Health Information Management

Health Information Management Articles by Topic: HIPAA

HHS unveils online breach notification forms; experts say they’re ‘straightforward,’ user-friendly

  • Health Information Compliance Insider, Issue 12, December 1, 2009

    The forms ended speculation about how HHS wanted covered entities to submit breach notifications to...

Limit your risk; address snooping problems swiftly, harshly

  • Health Information Compliance Insider, Issue 12, December 1, 2009

    Covered entities must strive to protect PHI against employees who snoop with preparation, strong...

Develop effective strategies for your breach notification response program

  • Health Information Compliance Insider, Issue 12, December 1, 2009

    Be determined and thorough, but also patient as you gather evidence and develop a smart game plan...

Health Information Compliance Insider®, December 2009

  • Health Information Compliance Insider, Issue 12, December 1, 2009

    Synopsis for full issue: In this issue of HICI, you’ll read how to effectively manage your...

Know these eight tips to ensure secure PHI

  • Medical Records Briefing, Issue 12, December 1, 2009

    HHS’ message is clear: Breaches of electronic protected health information (PHI) should not...

Medical Records Briefing, December 2009

  • Medical Records Briefing, Issue 12, December 1, 2009

    The December issue of MRB is full of time-saving tips and information for HIM directors. This...

HIPAA Q&A: Red Flags Rule

  • HIPAA Weekly Advisor, Issue 41, November 2, 2009

    Learn the answer to this tough compliance question.

BA contract addendum

  • HIPAA Weekly Advisor, Issue 41, November 2, 2009

    Does anyone have a sample of an addendum that can be added to our BA agreement that puts us into...

Add your feedback on HHS 'harm threshold'

  • HIPAA Weekly Advisor, Issue 41, November 2, 2009

    Want to add your feedback on HHS' new harm threshold?

Enforcement interim final rule published in FR

  • HIPAA Weekly Advisor, Issue 41, November 2, 2009

    The interim final rule becomes effective November 30. HHS has invited public comments on the...

Update: Economy slowing growth of electronic health record implementation in hospitals

  • Health Information Compliance Insider, Issue 11, November 1, 2009

    With the rapidly changing healthcare landscape, the study’s authors continue to follow up on...

AAHC: Privacy rule directly affects multisite research, subject participation

  • Health Information Compliance Insider, Issue 11, November 1, 2009

    Rebecca Herold, CISSP, CIPP, CISM, CISA, privacy, security, and compliance consultant at Rebecca...

Harm thresholds: Opportunity for CEs to be more accountable for PHI, breach mitigation

  • Health Information Compliance Insider, Issue 11, November 1, 2009

    The rule’s “harm threshold” provision provides CEs an avenue to avoid reporting a...

Health Information Compliance Insider®, November 2009

  • Health Information Compliance Insider, Issue 11, November 1, 2009

    In this issue of HICI, you’ll read how one paper’s authors believe the Privacy Rule...

Dell responds with positive changes

  • Briefings on HIPAA, Issue 11, November 1, 2009

    We found Dell to be significantly lacking in its abil¬ity or willingness to provide the support...

Harm thresholds: Opportunity for CEs to be more accountable for PHI, breach mitigation

  • Briefings on HIPAA, Issue 11, November 1, 2009

    The rule’s “harm threshold” provision provides CEs an avenue to avoid reporting a...

New contract requirements raise questions

  • Briefings on HIPAA, Issue 11, November 1, 2009

    Covered entities can be BAs. Rely on the regulatory experts in your field. I can’t speak for...

HIPAA Q&A: Business associate agreements, social networking sites, donor information

  • Briefings on HIPAA, Issue 11, November 1, 2009

    Learn the answer to this and more important HIPAA compliance questions.

Experts: Hospitals not the place for personal e-mail, social networking sites

  • Briefings on HIPAA, Issue 11, November 1, 2009

    Regardless of how you respond to these privacy and security vulnerabilities, understanding the...

HIPAA happenings

  • Medical Records Briefing, Issue 11, November 1, 2009

    The privacy and security changes pursuant to the Health Information Technology for Economic and...

Medical Records Briefing, November 2009

  • Medical Records Briefing, Issue 11, November 1, 2009

    Inside: Education, credentials just two of many factors that affect salary Ensure that BA...

Briefings on HIPAA, November 2009

  • Briefings on HIPAA, Issue 11, November 1, 2009

    In this issue of BOH, you’ll learn how some providers are offsetting the dangers posed by...

Ask these questions in your harm threshold risk assessment

  • HIPAA Weekly Advisor, Issue 40, October 26, 2009

    Ask these questions during your risk assessment to determine the level of harm to victims of a...

Speaking of HIPAA ...

  • HIPAA Weekly Advisor, Issue 40, October 26, 2009

    See what your HIPAA privacy and security colleagues are talking about on the HIPAA Update blog.

Experts: exemption from Red Flags Rule not necessary

  • HIPAA Weekly Advisor, Issue 40, October 26, 2009

    The House of Representatives filed a bill October 8 that would exempt a healthcare practice with 20...

HIPAA Q&A: Fundraising

  • HIPAA Weekly Advisor, Issue 39, October 19, 2009

    Learn the answer to this challenging HIPAA compliance question.

Thousands of doctors' information on stolen laptop

  • HIPAA Weekly Advisor, Issue 39, October 19, 2009

    Lisa Martinelli, Highmark, Inc.'s chief privacy officer, told the Tribune-Review the information...

Add your feedback on HHS 'harm threshold'

  • HIPAA Weekly Advisor, Issue 39, October 19, 2009

    Add your feedback to a hot-button issue -- HHS' HIPAA harm threshold in the interim final rule on...

Small healthcare entities may be exempt from Red Flags Rule

  • HIPAA Weekly Advisor, Issue 39, October 19, 2009

    The Red Flags Rule, which will be enforced beginning November 1, requires healthcare entities...

Congressmen disagree with HHS 'harm standard'

  • HIPAA Weekly Advisor, Issue 38, October 12, 2009

    The Congressmen say this concept was explicitly rejected when they crafted the American Recovery...

HIPAA Q&A: Taking PHI home

  • HIPAA Weekly Advisor, Issue 37, October 5, 2009

    Q. Several weeks ago, some security specialists indicated that their staff members take paper PHI...

New rules protect patients' genetic information

  • HIPAA Weekly Advisor, Issue 37, October 5, 2009

    In part, the rule ensures that genetic information is not used to deny healthcare coverage and will...

Lawyer: Providers not ready for HITECH compliance

  • HIPAA Weekly Advisor, Issue 37, October 5, 2009

    “People are shell-shocked,” says Blustein, partner and co-chair of Garfunkel Wild &...

HHS posts forms for breach notification

  • HIPAA Weekly Advisor, Issue 37, October 5, 2009

    HHS releases the step-by-step reporting form for breach notification.

HIM directors' salaries on the rise, but profession isn't exempt from poor economy

  • Medical Records Briefing, Issue 10, October 1, 2009

    HIM director salaries are on the rise, according to HCPro’s MRB salary survey. Half of the...

EHRs, incentives on the horizon

  • Health Information Compliance Insider, Issue 10, October 1, 2009

    The biggest difference between the two is that the patient has access to and the ability to change...

Experts: Expect more enforcement as OCR role expands

  • Health Information Compliance Insider, Issue 10, October 1, 2009

    OCR now will determine whether HIPAA security standards preempt any state laws, impose financial...

Demonstrate differences in EHRs and PHRs

  • Health Information Compliance Insider, Issue 10, October 1, 2009

    The Health Information Technology for Economic and Clinical Health (HITECH) Act includes financial...

EHRs, incentives on the horizon

  • Briefings on HIPAA, Issue 10, October 1, 2009

    : The Health Information Technology for Economic and Clinical Health (HITECH) Act includes...

HIPAA Q&A: Health plans, remote workers, and more

  • Briefings on HIPAA, Issue 10, October 1, 2009

    Learn the answer to this and more HIPAA compliance questions from your peers.

Interim final rule: Significant challenges for BAs, covered entities

  • Briefings on HIPAA, Issue 10, October 1, 2009

    Adjusting to some of the new requirements will be difficult, but other aspects of the rule...

Briefings on HIPAA, October 2009

  • Briefings on HIPAA, Issue 10, October 1, 2009

    In this issue of BOH, you’ll learn of the challenges stakeholders face in adopting EHRs and...

Know the HIM director's role in shift to HIPAA 5010

  • JustCoding News: Inpatient, Issue 40, September 30, 2009

    A hospital’s information technology project list is likely exponential. The transition to...

The meaning of meaningful use and its future

  • HIM Connection, Issue 39, September 29, 2009

    Nothing is concrete, but the fog surrounding meaningful use—its eventual definition...

Breach notification compliance deadline has passed

  • HIPAA Weekly Advisor, Issue 36, September 28, 2009

    The compliance date on HHS' interim final rule on breach notification has passed. Are you ready to...

Tip: Build trust with the Notice of Privacy Practices

  • HIPAA Weekly Advisor, Issue 36, September 28, 2009

    Don't forget to dish out those Notice of Privacy Practices.

HIPAA Update hot posts

  • HIPAA Weekly Advisor, Issue 36, September 28, 2009

    What's hot on the HIPAA Update blog?

Revisit your sanctions policy with HITECH in mind

  • HIM Connection, Issue 36, September 8, 2009

    The Health Information Technology for Economic and Clinical Health (HITECH) Act provides a...

Medical Records Briefing, September 2009

  • Medical Records Briefing, Issue 9, September 1, 2009

    This month’s issue covers a wide variety of topics of interest to HIM directors. Our cover...

Briefings on HIPAA September 2009

  • Briefings on HIPAA, Issue 9, September 1, 2009

    In this issue of BOH, you’ll read about how privacy and security officers play a role in...

The meaning of meaningful use and its future

  • Briefings on HIPAA, Issue 9, September 1, 2009

    HHS will review the recommendations and release a proposed rule by the end of the year. The content...

Revisit your sanctions policy with HITECH Act in mind

  • Briefings on HIPAA, Issue 9, September 1, 2009

    Review, or even rewrite, your policy if you think it’s outdated, says Dena Boggan, CPC, CMC...

Q&A: Radiology images, contact with patient?s father, faxing pathology reports, and more

  • Briefings on HIPAA, Issue 9, September 1, 2009

    If a patient asks our radiology department for a CD of his study images for his or her use, must...

INFOSweep service helps ensure PHI destruction on copiers

  • Briefings on HIPAA, Issue 9, September 1, 2009

    The service should be of interest to covered entities and business associates that require secure...

Minnesota health system trains staff members and tracks participation success via an online system

  • Briefings on HIPAA, Issue 9, September 1, 2009

    Colleagues John Jensen and Ross T. Janssen, Esq., CISSP, knew they needed a training system that...

Money, money, money: Privacy breaches get costly

  • HIM Connection, Issue 35, September 1, 2009

    The cost of a privacy breach far exceeds any fines authorized by the Health Information for...

Q&A: Contacting patients by mail

  • HIPAA Weekly Advisor, Issue 32, August 31, 2009

    Learn the answer to this tough HIPAA compliance question.

Business associates -- who are you?

  • HIPAA Weekly Advisor, Issue 32, August 31, 2009

    Business associates need to know who they are regarding HIPAA rules. Covered entities do, too.

HHS releases interim final rule for breach notification, secure PHI

  • HIM Connection, Issue 34, August 25, 2009

    HHS released an interim final rule regarding breach notification and the acceptable methods for...

FTC issues final breach notification rule for electronic health information

  • HIPAA Weekly Advisor, Issue 31, August 24, 2009

    The rule was issued under the mandate from Congress in the American Recovery and Reinvestment Act...

Check out our new HIPAA Update blog!

  • HIM Connection, Issue 33, August 18, 2009

    Since HIPAA first took effect in 2003, HCPro, Inc. has been an industry leader in privacy and...

Privacy and security breaches: Make your sanctioning message loud and clear

  • HIM Connection, Issue 33, August 18, 2009

    Hospitals should take a tiered approach when establishing sanction policies that consider various...

Check out our new HIPAA Update blog!

  • HIPAA Weekly Advisor, Issue 30, August 17, 2009

    You will find all these training resources on our new blog, HIPAA Update.

Sebelius shifts HIPAA security rule enforcement to Civil Rights Office

  • HIM Connection, Issue 32, August 11, 2009

    The secretary of HHS shifted enforcement of the HIPAA security rule from CMS to the Office for...

Q&A: E-mail communication

  • HIPAA Weekly Advisor, Issue 29, August 10, 2009

    Learn the answer to this challenging HIPAA scenario.

OCR: The HIPAA enforcer?

  • HIPAA Weekly Advisor, Issue 29, August 10, 2009

    Now that OCR has the HIPAA Security Rule under its umbrella, does that mean more enforcement?

Check out our new HIPAA Update blog!

  • HIPAA Weekly Advisor, Issue 29, August 10, 2009

    Welcome to our new HIPAA Update blog -- your one-stop shopping for HIPAA privacy and security...

Red Flags deadline moved to November 1

  • HIM Connection, Issue 31, August 4, 2009

    On July 29, the Federal Trade Commission announced that—for a third time—it has pushed...

KP Bellfower unsure if it will appeal second fine connected to Octomom

  • HIPAA Weekly Advisor, Issue 28, August 3, 2009

    The hospital was also hit with a $250,000 fine on May 15 for similar privacy violations against...

Q&A: Keeping a record of HIPAA training files

  • HIPAA Weekly Advisor, Issue 28, August 3, 2009

    Learn the answer to your tough HIPAA privacy and security questions.

Red Flags Rule deadline pushed back again

  • HIPAA Weekly Advisor, Issue 28, August 3, 2009

    Red Flags was supposed to go into effect on November 1, 2008, but it was pushed back to May 1...

HIPAA happenings: Privacy and security breaches: Make your sanctioning message loud and clear to ensure compliance

  • Medical Records Briefing, Issue 8, August 1, 2009

    Covered entities (CE) and business associates (BA) are not required to follow HHS guidance...

Medical Records Briefing, August 2009

  • Medical Records Briefing, Issue 8, August 1, 2009

    This month’s issue covers a wide variety of topics of interest to HIM directors. Our cover...

Create a culture of compliance

  • Briefings on HIPAA, Issue 8, August 1, 2009

    HIPAA may not be fun to teach, learn, or execute because of its complexity, but it needn’t be...

Q&A: Breach notification, summer help, HIPAA compliance

  • Briefings on HIPAA, Issue 8, August 1, 2009

    A: If the fax included the patient’s Social Security number, you probably need to inform the...

The long road to justice after a privacy breach

  • Briefings on HIPAA, Issue 8, August 1, 2009

    Ingersoll’s story, which she shared at the 2008 HIPAA Summit in Boston, is an example of how...

Rhode Island health information exchange blazes consumer-driven path

  • Briefings on HIPAA, Issue 8, August 1, 2009

    The Rhode Island health information exchange (HIE), named “currentcare,” will go live...

Briefings on HIPAA, August 2009

  • Briefings on HIPAA, Issue 8, August 1, 2009

    In this issue of BOH, you’ll read about one healthcare worker’s battle to fight a...

AAHC: HIPAA privacy rule has significant effect on research administration, processes

  • Health Information Compliance Insider, Issue 8, August 1, 2009

    Colleagues John Jensen and Ross T. Janssen, Esq., CISSP, knew they needed a training system that...

Case study: Create a culture of HIPAA compliance

  • Health Information Compliance Insider, Issue 8, August 1, 2009

    HIPAA may not be fun to teach, learn, or execute because of its complexity, but it needn’t be...

Case study: Create a culture of HIPAA compliance

  • HIM Connection, Issue 30, July 28, 2009

    You’re a HIPAA expert and a trainer in a hospital, which means two things are certain: You...

Health information exchanges see 40% growth from previous year

  • HIPAA Weekly Advisor, Issue 27, July 27, 2009

    In 2009 and 2010, HIEs are expected to see new opportunities with the American Recovery and...

Tips to get your business associates to comply with HIPAA

  • HIPAA Weekly Advisor, Issue 27, July 27, 2009

    The language in your business associate agreement should require the BA to notify the covered...

Q&A: Active duty members on the move

  • HIPAA Weekly Advisor, Issue 26, July 20, 2009

    The answers to your toughest HIPAA questions.

HHS hiring health information privacy specialists

  • HIPAA Weekly Advisor, Issue 26, July 20, 2009

    HHS is hiring privacy specliasts. What does this mean for enforcement?

Hospital slapped with second six-figure fine -- again

  • HIPAA Weekly Advisor, Issue 26, July 20, 2009

    This hospital did not learn from its first privacy mistake.

Minnesota health system trains staff and tracks participation success via an online system

  • Health Information Compliance Insider, Issue 8, July 16, 2009

    Perhaps the most revealing results pertained to research administration and processes, where the...

Ensure red flag compliance before August 1

  • HIM Connection, Issue 28, July 14, 2009

    The Federal Trade Commission (FTC) developed the Red Flags Rule pursuant to the Fair and Accurate...

Physician resistance remains obstacle to EHRs

  • HIPAA Weekly Advisor, Issue 24, July 6, 2009

    Now that hospitals have a draft of the meaningful use criteria that the Health Information...

Major privacy breaches: How to respond to their unique challenges with notifying patients, government

  • Health Information Compliance Insider, Issue 7, July 1, 2009

    All organizations must develop a plan for every scenario, even the nightmares you’d prefer...

Compliance update: FTC moves Red Flags Rule compliance deadline to August 1

  • Health Information Compliance Insider, Issue 7, July 1, 2009

    The FTC announced in early May that it delayed enforcement of the rule to give creditors and...

Breach notification requirements: FTC, HHS move forward with PHR breach notification guidelines

  • Health Information Compliance Insider, Issue 7, July 1, 2009

    The Health Information Technology for Economic and Clinical Health (HITECH) Act specifies the...

Health Information Compliance Insider®, July 2009

  • Health Information Compliance Insider, Issue 7, July 1, 2009

    In this issue of HICI, you’ll learn about where HHS is in terms of defining unsecure PHI...

Major privacy breaches: How to respond to their unique challenges with notifying patients, government

  • Briefings on HIPAA, Issue 7, July 1, 2009

    All organizations must develop a plan for every scenario, even the nightmares you’d prefer...

Q&A: Hospice communication, home computer use, outgoing mail, and more

  • Briefings on HIPAA, Issue 7, July 1, 2009

    Learn the answer to this and more of your challenging HIPAA questions.

HIPAA and the HITECH Act: HHS proposed guidance offers framework for securing PHI

  • Briefings on HIPAA, Issue 7, July 1, 2009

    The new HHS guidance, which is still at the draft stage, provides acceptable encryption and...

Hospitals may put patients in control of record sharing

  • Briefings on HIPAA, Issue 7, July 1, 2009

    “What if the decision to share information is the patient’s rather than the...

Release of information to patients and minimum necessary requirements

  • HIM Connection, Issue 26, June 30, 2009

    Q: When patients ask us to release their entire record, must we restrict disclosure to the minimum...

Ensure confidentiality when faxing patient information

  • HIM Connection, Issue 26, June 30, 2009

    HIPAA does not address faxing patient information specifically, but does protect it under the...

CMS issues fact sheet on HITECH Act

  • HIPAA Weekly Advisor, Issue 23, June 29, 2009

    Want to know all about the HITECH? CMS has a fact sheet for you.

Q&A: Hospice scenario

  • HIPAA Weekly Advisor, Issue 23, June 29, 2009

    Get your answers to the toughest HIPAA questions from your colleagues.

HIPAA 5010 requires IT to do more with fewer resources

  • HIPAA Weekly Advisor, Issue 23, June 29, 2009

    HIPAA 5010 is part of a growing laundry list of chores for providers out there today.

Many business associates not ready to comply with HIPAA

  • HIPAA Weekly Advisor, Issue 23, June 29, 2009

    Are business associates ready to comply with HITECH? Do you know who your BAs are? Some covered...

Sneak peek: White paper examines HIPAA and business associates

  • HIPAA Weekly Advisor, Issue 22, June 22, 2009

    What do you and your BAs need to know about new HIPAA laws? Here's a small slice.

Q&A: X-ray results

  • HIPAA Weekly Advisor, Issue 22, June 22, 2009

    The answers to your tough HIPAA compliance questions.

Meaningful use first draft could guide final definition

  • HIPAA Weekly Advisor, Issue 22, June 22, 2009

    The final definition of "meaningful use" could be quite different when CMS issues a...

TIP: Include Red Flags requirements in any new BA agreement

  • HIPAA Weekly Advisor, Issue 21, June 15, 2009

    Here's a tip on complying with the Red Flags Rule: Get it into your contract with a business...

HIPAA 5010 is one small, but necessary step toward ICD-10

  • HIPAA Weekly Advisor, Issue 21, June 15, 2009

    Before ICD-10, there's the HIPAA Version 5010. And you must be ready to comply.

Health Information Exchange will allow patients to share medical information

  • HIPAA Weekly Advisor, Issue 21, June 15, 2009

    Rhode Island patients can share their information with their state -- if they want to.

Plan for the future and trust that your revamped policies are sound

  • HIM Connection, Issue 23, June 9, 2009

    As technology grows, evolves, and spawns newer versions of itself, security and privacy challenges...

Q&A: Billing department

  • HIPAA Weekly Advisor, Issue 20, June 8, 2009

    The HIPAA privacy rule addresses disclosure of PHI for treatment and payment purposes and permits...

CVS works on patient privacy improvements following fine

  • HIPAA Weekly Advisor, Issue 20, June 8, 2009

    CVS promises it is working diligently on protecting patients' privacy.

Red Flags Rule: Comply now, avoid lawsuit later

  • HIPAA Weekly Advisor, Issue 20, June 5, 2009

    Red Flags Rule -- comply today. Be thankful you avoided public scrutiny tomorrow.

BA agreements: Consider additions to new contracts

  • HIM Connection, Issue 22, June 2, 2009

    The American Recovery and Reinvestment Act of 2009 hit business associates (BA) hard because they...

Understand the requirements for the privacy, security, and integrity of health information: IM.02.01.01 and IM.02.01.03

  • Medical Records Briefing, Issue 6, June 1, 2009

    Although the privacy, security, and integrity of health information have not been subjected to...

Health Information Compliance Insider®, June 2009

  • Health Information Compliance Insider, Issue 6, June 1, 2009

    In this issue of HICI, you?ll learn about the small changes you can make now to BA contracts in...

Medical Records Briefing, June 2009

  • Medical Records Briefing, Issue 6, June 1, 2009

    This month’s issue is full of time-saving tips and guidance. Our EHR beat column features one...

Q&A: Airlines calls

  • HIPAA Weekly Advisor, Issue 19, June 1, 2009

    Your answer to a HIPAA compliance question.

TIP: Put plan into action to comply with HITECH

  • HIPAA Weekly Advisor, Issue 19, June 1, 2009

    Here's a few ways to get started with compliance of HITECH.

HITECH UPDATE: HIPAA enforcement promises, but lacks specifics

  • HIPAA Weekly Advisor, Issue 19, June 1, 2009

    HHS has issued a report on what it's done since the American Recovery and Reinvestment Act of 2009...

Tenet employee charged with theft, HIPAA violations

  • HIPAA Weekly Advisor, Issue 19, June 1, 2009

    A Tenet Healthcare Corp. employee faces charges of access device fraud, criminal HIPAA violations...

Briefings on HIPAA June 2009

  • Briefings on HIPAA, Issue 6, June 1, 2009

    In this issue of BOH, you’ll learn how an effective risk assessment can be a money-saver (and...

Plan for the future and trust that your revamped policies are sound

  • Briefings on HIPAA, Issue 6, June 1, 2009

    You don’t have to know everything about new technology at once. Instead, start by following...

Risk and reward: Assess vulnerabilities now; avoid breaches later

  • Briefings on HIPAA, Issue 6, June 1, 2009

    Risk assessment is a process intended to protect the enterprise, its assets, and its ability to...

Q&A: Hospice staff, remote paperwork, and more

  • Briefings on HIPAA, Issue 6, June 1, 2009

    The answers to your challenging HIPAA questions.

AAHC: Privacy rule an obstacle course for biomedical research; HIPAA must be revisited

  • Briefings on HIPAA, Issue 6, June 1, 2009

    In January, the AAHC published The HIPAA Privacy Rule: Lacks Patient Benefit, Impedes Research...

CMS explains the importance of HIPAA 5010

  • HIM Connection, Issue 21, May 26, 2009

    CMS issued a special edition Medlearn Matters article (SE0904) that provides an overview of the...

Hackers breach college database

  • HIPAA Weekly Advisor, Issue 18, May 18, 2009

    Another breach of PHI by computer hackers has a university scrambling to notify people of 160,000...

Q&A: Retention of medical records

  • HIPAA Weekly Advisor, Issue 18, May 18, 2009

    The answers to your tough HIPAA questions.

REMINDER: Make your comments heard by HHS

  • HIPAA Weekly Advisor, Issue 18, May 18, 2009

    Let your thoughts be heard about unsecure PHI with HHS.

Review new AHIMA practice brief on sanction guidelines for privacy and security breaches

  • HIM Connection, Issue 19, May 12, 2009

    AHIMA released a new practice brief May 2 that addresses the importance of creating a united...

HITECH Act: Understand the changes to BA agreements

  • HIM Connection, Issue 18, May 5, 2009

    President Obama’s American Recovery and Reinvestment Act of 2009—specifically Title...

Medical Records Briefing May 2009

  • Medical Records Briefing, Issue 5, May 1, 2009

    This month’s issue is full of time-saving tips and guidance related to

Crack down on unauthorized uses and disclosures with your EHR?s audit log

  • Medical Records Briefing, Issue 5, May 1, 2009

    If you’re thinking about taking advantage of the incentive payments under the American...

Make medical identity theft prevention a top priority

  • Medical Records Briefing, Issue 5, May 1, 2009

    Medical identity theft is an ugly reality for healthcare organizations, patients, and payers...

Red Flags Rule enforcement delayed until August 1

  • HIM Connection, Issue 18, May 1, 2009

    The Federal Trade Commission (FTC) has extended the Red Flags Rule enforcement deadline to August 1...

HHS outlines ways to secure PHI, create safe harbor against security breach notification

  • HIM Connection, Issue 17, April 28, 2009

    HHS published guidance April 17 that identifies the technologies and methodologies that render...

Crack down on unauthorized use and disclosure of PHI with your EHR's audit log

  • HIM Connection, Issue 17, April 28, 2009

    If you’re thinking about taking advantage of the incentive payments for EHR implementation...

Q&A: Patient photographs

  • HIPAA Weekly Advisor, Issue 15, April 27, 2009

    How do you comply with HIPAA working with patient photographs?

HITECH UPDATE: Check your current system against HHS draft guidance

  • HIPAA Weekly Advisor, Issue 15, April 27, 2009

    Miss HHS' draft guidance on securing PHI? We've got it.

Business associates: HIPAA survey

  • HIPAA Weekly Advisor, Issue 15, April 27, 2009

    How should your business associates be trained? We want to know.

Groups oppose HHS Secretary nominee

  • HIPAA Weekly Advisor, Issue 15, April 27, 2009

    Senators are scheduled to vote on President Barack Obama's nomination for Secretary of HHS early...

Comment on security breach notification rule that targets personal health records

  • HIM Connection, Issue 16, April 21, 2009

    If you’ve got an opinion on the proposed rule to require vendors of a personal health record...

Review new FTC Red Flag rule guidance

  • HIM Connection, Issue 16, April 21, 2009

    The Federal Trade Commission (FTC) published a guide, Fighting Fraud with the Red Flags Rule: A...

HITECH UPDATE: HHS misses deadline for definition of unsecured PHI

  • HIPAA Weekly Advisor, Issue 14, April 20, 2009

    Looking for a new definition of unsecured protected health information?

Q&A: Diagnostic test results

  • HIPAA Weekly Advisor, Issue 14, April 20, 2009

    Learn the answers to your toughest HIPAA questions.

How should business associates train staff members?

  • HIPAA Weekly Advisor, Issue 14, April 20, 2009

    Business associates must be trained on the HIPAA Security Rule. We want to know what you think is...

Comment on security breach notification rule that targets personal health records

  • HIPAA Weekly Advisor, Issue 14, April 20, 2009

    The FTC will publish an interim final regulation no later than August 17, which is 180 days after...

Enforcement reaches new level: HITECH Act features stiffer penalties for privacy breaches

  • HIM Connection, Issue 15, April 14, 2009

    It’s just one part of the much-publicized American Recovery and Reinvestment Act of 2009, but...

Tip: Use OCR privacy and security guidance as a framework

  • HIPAA Weekly Advisor, Issue 13, April 13, 2009

    Organizations should use these OCR principles to better understand how they can exchange...

Red Flags Rule guidance published

  • HIPAA Weekly Advisor, Issue 13, April 13, 2009

    Red Flags Rule compliance is May 1. Here's a report the FTC released to get you on track.

Q&A: Accessing your own information

  • HIPAA Weekly Advisor, Issue 14, April 13, 2009

    Learn the answer to this important HIPAA compliance question.

HITECH UPDATE: How should business associates train staff members?

  • HIPAA Weekly Advisor, Issue 14, April 13, 2009

    How are business associates going to train staff members in light of the new HIPAA laws?

World Privacy Forum publishes HIPAA guide for patients

  • HIM Connection, Issue 14, April 7, 2009

    The World Privacy Forum announced its publication of a comprehensive HIPAA privacy guide written...

Employees fired for viewing mother of eight's records

  • HIPAA Weekly Advisor, Issue 13, April 6, 2009

    Here's what happens when a few staff members get nosey with a patient's record.

TIP: Review your 'hospice' signs for cars

  • HIPAA Weekly Advisor, Issue 13, April 6, 2009

    Any time you have a car with a sign that mentions you volunteer at a hospice, it could affect a...

HIPAA and the HITECH Act: Get your breach notification ready

  • HIPAA Weekly Advisor, Issue 13, April 6, 2009

    The HITECH calls for breach notification requirements for covered entities and business associates...

Q&A: Text messaging

  • HIPAA Weekly Advisor, Issue 13, April 6, 2009

    Are you text messaging information about patients? Know the answers regarding HIPAA concerns.

Q&A: Workers' compensation, minors' privacy, and more

  • Briefings on HIPAA, Issue 4, April 1, 2009

    Learn the answers to the toughest questions on HIPAA from our experts

HIE guidance just a framework for successful compliance

  • HIM Connection, Issue 13, March 31, 2009

    As part of its December 2008 Privacy and Security Toolkit, the Office for Civil Rights discussed...

Report: 1.5% of hospitals have EHRs

  • HIPAA Weekly Advisor, Issue 12, March 30, 2009

    Patients must have EHRs by 2014. About only 1.5% of hospitals have them, a new study says.

TIP: Know the basics of data encryption

  • HIPAA Weekly Advisor, Issue 12, March 30, 2009

    If you are looking to encrypt your data on patient records, here are some basic things to know.

HIPAA and the HITECH Act: Know all the provisions

  • HIPAA Weekly Advisor, Issue 12, March 30, 2009

    Know the major provisions in the HITECH Act? How about these, too?

Q&A: State-prison patients

  • HIPAA Weekly Advisor, Issue 12, March 30, 2009

    After a person is released from prison is it a HIPAA violation to release the patient’s...

Security breach exposes 1,000 SSNs

  • HIPAA Weekly Advisor, Issue 11, March 23, 2009

    An electronic security breach may have exposed 1,000 Social Security Numbers.

HIPAA and the HITECH Act: Mark these important dates

  • HIPAA Weekly Advisor, Issue 11, March 23, 2009

    Mark these important dates down on your HIPAA calendar.

Q&A: Funeral homes

  • HIPAA Weekly Advisor, Issue 11, March 23, 2009

    Funeral homes can call your covered entity with requests for patient information. How do you handle...

HIPAA, patient labels, and armbands

  • HIM Connection, Issue 11, March 17, 2009

      Q. Is it a breach of patient privacy and confidentiality if we print the patient’s...

Mark it down: Red flags rule compliance deadline is May 1

  • HIM Connection, Issue 11, March 17, 2009

    Medical identity theft is an ugly reality for healthcare organizations, patients, and payers...

Got a HIPAA case study?

  • HIPAA Weekly Advisor, Issue 10, March 16, 2009

    Got a success story regarding your HIPAA compliance or training program? Let us know.

TIP: Provide ongoing contract maintenance with your BA

  • HIPAA Weekly Advisor, Issue 10, March 16, 2009

    Business associates have new compliance requirements regarding the HIPAA Security Law. Here are a...

Google admits to privacy breach

  • HIPAA Weekly Advisor, Issue 10, March 16, 2009

    Google made a mistake you do not want to at your facility regarding software and patient records.

HIPAA and the HITECH Act: Know the level of penalties

  • HIPAA Weekly Advisor, Issue 10, March 16, 2009

    The federal goverment changed the penalties for privacy breaches. Here's how the break down.

Q&A: Working with police

  • HIPAA Weekly Advisor, Issue 10, March 16, 2009

    Does your facility come in contact with police warning you about patients who are addicted to...

TIP: Check out new FAQs about disposing PHI

  • HIPAA Weekly Advisor, Issue 9, March 9, 2009

    Got PHI questions? The Office for Civil Rights (OCR) may have your answer.

Q&A: Incarcerated spouse

  • HIPAA Weekly Advisor, Issue 9, March 9, 2009

    Learn the answer to this HIPAA question from one of our readers.

Obama looks to Kansas governor to lead HHS

  • HIPAA Weekly Advisor, Issue 9, March 9, 2009

    U.S. President leaned toward Kansas to find his pick as for the new head of HHS.

Understand the economic stimulus package’s effect on HIPAA

  • HIM Connection, Issue 9, March 3, 2009

    On February 17, U.S. President Barack Obama signed into law a $787 billion economic American...

Healthcare operations: How to approach HIPAA privacy rule ambiguity

  • HIM Connection, Issue 9, March 3, 2009

    When the OCR revised the HIPAA privacy rule in 2003, it specified accepted uses and disclosures for...

Q: Do patients need to renew HIPAA acknowledgements every year?

  • HIPAA Weekly Advisor, Issue 8, March 2, 2009

    Q: Do patients need to renew HIPAA acknowledgements every year?

Report issued on privacy protections applicable to electronic information

  • HIPAA Weekly Advisor, Issue 8, March 2, 2009

    The economic stimulus package approved on Feb. 17 included billions of dollars for health...

Reno judge says HIPAA doesn't prevent physician from sharing PHI

  • HIPAA Weekly Advisor, Issue 8, March 2, 2009

    HIPAA doesn’t prevent attorneys from questioning physicians about their patients&rsquo...

Tip: Comply with PCI DSS to help ensure the security of your patients' financial information

  • HIPAA Weekly Advisor, Issue 8, March 2, 2009

    The Payment Card Industry Security Standards Council updated its Payment Card Industry Data...

Tip: Get your 'board' on board by being prepared

  • HIPAA Weekly Advisor, Issue 6, February 23, 2009

    At some point, you will need to present an idea to your board of directors. Here’s one way to...

Understand the economic stimulus package's effects on HIPAA

  • HIPAA Weekly Advisor, Issue 6, February 23, 2009

    U.S. President Barack Obama signed into law last week an economic stimulus Act that has major...

Q&A: prescription records

  • HIPAA Weekly Advisor, Issue 6, February 23, 2009

    Q. May a spouse obtain the prescription records of an incarcerated spouse without written...

CVS to pay $2.25 million settlement for potential privacy breaches

  • HIPAA Weekly Advisor, Issue 6, February 23, 2009

    CVS will pay the price for potential privacy breaches on millions of patients’ records.

Take care when releasing protected health information to a funeral home

  • HIM Connection, Issue 7, February 17, 2009

    Q. Funeral homes sometimes call requesting a deceased patient’s Social Security number (SSN...

New HHS Web site

  • HIPAA Weekly Advisor, Issue 5, February 16, 2009

    HHS launched a new Web site including content on HIPAA regulations under a user-friendly format.

Tip: Get your 'board' on board

  • HIPAA Weekly Advisor, Issue 5, February 16, 2009

    Most providers will need to present an idea to their board of directors. Here’s one tip to...

Q&A: Notices of privacy practices

  • HIPAA Weekly Advisor, Issue 5, February 16, 2009

    Q. Do notices of privacy practices (NPP) apply to business associates of a covered entity, such as...

Economic stimulus bill set to arrive on Obama's desk

  • HIPAA Weekly Advisor, Issue 5, February 16, 2009

    The only step left to approve a $787 billion economic stimulus bill is President Barack...

PHRs: New consumer-driven trend can lead to better care, but also privacy challenges

  • HIM Connection, Issue 6, February 10, 2009

    As healthcare continues its push toward more transparency, consumers are taking a more proactive...

Tip: Make HIPAA training fun

  • APCs Weekly Monitor, Issue 6, February 6, 2009

    Mandatory HIPAA training usually generates the same excitement as a trip to the dentist. Sure, you...

Implement safeguards to prevent medical identity theft

  • HIM Connection, Issue 5, February 3, 2009

    You’ve undoubtedly seen the headlines and silently hoped it wouldn’t happen to your...

Address data encryption in 2009

  • HIM Connection, Issue 5, February 3, 2009

    Eat better, go to the gym more often, and take up a hobby; these are all fine New Year’s...

Tip: Make HIPAA training fun

  • HIPAA Weekly Advisor, Issue 3, February 2, 2009

    Want to make your HIPAA training a little more fun? Use the example of this facility and bring...

Q&A: Overhead paging

  • HIPAA Weekly Advisor, Issue 3, February 2, 2009

    Q. Is overhead paging a patient by name back to a clinic or hospital area a HIPAA violation? Learn...

HHS releases final medical identity theft report

  • HIPAA Weekly Advisor, Issue 3, February 2, 2009

    The consumer should be the key focus for consideration of prevention, detection, and remediation of...

VA agrees to pay $20 million to settle identity theft suit

  • HIPAA Weekly Advisor, Issue 3, February 2, 2009

    The VA must pay its veterans -- $20 million. The department settled a class-action lawsuit by five...

Report: HIPAA privacy rule negatively affects research

  • HIPAA Weekly Advisor, Issue 3, February 2, 2009

    The healthcare industry needs to be better on research. We can start by revising the HIPAA privacy...

Confront ROI challenges: Proceed with caution in situations involving sensitive conditions

  • Medical Records Briefing, Issue 2, February 1, 2009

    Sensitive scenarios require extra attention when releasing protected health information. Ensure...

AHIMA practice brief provides general ROI guidance

  • Medical Records Briefing, Issue 2, February 1, 2009

    When it comes to release of information (ROI), there is no one-stop shop that provides HIM...

Updated CoP reflect privacy, security, EHRs, and more

  • Medical Records Briefing, Issue 2, February 1, 2009

    EHRs, patient safety, privacy, and security are among the common themes in official updates to the...

ONC releases final report on medical identity theft

  • HIM Connection, Issue 4, January 27, 2009

    On January 15, the Office of the National Coordinator for Health Information Technology released a...

Updated CoP reflect privacy, security, EHRs, and more

  • HIM Connection, Issue 4, January 27, 2009

    EHRs, patient safety, privacy, and security are among the common themes in official updates to the...

Tip: Use these agenda items for office training

  • HIPAA Weekly Advisor, Issue 2, January 26, 2009

    You can never have enough HIPAA privacy and security training at your facility -- especially your...

WV health department warns patients of identity theft

  • HIPAA Weekly Advisor, Issue 2, January 26, 2009

    A West Virginia town’s health department officials identified a former temporary billing...

Insurer must show policy to prevent PHI breach

  • HIPAA Weekly Advisor, Issue 2, January 26, 2009

    BlueCross sent “explanation of benefit” forms to members in November that also featured...

Take advantage of newly-released medical identity theft resources

  • HIM Connection, Issue 3, January 20, 2009

    If you missed the October 15, 2008 day-long medical identity theft town hall meeting sponsored by...

NIST releases guide to protect confidentiality of PII

  • HIPAA Weekly Advisor, Issue 1, January 19, 2009

    Get your information on protecting the confidentiality of PII from NIST via its new release.

HHS releases update to Surgeon General's 'New Family Health History Tool'

  • HIPAA Weekly Advisor, Issue 1, January 19, 2009

    Consumers will be happy with this update as far as sharing their family health history.

Tip: Avoid these pitfalls at physician practices

  • HIPAA Weekly Advisor, Issue 1, January 19, 2009

    Physicians’ offices are not bereft of HIPAA compliance issues.

Data privacy in 2009: Expect stepped up red-flag enforcement

  • HIPAA Weekly Advisor, Issue 1, January 12, 2009

    Red flag -- get ready for red flag identity theft rules, which are mandatory May 1, 2009.

Officials to launch PHR Choice program this week

  • HIPAA Weekly Advisor, Issue 1, January 12, 2009

    Americans want more of a choice with healthcare, and HHS is ready to give it to them.

Privacy/security job titles

  • HIPAA Weekly Advisor, Issue 1, January 12, 2009

    You need to know if the roles of your privacy and security officers are compliant. Find out here.

TIP: Keep an eye on legislation in new Congress

  • HIPAA Weekly Advisor, Issue 1, January 12, 2009

    The Obama era begins this month. You should begin watching his Congress now.

Review new HHS draft model PHR privacy notice

  • HIM Connection, Issue 1, January 6, 2009

    On December 15, the Department of Health and Human Services (HHS) announced its initiation of the...

One health system implements a patient portal as a first step toward a fully integrated PHR

  • Medical Records Briefing, Issue 1, January 1, 2009

    Care New England, a three-hospital system in Rhode Island, was familiar with the acronym PHR...

Benchmarking survey: PHRs remain unchartered territory for some

  • Medical Records Briefing, Issue 1, January 1, 2009

    Personal health records (PHR) can literally change the world. Sound a bit lofty? Kerry Weems...

Form a discovery response team to effectively implement legal holds

  • HIM Connection, Issue 51, December 30, 2008

    The first step in creating a legal hold plan is the formation of a discovery response team.

TIP: How to set up your 'honeypots'

  • HIPAA Weekly Advisor, Issue 51, December 15, 2008

    Last week’s issue discussed the use of “honeypots,” fictitious medical records...

Employee posts remarks about patients on Web site

  • HIPAA Weekly Advisor, Issue 51, December 15, 2008

    An employee of a McKees Rocks, PA, OB/GYN office who posted unfavorable comments about patients on...

Massachusetts patients' information lost on stolen computer

  • HIPAA Weekly Advisor, Issue 51, December 15, 2008

    A laptop containing the PHI of approximately 50 patients was stolen from Salem (MA) Hospital, the...

Breach notification

  • HIPAA Weekly Advisor, Issue 51, December 15, 2008

    Q. It’s my understanding that HIPAA doesn’t require breach notification except through...

Tip: Use 'honeypots' to catch snooping employees

  • HIPAA Weekly Advisor, Issue 50, December 8, 2008

    Some facilities use “honeypots” as bait to catch snooping staff members who are in...

Data Privacy Day

  • HIPAA Weekly Advisor, Issue 50, December 8, 2008

    The International Association of Privacy Professions and Intel have teamed up to dedicate January...

Report on FERPA and HIPAA

  • HIPAA Weekly Advisor, Issue 50, December 8, 2008

    The Departments of Education and HHS recently issued guidance on the Family Educational Rights and...

Health plans

  • HIPAA Weekly Advisor, Issue 50, December 8, 2008

    A. A health plan can use Microsoft Outlook to exchange PHI with network physicians, but only if it...

A sweet tool to monitor snooping staff

  • APCs Weekly Monitor, Issue 49, December 5, 2008

    To catch snooping staff, some hospitals and other HIPAA-covered entities use fictitious medical...

Educators call for Electronic Health Records protection

  • HIPAA Weekly Advisor, Issue 48, December 1, 2008

    Two professors at Case Western Reserve University in Cleveland have called for increasing oversight...

Cover your ground on remote access employees

  • HIPAA Weekly Advisor, Issue 48, December 1, 2008

    Your remote access employees must follow company protocol for HIPAA compliance. In fact, you should...

Healthcare employee fired after leaving laptop unattended

  • HIPAA Weekly Advisor, Issue 48, December 1, 2008

    Vandals stole an unattended laptop that included health information of 100,000 patients from the...

Media inquiries

  • HIPAA Weekly Advisor, Issue 48, December 1, 2008

    Q. A member of the media contacts a hospital to inquire about a particular patient and identifies...

Certified career boosters: How credentials help you

  • Health Information Compliance Insider, Issue 12, December 1, 2008

    All you need is a few dollars, a few classes, and a passing exam grade, and those few letters...

Ensure safe transfer of PHI when selling a practice

  • Health Information Compliance Insider, Issue 12, December 1, 2008

    Every day, in every industry, businesses are bought and sold, new management replaces old...

Honeypots: A sweet tool you can use to monitor snooping staff members

  • Health Information Compliance Insider, Issue 12, December 1, 2008

    It doesn’t matter whether a staff member peeks at the medical record of Tiger Woods, John...

Health Information Compliance Insider December 2008

  • Health Information Compliance Insider, Issue 12, December 1, 2008

    Health Information Compliance Insider® December 2008 Inside: Honeypots: A sweet tool you can...

Home secure home: Mitigate remote access risks

  • Briefings on HIPAA, Issue 12, December 1, 2008

    Your healthcare facility today probably allows or has pondered the idea of allowing employees to...

Certified career boosters: How credentials help you

  • Briefings on HIPAA, Issue 12, December 1, 2008

    All you need is a few dollars, a few classes, and a passing exam grade, and those few letters...

Honeypots: A sweet tool for monitoring snooping

  • Briefings on HIPAA, Issue 12, December 1, 2008

    It doesn’t matter whether a staff member peeks at the medical record of Tiger Woods, John...

Lax enforcement? Not under the OIG’s watch

  • Briefings on HIPAA, Issue 12, December 1, 2008

    The Office of Inspector General (OIG) recently criticized CMS’ lack of HIPAA security rule...

Tip: Disaster preparedness

  • HIPAA Weekly Advisor, Issue 47, November 24, 2008

    You can never be too prepared for a disaster at your facility – for not only tornados...

AHIMA provides ROI guidelines

  • HIPAA Weekly Advisor, Issue 47, November 24, 2008

    The American Health Information Management Association (AHIMA) released an article aimed at helping...

Taking vitals

  • HIPAA Weekly Advisor, Issue 47, November 24, 2008

    Q. Do nurses violate HIPAA when they give patients injections or take their vital signs in public...

Consider AHA-endorsed tools to protect against medical identity theft

  • HIM Connection, Issue 45, November 18, 2008

    The American Hospital Association (AHA) announced in a November 4 press release that it has...

Tip: Ensure that staff members' cell phone use is compliant

  • HIPAA Weekly Advisor, Issue 46, November 17, 2008

    Transmitting PHI via cell phone or BlackBerry—whether verbally, via text message, or...

NIST releases guidelines for cell phone and PDA security

  • HIPAA Weekly Advisor, Issue 46, November 17, 2008

    The National Institute of Standards and Technology (NIST) released publication SP 800-124...

AHA endorses tool to protect against medical identity theft

  • HIPAA Weekly Advisor, Issue 46, November 17, 2008

    The American Hospital Association (AHA) announced in a November 4 press release that it has...

Jury duty

  • HIPAA Weekly Advisor, Issue 46, November 17, 2008

    A. Answering the court’s questions with the minimum information necessary would not have...

Protect ePHI in light of new OIG report

  • HIM Connection, Issue 44, November 11, 2008

    The Office of Inspector General (OIG) issued a final report October 27 reviewing CMS’ HIPAA...

Tip: Update and practice your disaster plan with staff members

  • HIPAA Weekly Advisor, Issue 45, November 10, 2008

    Frequent practice is essential to protecting patient information, maintaining business operations...

AHIMA reiterates importance of protecting privacy and security of health records

  • HIPAA Weekly Advisor, Issue 45, November 10, 2008

    The recent rash of privacy and security breaches involving high-profile victims illustrates the...

OIG calls HIPAA security rule oversight and enforcement ineffective

  • HIPAA Weekly Advisor, Issue 45, November 10, 2008

    The Office of Inspector General (OIG) issued a largely critical final report October 27 reviewing...

Registration area

  • HIPAA Weekly Advisor, Issue 45, November 10, 2008

    Q. We have a new registration area with a counter where patients sit when registering and signing...

What steps must we follow when disciplining employees involved in a privacy breach?

  • HIM Connection, Issue 43, November 4, 2008

    Ask the expert: What steps must we follow when disciplining employees involved in a privacy breach?

Use AHA sample policy to jump start compliance with red flag rules

  • HIM Connection, Issue 43, November 4, 2008

    On October 24 the American Hospital Association (AHA) published a sample policy hospitals can use...

Tip: Staff training is critical in preventing identity theft and complying with FTC 'Red Flags' rule

  • HIPAA Weekly Advisor, Issue 44, November 3, 2008

    Your healthcare organization may already have an identity theft policy in place to mitigate the...

NIST releases revised resource guide for implementing the HIPAA security rule

  • HIPAA Weekly Advisor, Issue 44, November 3, 2008

    The National Institute of Standards and Technology (NIST) released publication SP 800-66 Revision...

Q. Does HIPAA prohibit nursing departments from keeping patient care flow sheets in closed folders in patient rooms?

  • HIPAA Weekly Advisor, Issue 44, November 3, 2008

    A. Flow sheets should contain the minimum necessary information because they may be accessible to...

Discipline with the intent to educate when responding to HIPAA violations to minimize future incidents

  • Health Information Compliance Insider, Issue 11, November 1, 2008

    Despite the thoroughness of your policies and procedures, the effectiveness of your training, and...

Disaster preparedness: Design, update, and practice your disaster recovery and business continuity plans

  • Health Information Compliance Insider, Issue 11, November 1, 2008

    Disasters aren’t a threat only in areas susceptible to tornados, earthquakes, hurricanes...

Keep cell phone use compliant

  • Health Information Compliance Insider, Issue 11, November 1, 2008

    People use cell phones to chat with friends and family, send text messages, and photograph each...

Health Information Compliance Insider, November 2008

  • Health Information Compliance Insider, Issue 11, November 1, 2008

    Inside: Keep cell phone use compliant Disaster preparedness: Design, update, and practice your...

HIPAA: Transcription, breaches, and PHI for research

  • Medical Records Briefing, Issue 11, November 1, 2008

    Q. May a transcriptionist type a medical report pertaining to a visit between the physician and a...

Understand the details of personal health records to serve as a valuable patient resource

  • Medical Records Briefing, Issue 11, November 1, 2008

    This scenario is becoming increasingly common: A patient presents to the HIM department and...

Flag identity theft as federal rule takes effect

  • Medical Records Briefing, Issue 11, November 1, 2008

    Although identity theft is often associated with exploited credit cards, patients can also be...

Briefings on HIPAA, November 2008

  • Briefings on HIPAA, Issue 11, November 1, 2008

    Inside: Flag identity theft as federal rule takes effect Q&A: Handle flower deliveries, media...

Flag identity theft as federal rule takes effect

  • Briefings on HIPAA, Issue 11, November 1, 2008

    Although identity theft is often associated with exploited credit cards, patients can also be...

Q&A: Handle flower deliveries, media requests, and more

  • Briefings on HIPAA, Issue 11, November 1, 2008

    Learn the answers to the toughest HIPAA questions on privacy and security.

Disaster preparedness: Design, update, practice your plan

  • Briefings on HIPAA, Issue 11, November 1, 2008

    Disasters aren’t a threat only in areas susceptible to tornados, earthquakes, hurricanes...

Confront release of information challenges

  • Briefings on HIPAA, Issue 11, November 1, 2008

    Occasionally, special situations arise in which a patient may be unable to execute an authorization...

Trust in CellTrust’s Mobile Healthcare Solution messaging

  • Briefings on HIPAA, Issue 11, November 1, 2008

    Mobile devices, especially smart phones, have become increasingly important in healthcare.

Discipline with the intent to educate

  • Briefings on HIPAA, Issue 11, November 1, 2008

    Despite the thoroughness of your policies and procedures, the effectiveness of your training, and...

Nevada, Massachusetts, other states enacting regulations to prevent data breaches

  • HIPAA Weekly Advisor, Issue 43, October 27, 2008

    Thanks to new legislation, protecting people’s data is now of primary importance in several...

Study examines costs, benefits of unique patient identifiers

  • HIPAA Weekly Advisor, Issue 43, October 27, 2008

    Providing every person with a unique patient identification number would be worth the high price...

FTC suspends enforcement of red flags medical identity theft rule

  • HIPAA Weekly Advisor, Issue 43, October 27, 2008

    The Federal Trade Commission (FTC) has extended the red flags medical identity theft rule...

Q. Our state health department mails surveys to patients about their HIV status.

  • HIPAA Weekly Advisor, Issue 43, October 27, 2008

    Q. Our state health department mails surveys to patients about their HIV status. The exterior of...

Nurse fired after publicizing altercation with law enforcement over patient privacy

  • HIPAA Weekly Advisor, Issue 42, October 20, 2008

    San Juan Regional Medical Center has terminated the employment of a nurse who publicized an...

Experts says medical identity theft legislation may be on the horizon

  • HIPAA Weekly Advisor, Issue 42, October 20, 2008

    Experts attending the October 15 Medical Identity Theft Town Hall sponsored by the Office of the...

Atlanta hospital patients' outsourced data made public

  • HIPAA Weekly Advisor, Issue 42, October 20, 2008

    Human error—not hackers—is apparently to blame in a security breach that affected 45...

Q. Our organization received information indicating that medical personnel must attend at least 50 hours of HIPAA training annually.

  • HIPAA Weekly Advisor, Issue 42, October 20, 2008

    Q. Our organization received information indicating that medical personnel must attend at least 50...

NIST releases information security testing and assessment guide

  • HIPAA Weekly Advisor, Issue 41, October 13, 2008

    The National Institute of Standards and Technology (NIST) released the publication SP 800-115...

GAO report reviews advantages, risks of IT in healthcare

  • HIPAA Weekly Advisor, Issue 41, October 13, 2008

    Advances in information technology (IT) can improve the quality and other aspects of healthcare...

OCR addresses HIPAA privacy during a national or public emergency

  • HIPAA Weekly Advisor, Issue 41, October 13, 2008

    The OCR recently posted an FAQ regarding the status of the privacy rule during a national or public...

Q. What are the reporting requirements when a company laptop computer containing specially protected health information, such as mental health data, is stolen?

  • HIPAA Weekly Advisor, Issue 41, October 13, 2008

    Q. What are the reporting requirements when a company laptop computer containing specially...

Schwarzenegger approves new patient privacy legislation

  • HIPAA Weekly Advisor, Issue 40, October 6, 2008

    California Governor Arnold Schwarzenegger has signed legislation creating an oversight office to...

OIG to continue monitoring privacy and security oversight, enforcement

  • HIPAA Weekly Advisor, Issue 40, October 6, 2008

    The Office of Inspector General (OIG) will continue monitoring CMS and OCR HIPAA security rule and...

Federal 'red flag' identity theft rule takes effect

  • HIPAA Weekly Advisor, Issue 40, October 6, 2008

    Effective November 1, hospitals must have a plan to detect, mitigate, and prevent red flags that...

Q. We decided to improve physical security by distributing visitor badges to visitors and patients.

  • HIPAA Weekly Advisor, Issue 40, October 6, 2008

    Q. We decided to improve physical security by distributing visitor badges to visitors and patients...

Attention to detail, information exchange process makes Oregon DHS a compliance success story

  • Health Information Compliance Insider, Issue 10, October 1, 2008

    Kyle Miller, CISSP, has spent nearly three decades in information technology (IT), including work...

Offshoring a potentially risky cost saver for organizations

  • Health Information Compliance Insider, Issue 10, October 1, 2008

    Outsourcing medical billing, coding, and transcription overseas yields significant savings for...

HIPAA compliance in the ER

  • Health Information Compliance Insider, Issue 10, October 1, 2008

    The emergency room (ER) is one place where unpredictability is the norm, where critical and...

HIPAA in the ER: Exceptions, suggestions for compliance in a chaotic clinical setting

  • Briefings on HIPAA, Issue 10, October 1, 2008

    The emergency room (ER) is one place where unpredictability is the norm, where critical and...

Briefings on HIPAA October 2008

  • Briefings on HIPAA, Issue 10, October 1, 2008

    Inside: Keep your staff members’ e-mail private and secure HIPAA and the use of electronic...

Keep your staff members’ e-mail private and secure

  • Briefings on HIPAA, Issue 10, October 1, 2008

    In an era of instant connectivity, many physicians find that sending PHI and other confidential...

HIPAA and the use of electronic signatures and delivery

  • Briefings on HIPAA, Issue 10, October 1, 2008

    My friends in the e-commerce world tell me that they continually run into representatives of HIPAA...

Q&A: Visitor badges, stolen laptops, and more

  • Briefings on HIPAA, Issue 10, October 1, 2008

    Q. What are the reporting requirements when a company laptop containing specially protected health...

Attention to detail, information exchange process makes Oregon DHS a compliance success story

  • Briefings on HIPAA, Issue 10, October 1, 2008

    Kyle Miller, CISSP, has spent nearly three decades in information technology (IT), including work...

GAO says HHS still has work to do in ensuring health IT privacy

  • HIPAA Weekly Advisor, Issue 39, September 29, 2008

    The Government Accountability Office (GAO) on September 17 released a report on HHS’ work to...

Hospital employees fired for taking, posting photos online

  • HIPAA Weekly Advisor, Issue 39, September 29, 2008

    Two staff members guilty of taking patient photographs with cell phones and posting them on MySpace...

OCR releases privacy rule disclosure guides for providers and patients

  • HIPAA Weekly Advisor, Issue 39, September 29, 2008

    HHS’ Office for Civil Rights has published two guides (one for healthcare providers...

Q. Is it a HIPAA violation to display thank-you letters from patients or their families on a bulletin board or other type of display in a public area where visitors can read them?

  • HIPAA Weekly Advisor, Issue 39, September 29, 2008

    Q. Is it a HIPAA violation to display thank-you letters from patients or their families on a...

Colorado hospital reports patient information lost or stolen

  • HIPAA Weekly Advisor, Issue 38, September 22, 2008

    Boulder Community Hospital has notified police that copies of patient intake forms are...

EDS Corp. to pay $250,000 for mailing blunder

  • HIPAA Weekly Advisor, Issue 38, September 22, 2008

    EDS Corp. of Texas will pay $250,000 as part of a settlement for a mailing mistake that resulted in...

CMS reminds providers how to keep NPPES records updated, secure

  • HIPAA Weekly Advisor, Issue 38, September 22, 2008

    CMS reminds healthcare providers with NPIs that have records in the National Plan and Provider...

Q. A father takes his child to the dentist. The child is a covered party under the father's insurance policy.

  • HIPAA Weekly Advisor, Issue 38, September 22, 2008

    Q. A father takes his child to the dentist. The child is a covered party under the father’s...

NIH blocks public access to DNA database to protect privacy

  • HIPAA Weekly Advisor, Issue 37, September 15, 2008

    National Institute of Health (NIH) officials have removed two databases containing patient DNA...

ASCs to include ordering/referring physician names, NPIs on claims for diagnostic radiology services

  • HIPAA Weekly Advisor, Issue 37, September 15, 2008

    CMS has issued MLN Matters 6129 (based on Transmittal R5172CP), which clarifies changes affecting...

HHS Town Hall to focus on medical identity theft

  • HIPAA Weekly Advisor, Issue 37, September 15, 2008

    HHS’ Office of the National Coordinator for Health Information Technology will sponsor a Town...

Q. If an employer pays for employee physicals or consultations that are performed for employment purposes, do patients (employees) have a right to access the records as they would if they had paid for the services?

  • HIPAA Weekly Advisor, Issue 37, September 15, 2008

    Q. If an employer pays for employee physicals or consultations that are performed for employment...

Six Alzheimer's patients are victims in alleged identity theft scheme

  • HIPAA Weekly Advisor, Issue 36, September 8, 2008

    Six Alzheimer’s patients at Brookside Assisted Living in Buford, GA, are victims of identity...

California legislation aims to safeguard patient information

  • HIPAA Weekly Advisor, Issue 36, September 8, 2008

    The California Senate has approved a plan to protect patient privacy with new oversight and greater...

CMS posts HIPAA compliance review examples

  • HIPAA Weekly Advisor, Issue 36, September 8, 2008

    CMS will post sample findings and lessons learned from the security compliance reviews it began...

Q: May staff members in the home health field e-mail patient information if they use initials only?

  • HIPAA Weekly Advisor, Issue 36, September 8, 2008

    Q: May staff members in the home health field e-mail patient information if they use initials only?

Minimize mistakes when responding to the media

  • Briefings on HIPAA, Issue 9, September 1, 2008

    It doesn’t matter whether your facility is located in a large U.S. metropolitan area or a...

Covered entity pays for a potential HIPAA violation

  • Briefings on HIPAA, Issue 9, September 1, 2008

    HHS has thrown down the gauntlet; HIPAA violations may now come with a price. HHS and Seattle-based...

Q&A: What HIPAA requires when you sell your practice, do educational mailings, e-mail PHI, and more

  • Briefings on HIPAA, Issue 9, September 1, 2008

    Editor’s note: Brandt is president of Brandt & Associates, Inc., a healthcare consulting...

Train billing and coding staff members on HIPAA

  • Briefings on HIPAA, Issue 9, September 1, 2008

    Coding and billing staff members don’t have much face-to-face interaction with patients, but...

Briefings on HIPAA September 2008

  • Briefings on HIPAA, Issue 9, September 1, 2008

    Inside: Avoid the ‘dirty little secret’ inside healthcare Limit data leakage with...

Transition to ICD-10 to include HIPAA electronic transaction standards update

  • HIPAA Weekly Advisor, Issue 35, September 1, 2008

    On August 22, HHS announced a proposed regulation to replace the ICD-9 code sets now used to report...

Swedish hospital suspends nurse who posted surgery photos on Facebook

  • HIPAA Weekly Advisor, Issue 35, September 1, 2008

    A Stockholm hospital has suspended one of its nurses upon learning that she posted 14 photographs...

Healthcare staff frequent participants in medical identity theft

  • HIPAA Weekly Advisor, Issue 35, September 1, 2008

    Healthcare staff frequent participants in medical identity theft

Q. One of our physical therapy providers may sell his practice and has inquired whether HIPAA is a consideration with respect to his patients in this situation.

  • HIPAA Weekly Advisor, Issue 35, September 1, 2008

    Q. One of our physical therapy providers may sell his practice and has inquired whether HIPAA is a...

What you may not know about HIPAA but probably should

  • Health Information Compliance Insider, Issue 9, September 1, 2008

    Editor's note: This is HICI's second installment of little-known HIPAA facts from industry...

Train billing and coding staff members on HIPAA

  • Health Information Compliance Insider, Issue 9, September 1, 2008

    Editor's note: This is the fifth and final article in a series highlighting HIPAA training needs...

Minimize mistakes when responding to the media

  • Health Information Compliance Insider, Issue 9, September 1, 2008

    It doesn't matter whether your facility is located in the largest U.S. metropolitan area or a small...

Health Information Compliance Insider, September 2008

  • Health Information Compliance Insider, Issue 9, September 1, 2008

    Inside: Minimize mistakes when responding to the media; Train billing and coding staff...