Effective June 5, 2026: Oregon SB 1570
Ready for June 5, 2026? You’ll need to “Know Who Enters, Protect What’s Shared” when it comes to Oregon SB 1570 and the new rules for Law Enforcement interactions in Hospitals and FQHCs.
Ready for June 5, 2026? You’ll need to “Know Who Enters, Protect What’s Shared” when it comes to Oregon SB 1570 and the new rules for Law Enforcement interactions in Hospitals and FQHCs.
With every new headline about women’s reproductive health, providers and patients have been left wondering what’s next legally. Will they be protected or prosecuted? The answer could be down to interpretation of HIPAA’s Privacy Rule. To that end, OCR’s taken the position of clarification and strengthening PHI protections from the HIPAA perspective. On April 12, … Read more
HIPAA Summit Distinguished Service Award to Chris Apgar, CISSP, C-CISO, posthumously.
As things ease up, and slowly people return to the office, what steps do you need to take to make sure data and devices are secure? It’s not quite a reversal of what covered entities (CE) and business associates (BA) went through when everyone who was non-essential was required to go to remote work, but … Read more
It’s one of those questions that never goes away. The answer is, “Maybe” and very definitely, “Not always.” Contrary to popular belief, even after ransomware attacks, the safe harbor still applies when it comes to breaches. If your PHI data was encrypted prior to the ransomware attack that encrypted (aka “held for ransom”) it, you … Read more
A brief recap: The California Consumer Privacy Act (CCPA) aims to give California consumers greater control over their personal information by imposing certain obligations on entities covered by the law. The CCPA takes effect January 1, 2020. And as we said in an earlier blog article, you don’t have to be a California-based business to … Read more
A few days ago, after making multiple attempts on behalf of a client to verify and clarify how join.me supports HIPAA compliance, specifically participating in Business Associate Agreements, I found that they do not. In fact, they do not consider themselves subject to HIPAA regulations, regardless of the possibility of PHI being stored on the … Read more
Julia and I had the pleasure of attending the 2018 Privacy & Security Forum a couple of weeks ago. One of the sessions I attended was focused on what’s happening at OCR these days. The speaker was Roger Severino, Director of OCR, and the moderator was Adam Greene, partner at Davis Wright Tremaine, LLP. I … Read more
While conducting a workshop focused on privacy, the question came up about what covered entities and business associates supporting covered entities can charge for an electronic copy of a patient’s designated record set (aka PHI). My answer to the audience was partially correct and partially wrong. The following is an excerpt from the preamble to … Read more
The interview and subsequent articles about Charlie Sheen’s disclosure of being the intended victim of medical data blackmail stirred dynamic discussions among my privacy and security colleagues. It’s one more example of how, as our healthcare information continues to be digitized, there are more opportunities for data breaches to occur without an expert hacker’s involvement. What … Read more