Category: Privacy and Security

States Strengthen Laws Addressing Health Information Handling and Breach Response

Connecticut and Oregon were recently added to the increasing list of states  adopting stricter laws addressing the handling of health information and penalties in connection with breaches of health information.  Both states amended their respective data security and breach notification laws and they will now levy stricter requirements on entities that store or […]

HIPAA FAQ Series: Does HIPAA Protect the PHI of Deceased Individuals?

In order to protect the privacy and security of patients’ information, the Health Insurance Portability and Accountability Act (HIPAA) imposes substantial obligations on covered entities (certain providers, plans, and health care clearinghouses), as well as their business associates.  These obligations can be intrusive and costly, and can require substantial investments […]

HIPAA FAQ Series: Are Covered Entities and Business Associates Required to Encrypt PHI?

The Health Insurance Portability and Accountability Act (HIPAA) mandates that both Covered Entities and Business Associates protect the security of Protected Health Information (PHI) in a variety of ways.  Specifically, HIPAA’s Security Rule sets forth various technical, administrative, and physical safeguards that must be enacted in order to ensure the […]

CareFirst Discloses Data Breach

CareFirst, a Blue Cross Blue Shield plan serving the Washington D.C. metro area, became another in a line of health insurers to suffer a data breach as a result of hackers.  CareFirst and the FBI are examining the breach which potentially compromised 1.1 million customers.  The company reports that although […]

Colorado Pharmacy Reaches HIPAA Settlement with OCR Following Improper Records Disposal

Yesterday, the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) announced that Cornell Prescription Pharmacy of Denver, Colorado (“Cornell Pharmacy”) has agreed to settle potential violations of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).  Cornell Pharmacy, a single location pharmacy, will pay a $125,000 […]

HIPAA FAQ Series: Do You Need a BAA with Your Cloud Storage Provider?

This week, the HIPAA FAQ series continues with another topic about business associate agreements (BAAs). As most Covered Entities and Business Associates know, in the event that a Covered Entity utilizes a service provider that may have access to Protected Health Information (PHI), a BAA is required. Further, in the event […]

HIPAA FAQ Series: Do You Need a BAA with Your Mail Carrier?

This week, the HIPAA FAQ series continues with a topic about business associate agreements (BAAs).  Most Covered Entities and Business Associates are familiar with general BAA obligations.  In the event that a Covered Entity utilizes a service provider who may have access to Protected Health Information (PHI), a BAA is […]

HIPAA FAQ Series: Does HIPAA Permit Communications via E-mail with PHI Subjects?

Last week, we introduced a new series to this blog that will cover frequently asked questions regarding the Health Insurance Portability and Accountability Act (HIPAA).  This week, the series continues by delving into a hot topic that arises frequently: whether it is permissible for Covered Entities and Business Associates to […]

HIPAA FAQ Series: Are Covered Entities Liable for Business Associates’ HIPAA Violations?

This post marks the beginning of a new series on this blog covering various frequently asked questions regarding the Health Insurance Portability and Accountability Act (HIPAA).  There are many questions regarding HIPAA applicability, implementation, and liability that come up repeatedly.  We plan to use this series to discuss and analyze […]

The Aftermath of the Anthem Breach

On February 4, 2015, Anthem Inc. (“Anthem”) announced a data breach involving the personal information of up to 80 million individuals resulting from what it characterized as a sophisticated, targeted cyber-attack.  According to Anthem, the information involved in the data breach included: names; dates of birth; social security numbers; health care […]