Electronic Health Records
March 17, 2020 | Eric D. Fader | COVID-19 | Electronic Health Records | HIPAA | Legislation and Public Policy
As it has previously done for specific geographic areas affected by hurricanes, on March 15, the U.S. Department of Health and Human Services (HHS) issued a HIPAA Bulletin providing for a limited waiver of HIPAA sanctions and penalties for covered entities during the current COVID-19 (coronavirus) public health emergency.
Such waiver is primarily intended to
Read MoreMarch 12, 2020 | Ada Janocinska | Electronic Health Records | HIPAA | Hospitals | Legislation and Public Policy | Medical Devices and Wearables | Medicare and Medicaid | Private Insurers | Telehealth
The Centers for Medicare & Medicaid Services (CMS) and Office of the National Coordinator for Health Information Technology (ONC) have finalized two highly anticipated rules that are intended to give patients “unprecedented safe, secure access to their health data.”
ONC will establish a certification process for application programming interfaces (APIs) that will meet certain interoperability
Read MoreFebruary 27, 2020 | Eric D. Fader | Electronic Health Records | HIPAA | Legislation and Public Policy
On February 25, the American Medical Association (AMA) announced the release of its new Patient Records Electronic Access Playbook. The 100-page guide is intended to help physician practices navigate the legal and practical requirements of providing patients with access to their electronic health information.
The Playbook discusses relevant provisions of HIPAA and points out many
Read MoreFebruary 26, 2020 | Eric D. Fader | Cybersecurity | Electronic Health Records | HIPAA | Hospitals | Private Insurers
A recent article in HIPAA Journal, “Ransomware Attacks Have Cost the Healthcare Industry at Least $157 Million Since 2016,” discussed a new study by Comparitech that examined ransomware attacks on the healthcare industry. In the past three years, at least 172 ransomware attacks on healthcare entities in the U.S. have affected 1,446 facilities, providers and
Read MoreFebruary 20, 2020 | Eric D. Fader | Cybersecurity | Electronic Health Records | HIPAA | Legislation and Public Policy
The HIPAA Breach Notification Rule requires that smaller data breaches – those involving fewer than 500 patient records – must be reported to the U.S. Department of Health and Human Services (HHS) no later than 60 days after the end of the calendar year in which the breach occurred. This year, the reporting deadline is
Read MoreFebruary 14, 2020 | Eric D. Fader | COVID-19 | Electronic Health Records | HIPAA | Hospitals | Legislation and Public Policy
The U.S. Department of Health and Human Services (HHS) recently issued a Bulletin confirming that healthcare entities’ HIPAA obligations continue to apply even in public health emergencies. The February 2020 “HIPAA Privacy and Novel Coronavirus” Bulletin reminds HIPAA covered entities and their business associates that HIPAA Privacy Rule and Security Rule requirements remain in place
Read MoreFebruary 12, 2020 | Ada Janocinska | Electronic Health Records | HIPAA | Legislation and Public Policy | Litigation
In response to a recent federal court decision, the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) has modified its guidance regarding certain obligations imposed on covered entities when responding to individuals’ requests to send their protected health information (PHI) to third parties. In short, covered entities are no longer required
Read MoreFebruary 6, 2020 | Eric D. Fader | Electronic Health Records | Employer/Employee | Hospitals | Litigation
On January 31, a federal court in Massachusetts dismissed a lawsuit brought by the National Federation of the Blind (NFB) against Epic Systems Inc., that claimed that Epic’s electronic health records (EHR) software discriminates against blind hospital employees. The NFB had sued Epic on behalf of NFB members who allegedly suffered adverse employment actions because
Read MoreJanuary 13, 2020 | Behavioral Health | Electronic Health Records | HIPAA | Legislation and Public Policy
In an effort to provide further clarity to school administrators, healthcare professionals and families, the U.S. Department of Education and the Office for Civil Rights at the U.S. Department of Health and Human Services recently released updated joint guidance addressing the application of the Family Educational Rights and Privacy Act (FERPA) and the HIPAA Privacy
Read MoreJanuary 6, 2020 | Cybersecurity | Electronic Health Records | HIPAA | Hospitals | Litigation
Alabama’s DCH Health System is facing a federal lawsuit filed by some former patients who allege it was negligent in discovering and responding to a ransomware attack on its computer system. In addition to negligence, the complaint accuses DCH of invasion of privacy, breach of contract and breach of fiduciary duty, among other things. The
Read More