Header graphic for print
Privacy Law Blog

Posts by

A $1.2 Million Photocopier Mistake: Health Plan Settles with HHS in HIPAA Breach Case

Posted in Data Breaches, HIPAA, Identity Theft, Medical Privacy

We have heard the well-publicized stories of stolen laptops and resulting violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), and we generally recognize the inherent security risks and potential for breach of unsecured electronic protected health information posed by computer hard drives. We remember to “wipe” the personal data off of… Continue Reading

HHS Empowers Consumers to Know (and Enforce) their Rights Under HIPAA

Posted in Electronic Communications, HIPAA, Medical Privacy

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) published on its website a series of factsheets designed to educate consumers unfamiliar with their rights under the Health Insurance Portability and Accountability Act’s (HIPAA) Privacy and Security Rules.  These four factsheets are described in detail below and are available in… Continue Reading

HHS Announces New Patient Privacy and Security Protections

Posted in HIPAA, Medical Privacy, Mobile Privacy, Privacy Litigation, Security Breach Notification Laws, Uncategorized

On January 17, 2013, U.S. Department of Health and Human Services Secretary Kathleen Sebelius announced the final omnibus rule that among other things (1) increases patient privacy protections; (2) provides individuals with new rights to receive a copy of their electronic medical record in an electronic form;  and (3) provides individuals with the right to… Continue Reading

OCR Issues Guidance On HIPAA Privacy Rule’s De-Identification Standard

Posted in HIPAA, Medical Privacy

On November 26, 2012, the Department of Health and Human Services Office for Civil Rights (“OCR”) published a thirty-two page document titled “Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule” (“De-Identification Guidance”).  OCR described the guidance document as a culmination of two… Continue Reading

HIPAA Privacy In The Aftermath Of Sandy: Be Prepared For The Next Emergency

Posted in HIPAA, Medical Privacy, Miscellaneous, Mobile Privacy, Workplace Privacy

As health care providers, patients, family members, friends, and disaster relief agencies such as the American Red Cross continue to grapple with the aftermath of Hurricane Sandy it is important to be mindful of privacy regulations and to prepare in advance for the next emergency. The Health Insurance Portability and Accountability Act  of 1996 (“HIPAA”… Continue Reading