Effective June 5, 2026: Oregon SB 1570
Ready for June 5, 2026? You’ll need to “Know Who Enters, Protect What’s Shared” when it comes to Oregon SB 1570 and the new rules for Law Enforcement interactions in Hospitals and FQHCs.
Ready for June 5, 2026? You’ll need to “Know Who Enters, Protect What’s Shared” when it comes to Oregon SB 1570 and the new rules for Law Enforcement interactions in Hospitals and FQHCs.
OCR just signaled where HIPAA enforcement is heading and healthcare organizations should take note. In an April 23, 2026 news release re four ransomware investigation settlements, the OCR outlined 8 cybersecurity recommendations for covered entities and business associates. Learn more>
The Wall Street Journal scoop from April 22nd about what led to the Change Healthcare breach came after HHS created an FAQ about the incident. The scoop summary pulled these top 3 points about basic security: Compromised credentials to log into an application that allowed Change staff members to remotely access the network Multifactor authentication … Read more
With states weighing in on their own versions of how to handle reproductive health, there’s been confusion about what is and isn’t PHI when it comes to women’s healthcare since the overturn of Roe v Wade – the phrase “clear as mud” comes to mind. The Biden-Harris Administration’s “New Rule” for HIPAA helps clear the … Read more
With every new headline about women’s reproductive health, providers and patients have been left wondering what’s next legally. Will they be protected or prosecuted? The answer could be down to interpretation of HIPAA’s Privacy Rule. To that end, OCR’s taken the position of clarification and strengthening PHI protections from the HIPAA perspective. On April 12, … Read more
When it comes to vendor risk exposure and its management, you need to know how to implement a proper program that aligns with HIPAA compliance. Because whether you’re talking Cloud Service Providers or others, a solid vendor risk management program is key to potentially how well your organization can avoid a serious PHI security incident. … Read more
Hello everyone! The White House just announced that the COVID-19 Public Health Emergency (PHE) will end on May 11, 2023. This directly affects how telehealth services can be delivered. If you haven’t blocked out all memories of Spring 2020, you may recall that the Office for Civil Rights issued a Notice of Enforcement Discretion on … Read more
It’s time to circle back to the topic of remote access. Earlier I provided you a checklist to send to your remote working employees to assess workspace and workstation security. With new portable devices and web apps that support working from home, including transmitting large amounts of data with minimum resources, I feel it’s important … Read more
Well, remember the issues around what the “HIPAA exemption” in the California Consumer Privacy Act (CCPA) really applied to? We wrote about it here all the way back in May 2019. Turns out our impression was correct – so correct that California just passed a law to correct it! Here’s the skinny: On September 5, … Read more
Remember that brief moment when we thought the COVID-19 business impact was lifting? It was a nice thought, but we were wrong. We’re firmly in the midst of the pandemic with alleviation an ever-moving target. What does this mean for businesses, especially covered entities (CE) and business associates (BA)? Telework and telehealth present security risks, … Read more