<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3380636</id><updated>2026-04-02T15:26:31.985-05:00</updated><category term=":"/><title type='text'>HIPAA Blog</title><subtitle type='html'>A discussion of medical privacy issues buried in political arcana</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default?alt=atom'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default?alt=atom&amp;start-index=26&amp;max-results=25'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2983</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3380636.post-570439062336219429</id><published>2026-03-17T08:35:00.004-05:00</published><updated>2026-03-17T08:35:46.346-05:00</updated><title type='text'>Epic-Gorilla Health battle</title><summary type="text">&amp;nbsp;Epic Ramps Up the Fight: It appears that Epic is not happy simply rousing up some of its customers to sue Health Gorilla&amp;nbsp;regarding potential improper access to PHI through the CareQuality interoperability framework, part of Epic&#39;s Health Information Exchange structure, it seems that they are moving forward on multiple fronts.&amp;nbsp; Background here. A few days ago, it was announced that</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/570439062336219429/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/570439062336219429' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/570439062336219429'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/570439062336219429'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/03/epic-gorilla-health-battle.html' title='Epic-Gorilla Health battle'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-4921608790652103764</id><published>2026-02-03T22:55:00.003-06:00</published><updated>2026-02-03T22:55:58.493-06:00</updated><title type='text'>NoPP changes due in February</title><summary type="text">NoPP Changes Due February 16:&amp;nbsp; You&#39;ve likely seen plenty of law firms and others noting that HIPAA covered entities need to make changes to their Notices of Privacy Practices by February 16 to meet certain requirements included in HHS&#39; 2024 changes to HIPAA.&amp;nbsp; These changes stem from 2 separate rules, one relating to &quot;reproductive rights&quot; and one relating to substance use disorder </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/4921608790652103764/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/4921608790652103764' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4921608790652103764'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4921608790652103764'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/02/nopp-changes-due-in-february.html' title='NoPP changes due in February'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-5799962552160862660</id><published>2026-01-26T10:24:00.003-06:00</published><updated>2026-01-26T10:24:19.165-06:00</updated><title type='text'>Interview with OCR Chief Paula Stannard</title><summary type="text">OCR Chief Paula Stannard:My friend and reporter Theresa Defino recently interviewed Paula Stannard, the (new-ish) current Director of HHS&#39; Office for Civil Rights, the HIPAA enforcement agency.&amp;nbsp; This is Paula&#39;s third stint at OCR.&amp;nbsp; The interview is available here.&amp;nbsp;&amp;nbsp;Why do you want to hear what Paula Stannard has to say?OCR directors are political appointees who change with </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/5799962552160862660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/5799962552160862660' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/5799962552160862660'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/5799962552160862660'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/01/interview-with-ocr-chief-paula-stannard.html' title='Interview with OCR Chief Paula Stannard'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-5190492352149974482</id><published>2026-01-24T15:58:00.000-06:00</published><updated>2026-01-24T15:58:08.717-06:00</updated><title type='text'>OCR&#39;s January 2026 Cybersecurity Newsletter Highlights systems hardening</title><summary type="text">Check out OCR&#39;s January 2026 Cybersecurity Newsletter.&amp;nbsp; A link is here.The tips focus on system hardening, but most of the recommendations are just common sense.Patch softwareRemove unneeded software and servicesEnable and configure security settings</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/5190492352149974482/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/5190492352149974482' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/5190492352149974482'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/5190492352149974482'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/01/ocrs-january-2026-cybersecurity.html' title='OCR&#39;s January 2026 Cybersecurity Newsletter Highlights systems hardening'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-4206415915880221451</id><published>2026-01-24T15:53:00.001-06:00</published><updated>2026-01-24T15:53:10.474-06:00</updated><title type='text'>Update your NoPP if you are a Part 2 provider</title><summary type="text">&quot;Part 2&quot; Providers: Don&#39;t Forget to Update Your NoPPs by February 16.&amp;nbsp; Are you a &quot;Part 2&quot; provider?&amp;nbsp; If you don&#39;t know, you probably aren&#39;t.&amp;nbsp; &quot;Part 2&quot; refers to 42 CFR Part 2, which is the provision of the Code of Federal Regulations adding specifics to the general confidentiality provisions of 42 USC&amp;nbsp;290dd-2, requiring hightened confidentiality for the medical records of </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/4206415915880221451/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/4206415915880221451' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4206415915880221451'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4206415915880221451'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/01/update-your-nopp-if-you-are-part-2.html' title='Update your NoPP if you are a Part 2 provider'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-7223251569145504298</id><published>2026-01-06T09:15:00.002-06:00</published><updated>2026-01-06T09:15:58.884-06:00</updated><title type='text'>Healthcare Data Breaches in 2025</title><summary type="text">A Couple of Articles on Healthcare Data Breaches for 2025:&amp;nbsp;&amp;nbsp;1. Data breaches in the healthcare industry are more expensive, at an average of $9.8 million,&amp;nbsp;than any other industry.2. 57 million people were affected by healthcare data breaches in 2025, although the vast majority of that number came courtesy of the Change Healthcare breach, which affected almost 300 million </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/7223251569145504298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/7223251569145504298' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7223251569145504298'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7223251569145504298'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2026/01/healthcare-data-breaches-in-2025.html' title='Healthcare Data Breaches in 2025'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-170179632168322035</id><published>2025-12-01T08:49:00.002-06:00</published><updated>2025-12-01T08:49:39.039-06:00</updated><title type='text'>Evolving state of ransomware in Healthcare</title><summary type="text">The Evolving Threat of Ransomware in Healthcare: Attackers are getting faster, and ransomware software is getting trickier and cheaper, but healthcare organizations are getting better at stopping attacks before encryption occurs.&amp;nbsp; However, attackers are shifting their focus toward an extortion-only model: they don&#39;t encrypt your data, but they do access and copy PHI and threaten to release </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/170179632168322035/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/170179632168322035' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/170179632168322035'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/170179632168322035'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/12/evolving-state-of-ransomware-in.html' title='Evolving state of ransomware in Healthcare'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-4027873407410025996</id><published>2025-11-25T17:08:00.001-06:00</published><updated>2025-11-25T17:08:23.769-06:00</updated><title type='text'>Law firm data breaches</title><summary type="text">It&#39;s not just healthcare providers who suffer data breaches: I&#39;ve been keeping up a stack of law firm data breaches, meaning to write a post on them.&amp;nbsp; But I&#39;ve decided there&#39;s really not much to say, other than to note that a data breach can happen to anyone, and anyone who suffers a breach runs a decent likelihood to get sued by any individuals who might plausibly have been damaged by the </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/4027873407410025996/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/4027873407410025996' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4027873407410025996'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4027873407410025996'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/11/law-firm-data-breaches.html' title='Law firm data breaches'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-6070599707017501434</id><published>2025-11-25T08:48:00.003-06:00</published><updated>2025-11-25T08:48:44.590-06:00</updated><title type='text'>Healthcare Industry suffers the most data breaches</title><summary type="text">&amp;nbsp;Healthcare wins again:&amp;nbsp;Once again, the healthcare industry was the most affected industry when it came to data breaches in 2024.&amp;nbsp; Many reasons: the amount of personal information; the sensitivity, utility, and value of the information; the many different financial crimes that the information can help (identity theft, insurance fraud, ransom); the large and varied number of </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/6070599707017501434/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/6070599707017501434' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6070599707017501434'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6070599707017501434'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/11/healthcare-industry-suffers-most-data.html' title='Healthcare Industry suffers the most data breaches'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-7995575351319288938</id><published>2025-09-10T08:49:00.001-05:00</published><updated>2025-09-10T08:49:45.580-05:00</updated><title type='text'>OCR Issues Updated Version of SRA Tool</title><summary type="text">HHS&#39; OCR, Asst. Secretary for Health Policy Release Latest Version of Security Risk Analysis Tool: If you&#39;ve followed HIPAA much, you are aware that Security Rule compliance has always lagged Privacy Rule compliance.&amp;nbsp; At least part of this is because Privacy Rule requirements are much more of a one-size-fits-all regime, whereas Security Rule compliance requires a lot of individual </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/7995575351319288938/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/7995575351319288938' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7995575351319288938'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7995575351319288938'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/09/ocr-issues-updated-version-of-sra-tool.html' title='OCR Issues Updated Version of SRA Tool'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-8322059726186778416</id><published>2025-08-28T10:44:00.003-05:00</published><updated>2025-08-28T10:44:57.136-05:00</updated><title type='text'>OCR named enforcement agency for Part 2</title><summary type="text">OCR Named Enforcement Agency for Part 2: When HIPAA was first passed, the Privacy Rule was to be enforced by the Office for Civil Rights within HHS, and the rest of HIPAA was to be enforced by CMS.&amp;nbsp; I&#39;m not sure why that bifurcation happened, but a few years later HHS decided that OCR should be the enforcement agency for all of HIPAA.Yesterday, HHS announced that OCR is now the enforcement </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/8322059726186778416/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/8322059726186778416' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8322059726186778416'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8322059726186778416'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/08/ocr-named-enforcement-agency-for-part-2.html' title='OCR named enforcement agency for Part 2'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-6766523378023178750</id><published>2025-08-01T07:53:00.002-05:00</published><updated>2025-08-01T07:53:35.923-05:00</updated><title type='text'>Average Healthcare Data Breach Costs $7,420,000</title><summary type="text">Costs of a Data Breach: According to an IBM study, for the year ended February 2025, an average healthcare data breach costs almost $7.5 million.&amp;nbsp; Healthcare leads all industries in having the most expensive breaches, and the longest time before breaches are discovered.&amp;nbsp;&amp;nbsp;</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/6766523378023178750/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/6766523378023178750' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6766523378023178750'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6766523378023178750'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/08/average-healthcare-data-breach-costs.html' title='Average Healthcare Data Breach Costs $7,420,000'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-8600942999033922681</id><published>2025-07-14T09:20:00.001-05:00</published><updated>2025-07-14T09:20:41.047-05:00</updated><title type='text'>400 large breaches in first half of 2025</title><summary type="text">400 Large Breaches so far in 2025: HHS has announced that during the first six months of 2025, there were 400 &quot;large&quot; breaches (500 or more individuals affected) added to the HHS &quot;Wall of Shame.&quot;&amp;nbsp;&amp;nbsp;Breaches happen, so the fact that you have one doesn&#39;t mean you did anything wrong,&amp;nbsp; But it might: show me a copy of your most recent security risk assessment.&amp;nbsp; If you can&#39;t, then </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/8600942999033922681/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/8600942999033922681' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8600942999033922681'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8600942999033922681'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/07/400-large-breaches-in-first-half-of-2025.html' title='400 large breaches in first half of 2025'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-3869956215680846450</id><published>2025-07-08T19:38:00.009-05:00</published><updated>2025-08-26T17:02:17.735-05:00</updated><title type='text'>recent HIPAA settlements: Deer Oaks, BayCare, Comstar, Syracuse ASC</title><summary type="text">Let&#39;s catch up on some recent HIPAA enforcement actions:Deer Oaks, a HIPAA covered healthcare provider that provides behavioral health services primarily to residents in nursing homes and other facilities, misconfigured its IT systems to allow discharge summaries of 35 patients to be accessible online.&amp;nbsp; A few months later, Deer Oaks suffered a ransomware attack that affected the PHI of </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/3869956215680846450/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/3869956215680846450' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3869956215680846450'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3869956215680846450'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/07/deer-oaks-hipaa-fine.html' title='recent HIPAA settlements: Deer Oaks, BayCare, Comstar, Syracuse ASC'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-7217894762718224249</id><published>2025-06-20T07:25:00.002-05:00</published><updated>2025-06-20T07:25:40.527-05:00</updated><title type='text'>Finally! Biden administration&#39;s HIPAA abortion stupidity negated</title><summary type="text">Finally!! Biden Administration&#39;s HIPAA Abortion Stupidity Negated: As I previously wrote about at length, the asinine Biden Administration HIPAA abortion regulation has been overturned by a Federal judge in Texas.&amp;nbsp; The judge said the regulations were clearly intended to provide special protections for &quot;politically favored procedures,&quot; which is a power HIPAA does not grant to HHS.&amp;nbsp;&amp;nbsp;</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/7217894762718224249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/7217894762718224249' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7217894762718224249'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/7217894762718224249'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/06/finally-biden-administrations-hipaa.html' title='Finally! Biden administration&#39;s HIPAA abortion stupidity negated'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-3154011947744656877</id><published>2025-05-26T11:55:00.000-05:00</published><updated>2025-05-26T11:55:21.188-05:00</updated><title type='text'>Memorial Day Catch-Up Post</title><summary type="text">Happy Memorial Day!Sorry I&#39;ve not posted in forever, and when I do it&#39;s few and far between, but it has been a very busy spring and when I&#39;ve had time, I didn&#39;t think about the blog.&amp;nbsp; But here&#39;s a compilation of stuff that&#39;s happened since the beginning of the year (and a few things from the end of last year):Access cases: Oregon Health &amp;amp; Science University got tagged with one of the </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/3154011947744656877/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/3154011947744656877' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3154011947744656877'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3154011947744656877'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/05/memorial-day-catch-up-post.html' title='Memorial Day Catch-Up Post'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-6542388782318484685</id><published>2025-05-21T07:07:00.002-05:00</published><updated>2025-05-21T07:07:23.092-05:00</updated><title type='text'>Kettering Health (Ohio) Ransomware Event</title><summary type="text">Kettering Health (Ohio) Ransomware Event: Kettering Health, which operates 9 hospitals and a handful of other sites in and around Dayton, Ohio, has reported a ransomware event that happened May 20, preventing elective procedures.&amp;nbsp; The hospitals&#39; emergency rooms continued to be open.&amp;nbsp;&amp;nbsp;It&#39;s unclear at this point whether data was lost to the hackers, but the hackers apparently claim </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/6542388782318484685/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/6542388782318484685' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6542388782318484685'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6542388782318484685'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/05/kettering-health-ohio-ransomware-event.html' title='Kettering Health (Ohio) Ransomware Event'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-8422888887537552298</id><published>2025-03-21T08:39:00.002-05:00</published><updated>2025-03-21T08:39:15.241-05:00</updated><title type='text'>Email Remains Leading Security Risk Area</title><summary type="text">Email As a Data Breach Vector:&amp;nbsp;Almost 200 healthcare organizations suffered a cyberbreach involving their email systems over the last year.&amp;nbsp; Phishing is probably the biggest type of incident, mainly those that allow hackers to gain credentials and thus establish email rules that allow for data theft and potentially insertion of ransomware.&amp;nbsp;&amp;nbsp;Tightening systems helps, but even </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/8422888887537552298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/8422888887537552298' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8422888887537552298'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/8422888887537552298'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/03/email-remains-leading-security-risk-area.html' title='Email Remains Leading Security Risk Area'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-3366061788887483996</id><published>2025-03-14T09:39:00.000-05:00</published><updated>2025-03-14T09:39:01.841-05:00</updated><title type='text'>Information-blocking news: EMR company must allow client&#39;s BAs to access PHI</title><summary type="text">Information-blocking news: EMR company must allow client&#39;s BAs to access PHI:&amp;nbsp;I must admit I haven&#39;t been following this at all, but it&#39;s an interesting bit of news from the intersection of HIPAA privacy and 21st Century Cures Act interoperability.&amp;nbsp; As you know, HIPAA tries to put the brakes on data sharing, while the Cures Act tries to increase data sharing.&amp;nbsp; In this case, Real </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/3366061788887483996/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/3366061788887483996' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3366061788887483996'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/3366061788887483996'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/03/information-blocking-news-emr-company.html' title='Information-blocking news: EMR company must allow client&#39;s BAs to access PHI'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-1711113176109761256</id><published>2025-03-14T09:30:00.001-05:00</published><updated>2025-03-14T09:30:36.344-05:00</updated><title type='text'>PE-owned healthcare entities need to improve cybersecurity</title><summary type="text">PE-owned healthcare entities need to improve cybersecurity: I hate to say it, but at this point cybersecurity protections are more important than regular HIPAA blocking-and-tackling.&amp;nbsp; And apparently, private equity backed healthcare companies are worse than others, which is in many ways surprising.&amp;nbsp; Solid cybersecurity shouldn&#39;t be a heavy lift for nimble, tech-related companies, and </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/1711113176109761256/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/1711113176109761256' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/1711113176109761256'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/1711113176109761256'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/03/pe-owned-healthcare-entities-need-to.html' title='PE-owned healthcare entities need to improve cybersecurity'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-74672300656620583</id><published>2025-02-21T08:51:00.003-06:00</published><updated>2025-02-21T08:51:51.563-06:00</updated><title type='text'>Warby Parker</title><summary type="text">Warby Parker Pays $1.5 to Settle HIPAA ViolationI wasn&#39;t involved in this matter, so I don&#39;t have inside information and I&#39;m just speculating here.&amp;nbsp; But a couple of things stand out to me:What makes sense:&amp;nbsp;the breach came about from a pretty common variety of illegal access: &quot;credential stuffing,&quot; where someone gets access to one website, steals credentials (of either a massive amount </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/74672300656620583/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/74672300656620583' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/74672300656620583'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/74672300656620583'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/02/warby-parker.html' title='Warby Parker'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-4653946334721363465</id><published>2025-01-28T08:18:00.002-06:00</published><updated>2025-01-28T08:18:09.122-06:00</updated><title type='text'>Change Healthcare&#39;s Breach Victim Count Reaches 190,000,000</title><summary type="text">Change Healthcare&#39;s Breach Victim Count Reaches 190,000,000.&amp;nbsp; US population is about 340 million, which means the breach affected about 56% of the US population.&amp;nbsp; So, if you&#39;re an American, it&#39;s more likely than not that your PHI was exposed in the Change breach.&amp;nbsp;&amp;nbsp;A few months ago, a ransomware negotiator mentioned something to a client of mine that was a bit of a revelation.&amp;</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/4653946334721363465/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/4653946334721363465' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4653946334721363465'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/4653946334721363465'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/01/change-healthcares-breach-victim-count.html' title='Change Healthcare&#39;s Breach Victim Count Reaches 190,000,000'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-236377804386139859</id><published>2025-01-21T10:05:00.002-06:00</published><updated>2025-01-21T10:05:40.348-06:00</updated><title type='text'>Texas HHSC Suffers Breach</title><summary type="text">Texas Health and Human Services Commission Suffers HIPAA Breach: If you haven&#39;t figured it out yet, anyone with health data is potentially susceptible to a data breach, and that includes governmental entities.&amp;nbsp; The Texas Health and Human Services Commission, which oversees health and welfare programs in the state (including state Medicaid), reported recently that in November 2024, bad </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/236377804386139859/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/236377804386139859' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/236377804386139859'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/236377804386139859'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/01/texas-hhsc-suffers-breach.html' title='Texas HHSC Suffers Breach'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-6548496708945481340</id><published>2025-01-09T13:08:00.003-06:00</published><updated>2025-01-09T13:08:37.928-06:00</updated><title type='text'>PHI Deletion Nets $337,750 Fine</title><summary type="text">PHI Deletion Nets $337,750 Fine: This is a bit of an odd one: a Florida HIPAA business associate, USR Holdings, discovered that an unauthorized third party had access to its database for 3-4 months and deleted PHI of 2903 people.&amp;nbsp; The normal problems were there: failure to conduct a risk assessment, no risk management plan, no system activity review, and no backups.&amp;nbsp; The result was a $</summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/6548496708945481340/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/6548496708945481340' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6548496708945481340'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/6548496708945481340'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/01/phi-deletion-nets-337750-fine.html' title='PHI Deletion Nets $337,750 Fine'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3380636.post-108886417820986318</id><published>2025-01-09T12:57:00.002-06:00</published><updated>2025-01-09T12:57:36.657-06:00</updated><title type='text'>9th Ransomware Case: Virtual Private Network Solutions</title><summary type="text">9th Ransomware Case: Virtual Private Network Solutions:&amp;nbsp; HHS has entered into a settlement agreement with a HIPAA business associate who was hit with a ransomware attack in 2021 that resulted in the encryption of PHI.&amp;nbsp; VPN Solutions provides data hosting and cloud services to HIPAA covered entities, and in October of 2021 was hit by a ransomware attack that resulted in encryption of </summary><link rel='replies' type='application/atom+xml' href='https://hipaablog.blogspot.com/feeds/108886417820986318/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment/fullpage/post/3380636/108886417820986318' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/108886417820986318'/><link rel='self' type='application/atom+xml' href='https://www.blogger.com/feeds/3380636/posts/default/108886417820986318'/><link rel='alternate' type='text/html' href='https://hipaablog.blogspot.com/2025/01/9th-ransomware-case-virtual-private.html' title='9th Ransomware Case: Virtual Private Network Solutions'/><author><name>Jeff</name><uri>http://www.blogger.com/profile/12067054401696214042</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='https://img1.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>