We use cookies to customise content for your subscription and for analytics.
If you continue to browse Lexology, we will assume that you are happy to receive all our cookies. For further information please read our Cookie Policy.
Lexology logo
  Request new password

Search results

Order by most recent / most popular / relevance

Results: 1-10 of 102

HIPAA "mega rule", meet "super BAA": the CMS data use agreement

  • Fox Rothschild LLP
  • -
  • USA
  • -
  • January 24 2013

The recent release of the HIPAAHITECH "mega rule" or "omnibus rule" has given bloggers and lawyers like us plenty of topics for analysis and debate

Office of Civil Rights discusses two HIPAA enforcement tools - will these "red light cameras" deter new HIPAA violations?

  • Fox Rothschild LLP
  • -
  • USA
  • -
  • June 17 2012

The federal Office of Civil Rights (“OCR”) has publicized two tools that are available for OCR and individual State Attorneys General (“SAGs”) to deter and catch HIPAA privacy and security breaches that are similar to the red light cameras designed to deter and catch traffic violations

The parade of PHI security breaches: escalating enforcement activity by attorneys general - most recently in Indiana

  • Fox Rothschild LLP
  • -
  • USA
  • -
  • December 13 2010

The requirements under the HIPAAHITECH statutes and regulations for public disclosure of security breaches of Protected Health Information ("PHI") have been bringing to light new breaches of PHI security and direct intervention by attorneys general with respect to such breaches

Back to the SAIC breach and a look across the chasm between significant risk and actual harm resulting from a HIPAA breach

  • Fox Rothschild LLP
  • -
  • USA
  • -
  • December 6 2012

We have posted several blogs, including those here and here, tracking the reported 2011 theft of computer tapes from the car of an employee of Science Applications International Corporation (“SAIC”) that contained the protected health information (“PHI”) affecting approximately 5 million military clinic and hospital patients (the “SAIC Breach”

The parade of PHI security breaches: escalating enforcement activity by state Attorneys General - most recently in Vermont

  • Fox Rothschild LLP
  • -
  • USA
  • -
  • January 31 2011

As reported previously on this blog series, the requirements under the HIPAAHITECH statutes and regulations for public disclosure of security breaches of Protected Health Information ("PHI") have been bringing to light new breaches of PHI security and direct intervention by state attorneys general with respect to such breaches

SAIC and its military millions march - flooding the parade with possible PHI breaches - part 2

  • Fox Rothschild LLP
  • -
  • USA
  • -
  • October 25 2011

In an October 3, 2011 Securities and Exchange Commission (“SEC”) filing posted on its Web site, SAIC described itself as a FORTUNE 500 scientific, engineering, and technology applications company that uses its deep domain knowledge to solve problems of vital importance to the nation and the world, in national security, energy and the environment, critical infrastructure, and health

A New Year's resolution: review and analyze potentially applicable state laws whenever examining HIPAA compliance issues

  • Fox Rothschild LLP
  • -
  • USA
  • -
  • January 1 2012

The Order of Judge Richard Smoak in a recent Federal District Court case (Opis Management, LLC, et. al. v. Dudek, No. 4:11-cv-400RS-WCS (N.D. Fla., Tallahassee Division)) (the “Opis Order”) reminds us of the attention that must be paid to the interaction and potential conflicts or dual applicability of state law with HIPAA compliance

The parade of major PHI breaches marches onward - what lessons can be learned from comments by OCR's reviewing stand?

  • Fox Rothschild LLP
  • -
  • USA
  • -
  • June 24 2012

This blog series has been following breaches of Protected Health Information (“PHI”) that have been reported on the U.S. Department of Health and Human Services (“HHS”) list (the “HHS List”) of breaches of unsecured PHI affecting 500 or more individuals (the “List Breaches”

New turn in the parade of PHI breaches: Office of Civil Rights exacts heavy payments from Cignet Health and Massachusetts General Hospital

  • Fox Rothschild LLP
  • -
  • USA
  • -
  • March 1 2011

As reported previously, the requirements under the HIPAAHITECH statutes and regulations for public disclosure of security breaches of Protected Health Information ("PHI") have been bringing direct intervention by attorneys general with respect to enforcement actions regarding such breaches

The new and improved HIPAAHITECH rules: what employers need to know

  • Fox Rothschild LLP
  • -
  • USA
  • -
  • February 7 2013

On January 25, the new (final?) rules about HIPAA Privacy under the HITECH Act were issued in the Federal Register. While the effect of the new rules