Category Archives: HIPAA Enforcement

Subpoena Response that Violated HIPAA Costs a CT Healthcare Provider $853,000

Healthcare providers regularly receive subpoenas for medical records.  All too often, providers simply turn over the subpoenaed records without ensuring that the disclosure is permitted by law.  A recent Connecticut appeals court decision, Byrne v. Avery Center for Obstetrics and Gynecology, P.C., upheld a jury award of $853,000 for a healthcare provider’s improper medical record […]

DMC Law’s HIPAA Helpline Virtual Discussion Group

Every couple of months, DMC Law invites healthcare professionals who regularly grapple with privacy issues to gather (remotely) and discuss those issues.  The HIPAA Helpline is not a webinar.  It’s an interactive session.  DMC Law’s lawyers, Dena Castricone and Tracy Guarnieri, review legal requirements while participants share stories, questions and best practices.  The goal of […]

Three Dentists and a Psychiatrist Walk into a Bar: Four HIPAA Enforcement Actions that are No Joke

Three dentists and a psychiatrist walk into a bar . . . and they each walk out with a five-figure tab for HIPAA compliance failures.  It’s not funny, but the five-figure payment part is true and there’s a lot to be learned from their mistakes. The Department of Health and Human Services’ Office for Civil […]

A Year in Review: HIPAA Enforcement Action Resolutions in 2021

Here it is!  My annual summary of HIPAA enforcement action resolutions.  I know you all have been eagerly awaiting its arrival.  No plot twists or surprises this year – the enforcement themes are much the same as those in 2020.  As I explain below, Right of Access was again the star. 

OCR Announces Five More HIPAA Right of Access Resolutions

Yesterday, the Department of Health and Human Services’ Office for Civil Rights announced the resolution of five more HIPAA Right of Access claims. That brings the total number of Right of Access resolutions this year to 12 (including a civil monetary penalty), edging out last year’s total of 11. As for settlement and penalty amounts, the Right of Access total for 2021 has surpassed 2020 by more than $300,000.

Telehealth, Privacy, and the Three Little Pigs: A Year and a Half Later

In my July 23, 2020 blog post, I used the familiar characters in the beloved fable The Three Little Pigs to illustrate the importance of building a secure and compliant telehealth delivery system. I explained that, despite the Office for Civil Rights’ (OCR) announcement of enforcement discretion during the public health emergency (PHE), healthcare providers should establish HIPAA-compliant telehealth delivery systems before enforcement discretion ended. Because the PHE may soon be over, that message bears repeating.

A Less Demanding HIPAA Standard: the 5th Circuit Holds OCR to the Letter of the Law

By Dayle A. Duran, Esq., CIPP/US and Dena M. Castricone, CIPP/US and CIPM
In January 2021, the 5th Circuit Court of Appeals issued an unanticipated decision that will send ripples across the healthcare industry for years. Beyond giving healthcare privacy and security professionals cause for relief, the M.D. Anderson v. HHS decision restores faith in the checks and balances on regulatory agency enforcement power.

And the HIPAA Right of Access Enforcement Saga Continues…

OCR continues with vigorous enforcement of HIPAA’s Right of Access rules in 2021. In the first three months of the year, OCR announced five Right of Access settlements. The story is nearly identical in each – a patient requests records and a provider fails to timely provide access. Compliance with the Right of Access rules is relatively simple and one of the best ways to avoid unwanted attention from OCR.

HIPAA Enforcement in 2020: A Focus on Right of Access and Lessons Learned

Despite the pandemic, HIPAA enforcement was hot in 2020. There were nearly twice as many enforcement action resolutions last year than in each of the previous three years. The DHHS’ Office for Civil Rights (OCR), which enforces HIPAA, announced a total of 19 resolutions in 2020. The 2020 resolutions offer different lessons from previous enforcement years, as the most common issue for enforcement in 2020 is relatively new: the Right of Access under the HIPAA Privacy Rule.

OCR Kicks off its 2021 HIPAA Enforcement Year with Another Right of Access Settlement

OCR announced its first HIPAA enforcement resolution of 2021. Picking up where it left off in 2020, this settlement involves Right of Access claims and results in a large non-profit health system with several affiliated covered entities agreeing to pay $200,000 to settle claims related to two of its affiliated entities.