Health Data Management (HDM) reported today, May 12, that the Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS) is going to strengthen HIPAA Security Rule enforcement, based on statements made on Tuesday, May 11 by the OCR Deputy Director for Privacy, Susan McAndrew, at the Safeguarding Health Information conference in Washington, DC, co-sponsored by OCR and the National Institute of Standards and Technology (NIST). “To boost enforcement of the security rule, OCR has added investigators in 10 regional offices, McAndrew notes,” as reported by Joe Goedert in the HDM article, “OCR Boosting Security Enforcement,” which is available online. This report comes several days after…
Tag: Office for Civil Rights
OCR Issues Draft Guidance on Security Risk Analysis
The Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS) issued on May 7, 2010, Security Rule Draft Guidance on Risk Analysis. This is the first in a “series of guidance documents [that] will assist organizations in identifying and implementing the most effective and appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic protected health information. The materials will be updated annually, as appropriate.” This eight-page document is available online. The Draft Guidance on Risk makes the following key points: “The Security Rule does not prescribe a specific risk analysis methodology, recognizing that methods will vary dependent on the…
Prison Time for Privacy Breach of PHI; OCR Breach List Continues to Grow; More Training Needed
Health Data Management reported in its April 29, 2010, online HDM Daily that “[a] former researcher at the UCLA School of Medicine has been sentenced to four months in federal prison for violations of the HIPAA privacy rule.” You may access and read the article by Joseph Goedert, “Prison for HIPAA Privacy Violater“. On the same day, April 29, the Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS) reported on its Web site 67 entities reporting “Breaches Affecting 500 or More Individuals” over the period September 22, 2009 to March 19, 2010. That is up from the 36 that OCR listed on its initial…
OCR Identifies 36 Entities with Breaches Affecting 500 or More Individuals
On Monday, February 22, 2010, the federal government, through the Office for Civil Rights (OCR) of the Department of Health and Human Services (HHS), began enforcing the Breach Notification Rule for breaches occurring on or after that date. The Breach Notification for Unsecured Protected Health Information; Interim Final Rule, was published in the Federal Register on Monday, August 24, 2009 [74 FR 42739-42770] and was effective September 23, 2009. Since September 22, 2009, 36 breaches of privacy or security of protected health information (PHI) affecting 500 or more individuals have been reported to OCR. The total number of individuals affected was 1,073,657, with two of the breaches involving 359,000 (FL)…
Personal Health Records (PHRs) and the HIPAA Privacy Rule
U.S. Department of Health and Human Services, Office for Civil Rights Download (Requires Acrobat Reader)
The HIPAA Privacy Rule’s Right of Access and Health Information Technology
U.S. Department of Health and Human Services, Office for Civil Rights Download (Requires Acrobat Reader)
Privacy and Security Framework: Accountability Principle and FAQs
U.S. Department of Health and Human Services, Office for Civil Rights Download (Requires Acrobat Reader)
Privacy and Security Framework: Safeguards Principle and FAQs
U.S. Department of Health and Human Services, Office for Civil Rights Download (Requires Acrobat Reader)
Privacy and Security Framework: Collection, Use, and Disclosure Limitation Principle and FAQs
U.S. Department of Health and Human Services, Office for Civil Rights Download (Requires Acrobat Reader)
Privacy and Security Framework: Individual Choice Principle and FAQs
U.S. Department of Health and Human Services, Office for Civil Rights Download (Requires Acrobat Reader)

