Skip to content

Health care providers and contractors continue to be a popular target for hackers. Recently, CHSPSC LLC (CHSPSC), which provides various services to hospitals and clinics indirectly owned by Community Health Systems, Inc. of Tennessee, agreed to pay $2,300,000 to the Office for Civil Rights (OCR) in settlement of potential violations of HIPAA’s Privacy and Security Rules. The OCR investigation and settlement stemmed from a data breach affecting over six million people.
Continue Reading HIPAA Business Associate Pays $2.3 Million Settlement After Hackers Target PHI of Over 6 Million Individuals

The Office for Civil Rights (OCR) announced yesterday that it has settled five investigations in its HIPAA Rights to Access Initiative (Initiative), which it announced would be an enforcement priority for it starting in 2019. The Initiative is “to support individuals’ right to timely access to their health records at a reasonable cost under the HIPAA Privacy Rule.”

The addition of the five recent settlements brings the total to seven for OCR’s enforcement of the Initiative. The OCR’s press release states that the recent settlement involve five entities: Housing Works, Inc., All Inclusive Medical Services, Inc., Beth Israel Lahey Health Behavioral Sciences and King MD.
Continue Reading OCR Settles Five Investigations Under Right of Access Initiative

On June 12, 2020, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) issued timely HIPAA guidance (Guidance) regarding solicitations of blood and plasma donations from recovered COVID-19 patients.

In the Guidance, OCR affirms that health care providers can use patient information to identify patients that have recovered from COVID-19 to provide information about how they may donate plasma or blood with COVID-19 antibodies to support treatment of other patients with COVID-19. OCR explains that this use of protected health information would be permissible as part of a provider’s health care operations to enable case management of COVID-19 patient populations. OCR also reminds providers that because the activity is a health care operation and not for treatment purposes, HIPAA’s minimum necessary standard applies to any use or disclosure of protected health information in connection with the solicitation of blood or plasma donations.
Continue Reading HHS Issues Guidance for Providers on Soliciting COVID-19 Blood and Plasma Donations

These days, news stations are frequently running stories concerning people being treated for COVID-19, the providers working tirelessly to care for them, and politicians visiting health care facilities for a first-hand look at the crisis. In response to the media interest, the Office for Civil Rights (OCR) issued guidance on May 5, 2020 to healthcare providers answering the question “Does the COVID-19 Public Health Emergency alter the HIPAA Privacy Rule’s restrictions on disclosures of protected health information to the media?” The guidance reminds them “that the HIPAA Privacy Rule does not permit them to give media and film crews access to facilities” in which patient health information may be accessible without the patients’ authorization. This includes any areas of the facility where patients’ protected health information (PHI) may be accessible in any form (e.g., written, electronic, oral, or other visual or audio form).


Continue Reading OCR Issues Guidance About Media Access to Health Care Facilities

Connecticut Governor Ned Lamont recently issued four new executive orders to address the COVID-19 state of emergency (Executive Orders 7CC – 7FF) that contain provisions relevant to health care providers and facilities in the state.  Among other things, the Executive Orders (i) expand access to telehealth services, (ii) expand the available health care workforce, (iii) increase current reporting requirements for long-term care facilities, (iv) allow the Commissioner of the Department of Social Services (DSS) to scale back certain Medicaid program requirements, and (v) update requirements related to out-of-network emergency billing.  A summary of particularly significant changes contained in those Orders follows.
Continue Reading Connecticut Governor Expands Health Care Workforce, Access to Telehealth Services and Issues Other Important Health Care Updates in New Executive Orders

On April 9, 2020 the Department of Health & Human Services Office for Civil Rights (OCR) issued another Notification that it will exercise its enforcement discretion and not impose penalties for HIPAA violations in connection with good faith participation in the operation of COVID-19 testing sites during the COVID-19 emergency.
Continue Reading HHS Waives HIPAA Penalties for Operation of a Community-Based COVID-19 Testing Site

On March 27, Congress enacted the Coronavirus Aid, Relief, and Economic Security Act (CARES Act, or the Act), Public Law 116-136, a trillion-dollar stimulus bill intended to provide financial assistance to individuals and business affected by the COVID-19 pandemic.  The Act contains a broad range of measures intended to bolster the economy in the midst of the COVID-19 pandemic.  Unsurprisingly, a central focus of the Act is the provision of relief and support for hospitals and health care providers on the front lines of the COVID-19 pandemic.  This article provides a brief overview of some of the major pieces of the CARES Act, and the firm will provide additional updates on key aspects of the Act.
Continue Reading CARES Act Provides Vital Financial Support for Health Care Providers on COVID-19 Front Lines

On March 24, 2020, the U.S. Department of Health & Human Services (HHS) Office for Civil Rights (OCR) issued new HIPAA guidance to help providers and first responders in efforts to combat the COVID-19 pandemic.
Continue Reading OCR Issues Additional Guidance on HIPAA for Providers and First Responders on COVID-19 Front Lines

On March 20, the U.S. Department of Health and Human Services (HHS) issued additional guidance in the form of Frequently Asked Questions (FAQs) on HIPAA and telehealth services to help providers furnish care during the COVID-19 pandemic.

The FAQs follow and provide further information on the Notification of Enforcement Discretion issued by HHS on March 17 (Notification), in which HHS indicated that it would not penalize providers for using popular video chat applications, such as FaceTime and Skype, in good faith to provide telehealth services amid the COVID-19 pandemic.  HHS has emphasized, however, that the Notification does not allow the use of public-facing communications products, such as Facebook live or other livestreaming applications.
Continue Reading COVID-19: HHS Issues FAQs on HIPAA and Telehealth to Help Providers Maintain Access to Care During the Pandemic

As part of Executive Order No. 7F issued on March 18, Connecticut Governor Ned Lamont authorized the Commissioner of the Department Social Services (DSS) to “temporarily waive any requirements” set forth in state law, regulations, rules, policies or other directives concerning telehealth as is necessary to enable the Medicaid program “to cover applicable services provided through audio-only telehealth services.”  As a result, DSS will be able to expand Medicaid coverage for telehealth services that are provided by phone, and not just audio-video technology.
Continue Reading COVID-19: Lamont Authorizes DSS to Expand Access to Telehealth Services for Medicaid Beneficiaries in Response to Coronavirus Pandemic