Recent Articles

  • Risks of Mobile Health Apps: Are Health Apps Putting PHI at Risk?

    Published On: February 16th, 2021

    A recent study concluded that many popular mobile health apps pose a risk to protected health information (PHI) security. The study analyzed the security of 30 health apps that [...]

  • Sharp HealthCare Pays $70,000 to Settle Potential Right of Access Violation

    Published On: February 12th, 2021

    In February of 2021, Sharp HealthCare, doing business as Sharp-Rees Stealy Medical Centers (SRMC), paid $70,000 to the Department of Health and Human Services’ (HHS) Office for Civil Rights [...]

  • January Healthcare Breaches Affected Nearly 1 Million Patients

    Published On: February 11th, 2021

    January healthcare breaches predominantly affected healthcare providers with 22 of the 30 reported breaches targeting providers. Of the other breaches reported in January, two affected business associates, while [...]

  • Renown Health Fined $75,000 Under HIPAA Right of Access Initiative

    Published On: February 10th, 2021

    Not-for-profit Nevada health system Renown Health, P.C., has agreed to pay $75,000 to the Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) to settle a [...]

  • Cyberattack on Legal Billing Firm Impacts 36,000 UPMC Members

    Published On: February 9th, 2021

    In February of 2021, University of Pittsburgh Medical Center (UPMC) announced that the protected health information of over 36,000 patients may have been accessed by hackers. UPMC contracted with [...]

  • Thousands of Patient Files Posted to the Dark Web

    Published On: February 8th, 2021

    On February 5, 2021, tens of thousand of healthcare patient files from Leon Medical Centers and Nocona General Hospitals were posted for sale on the dark web during a [...]

Blog Categories

  • 42 CFR Part 2

    42 CFR Part 2 dictates rules for the confidentiality of substance abuse records. Find out when providers are permitted to share records and when they are not.

  • Healthcare Compliance

    Healthcare compliance is complex, especially when you have to meet multiple compliance standards. Learn how to navigate HIPAA, OSHA, and SOC 2 requirements.

  • Healthcare Data Breach Report

    Each month, we review what caused healthcare data breaches and how they could have been prevented. Learn how to protect your business from breaches and fines.

  • HIPAA Compliance

    Whether you’re a healthcare provider, health plan, or healthcare vendor, you must meet HIPAA standards. Learn what’s required for HIPAA compliance and how to implement a successful program.

  • HIPAA News

    Keep up to date on HIPAA news by checking in with us. We will provide you with information on changes to HIPAA law, healthcare breaches, HIPAA violations, and OCR fines.

  • HIPAA Violation Fines

    Healthcare organizations that fail to meet HIPAA Privacy, Security, or Breach Notification Rules can face HIPAA violation fines. Find out who has been fined and how they could have prevented penalties.

  • MACRA MIPS

    To be eligible for reimbursement under the Merit-based Incentive Payment System (MIPS), you must meet Medicare Access and CHIP Reauthorization Act (MACRA) standards.

  • OCR Enforcement

    The Office for Civil Rights (OCR) is the enforcing body of HIPAA. The OCR conducts investigations into potential HIPAA violations, issuing judgments that can result in settlements.

  • OIG Compliance

    The Office of Inspector General (OIG) released guidance, referred to as the seven elements of compliance. Find out how to implement an effective compliance program.

  • OSHA Healthcare Compliance

    OSHA healthcare compliance ensures a safe and healthy environment for patients and staff. Find out how to meet various OSHA standards specific to healthcare.

  • Right of Access

    The HIPAA Right of Access standard requires healthcare providers to comply with patient record requests. This standard is the most cited in HIPAA settlements. Learn the rules.

  • SOC 2 Compliance

    The American Institute of Certified Public Accountants (AICPA) created a cybersecurity framework called Service Organization Control Type 2 (SOC 2). Learn how about SOC 2 compliance.