Author: Colington Consulting

  • OCR Issues Quarterly Cybersecurity Newsletter

    On March 17, the HHS Office for Civil Rights issued its quarterly cybersecurity newsletter. The big take away from the newsletter and the OCR mantra, is most cybersecurity attacks in the healthcare sector can “prevented or substantially mitigated” if organizations implemented all the required safeguards under the HIPAA Security Rule. According to the newsletter, “the number of breaches due to hacking or IT incidents accounted for 66% of all breaches affecting 500 or more individuals reported to OCR in 2020.”

    However, in a recent presentation made by Nicholas Heesters, OCR’s Senior Advisor for Cybersecurity, at the HIPAA Summit, hacking and IT related incidents now account for 73% of all reported breaches. Regardless of the current percentages, this is concerning and organizations must do more to address technical safeguard requirements. Also troubling is the vector of the breaches with 52% affecting network servers and 28% by email, most likely due to phishing.

    There needs to a holistic approach to overall compliance which includes the integration of technical safeguards along with program management. Small to mid-size healthcare organizations that outsource their IT requirements must use managed service providers that understand the world of HIPAA compliance. The days of trying to handle IT inhouse, as small to mid-size provider, should be over. Most HIPAA Security Officers have too much on their plates now to handle vast IT requirements. As the newsletter bluntly states, “A regulated entity that has weak cybersecurity practices makes itself an attractive soft target.”

    Although not required by the HIPAA Security Rule, organizations should consider conducting a cybersecurity assessment to fully understand the landscape of potential threats. In addition, add some type of IT vulnerability assessment to enhance the requirement of a HIPAA Security Risk Assessment. Being proactive with a systematic approach to cybersecurity safeguards and HIPAA compliance program management can go a long way to help prevent hacking and breaches to occur.

    To read the OCR newsletter, click here.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management | Helping Organizations Achieve HIPAA Complianceโ„ข

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    This article was updated on June 14, 2026, and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

  • HIPAA Breach Deadlines for Under 500 Affected People

    Quick Answer: For HIPAA breaches affecting fewer than 500 individuals, covered entities must notify the Secretary of the U.S. Department of Health and Human Services (HHS) no later than 60 days after the end of the calendar year in which the breach was discovered.

    If a data breach affects fewer than 500 individuals, your organization is permitted to track and report these incidents to the federal government on an annual basis rather than immediately.

    Reports for these smaller breaches must be submitted to the Secretary of the U.S. Department of Health and Human Services (HHS) within 60 days of the end of the calendar year. This annual reporting must be completed online through the official HHS Office for Civil Rights (OCR) Breach Reporting Portal.

    Crucial Exception: Individual Notifications

    While federal government reporting can wait until the end of the year, individual patient notifications cannot.

    You must notify affected individuals without unreasonable delay, and absolutely no later than 60 days following the initial discovery of the breach.

    What Must Be Included in a HIPAA Breach Notification?

    To remain fully compliant with the HIPAA Privacy and Security Rules, every breach notification sent to an individual must contain the following details:

    • A Brief Description: A short summary of what happened, including the date of the breach and the date it was discovered.
    • Types of PHI Involved: A description of the specific types of Protected Health Information involved (e.g., full name, social security number, date of birth, home address, or medical history).
    • Mitigation Steps for Individuals: Clear instructions on what steps affected individuals should take to protect themselves from potential harm (e.g., credit monitoring or changing passwords).
    • Your Investigation & Remediation: A brief summary of what your covered entity is doing to investigate the breach, mitigate ongoing harm, and prevent future security incidents.
    • Contact Information: Clear contact details for the covered entity or business associate so individuals can ask follow-up questions.

    Ensure Your Practice is Fully HIPAA Compliant

    Navigating the nuances of the HIPAA Security Rule and proactive risk management can be challenging. At Colington Consulting, our team of regulatory experts specializes in making HIPAA compliance strategies painless, efficient, and tailored to your specific organizational needs.

    Have questions about breach reporting or need a comprehensive risk assessment? Schedule a free HIPAA Risk Review now.

    • Updated on June 7, 2026, and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: Reporting to the Secretary of HHS (Under 500 Affected): Governed by 45 CFR ยง 164.408(c). This section states that for breaches affecting fewer than 500 individuals, a covered entity must maintain a log and notify the Secretary no later than 60 days after the end of the calendar year in which the breach was discovered. Reporting to Affected Individuals: Governed by 45 CFR ยง 164.404. Subsection (b) mandates that individual notifications must be made without unreasonable delay and strictly no later than 60 calendar days after the discovery of the breach. Subsection (c) outlines the exact content elements required in the notice (such as the description of PHI types and mitigation steps).
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • Telehealth: Is Your Practice Adhering to the HIPAA Rules?

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    While the concept of telehealth has been around for years, it recently became the new normal for many healthcare providers. The coronavirus pandemic has created a situation where more medical offices and clinics are finding themselves conducting routine patient visits and follow-up appointments via a laptop or mobile device to limit office visits and the interaction between staff and patients.

    Unfortunately, implementing telehealth solutions that effectively provide distance care in the middle of a pandemic came with its own challenges. When the virus was spreading quickly, providers scrambled to find solutions that could help them better deliver medical services and efficiently cater to the fast-growing number of patients; many went for the first option they could find. While these solutions may be suitable for short-term use, some telemedicine platforms used today may not work in the long term. Why? They are not HIPAA compliant. Chances are if your organization is using a free version of a telecommunications product, it is not meeting HIPAA requirements.

    HIPAA Guidelines on Telehealth

    The U.S. Department of Health and Human Services (HHS) defines telehealth as โ€œthe use of electronic information and telecommunications technologies to support and promote long-distance clinical health care, patient and professional health-related education, and public health and health administrationโ€. Because of the security risks involved in delivering these services online, the HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) implement administrative, physical, and technical procedures to protect health information communicated electronically. Ideally, for telemedicine to be HIPAA compliant:

    • Only authorized users should have access to electronic Protected Health Information (ePHI).
    • A communications-monitoring system must be implemented to oversee communications containing ePHI and prevent accidental or malicious breaches.
    • The channels used to transmit ePHI must be secure enough to protect the integrity of patientsโ€™ data and communications. That said, non-secure, public facing platforms like Facebook Live, TikTok, or other video communication applications cannot be used. Because copies of communication can remain on the servers of these third parties, a CE is required to have a Business Associate Agreement (BAA) with, for example, Skype, Zoom, or Google to be compliant with HIPAA. However, because some service providers, whoโ€™s platforms were not designed for telehealth, will likely not enter into a BAA with a Covered Entity for telehealth services. The CE may be responsible for any penalties should there be an unauthorized disclosure of ePHI due to using these types of platforms that do not comply with HIPAA security guidelines.

    The good news? The HHS Office for Civil Rights has exercised its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. The bad? That wonโ€™t last, as there are obvious risks to continuing to use non-secure telemedicine solutions that may put ePHI in danger. As we enter the next phase of the pandemic, itโ€™s becoming clear that telemedicine will be an important part of patient care, which means healthcare organizations need to adopt platforms that can serve them for the long term. If your facility is operating a telehealth solution that is not HIPAA compliant, now itโ€™s time to set yourself up for success by investing in a platform or technology you will not have to abandon when the public health emergency ends. Remember, once your organization engages a telehealth delivery platform, an executed Business Associate Agreement must be in place with that vendor.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Why Organizations Must Conduct a HIPAA Risk Assessment

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    Data breaches targeting Electronic Protected Health Information (ePHI) are nothing new. In fact, with more healthcare organizations now storing patientsโ€™ medical records electronically, these attacks are at an all-time high. It is crucial that healthcare entities regularly conduct a HIPAA risk assessment to identify any threats or vulnerabilities that may put ePHI in jeopardy. A risk assessment, also known as a risk analysis, is not only useful in detecting data threats; itโ€™s also required by the Code of Federal Regulations (CFR). The HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) โ€œConduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the organization.โ€ The risk assessment process keeps your patientsโ€™ records safe and your organization on the right side of the CFR.

    Do Small Practices Need to Conduct a HIPAA Risk Assessment?

    Data breaches donโ€™t only occur in larger organizations; hackers can target small practices and businesses too. Regardless of the size of the organization, a HIPAA Risk Assessment must be conducted with the proper documentation of any gaps and weaknesses determined by the assessment. Itโ€™s essential and required.

    The Office of the National Coordinator for Health Information Technology (ONC), in partnership with the HHS Office for Civil Rights (OCR), saw the need to launch a Security Risk Assessment (SRA) Tool to help small and medium-sized healthcare organizations and BAs comply with the HIPAA Security Rule. The tool is meant to guide these entities in identifying security risks in their systems, policies, and processes and display results that they can use to mitigate any identified vulnerabilities. Since launching the original tool about ten years ago, revisions have been made and it is now more of a decision tree process.

    However, itโ€™s important to note that the CFRs do not make it mandatory for Covered Entities and Business Associates to use the SRA tool nor does it give specific guidelines on how risk assessment should be carried out. HHS recognizes that different sized businesses have different needs and vulnerabilities, as well as different levels of access to resources. The problem with the tool is it can become time consuming to use, leads to more questions about meeting compliance requirements, and inability to see all the questions until traversing through the process. Regardless of using the tool or outsourcing the assessment to a consultant or vendor, all CEs and BAs must have documented proof that they have conducted an accurate and thorough HIPAA security risk assessment.

    Failure to Perform a HIPAA Risk Assessment Can Result in Serious Penalties

    If just knowing that conducting a risk analysis is a HIPAA requirement isnโ€™t enough motivation to get you started with the process, then you should keep in mind that the fines for non-compliance can add up to hefty amounts. Some organizations like Excellus Health Plan, Inc., for instance, have had to pay up to $5.1 million to OCR for breaching ePHI. According to this press release, the penalty was attributed to the organizationโ€™s โ€œfailure to conduct an enterprise-wide risk analysis, and failures to implement risk management, information system activity review, and access controlsโ€, which put the privacy of millions of its patients in danger. So, carrying out a risk assessment does not only allow you to spot potential weaknesses in organizational information systems that contain ePHI; it also enables you to take the right actions as soon as possible to safeguard your ePHI data, which can protect your business from federal penalties and the need to enter into a resolution agreement with OCR.

    Need Help With Your HIPAA Compliance Program?

    HIPAA violations often stem from small, overlooked gaps in daily operations. Don’t wait for a patient complaint to trigger a federal investigation. Would Your Practice Pass a HIPAA Audit Tomorrow?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your practice.

  • Understanding the Role of a HIPAA Business Associate

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    The continued complexity of modern healthcare systems and growth of patientsโ€™ data mean that medical records can be stored in more places than just the doctorโ€™s office. The information may be kept and maintained offsite in a storage facility or on a cloud-based server operated by a third party. Any entity or individual that uses, processes, or discloses this data on behalf of the healthcare provider is called a HIPAA Business Associate. If an organization is contracted by a HIPAA Covered Entity (CE) to perform activities that involve accessing Protected Health Information (PHI) or electronic PHI (ePHI) in any way, they are considered a Business Associate (BA). Because Business Associates use protected patientsโ€™ data to support the operations of covered entities, the U.S. Department of Health and Human Services (HHS) requires adherence to the Code of Federal Regulations (CFR) to comply with HIPAA requirements.

    Business Associate Agreement (BAA)

    The HIPAA Privacy Rule states that, โ€œA covered entity must obtain satisfactory assurances from its Business Associate that the Business Associate will appropriately safeguard the protected health information it receives or creates on behalf of the covered entity. The satisfactory assurances must be in writing, whether in the form of a contract or other agreement between the covered entity and the business associate.โ€

    This means that before a covered entity can work with a Business Associate, the BA must sign a BAA stating that they will safeguard and treat PHI the way CFRs and the covered entity require them to. It does not matter whose version of the BAA is signed, whether provided by the CE or the BA, as long it is executed. According to the Health Information Technology for Economic and Clinical Health (HITECH) Act, a BAA must include specific information to meet HIPAA compliance such as a description of the required and allowed uses of PHI, declarations that the Business Associate will disclose information only as required by law, and proper safeguards to protect patientsโ€™ data from breach including steps to take should there be such security violations.

    Why are Some Business Associates Not Complying with HIPAA Regulations?

    One of the major reasons is that most of them have no idea that the law considers them Business Associates. Covered entities have made great strides in following HIPAA compliance requirements, but many Business Associates are still not aware of the need to comply or are just reluctant to do so. Under HITECH, the Office of Civil Rights (OCR) holds Business Associates liable for breaches, and it is imperative that these entities take the necessary steps to ensure HIPAA compliance. In this press release where a Business Associate pays $2.3 million to settle a breach, the OCR Director at the time, Roger Severino terms โ€œThe failure to implement the security protections required by the HIPAA Rules in an industry known as a target for hackers and cyber thievesโ€ inexcusable. Sure, following all the steps required to obtain HIPAA compliance may seem overwhelming, but it offers better protection for patientsโ€™ data, which helps Business Associates avoid these types of federal penalties.

    Helping Organizations Achieve HIPAA Complianceโ„ข

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • OCR Provides Ransomware Resources

    On September 21, the HHS Office for Civil Rights pushed out through their Listserv, a list of information to ensure that “HIPAA regulated entities are aware of the resources available to assist in preventing, detecting, and mitigating breaches of unsecured protected health information caused by hacking and ransomware.” Depending on the size of the organization and internal resources, some may handle theses critical issues in house. If this support is contracted to a managed service provider, your organization may want to make this information available to them.

    Healthcare data is a prime target for bad actor. Organizations must be pro-active in fighting cybersecurity threats, whether handled in house or contracted out as a service. The HIPAA regulations require a contingency plan be in place, regardless of the size of the organization in case ePHI data is compromised.

    Here is the list of those resources:

    HHS Health Sector Cybersecurity Coordination Center Threat Briefs:

    ยท https://www.hhs.gov/about/agencies/asa/ocio/hc3/products/index.html#sector-alerts

    HHS Resources on Section 405(d) of the Cybersecurity Act of 2015:

    OCR Guidance:

    CISA Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches:

    CISA Ransomware Guide:

    FBI Ransomware Resources:

    OCR Cybersecurity Newsletters:

    REMINDER: A ransomware attack may result in a breach of unsecured protected health information that triggers reporting requirements under the HIPAA Breach Notification Rule. HIPAA covered entities and business associates should review OCRโ€™s ransomware guidance at https://www.hhs.gov/sites/default/files/RansomwareFactSheet.pdffor information regarding potential breach notification obligations following a ransomware attack.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • OCR Settles Multiple Complaints Regarding Patient Right of Access

    by Jay Hodes โ€“ President, Colington Consulting

    In March and April of this year, the HHS Office for Civil Rights (OCR) announced its enforcement discretion when it came to some provisions within the HIPAA Security and Privacy Rules due to COVID-19. These notices were limited and narrow in scope. The March notice stated OCR would โ€œnot impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency.โ€ The April notice specified OCR โ€œwill not impose penalties for violations of certain provisions of the HIPAA Privacy Rule against health care providers or their business associates for the good faith uses and disclosures of protected health information (PHI) by business associates for public health and health oversight activities during the COVID-19 nationwide public health emergency.โ€

    It is my belief some in the healthcare sector, especially in the small to mid-size provider community, interpreted these notices to mean OCR was not going to enforce any of the HIPAA rules. That misunderstanding of enforcement discretion was enough for some organizations to put their HIPAA compliance programs on the back burner. The operational mindset, then and in some cases now, was there was not a need to perform required Security Risk Assessments, review or create HIPAA policies and procedures, or adhere to many of the obligations in the HIPAA Privacy Rule.

    Let me be clear; the rules are still the rules. Healthcare organizations and business associates must still comply with the HIPAA requirements. As the notices indicate, there still must be adherence to the good faith provision. That means regardless of any enforcement discretion, organizations must still be able to demonstrate compliance with the rules and show the effort to do so.

    As proof enforcement actions continue, this week OCR announced five settlements for violations under the HIPAA Privacy Rule that pertain to individualsโ€™ rights to access their medical records. Although not earth-shattering monetary settlement amounts that ranged from $3,500 to $70,000, these cases serve as another wake-up call to providers. There is just as much culpability under the Privacy Rule as the Security Rule.

    The two types of infractions in these recent cases involve (1) refusals by healthcare providers to give patients access and copies of their medical records and (2) when requests for medical records were made by personal representatives seeking access to those records for family members were denied.

    The OCR listserv email regarding these cases states โ€œOCR’s enforcement actions are designed to send a message to the health care industry about the importance and necessity of compliance with the HIPAA Rules.โ€ Message sending indeed as OCRโ€™s right of access initiative continues. OCR Director Roger Severino stated in the email “Today’s announcement is about empowering patients and holding health care providers accountable for failing to take their HIPAA obligations seriously enough.”

    Has your organization ever conducted a Privacy Assessment to see if requirements of the HIPAA Privacy Rule are being met and understood? This type of assessment is part of our overall assessment process for both Covered Entities and Business Associates.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Office for Civil Rights – Guidance on HIPAA IT Asset Inventories

    On August 25, 2020, OCR as part of its quarterly cybersecurity newsletter, provided outstanding guidance regarding HIPAA and IT Asset Inventories. As part of the risk assessment process at Colington Consulting, this is a critical area we address with all of our clients. We want to ensure there is a detailed asset inventory of all software, hardware, network or computing component that creates, receives, maintains, or transmits electronic protected health information (ePHI). Sometimes we find this information scattered into various documents or not centrally maintained. Our goal is to make sure there is a comprehensive list for software and hardware for these vital components throughout an organization.

    Here are some helpful sections from the newsletter:

    “The HIPAA Security Rule requires covered entities and business associates to ensure the confidentiality, integrity, and availability of all electronic protected health information (ePHI) that it creates, receives, maintains, or transmits. Conducting a risk analysis, which is an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI held by an organization, is not only a Security Rule requirement, but also is fundamental to identifying and implementing safeguards that comply with and carry out the Security Rule standards and implementation specifications. However, despite this long-standing HIPAA requirement, OCR investigations frequently find that organizations lack sufficient understanding of where all of the ePHI entrusted to their care is located. Although the Security Rule does not require it, creating and maintaining an up-to-date, information technology (IT) asset inventory could be a useful tool in assisting in the development of a comprehensive, enterprise-wide risk analysis, to help organizations understand all of the places that ePHI may be stored within their environment, and improve their HIPAA Security Rule compliance.”

    How to Create an IT Asset Inventory

    “An enterprise-wide IT asset inventory is a comprehensive listing of an organizationโ€™s IT assets with corresponding descriptive information, such as data regarding identification of the asset (e.g., vendor, asset type, asset name/number), version of the asset (e.g., application or OS version), and asset assignment (e.g., person accountable for the asset, location of the asset). When creating an IT asset inventory, organizations can include:

    • Hardware assets that comprise physical elements, including electronic devices and media, which make up an organizationโ€™s networks and systems. This can include mobile devices, servers, peripherals, workstations, removable media, firewalls, and routers.
    • Software assets that are programs and applications that run on an organizationโ€™s electronic devices. Well-known software assets include anti-malware tools, operating systems, databases, email, administrative and financial records systems, and electronic medical/health record systems. Though lesser known,there are other programs important to IT operations and security such as backup solutions, virtual machine managers/hypervisors, and other administrative tools that should be included in an organizationโ€™s inventory.
    • Data assets that include ePHI that an organization creates, receives, maintains, or transmits on its network, electronic devices, and media.”

    As part of this inventory process, we always recommend organizations have an accurate and up-to-date list of all vendors in which you have signed Business Associate Agreements in place with. You may also want to include a list of all types of physical, hard copy medical records, billing records, or any other paper documentation containing protected health information.

    All these asset inventory lists must be reviewed and confirmed during the risk assessment process.

    Not One and Done

    This should not be considered a “one and done” process. It is important to remember whoever is assigned this task, whether it is an individual or a department, that is an ongoing process. Lists must be updated as new equipment or software is added and legacy systems or devices are removed.

    Take Action Now

    If HIPAA compliance assistance is needed for your organization, we specialize in putting compliance programs in place or assessing your current program. We provide a full range of services that include conducting the required HIPAA Risk Assessment, ensuring critical asset inventory lists are in place, writing and customizing a HIPAA Risk Management Plan (HIPAA Policies and Procedures) for your organization, and providing your entire staff annual required HIPAA Security Awareness & Privacy Training through our web-based platform. Our fees are based on what specifically your organization will need to meet regulatory requirements and reasonably priced to accommodate any budget.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Best Practices for Teleworking & Telehealth Involving PHI/ePHI

    by Jay Hodes, President – Colington Consulting

    With the federal public health emergency in place as of January 31 to address COVID-19, many healthcare organizations have implemented teleworking options for their workforce. Providers are also using telehealth services to interact with their patients. For some organizations, this is a whole new world. If not already in place, organizations needed to implement policies and procedures to address these critical operational topics.

    The HHS Office for Civil Rights (OCR) has issued a number of guidance documents pertaining to this emergency. Here are some excerpts I feel are important:

    February 2020: โ€œIn an emergency situation, covered entities must continue to implement reasonable safeguards to protect patient information against intentional or unintentional impermissible uses and disclosures. Further, covered entities (and their business associates) must apply the administrative, physical, and technical safeguards of the HIPAA Security Rule to electronic protected health information.โ€

    As further stated in the guidance regarding PHI:

    โ€œThe HIPAA Privacy Rule protects the privacy of patientsโ€™ health information (protected health information) but is balanced to ensure that appropriate uses and disclosures of the information still may be made when necessary to treat a patient, to protect the nationโ€™s public health, and for other critical purposes.โ€

    March 2020: โ€œWhile the HIPAA Privacy Rule is not suspended during a public health or other emergency, the Secretary of HHS may waive certain provisions of the Privacy Rule under the Project Bioshield Act of 2004 (PL 108-276) and section 1135(b)(7) of the Social Security Act.โ€

    Although OCR has indicated some discretion with its enforcement authority and waiving some requirements, the HIPAA Privacy and Security Rules are still in place with very limited exceptions.

    With the OCR guidance clearly stated, there must be an operational balance and the need to apply a commonsense approach to minimize the risks for unauthorized disclosures in order for your workforce to be able to perform their jobs while teleworking and during telehealth sessions.

    Here are some best practices to consider implementing as part of your organizationโ€™s policies to address teleworking and telehealth sessions:

    • Staff should never leave any documents containing PHI in a vehicle overnight. Even if the vehicle is locked or the documents can be secured in a trunk, all PHI must be removed. No exceptions!
    • When working from home, the staff should follow the same protocols as if in an office, practice location, or providing services face-to-face. This means following the Minimum Necessary Requirement. If working from home and there are others in the house, such as family members or roommates, only have patient conversations where others cannot hear that conversation. Staff must try to make those conversations as private as possible. This includes VTC telehealth sessions and telephone calls.
    • Always keep documents containing PHI as secure as possible so others may not see them when performing work related duties.
    • Avoid having conversations with those in the house regarding any patient.
    • Never allow family members, roommates, or others in the house to access/use any organization issued devices including cell phones and laptops, unless personal use is approved by the organization.
    • If using a personal computer for organization business, make sure others in the home do not access while performing work related duties. If a computer needs to be utilized for non-organization business during the workday or shift, always log off from organization access or VPN.
    • If staff needs to leave an area in the home that is set up as a workstation to take a break, grab a coffee, or handle non-organization issues, always make sure to lock the computer and secure documents. Even for a few minutes.
    • At the end of the business day or shift, staff should log off from any computer they are using and properly secure any documents containing PHI.
    • If HIPAA compliant bags or containers are provided by the organization, then use those to secure the documents when not needed.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Additional Resources for Telehealth:

    OCR – FAQs on Telehealth and HIPAA during the COVID-19 nationwide public health emergency

    National Consortium of Telehealth Resource Centers

    The National Counsel – Best Practices for Telehealth During COVID-19 Public Health Emergency

    American Psychiatric Association – Best Practices in Videoconferencing-Based Telemental Health

    SAMHSA Telehealth Start-Up and Resource Guide

  • 6 More HIPAA Breaches Reported

    With healthcare attention clearly focused on combating the coronavirus, there were six more data breaches that occurred within a few days as the year began. The breaches reported by healthcare organizations, likely resulting in the unauthorized releases of patient data for at least 8,701 patients. As the sheer number of data breaches continues to rise, so too does your responsibility to protect the people who rely on your services. What happened in these latest occurrences, and what steps should you take to fulfil your obligation to prevent it from happening within your own organization?

    Kaiser Permanente is breached once again.

    Kaiser Permanente already had 4 data breaches by the time reports came out back in 2014. Then, in 2018, at least two more were reported. And then again in October of 2019. Now the latest breach occurred when Kaiser Permanente recently discovered letters have accidentally been mailed to patientsโ€™ former addresses. The HHSโ€™ Office for Civil Rights (OCR) breach portal indicates up to 500 patients may have been affected in this one. (This is not counting their prior breaches.)

    Riverview Health also experienced a mailing error.

    Much like Kaiser Permanenteโ€™s latest breach, this one also happened due to a mailing error. This time, however, the mix up exposed the names of 2,610 patients. Fortunately, no financial information – such as credit or debit card numbers – or medical data was exposed. However, the methods of patient notification used by Riverview are currently under review as a result of this incident.

    Harris Health System lost PHI during transport.

    On Friday, February 28th, Harris Health System announced that it was notifying 2,298 patients of a privacy breach that happened on December 30, 2019. Two envelopes that contained 143 pages of protected health information (PHI) were lost in transport to Ben Taub Hospital, which were being sent there for scanning and archiving in Harris Health’s electronic medical record system. The envelopes are thought to contain information on patients seen at Gulfgate Health Center from December 9, 2019 and December 27, 2019.

    Community Mental Health Council mental health records were found dumped in an alley.

    In 2012, the Community Mental Health Council was forced to permanently close its clinics due to lack of funding. Long after the fact, however, hundreds of medical records from CMHCl have been found abandoned in an alley in West Englewood, Chicago. The documents included full names, addresses, Social Security numbers, diagnosis information, medical records, and more. City officials are currently trying to determine who was responsible for dumping the records.

    Armada Physical Therapy had a server carried off.

    Data breaches through hacking, phishing scams, and mailing errors are nothing new. But what makes the breach of Armada Physical Therapy stand out is that this time around, someone actually broke into the building and stole an entire server. At the time of writing, the investigation is still ongoing, and the stolen server has not yet been recovered. The server holds intake forms that contain names, addresses, telephone numbers, email addresses, insurance numbers, and Social Security numbers for around 500 patients.

    Elk Ridge Dentistry had a hard drive stolen.

    Unlike the incident with Armada, one would imagine that stealing a portable hard drive is at least a bit easier than making off with an entire server. At least one such hard drive was stolen from Elk Ridge Dentistry. The hard drive in question was used to store backups, and was actually among several items taken from the practice. Much like Armadaโ€™s server, the hard drive has not yet been recovered. To make matters worse, it contained the records of 2,793 patients, which included names, addresses, dates of birth, healthcare information, X-ray images, Social Security numbers, treatment consent forms, referral letters, and emails.

    Take Action Now

    So many different occurrences all happening within such a short time should give anyone cause for serious alarm. The numbers are against you, and we here at Colington Consulting donโ€™t want you to become yet another statistic. Even as COVID-19 events have impacted healthcare organizations, we are still able to provide the majority of our services remotely. We are available and can set up an initial consultation to talk about our services and how we can assist your organization. Call us today at 844.740.7100 and find out how we can help you protect your patients from incidents like these.