SlideShare a Scribd company logo
1 of 21
The Intersection of OCR
Enforcement and Health Care
Data Privacy & Security
Agenda
 New Guidance from OCR
 HIPAA Security Rule and Cyber Security
 HHS and FTC Enforcement Update
 Resources
2
21st Century Cures/Opioid Crisis
https://www.hhs.gov/hipaa/for-professionals/special-topics/mental-
health/index.html
 HIPAA Helps Mental Health Professionals to Prevent Harm
 HIPAA Helps Family and Friends Stay Connected with Loved Ones Who Have a Substance
Use Disorder, including Opioid Abuse, or a Mental or Behavioral Health Condition
 When can I obtain treatment information about my loved one? (decision chart)
 If You Experience a Health or Mental Health Crisis, HIPAA Helps Your Doctors, Nurses, and
Social Workers to Reconnect You with Family, Friends, and Caregivers
 How HIPAA Allows Doctors to Respond to the Opioid Crisis
 When Your Child, Teenager, or Young Adult has Mental Illness: What Parents Need to Know
about HIPAA
 Am I my child’s personal representative under HIPAA?
 When may a mental health professional use professional judgment to decide whether to
share a minor client’s treatment information with a parent?
 When can parents access information about their minor child’s mental health treatment?
(Decision Chart)
 HIPAA Privacy Rule and Sharing Information Related to Mental Health
3
Recent Cyber Security Attacks,
Threats, and Trends
 2017 Cyber Healthcare & Life Sciences Survey
found that 47 percent of providers and health
plans had a security-related HIPAA violation or
a cybersecurity attack that impacted data.
 Office for Civil Rights data regarding Breaches
involving 500+ individuals
 Ransomware – WannaCry
 Phishing and Social Engineering
 Other Attacks
4
Preparing for a Cybersecurity Attack
It’s not a matter of IF an attack will occur, but
rather WHEN…
Steps to take to help address the WHEN:
 Implementing an effective compliance program
 Information assurance and information system
architecture
 Obtaining adequate cyberliability coverage
5
Key Security-Related Aspects of an
Effective Compliance Program
 View the HIPAA Security Rule only as a
baseline and policy framework requirement
– Risk Analysis and Risk Management Plans
– Encryption and password management
– “Addressable” does not mean “Optional”
 Ensuring internal/external expertise is
readily available
 Effective workforce training and monitoring
 Effective incident response procedures
6
Incident Handling Preparation
 Assign Roles and Responsibilities
 Assert Information needed to Construct
Event
 Define Relationships with Third Parties
 Train your Team
7
Cyber Security
https://www.hhs.gov/hipaa/for-
professionals/security/guidance/cybersecurity/index.html
 Cyber Security Checklist and Infographic
 Ransomware Guidance
 NIST Cybersecurity Framework
 OCR Cyber Awareness Newsletters
https://www.hhs.gov/hipaa/for-professionals/special-topics/cloud-
computing/index.html
 Cloud Computing
8Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
Effectively Responding to an Attack
 Time is of the Essence
– Immediate Isolation
– Notification Timeframes (including insurance
carrier)
 Engaging Outside Assistance
– Security forensic experts
– Legal counsel
– Law Enforcement
 Returning to Business As Usual
9
Key Takeaways
 Too small to be a target is a myth.
 Preparation does not guarantee Prevention,
but is the most important mitigation step.
 All individuals at your organization are
responsible and need to be involved.
 Time is always of the essence.
 Human error cannot be 100% prevented,
but awareness goes a long way.
10
HITECH Audit Program
Phase 2 Status
 166 covered entity desk audits
 41 business associate desk audits
 After Phase 2, on-site audits will be conducted as a part of the
permanent audit program.
– On-site audits will evaluate auditees against comprehensive
selection of controls in the audit protocol:
– https://www.hhs.gov/hipaa/for-professionals/compliance-
enforcement/audit/protocol/
11Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
Desk Audit Scope
 Covered Entities
– Security: risk analysis and risk management
– Breach: content and timeliness of notifications
– Privacy: notice and access
 Business Associates
– Security: risk analysis and risk management
– Breach: reporting to covered entities
12Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
Ratings
13
Compliance Effort Ratings – Legend
Rating Description
1 The audit results indicate the entity is in compliance with both goals and
objectives of the selected standards and implementation specifications.
2 The audit results indicate that the entity substantially meets criteria; it
maintains appropriate policies and procedures, and documentation and other
evidence of implementation meet requirements.
3 Audit results indicate entity efforts minimally address audited requirements;
analysis indicates that entity has made attempts to comply, but implementation
is inadequate, or some efforts indicate misunderstanding of requirements.
4 Audit results indicate the entity made negligible efforts to comply with the
audited requirements - e.g. policies and procedures submitted for review are
copied directly from an association template; evidence of training is poorly
documented and generic.
5 The entity did not provide OCR with evidence of serious attempt to comply with
the Rules and enable individual rights with regard to PHI.
Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
CE Desk Audit Ratings
14
Rating
Element # Provision 1 2 3 4 5 N/A
P55 Notice 2 34 40 11 16 0
P58 eNotice 59 16 4 6 15 3
P65 Access 1 10 27 54 11 0
BNR12 Timeliness 67 6 2 9 12 7
BNR13 Content 14 15 24 38 7 5
S2 Risk Analysis 0 9 20 21 13 0
S3 Risk Management 2 2 15 28 16 0
Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
BA Desk Audit Ratings
15
Rating
Element # Provision 1 2 3 4 5 N/A
BNR17 Notice to CEs 1 2 3 3 0 32
S2 Risk Analysis 3 5 15 12 6 0
S3 Risk Management 0 5 8 21 7 0
Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
Recent HHS Enforcement Actions
16
 April 24, 2017: CardioNet
– $2,500,000
– $2.5 million settlement shows that not understanding HIPAA requirements creates risk
 May 10, 2017: Memorial Hermann Health System (MHHS)
– $2,400,000
– Texas health system settles potential HIPAA violations for disclosing patient information
 May 23, 2017: St. Luke’s Roosevelt Hospital System Inc.
– $387,200
– Careless handling of HIV information jeopardizes patient’s privacy, costs entity $387k
 December 18, 2017: 21st Century Oncology
– $2,300,000
– $2.3 Million Levied for Multiple HIPAA Violations at NY-Based Provider
 February 1, 2018: Fresenius Medical Care North America (FMCNA)
– $3,500,000
– Five breaches add up to millions in settlement costs for entity that failed to heed HIPAA’s risk
analysis and risk management rules
 February 13, 2018: Filefax, Inc.
– $100,000
– Consequences for HIPAA violations don’t stop when a business closes
Recent FTC Enforcement Actions
17
 Feb 27, 2018:
– PayPal Settles FTC Charges that Venmo Failed to Disclose
Information to Consumers About the Ability to Transfer Funds
and Privacy Settings; Violated Gramm-Leach-Bliley Act
 Nov 29, 2017:
– FTC Gives Final Approval to Settlements with Companies that
Falsely Claimed Participation in Privacy Shield
 Nov 8, 2017:
– FTC Gives Final Approval to Settlement with Online Tax
Preparation Service
 Aug 15, 2017:
– Uber Settles FTC Allegations that It Made Deceptive Privacy
and Data Security Claims
GDPR: What’s All the Fuss?
 EU’s General Data Protection Regulation
– More broad territorial scope, and may apply to
entities with no physical presence in the EU
– Unlike HIPAA, applies to all personal data, not
just PHI
– Permits uses and disclosures of health data, but
exceptions do not always align with HIPAA
– Heavy fines and penalties
– Stay tuned for more information regarding
GDPR as applied to the U.S. health care industry
HHS/FTC Resources
 https://www.hhs.gov/hipaa/for-professionals/privacy/index.html
 https://www.hhs.gov/hipaa/for-professionals/security/index.html
 https://www.hhs.gov/hipaa/for-professionals/breach-
notification/index.html
 https://www.hhs.gov/hipaa/for-professionals/compliance-
enforcement/index.html
 https://www.ftc.gov/
 https://www.ftc.gov/system/files/documents/plain-language/pdf0205-
startwithsecurity.pdf
 https://www.ftc.gov/news-events/press-releases/2018/02/ftc-
recommends-steps-improve-mobile-device-security-update
 https://www.ftc.gov/news-events/press-releases/2018/02/ftc-report-
finds-some-small-business-web-hosting-services-could
19
Polsinelli Resources
 Polsinelli serves clients nationally:
– https://www.polsinelli.com/
– 100+ services and 70+ industry areas
– 800+ Attorneys
– https://www.polsinelli.com/professionals/lacevedo
– https://www.polsinelli.com/professionals/ipeters
– 20 Cities – Metropolitan offices in:
20
 Atlanta
 Boston
 Chicago
 Dallas
 Denver
 Houston
 Kansas City
 Los Angeles
 Nashville
 New York
 Phoenix
 St. Louis
 San Francisco
 Silicon Valley
 Washington, D.C.
 Wilmington
Polsinelli PC, Polsinelli LLP in California | polsinelli.com
Polsinelli PC provides this material for informational purposes only. The material provided herein is general and is not intended to be legal advice.
Nothing herein should be relied upon or used without consulting a lawyer to consider your specific circumstances, possible changes to applicable laws,
rules and regulations and other legal issues. Receipt of this material does not establish an attorney-client relationship.
Polsinelli is very proud of the results we obtain for our clients, but you should know that past results do not guarantee future results; that every case is
different and must be judged on its own merits; and that the choice of a lawyer is an important decision and should not be based solely upon
advertisements.
© 2018 Polsinelli® is a registered trademark of Polsinelli PC. In California, Polsinelli LLP.
21

More Related Content

What's hot

Iadmdhipmkt1.0
Iadmdhipmkt1.0Iadmdhipmkt1.0
Iadmdhipmkt1.0profit10
 
HIPAA Training (2017)
HIPAA Training (2017) HIPAA Training (2017)
HIPAA Training (2017) Arete-Zoe, LLC
 
Health Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - KloudlearnHealth Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - KloudlearnKloudLearn
 
HIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-WongHIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-WongLorianne Sainsbury-Wong
 
HIPAA Security Risk Analysis for Business Associates
HIPAA Security Risk Analysis for Business AssociatesHIPAA Security Risk Analysis for Business Associates
HIPAA Security Risk Analysis for Business AssociatesRedspin, Inc.
 
Redspin PHI Breach Report 2012
Redspin PHI Breach Report 2012Redspin PHI Breach Report 2012
Redspin PHI Breach Report 2012Redspin, Inc.
 
The HIPAA Security Rule: Yes, It's Your Problem
The HIPAA Security Rule: Yes, It's Your ProblemThe HIPAA Security Rule: Yes, It's Your Problem
The HIPAA Security Rule: Yes, It's Your ProblemSecurityMetrics
 
A brief introduction to hipaa compliance
A brief introduction to hipaa complianceA brief introduction to hipaa compliance
A brief introduction to hipaa compliancePrince George
 
You and HIPAA - Get the Facts
You and HIPAA - Get the FactsYou and HIPAA - Get the Facts
You and HIPAA - Get the Factsresourceone
 
HIPAA | HITECH
HIPAA | HITECHHIPAA | HITECH
HIPAA | HITECHrcabarloc
 
HIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceHIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceJay Hodes
 
HIPPA Security Presentation
HIPPA Security PresentationHIPPA Security Presentation
HIPPA Security PresentationRebecca Norman
 
Hipaa101 updated
Hipaa101 updatedHipaa101 updated
Hipaa101 updatedkkurapat
 
HIPAA Panel Discussion
HIPAA Panel Discussion HIPAA Panel Discussion
HIPAA Panel Discussion Dan Wellisch
 

What's hot (19)

Iadmdhipmkt1.0
Iadmdhipmkt1.0Iadmdhipmkt1.0
Iadmdhipmkt1.0
 
Compliance
ComplianceCompliance
Compliance
 
HIPAA Training (2017)
HIPAA Training (2017) HIPAA Training (2017)
HIPAA Training (2017)
 
The Basics of HIPAA
The Basics of HIPAA The Basics of HIPAA
The Basics of HIPAA
 
Health Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - KloudlearnHealth Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
Health Insurance Portability and Accountability Act (HIPPA) - Kloudlearn
 
HIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-WongHIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-Wong
 
HIPAA Security Risk Analysis for Business Associates
HIPAA Security Risk Analysis for Business AssociatesHIPAA Security Risk Analysis for Business Associates
HIPAA Security Risk Analysis for Business Associates
 
Hippa
HippaHippa
Hippa
 
Redspin PHI Breach Report 2012
Redspin PHI Breach Report 2012Redspin PHI Breach Report 2012
Redspin PHI Breach Report 2012
 
The HIPAA Security Rule: Yes, It's Your Problem
The HIPAA Security Rule: Yes, It's Your ProblemThe HIPAA Security Rule: Yes, It's Your Problem
The HIPAA Security Rule: Yes, It's Your Problem
 
A brief introduction to hipaa compliance
A brief introduction to hipaa complianceA brief introduction to hipaa compliance
A brief introduction to hipaa compliance
 
You and HIPAA - Get the Facts
You and HIPAA - Get the FactsYou and HIPAA - Get the Facts
You and HIPAA - Get the Facts
 
HIPAA | HITECH
HIPAA | HITECHHIPAA | HITECH
HIPAA | HITECH
 
Hi103 week 4 chpt 10
Hi103 week 4 chpt 10Hi103 week 4 chpt 10
Hi103 week 4 chpt 10
 
Hm300 week 6
Hm300 week 6 Hm300 week 6
Hm300 week 6
 
HIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of ComplianceHIPAA - Understanding the Basics of Compliance
HIPAA - Understanding the Basics of Compliance
 
HIPPA Security Presentation
HIPPA Security PresentationHIPPA Security Presentation
HIPPA Security Presentation
 
Hipaa101 updated
Hipaa101 updatedHipaa101 updated
Hipaa101 updated
 
HIPAA Panel Discussion
HIPAA Panel Discussion HIPAA Panel Discussion
HIPAA Panel Discussion
 

Similar to The Intersection of OCR Enforcement and Health Care Data Privacy & Security

Understanding HIPAA
Understanding HIPAAUnderstanding HIPAA
Understanding HIPAAManas Deep
 
HIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookHIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookElizabeth Dimit
 
Keys To HIPAA Compliance
Keys To HIPAA ComplianceKeys To HIPAA Compliance
Keys To HIPAA ComplianceCBIZ, Inc.
 
PSOW 2016 - HIPAA Compliance for EMS Community
PSOW 2016 - HIPAA Compliance for EMS CommunityPSOW 2016 - HIPAA Compliance for EMS Community
PSOW 2016 - HIPAA Compliance for EMS CommunityPSOW
 
Mbm Hipaa Hitech Ss Compliance Risk Assessment
Mbm Hipaa Hitech Ss Compliance Risk AssessmentMbm Hipaa Hitech Ss Compliance Risk Assessment
Mbm Hipaa Hitech Ss Compliance Risk AssessmentMBMeHealthCareSolutions
 
Comp8 unit6a lecture_slides
Comp8 unit6a lecture_slidesComp8 unit6a lecture_slides
Comp8 unit6a lecture_slidesCMDLMS
 
Hipaa checklist for healthcare software
Hipaa checklist for healthcare softwareHipaa checklist for healthcare software
Hipaa checklist for healthcare softwareConcetto Labs
 
Confidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAAConfidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAAParsons Behle & Latimer
 
Sarah Kim HIPAA for Small Providers
Sarah Kim HIPAA for Small ProvidersSarah Kim HIPAA for Small Providers
Sarah Kim HIPAA for Small ProvidersSarah Kim
 
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...eringold
 
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdf
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdfHIPAA-Compliant App Development Guide for the Healthcare Industry.pdf
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdfSuccessiveDigital
 
Describe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdfDescribe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdfmohammedfootwear
 
Hhs issues hipaa cyber attack response checklist
Hhs issues hipaa cyber attack response checklistHhs issues hipaa cyber attack response checklist
Hhs issues hipaa cyber attack response checklistTodd LaRue
 
Privacy and Security What types of health care data are protected u.pdf
Privacy and Security What types of health care data are protected u.pdfPrivacy and Security What types of health care data are protected u.pdf
Privacy and Security What types of health care data are protected u.pdfbadshetoms
 
Data and Network Security: What You Need to Know
Data and Network Security: What You Need to KnowData and Network Security: What You Need to Know
Data and Network Security: What You Need to KnowPYA, P.C.
 
The Importance of HIPAA Compliance in Digital Healthcare Solutions.pptx
The Importance of HIPAA Compliance in Digital Healthcare Solutions.pptxThe Importance of HIPAA Compliance in Digital Healthcare Solutions.pptx
The Importance of HIPAA Compliance in Digital Healthcare Solutions.pptxMocDoc
 
What Is Security Risk Analysis? By: MedSafe
What Is Security Risk Analysis? By: MedSafeWhat Is Security Risk Analysis? By: MedSafe
What Is Security Risk Analysis? By: MedSafeMedSafe
 

Similar to The Intersection of OCR Enforcement and Health Care Data Privacy & Security (20)

Healthcare and Cyber security
Healthcare and Cyber securityHealthcare and Cyber security
Healthcare and Cyber security
 
Understanding HIPAA
Understanding HIPAAUnderstanding HIPAA
Understanding HIPAA
 
HIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookHIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule Playbook
 
Keys To HIPAA Compliance
Keys To HIPAA ComplianceKeys To HIPAA Compliance
Keys To HIPAA Compliance
 
PSOW 2016 - HIPAA Compliance for EMS Community
PSOW 2016 - HIPAA Compliance for EMS CommunityPSOW 2016 - HIPAA Compliance for EMS Community
PSOW 2016 - HIPAA Compliance for EMS Community
 
Mbm Hipaa Hitech Ss Compliance Risk Assessment
Mbm Hipaa Hitech Ss Compliance Risk AssessmentMbm Hipaa Hitech Ss Compliance Risk Assessment
Mbm Hipaa Hitech Ss Compliance Risk Assessment
 
Comp8 unit6a lecture_slides
Comp8 unit6a lecture_slidesComp8 unit6a lecture_slides
Comp8 unit6a lecture_slides
 
Hipaa checklist for healthcare software
Hipaa checklist for healthcare softwareHipaa checklist for healthcare software
Hipaa checklist for healthcare software
 
Confidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAAConfidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAA
 
Sarah Kim HIPAA for Small Providers
Sarah Kim HIPAA for Small ProvidersSarah Kim HIPAA for Small Providers
Sarah Kim HIPAA for Small Providers
 
Hipaa basics
Hipaa basicsHipaa basics
Hipaa basics
 
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
PACT Cybersecurity Series Event, speaker Gregory M. Fliszar, Esq. of Cozen O'...
 
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdf
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdfHIPAA-Compliant App Development Guide for the Healthcare Industry.pdf
HIPAA-Compliant App Development Guide for the Healthcare Industry.pdf
 
Describe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdfDescribe one safeguard that should be in place to protect the confid.pdf
Describe one safeguard that should be in place to protect the confid.pdf
 
Hhs issues hipaa cyber attack response checklist
Hhs issues hipaa cyber attack response checklistHhs issues hipaa cyber attack response checklist
Hhs issues hipaa cyber attack response checklist
 
Privacy and Security What types of health care data are protected u.pdf
Privacy and Security What types of health care data are protected u.pdfPrivacy and Security What types of health care data are protected u.pdf
Privacy and Security What types of health care data are protected u.pdf
 
Data and Network Security: What You Need to Know
Data and Network Security: What You Need to KnowData and Network Security: What You Need to Know
Data and Network Security: What You Need to Know
 
The Importance of HIPAA Compliance in Digital Healthcare Solutions.pptx
The Importance of HIPAA Compliance in Digital Healthcare Solutions.pptxThe Importance of HIPAA Compliance in Digital Healthcare Solutions.pptx
The Importance of HIPAA Compliance in Digital Healthcare Solutions.pptx
 
What Is Security Risk Analysis? By: MedSafe
What Is Security Risk Analysis? By: MedSafeWhat Is Security Risk Analysis? By: MedSafe
What Is Security Risk Analysis? By: MedSafe
 
Risk management in Healthcare on Cloud
Risk management in Healthcare on CloudRisk management in Healthcare on Cloud
Risk management in Healthcare on Cloud
 

More from Polsinelli PC

Tax Cuts & Job Act Implications for Small Business Investments Companies
Tax Cuts & Job Act Implications for Small Business Investments Companies Tax Cuts & Job Act Implications for Small Business Investments Companies
Tax Cuts & Job Act Implications for Small Business Investments Companies Polsinelli PC
 
Preventing Compliance Quagmires in Senior Living Communities: Part 1 - Can So...
Preventing Compliance Quagmires in Senior Living Communities: Part 1 - Can So...Preventing Compliance Quagmires in Senior Living Communities: Part 1 - Can So...
Preventing Compliance Quagmires in Senior Living Communities: Part 1 - Can So...Polsinelli PC
 
Life After Escobar – Recent Developments In False Claims Act Litigation
Life After Escobar – Recent Developments In False Claims Act LitigationLife After Escobar – Recent Developments In False Claims Act Litigation
Life After Escobar – Recent Developments In False Claims Act LitigationPolsinelli PC
 
The Emerald Series: Emily's Road to the Ideal Workplace Get to Work (Off the ...
The Emerald Series: Emily's Road to the Ideal Workplace Get to Work (Off the ...The Emerald Series: Emily's Road to the Ideal Workplace Get to Work (Off the ...
The Emerald Series: Emily's Road to the Ideal Workplace Get to Work (Off the ...Polsinelli PC
 
Big Decisions: ACO Participation Reforming and Unwinding in 2019
Big Decisions: ACO Participation Reforming and Unwinding in 2019Big Decisions: ACO Participation Reforming and Unwinding in 2019
Big Decisions: ACO Participation Reforming and Unwinding in 2019Polsinelli PC
 
Tax Cuts & Jobs Act Implications for Banking Institutions
Tax Cuts & Jobs Act Implications for Banking Institutions Tax Cuts & Jobs Act Implications for Banking Institutions
Tax Cuts & Jobs Act Implications for Banking Institutions Polsinelli PC
 
340B Drug Pricing Under the Microscope
340B Drug Pricing Under the Microscope340B Drug Pricing Under the Microscope
340B Drug Pricing Under the MicroscopePolsinelli PC
 
The Emerald Series: It's (not) in the Handbook
The Emerald Series: It's (not) in the HandbookThe Emerald Series: It's (not) in the Handbook
The Emerald Series: It's (not) in the HandbookPolsinelli PC
 
Health Care "Prime" - The Future of the Ownership, Organization, Payment, and...
Health Care "Prime" - The Future of the Ownership, Organization, Payment, and...Health Care "Prime" - The Future of the Ownership, Organization, Payment, and...
Health Care "Prime" - The Future of the Ownership, Organization, Payment, and...Polsinelli PC
 
The Trump Labor Board Goes Back to the Future
The Trump Labor Board Goes Back to the FutureThe Trump Labor Board Goes Back to the Future
The Trump Labor Board Goes Back to the FuturePolsinelli PC
 
Fraud and Abuse - 2017 Year in Review
Fraud and Abuse - 2017 Year in ReviewFraud and Abuse - 2017 Year in Review
Fraud and Abuse - 2017 Year in ReviewPolsinelli PC
 
Health Care Policy Forecast: What to Expect in 2018
Health Care Policy Forecast: What to Expect in 2018Health Care Policy Forecast: What to Expect in 2018
Health Care Policy Forecast: What to Expect in 2018Polsinelli PC
 
Lessons learned from litigating real estate development projects
Lessons learned from litigating real estate development projectsLessons learned from litigating real estate development projects
Lessons learned from litigating real estate development projectsPolsinelli PC
 
Blockchain in Health Care
Blockchain in Health CareBlockchain in Health Care
Blockchain in Health CarePolsinelli PC
 
Mitigating Risk When Managing High Dose, Chronic Pain Patients
Mitigating Risk When Managing High Dose, Chronic Pain Patients Mitigating Risk When Managing High Dose, Chronic Pain Patients
Mitigating Risk When Managing High Dose, Chronic Pain Patients Polsinelli PC
 
The Feds Are Coming! Session One: The Rules Have Changed
The Feds Are Coming! Session One: The Rules Have ChangedThe Feds Are Coming! Session One: The Rules Have Changed
The Feds Are Coming! Session One: The Rules Have ChangedPolsinelli PC
 
Diamond Datascram Decimated
Diamond Datascram DecimatedDiamond Datascram Decimated
Diamond Datascram DecimatedPolsinelli PC
 
Artificial Intelligence and Machine Learning
Artificial Intelligence and Machine LearningArtificial Intelligence and Machine Learning
Artificial Intelligence and Machine LearningPolsinelli PC
 
Class Actions Close-Up
Class Actions Close-UpClass Actions Close-Up
Class Actions Close-UpPolsinelli PC
 
Diamond Datascram Decline
Diamond Datascram DeclineDiamond Datascram Decline
Diamond Datascram DeclinePolsinelli PC
 

More from Polsinelli PC (20)

Tax Cuts & Job Act Implications for Small Business Investments Companies
Tax Cuts & Job Act Implications for Small Business Investments Companies Tax Cuts & Job Act Implications for Small Business Investments Companies
Tax Cuts & Job Act Implications for Small Business Investments Companies
 
Preventing Compliance Quagmires in Senior Living Communities: Part 1 - Can So...
Preventing Compliance Quagmires in Senior Living Communities: Part 1 - Can So...Preventing Compliance Quagmires in Senior Living Communities: Part 1 - Can So...
Preventing Compliance Quagmires in Senior Living Communities: Part 1 - Can So...
 
Life After Escobar – Recent Developments In False Claims Act Litigation
Life After Escobar – Recent Developments In False Claims Act LitigationLife After Escobar – Recent Developments In False Claims Act Litigation
Life After Escobar – Recent Developments In False Claims Act Litigation
 
The Emerald Series: Emily's Road to the Ideal Workplace Get to Work (Off the ...
The Emerald Series: Emily's Road to the Ideal Workplace Get to Work (Off the ...The Emerald Series: Emily's Road to the Ideal Workplace Get to Work (Off the ...
The Emerald Series: Emily's Road to the Ideal Workplace Get to Work (Off the ...
 
Big Decisions: ACO Participation Reforming and Unwinding in 2019
Big Decisions: ACO Participation Reforming and Unwinding in 2019Big Decisions: ACO Participation Reforming and Unwinding in 2019
Big Decisions: ACO Participation Reforming and Unwinding in 2019
 
Tax Cuts & Jobs Act Implications for Banking Institutions
Tax Cuts & Jobs Act Implications for Banking Institutions Tax Cuts & Jobs Act Implications for Banking Institutions
Tax Cuts & Jobs Act Implications for Banking Institutions
 
340B Drug Pricing Under the Microscope
340B Drug Pricing Under the Microscope340B Drug Pricing Under the Microscope
340B Drug Pricing Under the Microscope
 
The Emerald Series: It's (not) in the Handbook
The Emerald Series: It's (not) in the HandbookThe Emerald Series: It's (not) in the Handbook
The Emerald Series: It's (not) in the Handbook
 
Health Care "Prime" - The Future of the Ownership, Organization, Payment, and...
Health Care "Prime" - The Future of the Ownership, Organization, Payment, and...Health Care "Prime" - The Future of the Ownership, Organization, Payment, and...
Health Care "Prime" - The Future of the Ownership, Organization, Payment, and...
 
The Trump Labor Board Goes Back to the Future
The Trump Labor Board Goes Back to the FutureThe Trump Labor Board Goes Back to the Future
The Trump Labor Board Goes Back to the Future
 
Fraud and Abuse - 2017 Year in Review
Fraud and Abuse - 2017 Year in ReviewFraud and Abuse - 2017 Year in Review
Fraud and Abuse - 2017 Year in Review
 
Health Care Policy Forecast: What to Expect in 2018
Health Care Policy Forecast: What to Expect in 2018Health Care Policy Forecast: What to Expect in 2018
Health Care Policy Forecast: What to Expect in 2018
 
Lessons learned from litigating real estate development projects
Lessons learned from litigating real estate development projectsLessons learned from litigating real estate development projects
Lessons learned from litigating real estate development projects
 
Blockchain in Health Care
Blockchain in Health CareBlockchain in Health Care
Blockchain in Health Care
 
Mitigating Risk When Managing High Dose, Chronic Pain Patients
Mitigating Risk When Managing High Dose, Chronic Pain Patients Mitigating Risk When Managing High Dose, Chronic Pain Patients
Mitigating Risk When Managing High Dose, Chronic Pain Patients
 
The Feds Are Coming! Session One: The Rules Have Changed
The Feds Are Coming! Session One: The Rules Have ChangedThe Feds Are Coming! Session One: The Rules Have Changed
The Feds Are Coming! Session One: The Rules Have Changed
 
Diamond Datascram Decimated
Diamond Datascram DecimatedDiamond Datascram Decimated
Diamond Datascram Decimated
 
Artificial Intelligence and Machine Learning
Artificial Intelligence and Machine LearningArtificial Intelligence and Machine Learning
Artificial Intelligence and Machine Learning
 
Class Actions Close-Up
Class Actions Close-UpClass Actions Close-Up
Class Actions Close-Up
 
Diamond Datascram Decline
Diamond Datascram DeclineDiamond Datascram Decline
Diamond Datascram Decline
 

Recently uploaded

From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...
From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...
From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...Sehrish Saba
 
Types of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM ITypes of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM Iyogita9398
 
Democratic Awareness with Legal Literacy POLS 303.pptx
Democratic Awareness with Legal Literacy POLS 303.pptxDemocratic Awareness with Legal Literacy POLS 303.pptx
Democratic Awareness with Legal Literacy POLS 303.pptxNarenderSharma219732
 
The Main Procedures for a Divorce in Greece
The Main Procedures for a Divorce in GreeceThe Main Procedures for a Divorce in Greece
The Main Procedures for a Divorce in GreeceBridgeWest.eu
 
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...Sangyun Lee
 
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...ZurliaSoop
 
Elective Course on Forensic Science in Law
Elective Course on Forensic Science  in LawElective Course on Forensic Science  in Law
Elective Course on Forensic Science in LawNilendra Kumar
 
Assignment of Law of crime.pptx including crpc
Assignment of Law of crime.pptx including crpcAssignment of Law of crime.pptx including crpc
Assignment of Law of crime.pptx including crpcKhushbooChoubey1
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理Airst S
 
5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdfTodd Spodek
 
Essential Components of an Effective HIPAA Safeguard Program
Essential Components of an Effective HIPAA Safeguard ProgramEssential Components of an Effective HIPAA Safeguard Program
Essential Components of an Effective HIPAA Safeguard ProgramColington Consulting
 
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样mefyqyn
 
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理F La
 
Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Nilendra Kumar
 
Jim Eiberger Rental Agreement Redacted Former Lease.docx
Jim Eiberger Rental Agreement Redacted Former Lease.docxJim Eiberger Rental Agreement Redacted Former Lease.docx
Jim Eiberger Rental Agreement Redacted Former Lease.docxDenver CO
 
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证trryfxkn
 
一比一原版(ASU毕业证书)亚利桑那州立大学毕业证成绩单原件一模一样
一比一原版(ASU毕业证书)亚利桑那州立大学毕业证成绩单原件一模一样一比一原版(ASU毕业证书)亚利桑那州立大学毕业证成绩单原件一模一样
一比一原版(ASU毕业证书)亚利桑那州立大学毕业证成绩单原件一模一样mefyqyn
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理Airst S
 
posts-harmful-to-secular-structure-of-the-country-539103-1.pdf
posts-harmful-to-secular-structure-of-the-country-539103-1.pdfposts-harmful-to-secular-structure-of-the-country-539103-1.pdf
posts-harmful-to-secular-structure-of-the-country-539103-1.pdfbhavenpr
 
ORane M Cornish affidavit statement for New Britain court proving Wentworth'...
ORane M Cornish affidavit statement  for New Britain court proving Wentworth'...ORane M Cornish affidavit statement  for New Britain court proving Wentworth'...
ORane M Cornish affidavit statement for New Britain court proving Wentworth'...Oranecornish
 

Recently uploaded (20)

From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...
From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...
From Scratch to Strong: Introduction to Drafting of Criminal Cases and Applic...
 
Types of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM ITypes of Agricultural markets LLB- SEM I
Types of Agricultural markets LLB- SEM I
 
Democratic Awareness with Legal Literacy POLS 303.pptx
Democratic Awareness with Legal Literacy POLS 303.pptxDemocratic Awareness with Legal Literacy POLS 303.pptx
Democratic Awareness with Legal Literacy POLS 303.pptx
 
The Main Procedures for a Divorce in Greece
The Main Procedures for a Divorce in GreeceThe Main Procedures for a Divorce in Greece
The Main Procedures for a Divorce in Greece
 
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
Sangyun Lee, Duplicate Powers in the Criminal Referral Process and the Overla...
 
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
Jual obat aborsi Bandung ( 085657271886 ) Cytote pil telat bulan penggugur ka...
 
Elective Course on Forensic Science in Law
Elective Course on Forensic Science  in LawElective Course on Forensic Science  in Law
Elective Course on Forensic Science in Law
 
Assignment of Law of crime.pptx including crpc
Assignment of Law of crime.pptx including crpcAssignment of Law of crime.pptx including crpc
Assignment of Law of crime.pptx including crpc
 
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
一比一原版(CQU毕业证书)中央昆士兰大学毕业证如何办理
 
5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf5-6-24 David Kennedy Article Law 360.pdf
5-6-24 David Kennedy Article Law 360.pdf
 
Essential Components of an Effective HIPAA Safeguard Program
Essential Components of an Effective HIPAA Safeguard ProgramEssential Components of an Effective HIPAA Safeguard Program
Essential Components of an Effective HIPAA Safeguard Program
 
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样
一比一原版(BCU毕业证书)伯明翰城市大学毕业证成绩单原件一模一样
 
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
一比一原版(TheAuckland毕业证书)新西兰奥克兰大学毕业证如何办理
 
Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.Cyber Laws : National and International Perspective.
Cyber Laws : National and International Perspective.
 
Jim Eiberger Rental Agreement Redacted Former Lease.docx
Jim Eiberger Rental Agreement Redacted Former Lease.docxJim Eiberger Rental Agreement Redacted Former Lease.docx
Jim Eiberger Rental Agreement Redacted Former Lease.docx
 
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
一比一原版(McMaster毕业证书)麦克马斯特大学毕业证学历认证可查认证
 
一比一原版(ASU毕业证书)亚利桑那州立大学毕业证成绩单原件一模一样
一比一原版(ASU毕业证书)亚利桑那州立大学毕业证成绩单原件一模一样一比一原版(ASU毕业证书)亚利桑那州立大学毕业证成绩单原件一模一样
一比一原版(ASU毕业证书)亚利桑那州立大学毕业证成绩单原件一模一样
 
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
一比一原版(QUT毕业证书)昆士兰科技大学毕业证如何办理
 
posts-harmful-to-secular-structure-of-the-country-539103-1.pdf
posts-harmful-to-secular-structure-of-the-country-539103-1.pdfposts-harmful-to-secular-structure-of-the-country-539103-1.pdf
posts-harmful-to-secular-structure-of-the-country-539103-1.pdf
 
ORane M Cornish affidavit statement for New Britain court proving Wentworth'...
ORane M Cornish affidavit statement  for New Britain court proving Wentworth'...ORane M Cornish affidavit statement  for New Britain court proving Wentworth'...
ORane M Cornish affidavit statement for New Britain court proving Wentworth'...
 

The Intersection of OCR Enforcement and Health Care Data Privacy & Security

  • 1. The Intersection of OCR Enforcement and Health Care Data Privacy & Security
  • 2. Agenda  New Guidance from OCR  HIPAA Security Rule and Cyber Security  HHS and FTC Enforcement Update  Resources 2
  • 3. 21st Century Cures/Opioid Crisis https://www.hhs.gov/hipaa/for-professionals/special-topics/mental- health/index.html  HIPAA Helps Mental Health Professionals to Prevent Harm  HIPAA Helps Family and Friends Stay Connected with Loved Ones Who Have a Substance Use Disorder, including Opioid Abuse, or a Mental or Behavioral Health Condition  When can I obtain treatment information about my loved one? (decision chart)  If You Experience a Health or Mental Health Crisis, HIPAA Helps Your Doctors, Nurses, and Social Workers to Reconnect You with Family, Friends, and Caregivers  How HIPAA Allows Doctors to Respond to the Opioid Crisis  When Your Child, Teenager, or Young Adult has Mental Illness: What Parents Need to Know about HIPAA  Am I my child’s personal representative under HIPAA?  When may a mental health professional use professional judgment to decide whether to share a minor client’s treatment information with a parent?  When can parents access information about their minor child’s mental health treatment? (Decision Chart)  HIPAA Privacy Rule and Sharing Information Related to Mental Health 3
  • 4. Recent Cyber Security Attacks, Threats, and Trends  2017 Cyber Healthcare & Life Sciences Survey found that 47 percent of providers and health plans had a security-related HIPAA violation or a cybersecurity attack that impacted data.  Office for Civil Rights data regarding Breaches involving 500+ individuals  Ransomware – WannaCry  Phishing and Social Engineering  Other Attacks 4
  • 5. Preparing for a Cybersecurity Attack It’s not a matter of IF an attack will occur, but rather WHEN… Steps to take to help address the WHEN:  Implementing an effective compliance program  Information assurance and information system architecture  Obtaining adequate cyberliability coverage 5
  • 6. Key Security-Related Aspects of an Effective Compliance Program  View the HIPAA Security Rule only as a baseline and policy framework requirement – Risk Analysis and Risk Management Plans – Encryption and password management – “Addressable” does not mean “Optional”  Ensuring internal/external expertise is readily available  Effective workforce training and monitoring  Effective incident response procedures 6
  • 7. Incident Handling Preparation  Assign Roles and Responsibilities  Assert Information needed to Construct Event  Define Relationships with Third Parties  Train your Team 7
  • 8. Cyber Security https://www.hhs.gov/hipaa/for- professionals/security/guidance/cybersecurity/index.html  Cyber Security Checklist and Infographic  Ransomware Guidance  NIST Cybersecurity Framework  OCR Cyber Awareness Newsletters https://www.hhs.gov/hipaa/for-professionals/special-topics/cloud- computing/index.html  Cloud Computing 8Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
  • 9. Effectively Responding to an Attack  Time is of the Essence – Immediate Isolation – Notification Timeframes (including insurance carrier)  Engaging Outside Assistance – Security forensic experts – Legal counsel – Law Enforcement  Returning to Business As Usual 9
  • 10. Key Takeaways  Too small to be a target is a myth.  Preparation does not guarantee Prevention, but is the most important mitigation step.  All individuals at your organization are responsible and need to be involved.  Time is always of the essence.  Human error cannot be 100% prevented, but awareness goes a long way. 10
  • 11. HITECH Audit Program Phase 2 Status  166 covered entity desk audits  41 business associate desk audits  After Phase 2, on-site audits will be conducted as a part of the permanent audit program. – On-site audits will evaluate auditees against comprehensive selection of controls in the audit protocol: – https://www.hhs.gov/hipaa/for-professionals/compliance- enforcement/audit/protocol/ 11Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
  • 12. Desk Audit Scope  Covered Entities – Security: risk analysis and risk management – Breach: content and timeliness of notifications – Privacy: notice and access  Business Associates – Security: risk analysis and risk management – Breach: reporting to covered entities 12Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
  • 13. Ratings 13 Compliance Effort Ratings – Legend Rating Description 1 The audit results indicate the entity is in compliance with both goals and objectives of the selected standards and implementation specifications. 2 The audit results indicate that the entity substantially meets criteria; it maintains appropriate policies and procedures, and documentation and other evidence of implementation meet requirements. 3 Audit results indicate entity efforts minimally address audited requirements; analysis indicates that entity has made attempts to comply, but implementation is inadequate, or some efforts indicate misunderstanding of requirements. 4 Audit results indicate the entity made negligible efforts to comply with the audited requirements - e.g. policies and procedures submitted for review are copied directly from an association template; evidence of training is poorly documented and generic. 5 The entity did not provide OCR with evidence of serious attempt to comply with the Rules and enable individual rights with regard to PHI. Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
  • 14. CE Desk Audit Ratings 14 Rating Element # Provision 1 2 3 4 5 N/A P55 Notice 2 34 40 11 16 0 P58 eNotice 59 16 4 6 15 3 P65 Access 1 10 27 54 11 0 BNR12 Timeliness 67 6 2 9 12 7 BNR13 Content 14 15 24 38 7 5 S2 Risk Analysis 0 9 20 21 13 0 S3 Risk Management 2 2 15 28 16 0 Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
  • 15. BA Desk Audit Ratings 15 Rating Element # Provision 1 2 3 4 5 N/A BNR17 Notice to CEs 1 2 3 3 0 32 S2 Risk Analysis 3 5 15 12 6 0 S3 Risk Management 0 5 8 21 7 0 Linda Sanches, Office for Civil Rights (OCR), U.S. Department of Health and Human Services
  • 16. Recent HHS Enforcement Actions 16  April 24, 2017: CardioNet – $2,500,000 – $2.5 million settlement shows that not understanding HIPAA requirements creates risk  May 10, 2017: Memorial Hermann Health System (MHHS) – $2,400,000 – Texas health system settles potential HIPAA violations for disclosing patient information  May 23, 2017: St. Luke’s Roosevelt Hospital System Inc. – $387,200 – Careless handling of HIV information jeopardizes patient’s privacy, costs entity $387k  December 18, 2017: 21st Century Oncology – $2,300,000 – $2.3 Million Levied for Multiple HIPAA Violations at NY-Based Provider  February 1, 2018: Fresenius Medical Care North America (FMCNA) – $3,500,000 – Five breaches add up to millions in settlement costs for entity that failed to heed HIPAA’s risk analysis and risk management rules  February 13, 2018: Filefax, Inc. – $100,000 – Consequences for HIPAA violations don’t stop when a business closes
  • 17. Recent FTC Enforcement Actions 17  Feb 27, 2018: – PayPal Settles FTC Charges that Venmo Failed to Disclose Information to Consumers About the Ability to Transfer Funds and Privacy Settings; Violated Gramm-Leach-Bliley Act  Nov 29, 2017: – FTC Gives Final Approval to Settlements with Companies that Falsely Claimed Participation in Privacy Shield  Nov 8, 2017: – FTC Gives Final Approval to Settlement with Online Tax Preparation Service  Aug 15, 2017: – Uber Settles FTC Allegations that It Made Deceptive Privacy and Data Security Claims
  • 18. GDPR: What’s All the Fuss?  EU’s General Data Protection Regulation – More broad territorial scope, and may apply to entities with no physical presence in the EU – Unlike HIPAA, applies to all personal data, not just PHI – Permits uses and disclosures of health data, but exceptions do not always align with HIPAA – Heavy fines and penalties – Stay tuned for more information regarding GDPR as applied to the U.S. health care industry
  • 19. HHS/FTC Resources  https://www.hhs.gov/hipaa/for-professionals/privacy/index.html  https://www.hhs.gov/hipaa/for-professionals/security/index.html  https://www.hhs.gov/hipaa/for-professionals/breach- notification/index.html  https://www.hhs.gov/hipaa/for-professionals/compliance- enforcement/index.html  https://www.ftc.gov/  https://www.ftc.gov/system/files/documents/plain-language/pdf0205- startwithsecurity.pdf  https://www.ftc.gov/news-events/press-releases/2018/02/ftc- recommends-steps-improve-mobile-device-security-update  https://www.ftc.gov/news-events/press-releases/2018/02/ftc-report- finds-some-small-business-web-hosting-services-could 19
  • 20. Polsinelli Resources  Polsinelli serves clients nationally: – https://www.polsinelli.com/ – 100+ services and 70+ industry areas – 800+ Attorneys – https://www.polsinelli.com/professionals/lacevedo – https://www.polsinelli.com/professionals/ipeters – 20 Cities – Metropolitan offices in: 20  Atlanta  Boston  Chicago  Dallas  Denver  Houston  Kansas City  Los Angeles  Nashville  New York  Phoenix  St. Louis  San Francisco  Silicon Valley  Washington, D.C.  Wilmington
  • 21. Polsinelli PC, Polsinelli LLP in California | polsinelli.com Polsinelli PC provides this material for informational purposes only. The material provided herein is general and is not intended to be legal advice. Nothing herein should be relied upon or used without consulting a lawyer to consider your specific circumstances, possible changes to applicable laws, rules and regulations and other legal issues. Receipt of this material does not establish an attorney-client relationship. Polsinelli is very proud of the results we obtain for our clients, but you should know that past results do not guarantee future results; that every case is different and must be judged on its own merits; and that the choice of a lawyer is an important decision and should not be based solely upon advertisements. © 2018 Polsinelli® is a registered trademark of Polsinelli PC. In California, Polsinelli LLP. 21

Editor's Notes

  1. Enterprise-wide Approach to security (not just an IT issue) Security Officers Internal expertise on IT issues, if not outsource STRONGLY advise against relying too heavily on EHR vendors