Friday, August 26, 2016

OCR Desk Audit Details - Ep 68


The OCR audits have begun.  On Wednesday, July 13, audit selected CEs where invited to a webinar. OCR staff walked through the processes they can expect for the audit and expectations for their participation.  The OCR published information from the webinar so we had to check it out and share what we learned with you guys.

 

For more details visit HelpMeWithHIPAA.com/68


Check out the latest episode!

Friday, August 19, 2016

Pokemon Go and HIPAA Breaches - Ep 67


Say it ain't so! Pokemon and a HIPAA breach really? REALLY!

Creatures are showing up in offices and hospitals just like everywhere else. The concept of keeping people active and engaged with their surroundings while playing a video game seems like a great idea from a healthcare standpoint. And then you actually do a risk assessment of it - this is where the wheels fall off that good idea train.

Get more details as HelpMeWithHIPAA.com/67


Check out the latest episode!

Friday, August 12, 2016

Healthcare Hack: PHI For Sell On The DarkNet - Ep 66


We first talked about this in Ep 62. Darknet sale of healthcare records. Now, more information is coming out and it gets more unfortunate for patients every time we read more.

Deep Dot Web broke the news: https://www.deepdotweb.com/2016/06/26/655000-healthcare-records-patients-being-sold/

We picked it up on Data Breaches.net because they were trying to figure out who the entities actually were in each case: https://www.databreaches.net/damn-anyone-know-what-facilities-these-are/

Get more info at https://HelpMeWithHIPAA.com/66


Check out the latest episode!

Friday, August 5, 2016

OCR resolution agreement - OHSU - EP 65


What happened?

  • March 23, 2013 Oregon Health & Science University notified HHS of a breach due to a stolen unencrypted laptop.
  • May 1, 2013 OCR notifies them they are investigating the incident
  • July 28, 2013 Oregon Health & Science University notified HHS of another breach resulting from storing ePHI at an internet-based service provider without a business associate agreement
  • November 8, 2013 OCR notifies them they are investigating the new incident
  • July 18, 2016 settlement announced for $2.7 million and a 3 year CAP

 

What can we learn from this?  Go to Help Me WithHIPAA.com/65


Check out the latest episode!