Understanding When Patient Authorization is Required Under HIPAA

Patient Authorization under HIPAA

Under the HIPAA Privacy Rule, covered entities are required to protect the confidentiality and integrity of individuals’ Protected Health Information (PHI). One of the most frequently asked questions is whether a provider needs a patient’s authorization to disclose PHI. The answer depends on the purpose of the disclosure. When Authorization Is Not Required The HIPAA […]

The Right of Access Initiative

right of access initiative

The Right of Access Initiative under HIPAA represents a crucial step toward empowering individuals with control over their health information. Launched in 2019 by the Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS), this initiative aims to ensure that covered entities, including healthcare providers and health plans, comply with […]

Reproductive Health Privacy: HIPAA Compliance by Dec. 2024

reproductive health care deadline December 2024

The U.S. Department of Health and Human Services (HHS) has issued the Final Privacy Rule to support reproductive health care and the protection of related health information under the Health Insurance Portability and Accountability Act (HIPAA). This amendment was designed to strengthen privacy and security for individuals seeking reproductive health care.  Other than Notice of […]

What to Look for in a Healthcare IT Company

IT healthcare company

Selecting the right IT company for a healthcare organization is critical to safeguarding data security, regulatory compliance, and optimal operational performance. Healthcare providers need to find a partner that can meet their specific needs while maintaining high standards of compliance, particularly with regulations like HIPAA. Below is a breakdown of key factors to consider when […]

Protecting Your Cybersecurity

OSHA and HIPAA compliance additional seats

If you use an on-premises Microsoft Exchange Server, it is important to reach out to your IT Support immediately to be sure updates are installed to boost your cybersecurity and protect against recently discovered critical security vulnerabilities. The vulnerabilities allow an attacker to compromise your network and steal information, encrypt data for ransom, or even […]

21st Century Cures Act and Patient Data

In March, the HHS Office of the National Coordinator for Health Information Technology (ONC) issued new rules to prevent health care providers, developers of certified health IT, and others in the healthcare industry from engaging in activities that block a patient’s access to their electronic health information. Building on the 21st Century Cures Act, these […]

Microsoft Ends Support of Certain Windows Systems

As technology improves, software providers and hardware manufacturers discontinue their support of older software and devices. A significant event that may impact your practice is just around the corner. Microsoft will end support for Windows 7 and Windows Server 2008 on January 14, 2020. This means that Microsoft will no longer provide improvements, bug fixes, […]

October is Cybersecurity Month!

Even though businesses of all sizes are targeted by hackers, small businesses and practices make up approximately 70% of data breaches due to cyberattacks. Patient information is very valuable and small businesses often have less protection than large businesses do in cybersecurity. Strengthen the human element Training employees is one of the best defenses against […]

Breaches by the Numbers September 2019

The Department of Health and Human Services Office for Civil Rights (OCR), has reported a staggering increase since this time last year of all forms of breaches of patient PHI. Note: These figures do not include any 2019 breaches that involved fewer than 500 individuals. A covered entity must notify the Secretary of a PHI […]

New HIPAA Fact Sheet for Business Associates

On May 24, the HHS Office for Civil Rights (OCR) released a new fact sheet for Business Associates explaining their liability for HIPAA compliance. OCR is the government enforcement agency for HIPAA compliance. They have the authority to take enforcement action against business associates for failing to comply with requirements and prohibitions. Since the implementation […]