HIPAA audit

HIPAA Audit: OCR Is On The Move

Last week, the HHS Office for Civil Rights (OCR) announced the launch of phase 2 of the HIPAA Audit Program. OCR’s goal is to proactively uncover and address risks and vulnerabilities to protected health information (PHI). Effective immediately, OCR will ensure Covered Entities (CEs), their Business Associates (BAs) and vendors have comprehensive risk management frameworks…

$3.5 million fine levied against Triple-S Management Corporation for HIPAA violations

It’s happened again. On Dec 1, 2015, a $3.5 million fine was levied against Triple-S Management Corporation, formerly known as American Health Medicare Inc., for HIPAA violations. OCR’s investigations indicated widespread non-compliance throughout the various subsidiaries of Triple-S, including: Failure to implement appropriate administrative, physical, and technical safeguards to protect the privacy of its beneficiaries’…

Offense is Sexy. Defense Wins the Game

What do all team champions have in common?  It doesn’t matter if we’re talking about football, baseball, basketball, hockey, soccer, cricket or just about any other team sport.  With few exceptions, the champion is extraordinarily competent at both offense and defense. Think about healthcare.  Offense is a given.  There are frequent C-Suite discussions about new…

Tally of breach incidents grows by a whopping 67 percent a year after HIPAA Omnibus Rule!

The US Department of Health and Human Services’ Office of Civil Rights (OCR) modified the HIPAA Act with the HIPAA Omnibus Rule coming into effect from the first quarter of 2013. The HIPAA Omnibus rule demanding high standards for breach notification regulations, enterprises worked to strengthen the privacy and security protection mandated by HIPAA. Other…

How Can BAs & Subcontractors Tackle the New Compliance Burden?

The HIPAA Omnibus rule has now brought business associates and subcontractors under its gamut, making it mandatory for them to comply with the requirements of the final rule, or face stiff penalties. So business associates and subcontractors are now bound to conduct risk assessments and make appropriate use of encryption along with other precautionary measures…