<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3380636</id><updated>2026-07-23T10:29:31.295-05:00</updated><category term=":"/><title type='text'>HIPAA Blog</title><subtitle type='html'>A discussion of medical privacy issues buried in political arcana</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default?alt=atom'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default?alt=atom&amp;start-index=26&amp;max-results=25'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2989</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3380636.post-1193784333225043799</id><published>2026-07-15T16:34:28.794-05:00</published><updated>2026-07-15T16:34:28.795-05:00</updated><title type='text'>Wilmer Hale data breach</title><summary type="text">Another law firm breached and sued: This time, it&#39;s Wilmer Hale.&amp;nbsp;&amp;nbsp;</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/1193784333225043799/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/1193784333225043799' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/1193784333225043799'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/1193784333225043799'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/07/wilmer-hale-data-breach.html' title='Wilmer Hale data breach'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-5901141066018063780</id><published>2026-07-14T08:06:01.295-05:00</published><updated>2026-07-14T08:06:01.295-05:00</updated><title type='text'>Security Rule Updates Postponed to July 2027</title><summary type="text">Security Rule Update Delayed: The likely effective date of the proposed revisions to the HIPAA Security Rule to increase encryption, MFA, and other security safeguard requirements has been pushed back.&amp;nbsp; The Notice of Proposed Rule Making was published January 2025, and HHS had indicated that it would likely be announced as final (possibly with some tweaks) in May 2026.&amp;nbsp; I was always </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/5901141066018063780/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/5901141066018063780' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/5901141066018063780'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/5901141066018063780'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/07/security-rule-updates-postponed-to-july.html' title='Security Rule Updates Postponed to July 2027'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-8144422004604495414</id><published>2026-07-07T09:50:51.317-05:00</published><updated>2026-07-07T09:50:51.317-05:00</updated><title type='text'>AI Usage Generally Requires a BAA</title><summary type="text">AI Usage Generally Requires a BAA: If you are a covered entity and you use any AI product, keep one thing in mind: if that AI product touches any patient information, you better have a BAA in place with the AI vendor.A business associate relationship exist whenever the BA provides a service to or for a covered entity and PHI is involved (used, disclosed, exchanged, etc.).&amp;nbsp; Many healthcare AI</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/8144422004604495414/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/8144422004604495414' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8144422004604495414'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8144422004604495414'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/07/ai-usage-generally-requires-baa.html' title='AI Usage Generally Requires a BAA'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-6973958904078290151</id><published>2026-07-07T09:18:36.509-05:00</published><updated>2026-07-07T09:18:36.509-05:00</updated><title type='text'>Law Firm Blank Rome Hit with Data Brach Suit</title><summary type="text">It happens to everyone, even lawyers: The biglaw firm Blank Rome was hit with a couple of class action lawsuits over a May data breach in which 57,000 individuals&#39; data was exposed.&amp;nbsp; Apparently an attorney was duped into uploading files that contained the information.&amp;nbsp; While this breach does not implicate HIPAA, in some ways it&#39;s worse because law firms often have some pretty valuable </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/6973958904078290151/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/6973958904078290151' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6973958904078290151'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6973958904078290151'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/07/law-firm-blank-rome-hit-with-data-brach.html' title='Law Firm Blank Rome Hit with Data Brach Suit'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-1239357617603407412</id><published>2026-06-22T16:15:44.434-05:00</published><updated>2026-06-22T16:15:44.435-05:00</updated><title type='text'>Law Firm Data Breaches</title><summary type="text">Law Firm Data Breaches Surge: While few of these are specifically HIPAA related (law firms can be business associates of covered entities, but that&#39;s not a relevant issue here), it is interesting to see how law firms are a hot new target for hackers.&amp;nbsp; Like healthcare entities, law firms have access to confidential and highly sensitive information; some attacks target business and deal </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/1239357617603407412/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/1239357617603407412' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/1239357617603407412'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/1239357617603407412'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/06/law-firm-data-breaches.html' title='Law Firm Data Breaches'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-2943954543387729932</id><published>2026-05-26T11:28:22.011-05:00</published><updated>2026-05-26T11:28:22.011-05:00</updated><title type='text'></title><summary type="text">&amp;nbsp;You already knew this, but the healthcare sector is still the industry most targeted for cybersecurity incidents.&amp;nbsp; Large amounts of data, good/useful data for hackers, a disjointed industry, and lots of small players with poor cybersecurity protections makes it such a big target.&amp;nbsp;&amp;nbsp;</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/2943954543387729932/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/2943954543387729932' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/2943954543387729932'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/2943954543387729932'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/05/already-knew-this-but-healthcare-sector.html' title=''/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-570439062336219429</id><published>2026-03-17T08:35:00.004-05:00</published><updated>2026-03-17T08:35:46.346-05:00</updated><title type='text'>Epic-Gorilla Health battle</title><summary type="text">&amp;nbsp;Epic Ramps Up the Fight: It appears that Epic is not happy simply rousing up some of its customers to sue Health Gorilla&amp;nbsp;regarding potential improper access to PHI through the CareQuality interoperability framework, part of Epic&#39;s Health Information Exchange structure, it seems that they are moving forward on multiple fronts.&amp;nbsp; Background here. A few days ago, it was announced that</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/570439062336219429/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/570439062336219429' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/570439062336219429'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/570439062336219429'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/03/epic-gorilla-health-battle.html' title='Epic-Gorilla Health battle'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-4921608790652103764</id><published>2026-02-03T22:55:00.003-06:00</published><updated>2026-02-03T22:55:58.493-06:00</updated><title type='text'>NoPP changes due in February</title><summary type="text">NoPP Changes Due February 16:&amp;nbsp; You&#39;ve likely seen plenty of law firms and others noting that HIPAA covered entities need to make changes to their Notices of Privacy Practices by February 16 to meet certain requirements included in HHS&#39; 2024 changes to HIPAA.&amp;nbsp; These changes stem from 2 separate rules, one relating to &quot;reproductive rights&quot; and one relating to substance use disorder </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/4921608790652103764/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/4921608790652103764' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4921608790652103764'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4921608790652103764'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/02/nopp-changes-due-in-february.html' title='NoPP changes due in February'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-5799962552160862660</id><published>2026-01-26T10:24:00.003-06:00</published><updated>2026-01-26T10:24:19.165-06:00</updated><title type='text'>Interview with OCR Chief Paula Stannard</title><summary type="text">OCR Chief Paula Stannard:My friend and reporter Theresa Defino recently interviewed Paula Stannard, the (new-ish) current Director of HHS&#39; Office for Civil Rights, the HIPAA enforcement agency.&amp;nbsp; This is Paula&#39;s third stint at OCR.&amp;nbsp; The interview is available here.&amp;nbsp;&amp;nbsp;Why do you want to hear what Paula Stannard has to say?OCR directors are political appointees who change with </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/5799962552160862660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/5799962552160862660' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/5799962552160862660'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/5799962552160862660'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/01/interview-with-ocr-chief-paula-stannard.html' title='Interview with OCR Chief Paula Stannard'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-5190492352149974482</id><published>2026-01-24T15:58:00.000-06:00</published><updated>2026-01-24T15:58:08.717-06:00</updated><title type='text'>OCR&#39;s January 2026 Cybersecurity Newsletter Highlights systems hardening</title><summary type="text">Check out OCR&#39;s January 2026 Cybersecurity Newsletter.&amp;nbsp; A link is here.The tips focus on system hardening, but most of the recommendations are just common sense.Patch softwareRemove unneeded software and servicesEnable and configure security settings</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/5190492352149974482/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/5190492352149974482' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/5190492352149974482'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/5190492352149974482'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/01/ocrs-january-2026-cybersecurity.html' title='OCR&#39;s January 2026 Cybersecurity Newsletter Highlights systems hardening'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-4206415915880221451</id><published>2026-01-24T15:53:00.001-06:00</published><updated>2026-01-24T15:53:10.474-06:00</updated><title type='text'>Update your NoPP if you are a Part 2 provider</title><summary type="text">&quot;Part 2&quot; Providers: Don&#39;t Forget to Update Your NoPPs by February 16.&amp;nbsp; Are you a &quot;Part 2&quot; provider?&amp;nbsp; If you don&#39;t know, you probably aren&#39;t.&amp;nbsp; &quot;Part 2&quot; refers to 42 CFR Part 2, which is the provision of the Code of Federal Regulations adding specifics to the general confidentiality provisions of 42 USC&amp;nbsp;290dd-2, requiring hightened confidentiality for the medical records of </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/4206415915880221451/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/4206415915880221451' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4206415915880221451'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4206415915880221451'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/01/update-your-nopp-if-you-are-part-2.html' title='Update your NoPP if you are a Part 2 provider'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-7223251569145504298</id><published>2026-01-06T09:15:00.002-06:00</published><updated>2026-01-06T09:15:58.884-06:00</updated><title type='text'>Healthcare Data Breaches in 2025</title><summary type="text">A Couple of Articles on Healthcare Data Breaches for 2025:&amp;nbsp;&amp;nbsp;1. Data breaches in the healthcare industry are more expensive, at an average of $9.8 million,&amp;nbsp;than any other industry.2. 57 million people were affected by healthcare data breaches in 2025, although the vast majority of that number came courtesy of the Change Healthcare breach, which affected almost 300 million </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/7223251569145504298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/7223251569145504298' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7223251569145504298'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7223251569145504298'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/01/healthcare-data-breaches-in-2025.html' title='Healthcare Data Breaches in 2025'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-170179632168322035</id><published>2025-12-01T08:49:00.002-06:00</published><updated>2025-12-01T08:49:39.039-06:00</updated><title type='text'>Evolving state of ransomware in Healthcare</title><summary type="text">The Evolving Threat of Ransomware in Healthcare: Attackers are getting faster, and ransomware software is getting trickier and cheaper, but healthcare organizations are getting better at stopping attacks before encryption occurs.&amp;nbsp; However, attackers are shifting their focus toward an extortion-only model: they don&#39;t encrypt your data, but they do access and copy PHI and threaten to release </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/170179632168322035/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/170179632168322035' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/170179632168322035'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/170179632168322035'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/12/evolving-state-of-ransomware-in.html' title='Evolving state of ransomware in Healthcare'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-4027873407410025996</id><published>2025-11-25T17:08:00.001-06:00</published><updated>2025-11-25T17:08:23.769-06:00</updated><title type='text'>Law firm data breaches</title><summary type="text">It&#39;s not just healthcare providers who suffer data breaches: I&#39;ve been keeping up a stack of law firm data breaches, meaning to write a post on them.&amp;nbsp; But I&#39;ve decided there&#39;s really not much to say, other than to note that a data breach can happen to anyone, and anyone who suffers a breach runs a decent likelihood to get sued by any individuals who might plausibly have been damaged by the </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/4027873407410025996/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/4027873407410025996' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4027873407410025996'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4027873407410025996'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/11/law-firm-data-breaches.html' title='Law firm data breaches'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-6070599707017501434</id><published>2025-11-25T08:48:00.003-06:00</published><updated>2025-11-25T08:48:44.590-06:00</updated><title type='text'>Healthcare Industry suffers the most data breaches</title><summary type="text">&amp;nbsp;Healthcare wins again:&amp;nbsp;Once again, the healthcare industry was the most affected industry when it came to data breaches in 2024.&amp;nbsp; Many reasons: the amount of personal information; the sensitivity, utility, and value of the information; the many different financial crimes that the information can help (identity theft, insurance fraud, ransom); the large and varied number of </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/6070599707017501434/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/6070599707017501434' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6070599707017501434'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6070599707017501434'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/11/healthcare-industry-suffers-most-data.html' title='Healthcare Industry suffers the most data breaches'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-7995575351319288938</id><published>2025-09-10T08:49:00.001-05:00</published><updated>2025-09-10T08:49:45.580-05:00</updated><title type='text'>OCR Issues Updated Version of SRA Tool</title><summary type="text">HHS&#39; OCR, Asst. Secretary for Health Policy Release Latest Version of Security Risk Analysis Tool: If you&#39;ve followed HIPAA much, you are aware that Security Rule compliance has always lagged Privacy Rule compliance.&amp;nbsp; At least part of this is because Privacy Rule requirements are much more of a one-size-fits-all regime, whereas Security Rule compliance requires a lot of individual </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/7995575351319288938/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/7995575351319288938' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7995575351319288938'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7995575351319288938'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/09/ocr-issues-updated-version-of-sra-tool.html' title='OCR Issues Updated Version of SRA Tool'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-8322059726186778416</id><published>2025-08-28T10:44:00.003-05:00</published><updated>2025-08-28T10:44:57.136-05:00</updated><title type='text'>OCR named enforcement agency for Part 2</title><summary type="text">OCR Named Enforcement Agency for Part 2: When HIPAA was first passed, the Privacy Rule was to be enforced by the Office for Civil Rights within HHS, and the rest of HIPAA was to be enforced by CMS.&amp;nbsp; I&#39;m not sure why that bifurcation happened, but a few years later HHS decided that OCR should be the enforcement agency for all of HIPAA.Yesterday, HHS announced that OCR is now the enforcement </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/8322059726186778416/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/8322059726186778416' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8322059726186778416'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8322059726186778416'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/08/ocr-named-enforcement-agency-for-part-2.html' title='OCR named enforcement agency for Part 2'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-6766523378023178750</id><published>2025-08-01T07:53:00.002-05:00</published><updated>2025-08-01T07:53:35.923-05:00</updated><title type='text'>Average Healthcare Data Breach Costs $7,420,000</title><summary type="text">Costs of a Data Breach: According to an IBM study, for the year ended February 2025, an average healthcare data breach costs almost $7.5 million.&amp;nbsp; Healthcare leads all industries in having the most expensive breaches, and the longest time before breaches are discovered.&amp;nbsp;&amp;nbsp;</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/6766523378023178750/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/6766523378023178750' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6766523378023178750'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6766523378023178750'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/08/average-healthcare-data-breach-costs.html' title='Average Healthcare Data Breach Costs $7,420,000'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-8600942999033922681</id><published>2025-07-14T09:20:00.001-05:00</published><updated>2025-07-14T09:20:41.047-05:00</updated><title type='text'>400 large breaches in first half of 2025</title><summary type="text">400 Large Breaches so far in 2025: HHS has announced that during the first six months of 2025, there were 400 &quot;large&quot; breaches (500 or more individuals affected) added to the HHS &quot;Wall of Shame.&quot;&amp;nbsp;&amp;nbsp;Breaches happen, so the fact that you have one doesn&#39;t mean you did anything wrong,&amp;nbsp; But it might: show me a copy of your most recent security risk assessment.&amp;nbsp; If you can&#39;t, then </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/8600942999033922681/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/8600942999033922681' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8600942999033922681'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8600942999033922681'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/07/400-large-breaches-in-first-half-of-2025.html' title='400 large breaches in first half of 2025'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-3869956215680846450</id><published>2025-07-08T19:38:00.009-05:00</published><updated>2025-08-26T17:02:17.735-05:00</updated><title type='text'>recent HIPAA settlements: Deer Oaks, BayCare, Comstar, Syracuse ASC</title><summary type="text">Let&#39;s catch up on some recent HIPAA enforcement actions:Deer Oaks, a HIPAA covered healthcare provider that provides behavioral health services primarily to residents in nursing homes and other facilities, misconfigured its IT systems to allow discharge summaries of 35 patients to be accessible online.&amp;nbsp; A few months later, Deer Oaks suffered a ransomware attack that affected the PHI of </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/3869956215680846450/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/3869956215680846450' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3869956215680846450'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3869956215680846450'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/07/deer-oaks-hipaa-fine.html' title='recent HIPAA settlements: Deer Oaks, BayCare, Comstar, Syracuse ASC'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-7217894762718224249</id><published>2025-06-20T07:25:00.002-05:00</published><updated>2025-06-20T07:25:40.527-05:00</updated><title type='text'>Finally! Biden administration&#39;s HIPAA abortion stupidity negated</title><summary type="text">Finally!! Biden Administration&#39;s HIPAA Abortion Stupidity Negated: As I previously wrote about at length, the asinine Biden Administration HIPAA abortion regulation has been overturned by a Federal judge in Texas.&amp;nbsp; The judge said the regulations were clearly intended to provide special protections for &quot;politically favored procedures,&quot; which is a power HIPAA does not grant to HHS.&amp;nbsp;&amp;nbsp;</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/7217894762718224249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/7217894762718224249' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7217894762718224249'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7217894762718224249'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/06/finally-biden-administrations-hipaa.html' title='Finally! Biden administration&#39;s HIPAA abortion stupidity negated'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-3154011947744656877</id><published>2025-05-26T11:55:00.000-05:00</published><updated>2025-05-26T11:55:21.188-05:00</updated><title type='text'>Memorial Day Catch-Up Post</title><summary type="text">Happy Memorial Day!Sorry I&#39;ve not posted in forever, and when I do it&#39;s few and far between, but it has been a very busy spring and when I&#39;ve had time, I didn&#39;t think about the blog.&amp;nbsp; But here&#39;s a compilation of stuff that&#39;s happened since the beginning of the year (and a few things from the end of last year):Access cases: Oregon Health &amp;amp; Science University got tagged with one of the </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/3154011947744656877/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/3154011947744656877' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3154011947744656877'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3154011947744656877'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/05/memorial-day-catch-up-post.html' title='Memorial Day Catch-Up Post'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-6542388782318484685</id><published>2025-05-21T07:07:00.002-05:00</published><updated>2025-05-21T07:07:23.092-05:00</updated><title type='text'>Kettering Health (Ohio) Ransomware Event</title><summary type="text">Kettering Health (Ohio) Ransomware Event: Kettering Health, which operates 9 hospitals and a handful of other sites in and around Dayton, Ohio, has reported a ransomware event that happened May 20, preventing elective procedures.&amp;nbsp; The hospitals&#39; emergency rooms continued to be open.&amp;nbsp;&amp;nbsp;It&#39;s unclear at this point whether data was lost to the hackers, but the hackers apparently claim </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/6542388782318484685/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/6542388782318484685' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6542388782318484685'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6542388782318484685'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/05/kettering-health-ohio-ransomware-event.html' title='Kettering Health (Ohio) Ransomware Event'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-8422888887537552298</id><published>2025-03-21T08:39:00.002-05:00</published><updated>2025-03-21T08:39:15.241-05:00</updated><title type='text'>Email Remains Leading Security Risk Area</title><summary type="text">Email As a Data Breach Vector:&amp;nbsp;Almost 200 healthcare organizations suffered a cyberbreach involving their email systems over the last year.&amp;nbsp; Phishing is probably the biggest type of incident, mainly those that allow hackers to gain credentials and thus establish email rules that allow for data theft and potentially insertion of ransomware.&amp;nbsp;&amp;nbsp;Tightening systems helps, but even </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/8422888887537552298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/8422888887537552298' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8422888887537552298'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8422888887537552298'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/03/email-remains-leading-security-risk-area.html' title='Email Remains Leading Security Risk Area'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-3366061788887483996</id><published>2025-03-14T09:39:00.000-05:00</published><updated>2025-03-14T09:39:01.841-05:00</updated><title type='text'>Information-blocking news: EMR company must allow client&#39;s BAs to access PHI</title><summary type="text">Information-blocking news: EMR company must allow client&#39;s BAs to access PHI:&amp;nbsp;I must admit I haven&#39;t been following this at all, but it&#39;s an interesting bit of news from the intersection of HIPAA privacy and 21st Century Cures Act interoperability.&amp;nbsp; As you know, HIPAA tries to put the brakes on data sharing, while the Cures Act tries to increase data sharing.&amp;nbsp; In this case, Real </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/3366061788887483996/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/3366061788887483996' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3366061788887483996'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3366061788887483996'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/03/information-blocking-news-emr-company.html' title='Information-blocking news: EMR company must allow client&#39;s BAs to access PHI'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>