Small but significant changes in meaningful use rules simplify compliance

The Department of Health and Human Services (HHS) today announced the release of final versions of its rule on meaningful use and its electronic health record (EHR) incentive program and associated health IT standards and certification…

Alleged health data disclosure via Facebook raises legal and policy issues

Reports of potential breaches of patient privacy at Tri-City Medical Center in Oceanside, California have garnered the HIPAA-related attention you would expect, but are also raising questions about the availability and use of social networking sites…

HHS says stronger HIPAA enforcement on the way with privacy and security audits

Representatives from the HHS Office for Civil Rights (OCR) said last week that OCR plans to begin conducting HIPAA compliance audits for security and privacy later this year, implementing a proactive audit program required under the…

HHS publishes new guidance on conducting risk analysis

Under the administrative safeguard provisions of the HIPAA Security Rule, covered entities are required to perform a risk analysis, specifically to “conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality,…

Thoughts about EHRs and accounting of disclosures

One of the provisions of the Health Information Technology for Economic and Clinical Health (HITECH) Act portion of the Recovery Act changed the requirements for HIPAA-covered entities to maintain an accounting of disclosures of health information….

Grand jury indicts man allegedly responsible for Las Vegas University Medical Center breach

In a follow-up to a HIPAA breach as Las Vegas’ University Medical Center reported last November, the FBI investigation into the matter has resulted in an indictment of the UMC employee allegedly responsible for selling data…

Healthcare providers missing the mark on risk assessments

As the comment period continues for the recently published proposed rules and draft certification criteria and standards associated with “meaningful use” of electronic health records, it appears that a large proportion of healthcare providers are not…