Is HIPAA enforcement getting any stronger?

Following the disclosure in November that employees at University Medical Center of Southern Nevada (UMC) have been sending patient information outside the hospital to personal injury lawyers and other outsiders, the FBI opened a criminal investigation…

BCBSA data breach another lesson in policy enforcement

Recent news that the Blue Cross Blue Shield Association (BCBSA) suffered the theft of an employee’s personal laptop that contained personal information on hundreds of thousands of physicians illustrates once again that it is not enough…

Health information exchange outside HIPAA

The Social Security Administration (SSA) has essentially been the first government adopter of the Nationwide Health Information Network (NHIN), going into production early this year with an information exchange with MedVa to receive medical records in…

A few new (and sharper) teeth in HIPAA enforcement

Several valid criticisms of HIPAA since the Privacy Rule went into effect in 2003 concern lackluster efforts on enforcement of the rule’s requirements and insufficient penalties for non-compliance. The basic civil penalty for unintentional violation is…

Accounting of disclosures to become more comprehensive

One of the requirements under the HIPAA Privacy Rule is that covered entities maintain an “accounting of disclosures” of protected health information, in part so that an individual may request a record of who accessed their…