For Clarity’s Sake: Feedback on Recent OCR Recommendations

New Rule OCR Recommendations Clarified

OCR just signaled where HIPAA enforcement is heading and healthcare organizations should take note. In an April 23, 2026 news release re four ransomware investigation settlements, the OCR outlined 8 cybersecurity recommendations for covered entities and business associates. Learn more>

You Have Time, HIPAA’s Security Rule Hasn’t Changed Yet

NPRM Security Rule proposed

You’re fine, really. No need to panic. Yes, the NPRM is [finally] progressing. BUT – it’s not yet time to overhaul HIPAA Security Policies & Procedures, or buy new tools. Read my latest article to learn why (and DM me if you’d like a free copy of my latest webinar material relating to the NPRM). Read on to learn more.

Reproductive Health & HIPAA: Key Takeaways from the New Rule

HIPAA New Rule Reproductive Health

With states weighing in on their own versions of how to handle reproductive health, there’s been confusion about what is and isn’t PHI when it comes to women’s healthcare since the overturn of Roe v Wade – the phrase “clear as mud” comes to mind. The Biden-Harris Administration’s “New Rule” for HIPAA helps clear the … Read more

Audit Log Monitoring: Tiresome But Oh-So-Necessary

audit-log-monitoring

Audit log monitoring is probably one of the most unsexy, uninteresting activities a healthcare organization or business associate has to do.  But neglect it at the risk of your solid bottom line and reputation. Last time we talked about how you can get into legal (and costly) hot water with badly aligned policies and procedures … Read more

Healthcare Organizations: What can get you into [costly] hot water?

healthcare org costly hot

For healthcare organizations and the businesses that support them, regulation and legislation too often turn into lawsuits and settlements. What’s happening to get you into trouble in the first place? How can you avoid the serious costs they bring – to the bottom line and to reputation? Here’s what Julia and I often see from … Read more

How the SHIELD Act Expands Legal Reach on Breaches

New York SHIELD Act image

Interested in some (thankfully) non-pandemic related news? New York State’s SHIELD Act is in effect as of March 21, 2020. The SHIELD Act (Stop Hacks and Improve Electronic Data Security Act) takes several actions, including: broadening the definition of “Private Information”, expanding the definition of breach, and expanding the reach of the law to include … Read more

When It’s OK to Share: OCR’s Novel Coronavirus Disease (COVID-19) Limited Waiver

OCR Limited Waiver HIPAA

Novel Coronavirus, aka COVID-19, is on track to stretch our healthcare system to the breaking point, and our healthcare providers along with it. In effect as of March 15, 2020, the OCR’s published a Limited Waiver of HIPAA Sanctions and Penalties that during this National Emergency could give care providers one less source of anxiety … Read more

What does the CCPA have to do with Policies & Procedures?

policies procedures CCPA

Compliance with CCPA is entwined with how you do business. Your business operations (the “how and what”) directly link to company policy, controls, processes: policies and procedures. You could say that the CCPA has everything to do with policies and procedures. Which is why you need to update yours – yesterday. Not convinced? Let’s go … Read more

Consumers in the Regulatory Driver’s Seat: Protecting Personal Data Privacy

protect personal data privacy

Consumers on the warpath to protect personal data privacy are making strides in state houses. For instance, here’s an update on Oregon’s Senate Bill 703 re selling health information. If you use Big Data at all, you’ve probably been following this Bill. It’s basically saying that anyone selling personal health information, although thoroughly de-identified, would … Read more