Skip to content

On June 9, 2020 the Health and Human Services Office for Civil Rights (OCR) announced it had reached an Early Case Resolution (ECR) with the State of Connecticut and a separate ECR with Hartford Hospital. Both ECRs involve the rights of patients with disabilities to have reasonable access to support persons in hospital settings during COVID-19. OCR had received complaints that the COVID-19 hospital visitor policies of the State and the hospital violated the Americans with Disabilities Act (ADA) by failing to make exceptions for patients needing support persons for their care.
Continue Reading OCR Reaches Early Case Resolutions with the State of Connecticut and a Private Hospital Regarding Rights of Persons with Disabilities to Have Reasonable Access to Support Persons in Hospital Settings During COVID-19

These days, news stations are frequently running stories concerning people being treated for COVID-19, the providers working tirelessly to care for them, and politicians visiting health care facilities for a first-hand look at the crisis. In response to the media interest, the Office for Civil Rights (OCR) issued guidance on May 5, 2020 to healthcare providers answering the question “Does the COVID-19 Public Health Emergency alter the HIPAA Privacy Rule’s restrictions on disclosures of protected health information to the media?” The guidance reminds them “that the HIPAA Privacy Rule does not permit them to give media and film crews access to facilities” in which patient health information may be accessible without the patients’ authorization. This includes any areas of the facility where patients’ protected health information (PHI) may be accessible in any form (e.g., written, electronic, oral, or other visual or audio form).

Continue Reading OCR Issues Guidance About Media Access to Health Care Facilities

On April 9, 2020 the Department of Health & Human Services Office for Civil Rights (OCR) issued another Notification that it will exercise its enforcement discretion and not impose penalties for HIPAA violations in connection with good faith participation in the operation of COVID-19 testing sites during the COVID-19 emergency.
Continue Reading HHS Waives HIPAA Penalties for Operation of a Community-Based COVID-19 Testing Site

On March 24, 2020, the U.S. Department of Health & Human Services (HHS) Office for Civil Rights (OCR) issued new HIPAA guidance to help providers and first responders in efforts to combat the COVID-19 pandemic.
Continue Reading OCR Issues Additional Guidance on HIPAA for Providers and First Responders on COVID-19 Front Lines

On March 20, the U.S. Department of Health and Human Services (HHS) issued additional guidance in the form of Frequently Asked Questions (FAQs) on HIPAA and telehealth services to help providers furnish care during the COVID-19 pandemic.

The FAQs follow and provide further information on the Notification of Enforcement Discretion issued by HHS on March 17 (Notification), in which HHS indicated that it would not penalize providers for using popular video chat applications, such as FaceTime and Skype, in good faith to provide telehealth services amid the COVID-19 pandemic.  HHS has emphasized, however, that the Notification does not allow the use of public-facing communications products, such as Facebook live or other livestreaming applications.
Continue Reading COVID-19: HHS Issues FAQs on HIPAA and Telehealth to Help Providers Maintain Access to Care During the Pandemic

The Office of Civil Rights (OCR) last month provided guidance and a reminder to HIPAA covered entities and their business associates regarding the sharing of patient health information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule during an outbreak or emergency situation such as what we are all facing right now with the Novel Coronavirus (2019-nCoV) outbreak.
Continue Reading U.S. Health & Human Services – Office of Civil Rights Issued Guidance Regarding HIPAA Privacy and Novel Coronavirus

On December 12, 2019, the U.S. Department of Health and Human Services Office for Civil Rights (OCR) announced its second “HIPAA Right of Access Initiative” settlement of alleged HIPAA violations.

The HIPAA Right of Access Initiative is a recent effort by OCR to monitor compliance with HIPAA requirements addressing patient rights to prompt access to medical records, in a readily producible format, without being subject to excessive fees. OCR announced its first settlement under the Right of Access Initiative in September 2019 (see our analysis of that settlement here), and this second settlement indicates a continued focus by OCR on HIPAA compliance by providers when responding to patient requests for records.
Continue Reading OCR Announces Second $85,000 Settlement for Alleged Violations of the Individual Right of Access under HIPAA

The Office for Civil Rights (OCR) announced on October 23, 2019 that Jackson Health System (Jackson), a not-for-profit hospital system comprised of six hospitals, urgent care centers, nursing facilities, and primary care and specialty services based in Miami, Florida, has waived its right to a hearing and did not contest the findings set forth in the OCR’s Notice of Proposed Determination (NPD), and has agreed to pay the full civil monetary penalty assessed by OCR. This unusual step means that Jackson will pay the full fine of $2.15 million.

According to the OCR, Jackson notified the OCR in 2013 that paper records of 256 patients’ personal health information (PHI) located in three boxes were lost in 2012. It thereafter reported in 2016 that the loss was actually 1,436 patient records.Continue Reading Jackson Health System Fined by OCR

On September 9, 2019, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced that it had settled its first ever HIPAA enforcement action arising from alleged violations of the individual right to access health information under HIPAA. OCR entered into a settlement with Bayfront Health St. Petersburg (Bayfront) in response

In a development that may – understandably – have been overlooked by many heading into Memorial Day weekend, on May 24, 2019, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) issued a Fact Sheet on Direct Liability of Business Associates under the Health Insurance Portability and Accountability Act (HIPAA).

The Fact Sheet provides an important reminder to covered entities, business associates, and their counselors regarding the circumstances in which OCR may – and may not – take enforcement actions directly against business associates for violations of HIPAA regulations. In the Fact Sheet, OCR explains that in 2009 the Health Information Technology for Economic and Clinical Health (HITECH) Act made business associates “directly liable for compliance with certain requirements” under HIPAA’s regulations, as addressed by OCR in its 2013 Omnibus Rule.Continue Reading OCR Issues Fact Sheet Listing Circumstances in which Business Associates May Face Direct Liability for HIPAA Violations

Please note that as of January 1, 2023 our Privacy Policy has changed. Click here for details on our new terms.

OK