Breaking Compliance News Blog

When HIPAA security is a public health issue

Posted by Margaret Scavotto & Scott Gima on 1/18/22 9:00 AM

Read More

Topics: HIPAA, data breach, security, compliance, webinar

Have you upped your HIPAA game during COVID?

Posted by Margaret Scavotto, JD, CHC on 1/11/22 8:00 AM

HIPAA was a high priority for most healthcare providers before the pandemic.

 

COVID-19 stretched resources and lengthened to-do lists, and has made it harder to keep up with HIPAA compliance.

 

Which is tricky, because HIPAA risk has only increased during the pandemic, for two reasons.

 

First, hackers are opportunists.

They know the pandemic strains healthcare facilities, and a cyberattack might be more successful on a provider facing a COVID-19 surge. In March 2020, U.S. authorities warned that hackers were focusing their efforts on the three states hit the hardest by coronavirus: California, New York, and Washington – and hackers were targeting employees working from home.

Second, the pandemic has brought new ways to violate HIPAA.

Providers and vendors have scrambled to implement testing sites and vaccine clinics, ways to manage the data flowing in and out of testing sites and vaccine clinics, and software programs to sign up for testing and vaccines – to name a few. Many of these methods had to be put together hastily, as they were urgently needed. Was HIPAA the first consideration? Probably not. This inevitably led to breaches.

For example:

  • Denton County, Texas announced a breach involving a third-party application used by the County for COVID-19 vaccination clinics. This application had a configuration error that exposed information about individuals who received vaccinations.
  • An agency employee at Atacadero State Hospital in California improperly accessed patient and employee information, including COVID-19 test results. The records involved 1,735 employees and former employees, and 1,217 job applicants. The improper access was discovered during an “annual review of employee access to data folders, and the employee is believed to have been improperly accessing the information for about 10 months….”
  • The Lake County Health Department and Community Health Center in Illinois announced that 24,000 patient names were on a spreadsheet sent attached to an unencrypted email to an employee’s personal email address. 
  • Indiana’s COVID-19 online contact tracing survey was breached, compromising the data of hundreds of thousands of Indiana residents. The breach was caused by a software misconfiguration that left the information visible to the public.

I know resources are stretched thin, and people are exhausted. But it is still important to ask: Have you upped your HIPAA game during the pandemic? Has your organization addressed evolving threats that COVID-19 has brought the healthcare industry?

Here are some more questions to ask:

Read More

Topics: HIPAA, data breach, security, compliance, webinar

Sign Up: Top 10 Compliance Tips for a Sucessful 2022

Posted by Margaret Scavotto, JD, CHC on 10/20/21 9:45 AM

 
Read More

Topics: Training and Education, HIPAA, compliance, COVID-19, webinar

Sign Up: Top 10 Compliance Tips for a Sucessful 2022

Posted by Margaret Scavotto, JD, CHC on 10/13/21 3:12 PM

Read More

Topics: Training and Education, HIPAA, compliance, COVID-19, webinar

Earn 5 CEUs with MPA’s Virtual HIPAA Training!

Posted by Margaret Scavotto, JD, CHC on 8/10/21 9:15 AM

HIPAA is a lot!

MPA's e-course makes it easier to keep up with privacy, security, breach notification, and social media.

Sign up for MPA's Virtual HIPAA Training Course

*** Approved for 5 hours of NAB CEUs***

Read More

Topics: Training and Education, HIPAA, Social Media, security, breach notification, privacy, webinar

Earn 5 CEUs with MPA’s Virtual HIPAA Training!

Posted by Margaret Scavotto, JD, CHC on 8/5/21 11:40 AM

HIPAA is a lot!

MPA's e-course makes it easier to keep up with privacy, security, breach notification, and social media.

Sign up for MPA's Virtual HIPAA Training Course

*** Approved for 5 hours of NAB CEUs***

Read More

Topics: Training and Education, HIPAA, Social Media, security, breach notification, privacy, webinar

Choose MPA's next free compliance webinar!

Posted by Margaret Scavotto, JD, CHC on 4/6/21 10:10 AM

MPA offers a free compliance and HIPAA webinar series to keep you current.

Read More

Topics: HIPAA, compliance, webinar

Earn 5 CEUs with MPA’s Virtual SNF Compliance Officer Training!

Posted by Margaret Scavotto, JD, CHC on 2/10/21 1:42 PM

Compliance is mandatory for SNFs! Is your compliance program survey-ready?

Sign up for MPA's Virtual Compliance Officer Training Course

*** Approved for 5 hours of NAB CEUs***

Read More

Topics: Training and Education, Affordable Care Act, compliance, compliance officer, Phase 3, webinar

* Free Webinar: HIPAA Wake-Up Calls!

Posted by Margaret Scavotto, JD, CHC on 2/10/21 10:27 AM

Sign up for MPA's free webinar:

HIPAA Wake-Up Calls

Tuesday February 16th at 12 pm CST

In 2020, there were 19 HIPAA settlements totaling $13,554,900. The settlements ranged between $10,000 and $6.85 million, and affected between one and 16,649,249 patients.

Read More

Topics: HIPAA, security, compliance, breach notification, privacy, webinar

Earn 5 CEUs with MPA’s Virtual SNF Compliance Officer Training!

Posted by Margaret Scavotto, JD, CHC on 2/9/21 10:31 AM

Compliance is mandatory for SNFs! Is your compliance program survey-ready?

Sign up for MPA's Virtual Compliance Officer Training Course

*** Approved for 5 hours of NAB CEUs***

Read More

Topics: Training and Education, Affordable Care Act, compliance, compliance officer, Phase 3, webinar

    Privacy Policy           Terms of Use