HIPAA News
Social Media HIPAA Violation: Healthcare Provider Not Liable

Social Media HIPAA Violation: Healthcare Provider Not Liable

This week a case against University of Cincinnati Medical Center (UCMC) was presided over by Judge Jody Luebbers in the Hamilton County Common Pleas Court in relation to the posting of Protected Health Information of a patient on social media. The incident that lead...

Electronic HIPAA Transactions: New Rules Approved by CAQH CORE

Electronic HIPAA Transactions: New Rules Approved by CAQH CORE

As part of Phase IV of the CAQH® CORE® Operating Rules, the CAQH® Committee on Operating Rules for Information Exchange (CORE®) recently approved new national rules for electronic HIPAA transactions. These new rules for electronic HIPAA transactions govern four groups...

ICD-10 Transition: WEDI Issues New Resources

ICD-10 Transition: WEDI Issues New Resources

The Workgroup for Electronic Data Interchange (WEDI) has developed two new resources to help groupsput in place the new ICD-10 codes required by the Health Insurance Portability and Accountability Act (HIPAA). The new resources, ICD-10 State Workers’ Compensation...

HIPAA Compliance Audits to Commence in 2016: New Deputy Director

HIPAA Compliance Audits to Commence in 2016: New Deputy Director

The newly appointed Deputy Director for Information Privacy at the Department of Health and Human Services’ Office for Civil Rights has been adjusting to her new role at the OCR since her appointment earlier this year, but until recently she has not given spoken to...

Cancer Care Group to Pay $750,000 HIPAA Non-Compliance Penalty

Cancer Care Group to Pay $750,000 HIPAA Non-Compliance Penalty

Cancer Care Group, an Indiana-based radiation oncology private physician practice, has agreed to settle with the Department of Health and Human Services’ Office for Civil Rights for $750,000, for potential HIPAA breaches relating to a 2012 data violation. In August...

FitBit Launches HIPAA Compliant Wellness Platform

FitBit Launches HIPAA Compliant Wellness Platform

Fitbit, America’s leading producer of activity and fitness trackers, announced it has developed a HIPAA compliant wellness platform which it should corner the lucrative healthcare market. The company has dabbled with health and fitness trackers for the healthcare...

OIG: VA Vulnerable to Data Exposure Via Employees’ Social Media App

OIG: VA Vulnerable to Data Exposure Via Employees’ Social Media App

The VA Office of the Inspector General (OIG) has recently issued the findings of its administrative examination of  into improper web-based collaboration technology by the Department of Veteran Affairs (VA). It found the agency is particularly vulnerable to data...

HIPAA and Patient Telephone Calls Rules Confirmed by FCC

HIPAA and Patient Telephone Calls Rules Confirmed by FCC

The Federal Communication Commission (FCC) has released a Declaratory Ruling and Order to clarify the rules in relation HIPAA and patient telephone calls. Some healthcare providers have had difficulty understanding the rules regarding HIPAA and patient telephone...

HIPAA HPID Use Opposed American Hospital Association

HIPAA HPID Use Opposed American Hospital Association

This week, the Vice President and Deputy Director of the American Hospital Association (AHA) sent a correspondence to the Centers for Medicare & Medicaid Services (CMMS) revealing concern over the implementation of Health Plan Identification numbers (HPIDs) and...

Small Dental Practices HIPAA Compliance Tool Released

Small Dental Practices HIPAA Compliance Tool Released

Being compliant with HIPAA Privacy and Security Rules can be a challenge for all organizations, regardless of size. However, smaller healthcare providers tend to have more issues. Budgets tend to be tighter, and a lack of suitable staff means progress is slow. This...

URMC Takes Steps to Avoid Future Patient Privacy Violations

URMC Takes Steps to Avoid Future Patient Privacy Violations

In May, The University of Rochester Medical Center experience a data violation after a member of staff took the Protected Health Information (PHI) of patients to a new employer, The employee in question,  who was trying to ensure continuity of patient care, was a...

FCC Clarifies Rules Regarding HIPAA and Patient Telephone Calls

FCC Clarifies Rules Regarding HIPAA and Patient Telephone Calls

The FCC has recently clarified it the rules regarding HIPAA and patient telephone calls, but fails to properly consider automated telephone calls. There has been some confusion reported by healthcare authorities over the rules regarding HIPAA and patient telephone...

BYOD Schemes: Samsung Galaxy Hacking Vulnerability Worrying

BYOD Schemes: Samsung Galaxy Hacking Vulnerability Worrying

Electronics giant Samsung has yet to issue a fix for a  a security vulnerability existing on Samsung Galaxy devices, 7 months after the company was first alerted to it. A hacking vulnerability affecting S3 to S6 models of Samsung Galaxy phones was identified that...

New OCR Deputy Director for Health Information Privacy Appointed

Deven McGraw been appointed to the role of Deputy Director of Health Information Privacy, and must get the agency auditing, advising and enforcing as it is supposed to be. Ms McGraw will be filling the role left vacant by  departure of Susan McAndrew, who retired last...

HIPAA-Covered Entities Set for Compliance Audits

HIPAA-Covered Entities Set for Compliance Audits

A survey recently released by Healthcare Information Security Today (HIST) shows many Covered Entities (CEs) are making the same compliance errors that were uncovered during the initial phase of audits. It has been three years since the OCR finished the pilot phase of...

Windows Server 2003 Will Soon be a Breach of HIPAA Compliance

Windows Server 2003 Will Soon be a Breach of HIPAA Compliance

Microsoft has revealed it will be stopping ceasing patches and software updates for Windows Server 2003 on July 15, 2015. Any HIPAA-covered body that is still running the defunct software on any of its servers after this date will be in violation of the HIPAA Security...

Lack of Skilled Staff Means Cybersecurity Services are Being Outsourced

Lack of Skilled Staff Means Cybersecurity Services are Being Outsourced

A lack of a appropriate workforce with appropriate skills to improve cybersecurity defenses is leading many CISOs and CIOs to look outside their organizations for assistance. Businesses and healthcare suppliers are now increasingly hiring third party consultants and...

HIPAA Violation Discovered by Crown Point Medical Tests

HIPAA Violation Discovered by Crown Point Medical Tests

A former business owned by Crown Point Medical Tests has breached the Health Insurance Portability and Accountability Act (HIPAA) after it did not securely dispose of files containing the Protected Health Information (PHI) of at least 167 people. The victims had...

Telephone Phishing Attack: Chicago Medical Records Used

Telephone Phishing Attack: Chicago Medical Records Used

Cybercriminals are stealing healthcare IT devices to gain access to Protected Health Information (PHI) so they can can make false insurance claims, apply for credit, and obtain medical prescriptions and services. This is one of many ways that data is obtained to...

Data Breach Laws Amended in Nevada and North Dakota

Data Breach Laws Amended in Nevada and North Dakota

North Dakota and Nevada have updated their breach notification laws this year, joining the growing list of states to do so. In May 2017, new laws were passed to tighten up the legislation and expand “personal information” definitions, with the two states following the...

OCR Confirms HIPAA Re-Screening Surveys Dispatched

OCR Confirms HIPAA Re-Screening Surveys Dispatched

The Department of Health and Human Services’ Office for Civil Rights has confirmed – to Fierce Health IT – that its preliminary HIPAA surveys have now been issued, marking the start of the 2015 HIPAA compliance audits. In a recent article in the National Law Review,...

Study: HIPAA Data De-identification Improvements Are Needed

Study: HIPAA Data De-identification Improvements Are Needed

According to HIPAA Rules, healthcare providers and other covered entities (CEs) are allowed to use the Protected Health Information (PHI) of patients – and share this data with others – provided that this data has been de-identified. It must not be possible for PHI...

Advice on HIPAA and Workplace Wellness Programs Issued by OCR

Advice on HIPAA and Workplace Wellness Programs Issued by OCR

Protected Health Information (PHI) is kept secure  under Health Insurance Portability and Accountability Act Rules, which requires adherence from covered entities (CEs) to put in place a number of controls to ensure that healthcare data is not disclosed to...

OCR Indicates Major Increase in HIPAA Audits

OCR Indicates Major Increase in HIPAA Audits

The second round of HIPAA compliance audits have yet to commence, the last round was  in 2012, but they are supposedly returning and will be bigger and bolder than before. The Department of Health and Human Services’ Office for Civil Rights (OCR) indicated to...

Top HIPAA Compliance Rating for Microsoft Office 365

Top HIPAA Compliance Rating for Microsoft Office 365

Microsoft Office 365 cloud services for the healthcare industry has been awarded the highest possible HITRUST CSF rating – achieving a maximum score of five – in a certification review of its security and privacy controls begun by Centura Health. The Health...

Medical Record Subpoenas: HIPAA Violation Warning Issued

Medical Record Subpoenas: HIPAA Violation Warning Issued

Law firm, Day Pitney LLP, has released a warning to healthcare workers to be careful when disclosing Protected Health Information, even when asked to supply medical records to attorneys under subpoena. A Connecticut Supreme Court ruling in November 2014 allowed a...

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

COMPREHENSIVE HIPAA TRAINING

Privacy is key to everything that we do at J Flowers Health Institute. We require the highest data privacy standards in our daily operations between our team members and patients. The HIPAA compliance and cyber security training we provide to our teams with ComplianceJunction creates enormous value for our organization.

Kevin DeLoach

Chief Operating Officer
J. Flowers Health Institute