It’s Your Call – August 2021
OSHA: Why did OSHA issue the Emergency Temporary Standard (ETS)? OSHA determined that SARS-CoV-2 is a grave danger for workers in healthcare settings, and studies have been conducted to validate this claim. Although the General Duty Clause imposes a general duty for employers to keep a workplace free of recognized hazards, it fell short of […]
Audit Logs
August 2021 A covered entity recently discovered that a former employee had “snooped” (inappropriately accessed) over 10,000 patient records almost 4 years after the snooping began. The employee accessed the records in the EHR over a period of about 14 months. That’s over 700 records per month. The snooping went undetected until the former employee […]
Diabetes App Security Advisory from CISA

Patients and physicians who have the diabetes apps/devices listed below and use the mylife Cloud and/or mylife Mobile Application should update to the current version of the application and update account passwords ASAP as a security measure. The app is not secure and not sufficiently protecting usernames and passwords making their data vulnerable to exposure/hacking. […]
It’s Your Call July 2021

OSHA: What should we know about the B.1.617.2 (Delta) variant? The B.1.617.2 (Delta) variant is a mutation of the SARS-CoV-2 virus, and it has been reported in 77 countries including the United States and in the United Kingdom. Of the 3 variant classifications, the Delta variant is considered a variant of concern (VOC) because it […]
The Recognized Security Practices Safe Harbor and the OCR
It is hard going a day without seeing a cybersecurity attack in the headlines. Over the past year and a half, the number of attacks has increased by over 350%. Healthcare entities of all sizes are an enticing target for attackers because just 1 patient record can fetch $200 or more on the dark web. […]
It’s Your Call June 2021

OSHA: Several of our vaccinated employees have a greater risk of being exposed to SARS-CoV-2 and the potential for prolonged, close contact with someone with SARS-CoV-2. If vaccinated workers are asymptomatic, what testing is recommended? The CDC recommends a series of two viral tests: one immediately and the other one 5-7 days after exposure. Furthermore, […]
OSHA JOINS WITH THE FDA TO ISSUE AN ALERT ON HAIOU SAFETY NEEDLES

The FDA is issuing an alert on Haiou safety needles as well as recommending healthcare providers stop using certain syringes and needles with needle safety devices manufactured by Guangdong Haiou Medical Apparatus Co., LTD. The FDA received information about quality issues, including certain Haiou needles detaching from the syringe and needle safety device failures. 1ml […]
The 21st Century Cures Act and Healthcare Information Blocking

What is information blocking? Anything a healthcare provider knows is likely to interfere with the ability of a patient or other authorized person(s) to access, exchange, or use electronically protected health information (ePHI). Taking longer than allowed to respond to patients’ requests for access to their records, or not responding at all. Charging patients a […]
It’s Your Call May 2021
HIPAA: How many enforcements have been issued by the OCR in their HIPAA Right of Access Initiative? Answer: As of April 28, 2021, there have been 18 enforcements that all include a monetary penalty and a 1-2 year corrective action plan and monitoring by the OCR. The highest penalty was issued to a facility that […]
OCR Alert – Postcard Disguised as Official Communication

Some healthcare organizations have received postcards that appear to be from the OCR that they are required to participate in a “Required Security Risk Assessment” and they are to send their risk assessment to a website. This is not from the OCR or the U.S. Department of Health and Human Services, it is an advertisement […]
