Filefax, Inc. (“Filefax”), an Illinois company that intimately handled sensitive Personal Health Information (“PHI”), paid $100,000 to the Department of Health and Human Services (“HHS”) to settle potential violations of the Health Insurance Portability and Accountability Act (“HIPAA”). The payment stemmed from, when still in business, Filefax allegedly improperly disclosing the PHI of approximately 2,150 people when not properly securing
Continue Reading Healthcare Business Owners—HIPAA Still Applies After Closing Down Your Business

Picture1Under the Privacy Rule, HIPAA covered entities (health care providers and health plans) are required to provide individuals, upon request, with access to their protected health information (PHI) in one or more “designated record sets” maintained by or for the covered entity.

Covered entities are also required to protect the individual’s PHI from unauthorized disclosure. How must a covered entity
Continue Reading The Individual’s Rights Under HIPAA to Access their Health Information- Verifying the Identity of the Person Requesting PHI

laptop_data_breach_iStock_000015066702XSmall_400x300The US Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) released final rules on January 17, 2013 governing the privacy and security of protected health information under HIPAA and the HITECH Act.  The new rules take effect March 26, 2013; compliance is expected by September 23, 2013. This post will focus on the changes to the

Continue Reading New Breach Notification Requirements Released