(866) 635-2689 for Personal Injury or (866) 635-9402 for Criminal Defense
Find a Local Lawyer
Divorce (866) 635-6190
Personal Injury (866) 635-2689
Criminal Defense (866) 635-9402
HIPAA Blog 

Discussion of medical privacy issues buried in political arcana.
Post Frequency: 5.4/day Last Entry: May 21, 2013 at 23:00:01 Recent Entries: 985
By Jeffery P. Drummond
Go to HIPAA Blog, find other Health Law blogs, or browse all law blogs.
Idaho State University Settles
Posted on May 21, 2013Idaho State University Settles for $400,000: They left a server firewall down, putting 17,500 patients' PHI at risk. Seems pretty steep. . . .
Prescription Reminders: CVS' move
Posted on May 13, 2013Prescription Reminders: CVS' move to stop providing manufacturer-funded prescription reminder services has triggered calls from pharmacy trade groups to HHS, asking them to loosen up the "marketing" rules to allow these things to proceed. I tend to agree -- the tight marketing rules are too convoluted and too easy to violate, and activities that are much more beneficial than harmful are caught
University of Rochester Medical
Posted on May 10, 2013University of Rochester Medical Center data breach: a resident lost a flash drive, probably in the laundry. The flash drive had PHI on a little more than 500 patients, but it was . . . drum roll please . . . unencrypted, resulting in the need for a breach report...
Social Media: Tweeting and webcasting
Posted on May 10, 2013Social Media: Tweeting and webcasting births, surgeries, and the like.
"Storage" Creates a BA Relationship:
Posted on May 07, 2013"Storage" Creates a BA Relationship: Where do you store your old medical records? Lots of small practices rent a self-storage unit somewhere to keep boxes of old paper medical records. Those storage facilities don't consider themselves to be in the "medical record storage" business, don't intend to access the records, don't "maintain" them in the traditional sense of the word, don't have
The HIPAA Omnibus Rule Blows Up
Posted on May 06, 2013The HIPAA Omnibus Rule Blows Up Refill Reminders: Some of the hardest components of the Omnibus Rule to figure out are the changes to marketing and restrictions on sale of PHI. Any communication urging the recipient to purchase a good or service is marketing...
OCR Helps Consumers Understand
Posted on May 01, 2013OCR Helps Consumers Understand HIPAA: OCR has posted a series of factsheets, in different languages, to help consumers understand their rights under HIPAA. These are complimented by a series of YouTube videos for consumers (one of which is targeted at providers and describes how to establish basic safeguards)...
Meaningful Use and HIPAA: If you
Posted on May 01, 2013Meaningful Use and HIPAA: If you are a healthcare provider who is receiving federal incentive payments under the HITECH Act for "meaningful use" (i.e., you are a meaningful user of an Electronic Medical Record, have attested to it, and receive incentive payments from CMS), you stand a 5% chance of being audited, either before or after payment is made...
When HIPAA Kills: Or at least when
Posted on April 30, 2013When HIPAA Kills: Or at least when confusion about how much privacy to afford the patient results in harm to others.
Arizona Counseling and Treatment
Posted on April 24, 2013Arizona Counseling and Treatment Services breach: This behavioral health provider suffered a data breach when a laptop and hard drive (unencrypted, natch) were stolen from an employee's home, resulting in notification to 3000 patients. The laptop had tracking software and was wiped, but the hard drive didn't have that functionality...
This is a little disconcerting:
Posted on April 24, 2013This is a little disconcerting: HHS, in its HIPAA audit program, has discovered that approximately one-third of providers' and insurers' noncompliance problems stemmed from a lack of awareness of requirements facing them. 47 out of 61 healthcare providers audited haven't done a satisfactory security risk analysis either...
Another data breach, another lawsuit.
Posted on April 22, 2013Another data breach, another lawsuit. This time in Glens Falls, NY.
HIPAA as a Hinderance to Gun Purchase
Posted on April 19, 2013HIPAA as a Hinderance to Gun Purchase Background Checks: It's been posited that the National Instant Criminal Background Check System, which is supposed to help prevent guns from being purchased by those not allowed to have them, doesn't work as well as it should because some people don't report information due to HIPAA concerns...
Class-Action Suit: Employees at
Posted on April 18, 2013Class-Action Suit: Employees at Florida Hospital - Celebration were recently sentenced to jail time for stealing patient data relating to patients who were in car wrecks and selling it to chiropractors and plaintiff's attorneys. The thefts occurred between 2009 and 2011, and obviously the hospital didn't know the employees were doing it...
General HIPAA article from Buffalo.
Posted on April 16, 2013General HIPAA article from Buffalo. In an unusual twist, I can't find anything wrong in it.
HIPAA Violation: 12 years in prison
Posted on April 15, 2013HIPAA Violation: 12 years in prison for HIPAA identity theft and Medicare fraud.
Interesting HIPAA preemption case:
Posted on April 15, 2013Interesting HIPAA preemption case: The 11th Circuit has ruled that a Florida rule that requires nursing homes to give PHI of deceased patients to the next of kin is superseded by HIPAA's privacy requirements, which only allow the information to be given to the "personal representative," or executor of the estate...
Social Media Issues: If you were
Posted on April 12, 2013Social Media Issues: If you were at my Texas Medical Association presentation yesterday or the day before in Houston (or in preceding weeks across the state), you heard me make the point about risks of emailing with patients (and the greater risk of texting with them)...
Out on a Limb: Electronic communications
Posted on April 04, 2013Out on a Limb: Electronic communications between doctors and patients may help, but may cause problems.
Via BNA: California's AG is looking
Posted on March 26, 2013Via BNA: California's AG is looking closely at health record privacy and data breaches. (subscription required, sorry).
Even small breaches have consequences:
Posted on March 26, 2013Even small breaches have consequences: In Massachusetts, a physician practice employee snoops into 200 records in an electronic medical record, and Hallmark Health System has to notify all of the patients and the Mass. and NH attorneys general.
Doctors and their online presences:
Posted on March 22, 2013Doctors and their online presences: Interesting article, slightly off topic.
Verizon Announces Secure Universal
Posted on March 04, 2013Verizon Announces Secure Universal Messaging System at HIMSS: the Health Information Management Systems Society (HIMSS) conference is going on in New Orleans, and according to BNA, Verizon has announced that it is developing an open-source, secure messaging system that will allow healthcare providers to text safely and securely...
Non-HIPAA HIPAA violation: a Detroit
Posted on February 26, 2013Non-HIPAA HIPAA violation: a Detroit healthcare worker sold PHI of Medicare beneficiaries to home health care agencies, who falsely billed Medicare for services not provided. Clarence Cooper pled guilty to one count of conspiracy to commit healthcare fraud, and faces up to 10 years in prison...
Five Ways to Improve HIEs: Health
Posted on February 20, 2013Five Ways to Improve HIEs: Health Information Exchanges are big part of the future of healthcare delivery and process, but they haven't progressed as many expected they would. The reasons why are pretty predictable: the inherent conflict between information exchange and privacy concerns, different goals/objectives/interests pursued by different participants in the HIE industry, incompatability
OCR to Focus Audits on Entities
Posted on February 20, 2013OCR to Focus Audits on Entities with Long-Standing Patterns of Non-Compliance. According to BNA (subscription required), OCR will look for organizations with long histories of noncompliance, across all areas of the healthcare industry. Entities that can demonstrate efforts to create and nurture a "culture of compliance" will come out of audits looking good...
Mental Health and HIPAA: Balance.
Posted on February 15, 2013Mental Health and HIPAA: Balance. I always say that the problem with privacy advocates is that absolute privacy is a bad thing, and prevents necessary health and safety from happening. Take mental health records. That's obviously a very sensitive area of medical records...
Facebook Follies: A physician posts
Posted on February 12, 2013Facebook Follies: A physician posts a note on Facebook complaining about a patient who is always late to her OB appointments. A commenter asks why she doesn't fire the patient, and the doctor says that the patient previously miscarried. Someone else sees the post, takes a screenshot, and posts that on the "new moms" Facebook page of the hospital where the physician works...
Slightly off-topic: Dr. Kevin MD:
Posted on February 11, 2013Slightly off-topic: Dr. Kevin MD: Advice to physicians for enhancing your online presence.
Shiner's Saison: Picked up a growler
Posted on February 01, 2013Shiner's Saison: Picked up a growler of Shiner's FM966 farmhouse ale at Whole Foods on the way home tonight, and enjoying it watching the Stars' new rookies Roussel (first NHL goal) and Oleksiak ("the big rig" at 6'7" and 240 lbs) play Phoenix. Like most Shiner beers, it's a good, solid, but not showy saison beer...
Next
New Baptist Covenant Blog
Last week, I pointed to the New Baptist Convenant website, now onl...
The Mexico Trucker Blog
I've written before about the perceived problems with relaxed rest...
COBRA Continuation of Healthcare Coverage after Layoff
Pensions and Health Care Coverage for Dislocated Workers
Is it libel to write blog posts and/or online reviews about a local business that defames one's reputation?
Libel is the form of defamation expressed in fixed-- usually written form. Sland...
How can I make my blog more popular?
You have to write and submit articles, with backlinks to your blogsite....

Is it libel to write blog posts and/or online reviews about a local business that defames one's reputation?
Libel is the form of defamation expressed in fixed-- usually written form. Sland...
How can I make my blog more popular?
You have to write and submit articles, with backlinks to your blogsite....








