Search Realtime IT Compliance

Entries from Realtime Community | IT Compliance tagged with 'privacy rule'


FTC Issued Consent Order for GLBA Privacy Rule and Safeguards Rule Violations

Today the FTC issued a consent order against mortgage lender James B. Nutter & Company for GLBA Privacy Rule and Safeguards Rule violations resulting from having an inadequte information security program and safeguards. The requirements will result in, among other...

2ND HIPAA Sanction: CVS Must Pay $2.25 Million And Improve Info Sec Practices For Improper Disposal

The 2nd ever to date HIPAA sanction has been handed down by the Department of Health and Human Services (HHS)......

FYI: New Website for Health Information Privacy

I just got this email notification from the Department of Health and Human Services (HHS) Office of Civil Rights (OCR) yesterday......

Patient Privacy in Peril: EHRs, HITECH Act and $20B Handouts

On February 2 Allscripts released a report, "The 2009 Economic Stimulus Plan and the Electronic Health Record: Opportunities and Challenges for U.S. Medical Groups; A Survey of 1,800 Healthcare Professionals" (NOTE: Registration is required, but it's free.) A few excerpts...

New Report Finds HIPAA Privacy Rule Is Ineffective As Written

Today the Institute of Medicine (IOM) released a report, "Beyond the HIPAA Privacy Rule: Enhancing Privacy, Improving Health Through Research"......

FTC Applies GLBA & FTC Act Sanctions To Mortgage Lender

I anticipate that with the big $700 billion "rescue" plan the government is going to continue the increased compliance activities......

HIPAA Compliance During Emergencies and Disasters

Yesterday the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) posted a new HIPAA frequently asked question (FAQ) to their site; a great question that many organizations do not even consider until after the fact......

More On The HHS HIPAA Compliance Activities

Today I communicated with Sue Marquette Poremba at SC Magazine for an article she published this afternoon, "Proliferating HIPAA complaints and medical record breaches" She had seen my blog posting from yesterday, "HIPAA Complaints And Associated Resolutions Since 2003" and...

HIPAA Complaints And Associated Resolutions Since 2003

The U.S. Health Insurance Portability and Accountability Act (HIPAA) has required compliance from covered entities (CEs) since 2003. The Department of Health and Human Services (HHS) is the Federal agency with regulatory oversight for compliance; with the Office of Civil...

CMS Announces Plans To Actively Audit Hospitals For HIPAA Compliance

The U.S. Centers for Medicare and Medicaid Services (CMS) announced last week that they plan to audit 10 - 20 hospitals for HIPAA compliance in the next 9 months according to a Government Health IT article....

CMS Hires A Fox To Guard The HIPAA Henhouse

I just read a very interesting article, "CMS' HIPAA watchdog presents potential conflict" that made me go Hmmm!! The genesis of the article is that the Centers for Medicare and Medicaid Services (CMS), the agency that is responsible for the...

FTC Fines Mortgage Co. For Tossing PII Into Dumpster: FACTA/FCRA, GLBA, & FTC Act Violations

On December 17 the U.S. Federal Trade Commission (FTC) fined and penalized American United Mortgage Company for throwing the personally identifiable information (PII) and financial information of its customers and consumers into an open, publicly-accessible dumpster. Under the terms of...

HIPAA, The Insider Threat & Prison Time

It seems there are more and more stories related to patient privacy and HIPAA popping up lately. Today another story caught my eye related to them....

Another Hospital Suspends Staff For Violating HIPAA Requirements

A couple of weeks ago I blogged about the Ivinson Memorial Hospital applying sanctions to their staff for violating HIPAA requirements. They have set a good example...another hospital has also applied sanctions...suspending 27 of their staff members for violating HIPAA...

A Hospital Actively Enforcing HIPAA Requirements!

It is great to see a story published about a hospital, actually any type of organization that is a covered entity (CE), that is actively and seriously trying to be in compliance with HIPAA requirements....

The First Ever HIPAA Audit: Where's The Report? Does It Have Beef?

Gosh, I just had a flashback to the "Where's the Beef" commercial from years ago... :) The U.S. Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule went into effect in April, 2001, and gave covered entities (CEs) two years...

HIPAA & 4 Lessons From an Insider Threat Example: Former Healthcare IT Manager Hacks Into System and Deletes PHI

There are so many ways in which bad things can happen with the authorized access personnel and business partners have to sensitive data, personally identifiable information (PII), and business systems. Many times the bad things that happen are a result...

HIPAA Violation in Divorce Proceeding?

During a divorce case in Illinios, K.S. Kim claimed a hospital violated HIPAA by sending her health records to her ex-husband's attorney....

HIPAA: More Changes and Initiatives by HHS

I've been reading so much about HIPAA lately; no enforcement actions yet, but a lot of changes, proposals and initiatives. Two more I read about recently:...

HIPAA: Advisory Workgroup Proposes PHI Security and Privacy Requirements Should Apply to All Organizations

The Department of Health and Human Services (HHS) has a Confidentiality, Privacy, and Security Workgroup, also known as the American Health Information Community, that is made up of practitioners, IT folks, lawyers and other leaders outside of the government who...

Admitted HIPAA Noncompliance at UPMC: Penalties Must Be Applied to Make Laws Effective

On April 13 the Pittsburgh Tribune-Review reported that the University of Pittsburgh Medical Center (UPMC) admitted to using the records of 80 patients, including names and Social Security numbers, for a presentation they made at a 2002 symposium, in violation...

HIPAA Security Rule and Privacy Rule Enforcement Reportedly Going To Be Pursued In 2007

Something that has bothered me, and many others, for a very long time is how there have been absolutely no enforcement actions for the Health Insurance Portability and Accountability Act (HIPAA) privacy rule or security rule since they went into...

Site Tags

Site tags used on this blog: