Don’t Ring in the New Year with a HIPAA Audit – Safeguard Yourself Now

1 Indest-2008-1By George F. Indest III, J.D., M.P.A., LL.M., Board Certified by The Florida Bar in Health Law

Here’s a scary reminder: There are people attempting to hack into electronic health systems every second of every day. Thankfully, most of these attempts are unsuccessful due to the preventive technologies in place to safeguard such information. However, electronic data will never be 100 percent secure.

Electronic health records promised was intended to be a tool for doctors to share patient data, reduce prescription drug errors, and allow patients convenient access to their records. However, since the transition to digital medical records, there have been concerns from patients about privacy, security and identity theft.

Recently, the […]

Appeals Court Upholds Medical Malpractice Law Changes

By George F. Indest III, J.D., M.P.A., LL.M., Board Certified by The Florida Bar in Health Law

On July 21, a state appeals court in Tallahass2 Indest-2009-1ee upheld the constitutionality of a controversial change in Florida’s medical malpractice law. It ruled that some privacy rights are waived when patients pursue medical malpractice lawsuits. A federal appeals court last year also upheld the change in Florida’s law.

The decision by a three-judge panel of the First District Court of Appeal resulted from a 2013 change in the medical malpractice law. The Republican-controlled Florida Legislature passed the amendments to the laws after a lobbying dispute between groups like doctors and plaintiffs’ attorneys.

Ex Parte Communications […]

By |2024-03-14T10:01:01-04:00June 1, 2018|In the News, The Health Law Firm Blog|

HIPAA Basics For Licensed Health Care Professionals: Privacy, Security, and Breach Notification Rules

4 Indest-2009-3By George F. Indest III, J.D., M.P.A., LL.M., Board Certified by The Florida Bar in Health Law

The Department of Health and Human Services (HHS) recently issued a Health Insurance Portability and Accountability Act (HIPAA) fact sheet for health care professionals and organizations. The overview is titled “HIPAA Basics for Providers: Privacy, Security and Breach Notification Rules” and is intended to provide HIPAA covered entities such as physicians, health care facilities and other licenced health care professionals with a basic overview of HIPAA’s rules and responsibilities. Click here to view the HIPAA fact sheet.

HIPAA Privacy Rule.

The privacy rule is established as a standard for the protection of protected […]

By |2024-03-14T10:01:01-04:00June 1, 2018|In the News, The Health Law Firm Blog|

Avoiding HIPAA Violations

Michael L. Smith HeadshotBy Michael L. Smith, JD, RRT

Every respiratory therapist knows that the Health Insurance Portability and Accountability Act (HIPAA) requires hospitals and health care providers to maintain the confidentiality of their patients’ protected health information (PHI). RTs may not know that the Department of Health and Human Services (HHS) Office of Civil Rights (OCR) is investigating HIPAA violations and imposing sanctions on hospitals and other covered entities for violations. RTs also may not know that the Department of Justice is criminally prosecuting particularly egregious HIPAA violations.

HIPAA violations still occur despite the fact that we have years of training and experience in protecting patient privacy. Hospitals and health […]

By |2024-03-14T10:00:25-04:00June 1, 2018|In the Know, The Health Law Firm Blog|

Patient Privacy Breach at Nemours Follows Florida Hospital Information Leak

After a patient privacy breach at Florida Hospital a few weeks ago, another patient records scare has hit Florida – this time at Nemours.

According to the Orlando Sentinel, information belonging to Central Florida patients of Nemours Children’s Health System has gone missing.

Computer back-up tapes containing old patient billing information have disappeared from the Wilmington, Del., office of Nemours. These tapes were not password protected and stored in a locked cabinet. Company officials believe the cabinet may have been removed when the office was  remodeled in August.

Stored in the missing tapes are patient names, addresses, dates of birth, social security numbers, insurance information, medical diagnoses and treatment codes, as well as bank account information. If stolen, this information could […]

By |2024-03-14T10:00:25-04:00June 1, 2018|In the News, The Health Law Firm Blog|

Are You Ready for HIPAA and HITECH Audits?

The Office for Civil Rights (OCR) of the U.S. Department of Health and Human Services (HHS) is launching a pilot program this month to make sure covered entities are in compliance with HIPAA privacy and security rules and breach notification standards, according to the OCR. The OCR will perform up to 150 audits to assess HIPAA compliance.

The HITECH Act requires HHS to perform periodic audits to check for HIPAA compliance. The audits will be conducted from November 2011 through December 2012. Initially these audits will likely focus on hospitals and insurance companies, but HMEs could also be a target.

Though early audits are likely to be educational, in order to get a […]

Alleged HIPAA Privacy Violations at the Center of a Recent Physician Group Settlement with HHS

By George F. Indest III, J.D., M.P.A., LL.M., Board Certified by The Florida Bar in Health Law

A small physician group has reached a settlement with the United States Department of Health and Human Services (HHS) Office for Civil Rights (OCR) over alleged Health Insurance Portability and Accountability Act of 1996 (HIPAA) violations. The settlement was reached on April 17, 2012 and requires Phoenix Cardiac Surgery (PCS) to pay OCR $100,000 and enter into a one-year corrective action plan (CAP).

The Resolution Agreement and Corrective Action Plan can be viewed here.

HIPAA Complaint Against PCS Stemmed from Internet Calendar Postings

OCR’s investigation of PCS was launched in 2009 after a […]

By |2024-03-14T10:00:30-04:00June 1, 2018|HIPAA, The Health Law Firm Blog|

OCR Releases Results From First Round of HIPAA Audits

By George F. Indest III, J.D., M.P.A., LL.M., Board Certified by The Florida Bar in Health Law

The Office for Civil Rights’ (OCR) has release information on the initial round of mandated audits of Health Insurance Portability and Accountability Act (HIPAA) covered entities. The OCR announced official details concerning the audits at an OCR and National Institute of Standards and Technology (NIST) conference held June 6, 2012.

Initial HIPAA Audits Started November 2011.

As required by the HITECH Act, the OCR began auditing selected covered entities’ compliance with the privacy and security provisions of HIPAA and its implementing regulations in November 2011. The OCR selected 150 covered entities to be […]

By |2024-03-14T10:00:32-04:00June 1, 2018|HIPAA, The Health Law Firm Blog|

Preparing for HIPAA Audits

By George F. Indest III, J.D., M.P.A., LL.M., Board Certified by The Florida Bar in Health Law

The Office of Civil Rights (OCR) has recently released the initial results for the first round of HIPAA audits, as well as the HIPAA audit protocol. Covered entities need to review both the audit results and audit protocol to assist in preparing for the possibility of a HIPAA audit.

Tips to Prepare for a HIPAA Audit.

Although the first round of audits has concluded, HIPAA audits will continue to be conducted through December 2012. Covered entities that avoided the first round of HIPAA audits can learn from the results released by OCR. The OCR […]

By |2024-03-14T10:00:32-04:00June 1, 2018|HIPAA, The Health Law Firm Blog|

Remedies for Violation of HIPAA Privacy Rights and Medical Confidentiality – Part 1

By George F. Indest III, J.D., M.P.A., LL.M., Board Certified by The Florida Bar in Health Law

I receive many questions and e-mails about possible violations of the Health Insurance Portability and Accountability Act’s (HIPAA) Privacy Regulations and Security Regulations, and breaches of confidentiality of medical records and medical information.  I will attempt to explain and clarify this issue a little in this short blog.

More detailed information on HIPAA Privacy Regulations and Security Regulations, can be found at: http://www.hhs.gov/ocr/privacy/hipaa/understanding/index.html

There is no private cause of action allowed to an individual to sue for a violation of the federal HIPAA or any of […]

By |2024-03-14T10:00:37-04:00June 1, 2018|HIPAA, In the Know, The Health Law Firm Blog|
Go to Top