Search
As data theft, ransomware, network attacks and accidental privacy violations continue to plague healthcare organizations of all sizes, HHS Office for Civil Rights has announced plans to devote more resources to investigating smaller breaches.
Federal overseers have seldom penalized the healthcare organizations responsible for safeguarding this data, a ProPublica review shows.
The Office for Civil Rights, the HHS division responsible for enforcing HIPAA, is slated to get a new director after the official departure of Leon Rodriguez.
Security events in U.S. hospitals cost an estimated $1.6 billion each year. Nearly one of every five hospitals experiences a security breach, with the bill averaging $810,000 per breach.
The U.S. Department of Health and Human Services has settled with Affinity Health Plan, a New York-based managed care plan, for HIPAA violations to the tune of $1,215,780 after a photocopier containing patient information was compromised.
The most eagerly awaited -- if not anxiety-laden -- set of regulations in the healthcare spectrum arrived late Thursday: HHS issued modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules.
HHS issued modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules late Thursday. The four-part final rule is designed to enhance patients' privacy rights and increase HHS' ability to enforce security protections.
The Alaska Department of Health and Social Services (DHSS) -- the state's Medicaid agency -- has agreed to pay $1.7 million to the U.S. Department of Health and Human Services (HHS) to settle possible violations of the HIPAA Security Rule, making it the second largest settlement for HIPAA violations to date.
HHS settles with an Arizona physicians' practice for $100,000 over their failure to adequately protect patient health records.
Blue Cross Blue Shield of Tennessee (BCBST) has settled a potential violation of HIPAA privacy and security provisions with the Department of Health and Human Services for $1.5 million. It is the first enforcement action resulting from the HITECH Breach Notification Rule.