COVID-19 has ushered in the mass acceptance of telehealth, with so much optimism and excitement around the technology. But like many new technologies, the initial use is rushed and not well thought out with many providers trying to figure out the right technology, best practices, and optimal patient experience. We have seen temporary waivers to...
Mask Mandate Whatever your opinion is of wearing, or not wearing a mask, there are in increasing number of mandates being put in place by governments or independent establishments in an effort to mitigate the spread of COVID-19. This mask mandate means that most people over a certain age need to have their face covered,...
A year of credit monitoring along with identity theft monitoring services. That’s what most of us settle for when we find out that our personal data has been compromised. We are alerted, we change our password, we read the letter that offers these services and may or may not sign up for them. Some individuals...
Employee Privacy in a Pandemic COVID-19 has presented businesses with a new challenge in keeping their company safe and it starts with employee health. As they re-open in the wake of the pandemic, they must keep track of individual health with regard to who is sick and how it might affect the company as a...
Data breaches are extremely common as technology continues to advance. Of those breaches, small and medium-sized businesses (SMBs) are a favored target for cybercriminals. In fact, more than 70% of attacks target small businesses, according to the National Cyber Security Alliance, and as many as 60% of hacked SMBs go out of business following a...
Have you ever wondered what exactly triggers a breach case investigated by Health and Human Services? While a number of things may attribute to an investigation, according to Deven McGraw, deputy director for health information privacy at the HHS Office for Civil Rights, nearly every breach case investigated by the department stems from a...
In the January, 2017 edition of the OCR Cyber Newsletter (PDF), OCR gives guidance to what is required from Covered Entities and Business Associate regarding auditing / monitoring of access to PHI. Covered Entities and Business Associates should make sure that they appropriately review and secure audit trails, and they use the proper tools to...
Quite often we hear about data breaches, but we don’t always hear about the consequences. On February 17, Memphis, TN media sources ran articles about a man who was indicted on felony fraud charges. According to a Commercial Appeal newspaper article: “Jeremy Jones is charged in a scheme to steal the identities of more than...
The Department of Health and Human Services (HHS) has issued guidance regarding an Individual’s Right under HIPAA to Access their Health Information. The link should be bookmarked by all organizations as a reference for future guidance, questions and answers: http://www.hhs.gov/hipaa/for-professionals/privacy/guidance/access/index.html Here is the introduction text from the guidance: Providing individuals with easy access to their...
The Computer Fraud and Abuse Act CFAA is not a very widely known piece of federal legislation but could help companies that have been victims of employee or ex-employee theft of digital information. According to an article over at Fox Rothschild LLP the CFAA can be used to help companies that have had employees or...
Recent Comments