All posts by Leah Roffman

HIPAA FAQ Series: Are Covered Entities Liable for Business Associates’ HIPAA Violations?

This post marks the beginning of a new series on this blog covering various frequently asked questions regarding the Health Insurance Portability and Accountability Act (HIPAA).  There are many questions regarding HIPAA applicability, implementation, and liability that come up repeatedly.  We plan to use this series to discuss and analyze […]

Deadline Approaching for Reporting 2014 HIPAA Breaches

All covered entities that discovered security breaches under the Health Insurance Portability and Accountability Act (“HIPAA”) in 2014 should be aware of an upcoming reporting deadline.  Specifically, breaches that affected fewer than 500 individuals and were discovered in 2014 must be reported to the U.S. Department of Health and Human […]

Next Round of HIPAA Audits to Begin “Expeditiously”

During a media roundtable held this week, the Director of the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) Jocelyn Samuels provided additional information regarding the long awaited next round of audits for compliance with the Health Insurance Portability and Accountability Act (HIPAA).  Specifically, she said […]

Obama Advocates Federal Breach Reporting Law

On January 12, 2015, President Obama delivered a speech at the Federal Trade Commission during which he set forth several proposals, including the Personal Data Notification and Protection Act (the “Act”).  The Act would institute a federal data breach reporting framework by requiring businesses that hold consumer data to issue […]

Alaska Provider Reaches HIPAA Settlement with OCR for Security Deficiencies

On December 8, 2014, the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) announced that Anchorage Community Mental Health Services (“ACMHS”) has agreed to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).  ACMHS will pay a $150,000 penalty and also enter […]

Federal Advisory Group Considers Patient Data Standards

This week, the Privacy and Security Workgroup within the Health IT Policy Committee was tasked by the U.S. Department of Health and Human Services (“HHS”) to discuss certain patient data protections.  Specifically, they were asked to consider “updates or additional policies needed to address ethical privacy frameworks and research standards” […]

OCR Rep Discusses HIPAA Violations, Enforcement Actions, and Upcoming Audit Program

Last week, the National Institute of Standards and Technology (“NIST”), in conjunction with the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”), hosted a conference entitled “Safeguarding Health Information: Building Assurance through HIPAA Security.”  Both OCR officials and others within the industry spoke regarding HIPAA developments.  […]