Leon Rodriguez, director of the Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) recently conducted an interview with HealthcareInfoSecurity. Click on the link to listen to the full interview. Rodriguez gave some valuable insight into OCR’s plans for 2013 and beyond as well as guidance that organizations should follow to protect...
According to a report produced by the Health Information Trust Alliance (HITRUST), there has been little progress in reducing the amount of healthcare related data breaches. A close look at the HHS data reveals that since 2009 the industry has experienced 495 breaches involving 21 million records at an estimated cost of $4 billion. With...
The Alaska Department of Health and Social Services (DHSS) was handed a $1.7 million fine by the Office of Civil Rights (OCR). The fine is one of the largest imposed on an organization. A closer look reveals why the fine was so large. Healthcare Info Security gives an in-depth look at the fine. The Alaska...
There are many threats to patient information and financial resources and one that seems to be popping up a lot lately is phishing scams. A phishing scam is basically an email that looks like a legitimate email from a bank, credit card company, retail stores, social networks (Facebook, Twitter, LinkedIn, etc.). The email usually has...
We are excited to announce our new Small Business Package. The Small Business Package is for organizations with 10 or fewer employees. We have reduced the price of the complete HIPAA Secure Now! service from $1,750.00 to $999.00. The Small Business Package is exactly the same as our regular service and includes custom policies and...
You’ve seen hundreds of companies selling HIPAA products. There are HIPAA training videos, policy templates, consultants, HIPAA books, HIPAA coffee mugs and the list goes on and on. And yet “become HIPAA compliant” is still on your long list of things to do. Have you asked yourself why you never seem to get to “become...
We have written about the HIPAA fine and reputation damage to Phoenix Cardiac Surgery. Phoenix Cardiac Surgery is a small 5 physician specialist in Phoenix, AZ. Let’s quickly review why the Office of Civil Rights fined Phoenix Cardiac Surgery $100,000. Lack of HIPAA Policies and Procedures Lack of HIPAA training for all workforce members Lack...
The Phoenix Cardiac Surgery medical practice was handed a $100,000 fine for failing to protect patient information. The resulting resolution agreement from the Office of Civil Rights (OCR) is very interesting. Let’s take a look at is. The full resolution agreement can be found here (PDF). Lack of training for employees (a) From April 14,...
In the Ponemon 2011 Cost of Data Breach Study, 41% of breaches were due to third party mistakes. Take a step back and think about the impact of that number. The use of third party organizations are more and more common. According to the HHS.gov website, some examples of third party / business associates include:...
The Office of Civil Rights (OCR) has released a series of videos to help practices and medical professionals understand the HIPAA regulations. Unfortunately as of today it is not a very well-known resource, each of the 4 videos has less than 75 views. Hopefully with more awareness of this resource, more people will watch the...
Recent Comments