIPAA Training for Student Nurses

HIPAA training for student nurses holds substantial importance in preparing these future healthcare professionals to effectively navigate the complex landscape of patient information privacy and security, offering them a comprehensive understanding of the legal and...
Who Can Sue for A HIPAA Violation?

Who Can Sue for A HIPAA Violation?

Who can sue for a HIPAA violation? Unlike the California Consumer Privacy Act (CCPA), there is no private cause of action in HIPAA, so that means a patient cannot sue for a HIPAA breach even if their protected health information has been impermissibly disclosed or...
What to do Following an Accidental HIPAA Violation

What to do Following an Accidental HIPAA Violation

The vast majority of entities covered by the Health Insurance Portability and Accountability Act (HIPAA) provide regular training to employees on their responsibilities under HIPAA, and employees are diligent and take care not to violate the HIPAA Rules or put patient...
HIPAA Certification Explained

HIPAA Certification Explained

Many suppliers would like HIPAA certification to confirm they are fully compliant with HIPAA Rules and are knowledgeable with all parts of the Health Insurance Portability and Accountability Act (HIPAA), but can HIPAA certification be achieved in order to confirm...
Can you ask for Proof of COVID-19 Vaccine Status?

Can you ask for Proof of COVID-19 Vaccine Status?

Due to the volume of federal, state, and international privacy regulations, it is understandable some businesses may be uncertain about whether you can ask for proof of COVID-19 vaccination status. The short answer to the question is yes. There are no federal, state,...
How to Comply with HIPAA Password Requirements

How to Comply with HIPAA Password Requirements

Although the text of HIPAA contains only one reference to passwords, there are several other areas of the Act in which it is inferred HIPAA password requirements exist. For example, under the Technical Safeguards of the Security Rule (45 CFR § 164.312), covered...
What are the GDPR Password Requirements?

What are the GDPR Password Requirements?

The new General Data Protection Regulation (GDPR) which comes into force in May 2018 does not outlaw the use of a simple username and static password system for accessing personal data, but GDPR does state that data access procedures need to be secure. More...
HIPAA Breaches & Healthcare Students

HIPAA Breaches & Healthcare Students

The value of providing healthcare students with Health Insurance Portability and Accountability Act (HIPAA) training cannot be underestimated as it can prevent serious data breaches from occurring while also increasing the employability of the individuals who...

HR Managers & HIPAA Compliance

Most HR managers will be aware that if the organization operates a self-funded health insurance plan which is also self-administered, employees with access to protected health information (PHI) are required to undergo HIPAA training. HIPAA training should be provided...
GDPR Compliance in the Insurance Sector

GDPR Compliance in the Insurance Sector

The General Data Protection Regulation (GDPR) became enforceable on May 25 2018 and brought with it a number of rules that could, if broken, may result in the sanctioning of heavy fines. One sector where GDPR has had a huge impact is insurance industry, particularly...
HIPAA & Telehealth Types Explained

HIPAA & Telehealth Types Explained

Telehealth is an area that is very important to pay particular attention to when addressing the Health Insurance Portability and Accountability Act (HIPAA) compliance so it is important to be aware of the many different types of telehealth that have been created to...
Data Breach Leads to Massive Carrefour Fine

Data Breach Leads to Massive Carrefour Fine

In France the data protection regulator, Commission nationale de l’informatique et des libertés (CNIL), has penalised French retail giant Carrefour more than €3m ($3.7m) in relation to a number of breaches of the European Union’s General Data Protection Regulation....
HIPAA Breach Cases 2020

HIPAA Breach Cases 2020

Listed here is a summary of some of the most significant HIPAA breach cases that have lead to settlement agreements with the Department of Health and Human Services’ Office for Civil Rights (OCR). We have also listed some cases that have been pursued by OCR after a...
1 Million Impacted in Blackbaud Data Breach

1 Million Impacted in Blackbaud Data Breach

Another four healthcare suppliers have broadcast HIPAA breach alerts  in relation to the Blackbaud ransomware attack and data breach. Just after the Northwestern Memorial HealthCare group revealed that the personal information of 55,983 clients had been impacted, an...