gwb | Grubman Warner Berry

Search results for: HIPAA

Computer servers and data center

HIPAA & Cyber Security

Cybersecurity has quickly become the number one concern for healthcare providers in the United States and for good reason. According to the HHS Office for Civil Rights (OCR), cyber incidents in health care are on the rise. From 2018-2022, there has been a 93% increase in large breaches reported to OCR, with a 278% increase […]

Read More
Medical billing documents and calculator

Payor Audits & Overpayment Appeals

Healthcare providers regularly receive medical record requests and overpayment demands from various payors, including Medicare and Medicaid, and commercial health insurance plans. Although many of these requests are “routine” in nature and do not lead to any adverse findings, the consequences of an inadequate response could be devastating, as these audits often lead to significant […]

Read More

Proposed Update to HIPAA Security Rule

The Office for Civil Rights (OCR) at the U.S.  Department of Health and Human Services (HHS) issued a Notice of Proposed Rulemaking (NPRM) to modify the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule on December 27, 2024.  This would be the first update to the HIPAA Security Rule since 2013. The […]

Read More

OCR’s Right of Access Initiative: Practice Pays $20k to Settle Allegations of HIPAA Violation

Chilivis Grubman attorneys have written extensively about the HIPAA Right of Access Initiative by the U.S. Department of Health and Human Services (HHS) Office of Civil Rights (OCR), which was first announced in 2019.  HIPAA rules allow patients (or designated representatives) to request copies of their health information.  Once a covered entity receives a request, it has […]

Read More

OCR HIPAA Right of Access Initiative Reaches Dental Practices

In 2019, the U.S. Department of Health and Human Services’ Office of Civil Rights (OCR) announced its HIPAA Right of Access Initiative.  Under the Initiative, OCR investigates violations of the HIPAA Privacy Rules, particularly related to the ability of patients to access their PHI.  The HIPAA Privacy Rule generally requires covered entities to provide individuals […]

Read More

The HIPAA Journal Posts December 2021 Healthcare Data Breach Report

The HIPAA Journal, a well-known website that provides broad coverage of HIPAA compliance and news, recently released its December 2021 Healthcare Data Breach Report.  The Data Breach Report analyzes data breach statistics provided by HHS’ Office for Civil Rights (OCR) and provides the information in a clear form.   The Data Breach Report provides interesting statistics […]

Read More

Partial Compliance is Not Compliance: OCR Resolves HIPAA Right of Access Investigation Related to A Parent’s Access to Minor Child’s Complete Medical Records

Children’s Hospital & Medical Center (CHMC) is the latest healthcare organization to have possibly violated the HIPAA right of access requirements resulting in a settlement, according to an announcement by the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS).  OCR’s announcement marks the twentieth settlement related to violations of […]

Read More

Lessons from the Most Recent OCR HIPAA Settlement

On June 2, 2021, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services announced another settlement of an enforcement action in its Health Insurance Portability and Accountability Act (HIPAA) Right of Access Initiative. This is the nineteenth settlement so far under the initiative. This most recent settlement arose from […]

Read More

M.D. Anderson Wins Appeal Overturning $4.35 Million Penalty for Alleged HIPAA Breaches

The University of Texas M.D. Anderson Cancer Center (“M.D. Anderson”) successfully appealed the imposition of $4.35 million in civil monetary penalties (“CMP”). In 2017, CMPs were imposed against M.D. Anderson for alleged HIPAA breaches that occurred in 2011 and 2012.  The breaches involved electronically protected health information (“ePHI”) of nearly 35,000 individuals that was improperly […]

Read More

HIPAA Right of Access Initiative: OCR Announces Two More Settlements

CG Attorneys continue to monitor and provide updates regarding the HIPAA Right of Access Initiative by the U.S. Department of Health and Human Services’(HHS) Office of Civil Rights (OCR).  Under the HIPAA Right of Access Initiative, OCR has made a determined effort to investigate claims that covered entities have violated patients’ right to access protected […]

Read More

OCR Enforcement Actions Continue Under HIPAA Right of Access Initiative with Thirteenth Settlement

CG attorneys have discussed the U.S. Department of Health and Human Services’(HHS) Office of Civil Rights (OCR) focus on patient access to records in its “HIPAA Right of Access Initiative.”  Under this initiative, OCR settled numerous actions involving medical practices that potentially violated the HIPAA Privacy Rule’s right of access requirements (45 C.F.R. § 164.524), including […]

Read More

And Another One: Eleventh Settlement as HHS Continues to Prioritize HIPAA Right of Access Enforcement Against Large and Small Covered Entities

The HIPAA Privacy Rule generally requires covered entities to provide individuals access to their “designated record sets” maintained by or for the covered entity, as defined by 45 C.F.R. § 164.501.  There are specific requirements to comply with the HIPAA Privacy Rule’s Right of Access mandate, including methods of providing access, timeliness in providing access, […]

Read More

HHS Levies $25,000 Fine in Tenth HIPAA Right of Access Enforcement Action

Over the past year, CG attorneys have alerted readers about the focus of U.S. Department of Health and Human Services’(HHS) Office of Civil Rights (OCR) on patient access to records in its “HIPAA Right of Access Initiative.”  Under this initiative, OCR announced at least ten settlements involving medical practices that allegedly violated HIPAA’s record access […]

Read More

HIPAA News: August 2020 Data Breach Report

The online HIPAA Journal has published the statistics for reported breaches of protected health information (PHI) of 500 or more patients occurring during August, 2020, available here.  The total number of such breaches reported was 37, virtually identical to the number of breaches reported in July and a significant decrease from June.  Notably, however, the […]

Read More

Breaking News Regarding COVID-19, Medicare Telehealth Rules, and HIPAA Enforcement

Trump Administration Loosens Telehealth and HIPAA Rules to Help Combat COVID-19 Crisis Earlier today, March 17, 2020, the Trump administration announced that, due to the COVID-19 crisis, Medicare providers may now use phone and video conference, including FaceTime and Skype, to see patients, with no penalties. This includes blanket HIPAA waivers, as well as Medicare […]

Read More

Leap Year Means a February Deadline for HIPAA Breach Notifications

The HIPAA Breach Notification Rule requires covered entities, business associates, vendors of personal health records, and other third-party service providers handling protected health information to notify individuals and entities (depending on magnitude) of a breach of unsecured protected health information.  45 C.F.R. §§ 164.400 – 164.414. Any impermissible use or disclosure under the HIPAA Privacy […]

Read More

Ambulance Company’s Lost Unencrypted Laptop Results in $65,000 HIPAA Settlement

The Department of Health and Human Services, Office for Civil Rights (“OCR”) ended 2019 with an agreement with West Georgia Ambulance, Inc. (“WGA”) to resolve potential violations of the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”).   The alleged HIPAA violations arose on December 13, 2012, when WGA reported that an unencrypted laptop fell […]

Read More

CMS Imposes $4.6 Million in Civil Monetary Penalties for HIPAA Violations

The Department of Health and Human Services’ Office for Civil Rights (OCR) imposed civil monetary penalties (CMP) of $3 million and $1.6 million for HIPAA violations in the first half of November. $3 million CMP: Failure to Encrypt Devices In 2010, the University of Rochester Medical Center (URMC), one of New York’s largest health systems, […]

Read More

HHS-OCR Reports Record-Breaking Year for HIPAA Enforcements in 2018

In 2018, the Department of Health and Human Services’ Office for Civil Rights (OCR) settled ten cases and won summary judgment from an Administrative Law Judge (ALJ), all of which resulted in recoveries totaling $28.7 million from HIPAA enforcement actions. The previous record was from 2016 when OCR recovered $23.5 million from its HIPAA enforcement […]

Read More

Colorado Hospital Agrees to Pay Over $100,000 to Resolve Potential HIPAA Violations

The U.S. Department of Health and Human Services Office of Civil Rights recently announced that Pagosa Springs Medical Center (“PSMC”) in Colorado has agreed to pay $111,400 to resolve allegations that it potentially violated HIPAA’s Privacy and Security Rules. OCR opened its investigation into PSMC over allegations that a former employee of PSMC had obtained […]

Read More

Get in Touch With Us

For more information or to arrange a consultation, please contact us by telephone at (404) 233-4171 or online by submitting the form below. The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship nor create an expectancy of a potential attorney-client relationship. Do not submit information which is confidential or time sensitive, as it may not be treated as such.