Recent Articles

  • Mayo Clinic Breach Leads to Healthcare Class Action Lawsuits

    Published On: December 4th, 2020

    Back in August, Mayo Clinic announced that one of their former employees inappropriately accessed the medical records of 1,600 patients. This insider breach led several affected patients to file [...]

  • Is Mailgun HIPAA Compliant?

    Published On: December 3rd, 2020

    Mailgun is a software provider that offers email services including regular email, email marketing, and analytics. But as a healthcare organization, you must determine whether or not a software [...]

  • Health Department Breach Exposes COVID Test Results

    Published On: December 2nd, 2020

    It was recently announced that the Delaware Division of Public Health (DPH) mailed out breach letters to 10,000 patients. These patients, who had been tested for COVID-19, had their [...]

  • Mental Health Services Breach Affects 295k Patients

    Published On: December 1st, 2020

    AspenPointe Inc., a mental health and substance abuse provider, suffered a cyberattack that allowed unauthorized access to their network. Details regarding the mental health services breach are discussed. Mental [...]

  • Coronavirus Violations Leads to Long Island Nursing Home OSHA Fines

    Published On: November 30th, 2020

    The federal Occupational Safety and Health Administration (OSHA), which sets and enforces standards for workplace safety, recently cited a Long Island, New York nursing and rehabilitation center, for alleged [...]

  • Is Twilio HIPAA Compliant?

    Published On: November 27th, 2020

    Twilio is a popular direct marketing tool that allows users to send text messages and emails, automate phone calls, and build videos. But as a healthcare organization, you must [...]

Blog Categories

  • 42 CFR Part 2

    42 CFR Part 2 dictates rules for the confidentiality of substance abuse records. Find out when providers are permitted to share records and when they are not.

  • Healthcare Compliance

    Healthcare compliance is complex, especially when you have to meet multiple compliance standards. Learn how to navigate HIPAA, OSHA, and SOC 2 requirements.

  • Healthcare Data Breach Report

    Each month, we review what caused healthcare data breaches and how they could have been prevented. Learn how to protect your business from breaches and fines.

  • HIPAA Compliance

    Whether you’re a healthcare provider, health plan, or healthcare vendor, you must meet HIPAA standards. Learn what’s required for HIPAA compliance and how to implement a successful program.

  • HIPAA News

    Keep up to date on HIPAA news by checking in with us. We will provide you with information on changes to HIPAA law, healthcare breaches, HIPAA violations, and OCR fines.

  • HIPAA Violation Fines

    Healthcare organizations that fail to meet HIPAA Privacy, Security, or Breach Notification Rules can face HIPAA violation fines. Find out who has been fined and how they could have prevented penalties.

  • MACRA MIPS

    To be eligible for reimbursement under the Merit-based Incentive Payment System (MIPS), you must meet Medicare Access and CHIP Reauthorization Act (MACRA) standards.

  • OCR Enforcement

    The Office for Civil Rights (OCR) is the enforcing body of HIPAA. The OCR conducts investigations into potential HIPAA violations, issuing judgments that can result in settlements.

  • OIG Compliance

    The Office of Inspector General (OIG) released guidance, referred to as the seven elements of compliance. Find out how to implement an effective compliance program.

  • OSHA Healthcare Compliance

    OSHA healthcare compliance ensures a safe and healthy environment for patients and staff. Find out how to meet various OSHA standards specific to healthcare.

  • Right of Access

    The HIPAA Right of Access standard requires healthcare providers to comply with patient record requests. This standard is the most cited in HIPAA settlements. Learn the rules.

  • SOC 2 Compliance

    The American Institute of Certified Public Accountants (AICPA) created a cybersecurity framework called Service Organization Control Type 2 (SOC 2). Learn how about SOC 2 compliance.