Friday, September 16, 2016

OCR small breach investigations increasing - Ep 71


OCR recently released another memo concerning compliance enforcement efforts.  They say effective August 2016, they have started an initiative to more widely investigate breaches involving under 500 patients.  That means that OCR small breach investigations will begin happening immediately.  In the past, the policy had been to investigate all breaches over 500 patients but not under.  

More information at HelpMeWithHIPAA.com/71

 


Check out the latest episode!

Friday, September 9, 2016

Insider Threats: Do you know who your employees are? - Ep 70


OCR published a memo on Aug 1, 2016.  The title is "Do you know who your employees are?".  It is a great reminder about insider threats that we should all worry about regularly.

Quoted directly from the memo.
============================
Although all insider threats are not malicious or intentional, the effect of these threats can be damaging to a Covered Entity and Business Associate and have a negative impact on the confidentiality, integrity, and availability of its ePHI.

According to a survey recently conducted by Accenture and HfS Research, 69% of organization representatives surveyed had experienced an insider attempt or success at data theft or corruption. Further, it was reported by a Covered Entity that one of their employees had unauthorized access to 5,400 patient’s ePHI for almost 4 years.

For more visit: HelpMeWithHIPAA.com/70


Check out the latest episode!

Friday, September 2, 2016

OCR 2016 settlements keep coming - Ep 69


So far in 2016 there have been 10 resolution agreements announced. One more and this year will equal the number of agreements in all of 2015 & 2014!

The latest two also include the largest one announced yet - $5.5m with Advocate Health.

Before that though was The University of Mississippi Medical Center - Ole Missto those of us in the SEC world. It wasn't something to "shake a stick at" with a$2.75m resolution amount.

The total amount for those 10 announcements so far in 2016 = $20,314,800

Of course the details are what we usually pay more attention to since it tells us exactly what OCR has a problem with in each case. It makes it clear what OCR wants all of us to learn from these folks mistakes.

For more visit HelpMeWithHIPAA.com/69


Check out the latest episode!

Friday, August 26, 2016

OCR Desk Audit Details - Ep 68


The OCR audits have begun.  On Wednesday, July 13, audit selected CEs where invited to a webinar. OCR staff walked through the processes they can expect for the audit and expectations for their participation.  The OCR published information from the webinar so we had to check it out and share what we learned with you guys.

 

For more details visit HelpMeWithHIPAA.com/68


Check out the latest episode!

Friday, August 19, 2016

Pokemon Go and HIPAA Breaches - Ep 67


Say it ain't so! Pokemon and a HIPAA breach really? REALLY!

Creatures are showing up in offices and hospitals just like everywhere else. The concept of keeping people active and engaged with their surroundings while playing a video game seems like a great idea from a healthcare standpoint. And then you actually do a risk assessment of it - this is where the wheels fall off that good idea train.

Get more details as HelpMeWithHIPAA.com/67


Check out the latest episode!

Friday, August 12, 2016

Healthcare Hack: PHI For Sell On The DarkNet - Ep 66


We first talked about this in Ep 62. Darknet sale of healthcare records. Now, more information is coming out and it gets more unfortunate for patients every time we read more.

Deep Dot Web broke the news: https://www.deepdotweb.com/2016/06/26/655000-healthcare-records-patients-being-sold/

We picked it up on Data Breaches.net because they were trying to figure out who the entities actually were in each case: https://www.databreaches.net/damn-anyone-know-what-facilities-these-are/

Get more info at https://HelpMeWithHIPAA.com/66


Check out the latest episode!

Friday, August 5, 2016

OCR resolution agreement - OHSU - EP 65


What happened?

  • March 23, 2013 Oregon Health & Science University notified HHS of a breach due to a stolen unencrypted laptop.
  • May 1, 2013 OCR notifies them they are investigating the incident
  • July 28, 2013 Oregon Health & Science University notified HHS of another breach resulting from storing ePHI at an internet-based service provider without a business associate agreement
  • November 8, 2013 OCR notifies them they are investigating the new incident
  • July 18, 2016 settlement announced for $2.7 million and a 3 year CAP

 

What can we learn from this?  Go to Help Me WithHIPAA.com/65


Check out the latest episode!