Author: Colington Consulting

  • OCR Provides Guidance on Telehealth During the COVID-19 Emergency

    Yesterday, the HHS Office for Civil Rights (OCR), announced it will exercise its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. This notification is effective immediately.

    Here is the complete transcript of the OCR notification:

    Notification of Enforcement Discretion for Telehealth Remote Communications during the COVID-19 Nationwide Public Health Emergency

    We are empowering medical providers to serve patients wherever they are during this national public health emergency. We are especially concerned about reaching those most at risk, including older persons and persons with disabilities. โ€“ Roger Severino, OCR Director.

    The Office for Civil Rights (OCR) at the Department of Health and Human Services (HHS) is responsible for enforcing certain regulations issued under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act, to protect the privacy and security of protected health information, namely the HIPAA Privacy, Security and Breach Notification Rules (the HIPAA Rules).

    During the COVID-19 national emergency, which also constitutes a nationwide public health emergency, covered health care providers subject to the HIPAA Rules may seek to communicate with patients, and provide telehealth services, through remote communications technologies. Some of these technologies, and the manner in which they are used by HIPAA covered health care providers, may not fully comply with the requirements of the HIPAA Rules.

    OCR will exercise its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. This notification is effective immediately.

    A covered health care provider that wants to use audio or video communication technology to provide telehealth to patients during the COVID-19 nationwide public health emergency can use any non-public facing remote communication product that is available to communicate with patients. OCR is exercising its enforcement discretion to not impose penalties for noncompliance with the HIPAA Rules in connection with the good faith provision of telehealth using such non-public facing audio or video communication products during the COVID-19 nationwide public health emergency. This exercise of discretion applies to telehealth provided for any reason, regardless of whether the telehealth service is related to the diagnosis and treatment of health conditions related to COVID-19.

    For example, a covered health care provider in the exercise of their professional judgement may request to examine a patient exhibiting COVID- 19 symptoms, using a video chat application connecting the providerโ€™s or patientโ€™s phone or desktop computer in order to assess a greater number of patients while limiting the risk of infection of other persons who would be exposed from an in-person consultation. Likewise, a covered health care provider may provide similar telehealth services in the exercise of their professional judgment to assess or treat any other medical condition, even if not related to COVID-19, such as a sprained ankle, dental consultation or psychological evaluation, or other conditions.

    Under this Notice, covered health care providers may use popular applications that allow for video chats, including Apple FaceTime, Facebook Messenger video chat, Google Hangouts video, or Skype, to provide telehealth without risk that OCR might seek to impose a penalty for noncompliance with the HIPAA Rules related to the good faith provision of telehealth during the COVID-19 nationwide public health emergency. Providers are encouraged to notify patients that these third-party applications potentially introduce privacy risks, and providers should enable all available encryption and privacy modes when using such applications.

    Under this Notice, however, Facebook Live, Twitch, TikTok, and similar video communication applications are public facing, and should not be used in the provision of telehealth by covered health care providers.

    Covered health care providers that seek additional privacy protections for telehealth while using video communication products should provide such services through technology vendors that are HIPAA compliant and will enter into HIPAA business associate agreements (BAAs) in connection with the provision of their video communication products. The list below includes some vendors that represent that they provide HIPAA-compliant video communication products and that they will enter into a HIPAA BAA.

    • Skype for Business
    • Updox
    • VSee
    • Zoom for Healthcare
    • Doxy.me
    • Google G Suite Hangouts Meet

    Note: OCR has not reviewed the BAAs offered by these vendors, and this list does not constitute an endorsement, certification, or recommendation of specific technology, software, applications, or products. There may be other technology vendors that offer HIPAA-compliant video communication products that will enter into a HIPAA BAA with a covered entity. Further, OCR does not endorse any of the applications that allow for video chats listed above.

    Under this Notice, however, OCR will not impose penalties against covered health care providers for the lack of a BAA with video communication vendors or any other noncompliance with the HIPAA Rules that relates to the good faith provision of telehealth services during the COVID-19 nationwide public health emergency.

    OCR has published a bulletin advising covered entities of further flexibilities available to them as well as obligations that remain in effect under HIPAA as they respond to crises or emergencies at https://www.hhs.gov/sites/default/files/february-2020-hipaa-and-novel-coronavirus.pdf – PDF.

    Guidance on BAAs, including sample BAA provisions, is available at https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html.

    Additional information about HIPAA Security Rule safeguards is available at https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html.

    HealthIT.gov has technical assistance on telehealth at https://www.healthit.gov/telehealth.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • How to Avoid a $100,000 HIPAA Settlement

    By Jay Hodes, President โ€“ Colington Consulting

    Question: How can an organization avoid a large HIPAA settlement with the HHS Office for Civil Rights (OCR)?

    Up to this point, the OCR has settled HIPAA violation cases with predominantly larger healthcare organizations. However, OCRโ€™s enforcement priority and direction has changed and all healthcare providers, regardless of size, must be on guard for the โ€œmessage sending casesโ€ on which OCR is currently focusing.

    As a case in point, on the first day of the recent National HIPAA Summit held in Arlington, Virginia, OCR announced a $100,000 settlement for a HIPAA violation case involving the practice of Steven A. Porter, M.D., a gastroenterological services provider and solo practitioner. This โ€œmessage sendingโ€ was twofold: 1) Serena Mosley-Day, Senior Advisor for HIPAA Compliance and Enforcement for OCR, provided a presentation emphasizing that small providers are not immune to OCR scrutiny and must meet the same requirements under HIPAA as do larger healthcare organizations; and 2) Announcing the settlement at a Summit where attendees included attorneys, Chief Compliance Officers, HIPAA Security and Privacy Officials, IT and cybersecurity experts was timed for maximum impact.

    According to the HIPAA Settlementโ€™s press release, Dr. Porter โ€œfiled a breach report with OCR related to a dispute with a business associate. OCRโ€™s investigation determined that Dr. Porter had never conducted a risk analysis at the time of the breach report, and despite significant technical assistance throughout the investigation, had failed to complete an accurate and thorough risk analysis after the breach and failed to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.โ€

    OCR Director Roger Severinoโ€™s comments in the press release are especially noteworthy. He states that โ€œAll health care providers, large and small, need to take their HIPAA obligations seriously,โ€ and โ€œthe failure to implement basic HIPAA requirements, such as an accurate and thorough risk analysis and risk management plan, continues to be an unacceptable and disturbing trend within the health care industry.โ€

    OCR has previously said that 95% of reported breaches are resolved with technical guidance. The key to avoiding a costlier outcome is to demonstrate to OCR that your organization has a HIPAA compliance plan in place and to cooperate with the OCR breach investigation.

    Answer: To reduce the risk of penalty or settlement or the cost of mitigating a breach, an organization MUST implement and maintain a HIPAA compliance program as follows:

    • Develop and implement policies and procedures to address all the HIPAA Security Standards and Implementation Specifications.
    • Prepare a HIPAA Risk Management Plan that includes policies and procedures, asset inventories, HIPAA-related forms and reports, a facility security plan, and a documented contingency plan.
    • Conduct he required HIPAA Security Risk Assessment.
    • Provide HIPAA Security Awareness Training to the entire workforce.
    • Assign HIPAA Security and Privacy Officer(s) to manage a HIPAA compliance program. Regardless of size, an organization must designate a workforce member(s) to handle these required responsibilities.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • The State of HIPAA Compliance in 2019 โ€“ Sound the Alarm Bells

    By Jay Hodes, President โ€“ Colington Consulting

    Recently, Buck, โ€œan integrated HR and benefits consulting, technology, and administration services providerโ€ based in New York, produced a 2019 HIPAA Readiness Survey. After reading the Survey, I was not surprised by the results, for its message is loud and clear: It is time to sound the alarm bells.

    In my mission to help organizations achieve HIPAA compliance, I know where organizations typically struggle in complying with HIPAA regulations. Several of the Surveyโ€™s findings drive home that point:

    • 42% of survey participants did not know when a risk/threat analysis was last conducted, or they last conducted one more than five years ago.
    • 33% of survey respondents either have not inventoried their business associates or did not know if they had done so; 16% did not have current business associate agreements or did not know if they had them.
    • 35% indicated they last offered HIPAA training between one and five years ago, 13% provide training only during onboarding, and 10% did not know when HIPAA training was last provided.

    The Survey states that โ€œstrong governance is essential to protecting informationโ€ and โ€œunderstanding the rules and complying with them in a way that protects your organization is the best way to prevent a breach and the only way to emerge successfully from a HIPAA audit.โ€

    Governance, Risk, and Compliance (GRC) and Beyond

    I recently had lunch with a GRC expert who pointed out that organizations are considered โ€œnegligentโ€ if they disregard or plead ignorance of HIPAA compliance requirements and other industry-wide regulatory controls and standards. The HHS Office for Civil Rights continues an aggressive campaign of seeking civil monetary penalties from organizations for HIPAA violations. In addition, these same negligent organizations expose themselves to class action lawsuits from individuals seeking damages from breaches of personally identifiable information. In summary, HIPAA compliance should be driven by costโ€”the costs incurred from both government penalties as well as the time and money spent on re-mediating the damage caused by data breaches.

    Sound the Alarm?

    Rather than sound the alarm after the fact, organizations should focus their urgency on prevention and corrective measures before a violation or data breach. GRC is not meant to be a one-and-done approach to punch a regulatory ticket, but rather a systematic process to deal with risk management, including conducting audits and assessments; reviewing the results; and implementing the changes necessary to mitigate risk. This process will take effort, buy-in, and cooperation from all organizational levels, especially from the leadership team.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Coronavirus and HIPAA – An Announcement from HHS

    In light of the recent Novel Coronavirus outbreak, the U.S. Department of Health and Human Services (HHS) has issued a reminder for HIPAA adherence pertaining to the ways that patient information can be shared during outbreaks of infectious disease and other emergency situations such as this one.

    According to the Office for Civil Rights, HIPAA covered entities may disclose, without patient authorization, protected health information (PHI) about the patient as necessary to perform treatment. How far does this leeway extend and how will privacy be protected during outbreaks? Letโ€™s take a closer look.

    HIPAA applies only to covered entities and business associates

    According to HHS, by law the HIPAA Privacy Rule applies only to covered entities โ€“ โ€œhealth plans, health care clearinghouses, and certain health care providers.โ€ At least this much has not changed. Normally, individuals, organizations and agencies that meet the definition of a covered entity under HIPAA would have to comply with the requirements to protect the privacy and security of health information and must provide individuals with certain rights with respect to their health information.

    However, โ€œtreatmentโ€ in these cases can include the coordination or management of healthcare and related services by one or more providers, which could also include consultations between providers as well as the referral of patients.

    Employees may not access or disclose patient records for an unauthorized purpose

    This much has not changed either. Under HIPAA, employees may only access or disclose patient records when specifically authorized to do so as part of their job, or when required to do so under law. Employees are not allowed to look up a patientโ€™s medical record to see if it mentions anything about coronavirus, no matter how strong that temptation may be.

    Information CAN be shared with friends and family of the coronavirus patient

    Family members, friends, and any individual involved in the care of the patient can be notified about the patientโ€™s condition so long as verbal permission has been obtained, or that it can be reasonably inferred that the patient does not object. If a patient is incapacitated, then professional judgement should be used as to whether the sharing of information is in the patientโ€™s best interest.

    Patient data may be shared to protect public health

    Providing specific information about an identifiable patient to the media or public at large is not permitted. However, if there is serious or imminent threat to the health and safety of another person or to the public, necessary information may be shared in order to protect those who would be affected. It should be noted that even this must be restricted. In general, the information thatโ€™s shared should be as minimal as possible.

    When outbreaks like these occur, itโ€™s easy for the public to begin to panic. From there itโ€™s a slippery slope, as rules and regulations can become blurred amidst the chaos. Thatโ€™s why when incidents like these do happen, itโ€™s more important than ever to have a clear set of guidelines to follow. And itโ€™s even more important to make sure youโ€™re following them correctly. Do not allow public panic to sway you from civic responsibility and the law.

    Take Action Now

    For more information on determining when and how information should be disclosed in the event of an emergency such as coronavirus and other similar outbreaks, HHS has published an Emergency Preparedness Decision Tool which can be found here.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Important Notice Regarding Individualsโ€™ Right of Access to Health

    On January 28, the HHS Office for Civil Rights issued an important notice regarding an individualsโ€™ right of access to health records and more specifically, when a request is made to transmit medical records to a third party.

    Here is the full transcript of the notice:

    On January 25, 2013, HHS published a final rule entitled โ€œModifications to the HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health Act, and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules.โ€ (2013 Omnibus Rule). A portion of that rule was challenged in federal court, specifically provisions within 45 C.F.R. ยง164.524, that cover an individualโ€™s access to protected health information. On January 23, 2020, a federal court vacated the โ€œthird-party directiveโ€ within the individual right of access โ€œinsofar as it expands the HITECH Actโ€™s third-party directive beyond requests for a copy of an electronic health record with respect to [protected health information] of an individual . . . in an electronic format.โ€ Additionally, the fee limitation set forth at 45 C.F.R. ยง 164.524(c)(4) will apply only to an individualโ€™s request for access to their own records, and does not apply to an individualโ€™s request to transmit records to a third party.

    The right of individuals to access their own records and the fee limitations that apply when exercising this right are undisturbed and remain in effect. OCR will continue to enforce the right of access provisions in 45 C.F.R. ยง 164.524 that are not restricted by the court order. A copy of the court order in Ciox Health, LLC v. Azar, et al., No. 18-cv-0040 (D.D.C. January 23, 2020), may be found at https://ecf.dcd.uscourts.gov/cgi-bin/show_public_doc?2018cv0040-51.

    What Healthcare Providers Should Know

    The HIPAA Privacy Rule permits a covered entity to impose a reasonable, cost-based fee to provide the individual (or the individualโ€™s personal representative) with a copy of the individualโ€™s PHI, or to direct the copy to a designated third party. The fee may include only the cost of certain labor, supplies, and postage:

    1. Labor for copying the PHI requested by the individual, whether in paper or electronic form.ย  Labor for copyingย includes onlyย labor for creating and delivering the electronic or paper copy in the form and format requested or agreed upon by the individual, once the PHI that is responsive to the request has been identified, retrieved or collected, compiled and/or collated, and is ready to be copied.ย  Labor for copyingย does not includeย costs associated with reviewing the request for access; or searching for and retrieving the PHI, which includes locating and reviewing the PHI in the medical or other record, and segregating or otherwise preparing the PHI that is responsive to the request for copying.
    2. Supplies for creating the paper copy (e.g.,ย  paper, toner) or electronic media (e.g., CD or USB drive)ย ifย theย  individual requests that the electronic copy be provided on portable media.ย  However, a covered entity mayย notย require anย  individual to purchase portable media; individuals have the right to have theirย  PHI e-mailed or mailed to them upon request.
    3. Labor to prepare an explanation or summary of the PHI, if the individualย in advanceย both chooses to receive an explanation or summaryย andย agrees to the fee that may be charged.
    4. Postage, when the individual requests that the copy, or the summary or explanation, be mailed.

    Thus, costs associated with updates to or maintenance of systems and data, capital for data storage and maintenance, labor associated with ensuring compliance with HIPAA (and other applicable law) in fulfilling the access request (e.g., verification, ensuring only information about the correct individual is included, etc.) and other costs not included above,ย even if authorized by State law, areย not permitted for purposes of calculating the fees that can be charged to individuals.ย  See 45 CFR 164.524(c)(4).

    Further, while the Privacy Rule permits the limited fee described above, covered entities should provide individuals who request access to their information with copies of their PHI free of charge.ย  While covered entities should forgo fees for all individuals, not charging fees for access is particularly vital in cases where the financial situation of an individual requesting access would make it difficult or impossible for the individual to afford the fee.ย  Providing individuals with access to their health information is a necessary component of delivering and paying for health care. We will continue to monitor whether the fees that are being charged to individuals are creating barriers to this access, will take enforcement action where necessary, and will reassess as necessary the provisions in the Privacy Rule that permit these fees to be charged.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Critical Vulnerabilities in Microsoft Windows Operating Systems

    The Cybersecurity and Infrastructure Security Agency (CISA) issued guidance regarding vulnerabilities in Microsoft Windows Operating Systems. If your organization manages all IT related services in-house and utilizes Microsoft systems, please be aware of this warning.

    Read the Alert

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • HIPAA and Home Health Care Providers

    by Jay Hodes, President – Colington Consulting

    Over the last few months, I attended a number of events with geriatric care managers and home health agency owners. It was extremely insightful learning about the tremendous services these professionals provide to our aging population. As more and more seniors consider aging in place and remain in their homes, the need for home health services is exploding.

    After speaking with some care managers, I subtly brought up the subject of HIPAA and how it may be applicable to certain aspects of the services they provide. Most those who provide non-medical care said that they were unaware of specific HIPAA requirements and admittedly did not know if it applied to what they do. I asked if they or their staff were maintaining client files that contained any protected health information (PHI). Most said yes, as this type of information is vital to the type of services provided to their clients.

    When I asked about taking the proper safeguards to protect client health information and other personally identifiable information (PII) they maintain, most if not all said they had no formal safeguards in place. What was even more unsettling was very few of these companies even had an employee policy and procedure manual that covered protecting client health information. From what I was told, a great deal of client health information is passed through unsecured means, including unsecured texting and email exchanges, along with the use of file sharing services.

    The HIPAA Privacy Rule requires healthcare providers, regardless of size, provide the proper safeguards of individually identifiable health information. Technically, a home health or geriatric care manager that does not provide skilled medical care does not meet the regulatory definition of a covered entity or business associate under this rule unless they are filing health insurance claims for clients. That poses a significant grey area in terms of mandating specific requirements for this category of professional caregiver. If a breach of client records did occur, the government would have no idea it happened. There are no notification requirements and no mandates to inform clients their health and personal information may have been compromised.

    Professional caregivers must be bound to protecting the confidentiality of client health information. Although there may not be a regulatory requirement, caregivers must be attentive to HIPAA regulations and use this guidance as a model to safeguard records. After all, they are dealing with and managing client health concerns every day on the job.

    I am usually asked, โ€œWhere do I start?โ€ Here are some suggestions to follow:

    1. Develop a Privacy Policy and Procedure Manual that is distributed to all staff. The manual needs to cover areas such as:
    • Notice of Privacy Practices
    • Uses and Disclosures of Protected Health Information Requiring Client Authorization
    • โ€œMinimum Necessaryโ€ Use and Disclosure of Protected Health Information
    • Uses and Disclosures of Protected Health Information where the Client has an Opportunity to Agree or Object
    • Access of Individuals to Protected Health Information
    • Accounting for Disclosure of Protected Health Information
    • Business Associate Agreements
    • How to Safeguard Protected Health and Personal Information
    • Complaints to Your Company or Business; Mitigation
    1. Require some type of security awareness training be conducted for all staff, regardless of their job function, on an annual basis and any time you take on a new employee.
    2. If you are currently using smartphones to text client health information, I would recommend against it. I know this may pose an inconvenience, but it is a prudent security measure. There are secure texting services available. If phones need to be used, it is best to call each other and discuss client health information in a private setting.
    3. From an IT perspective, the following safeguards should be in place:
    • Ensure there is full disc encryption on all laptops/computers used by the company staff. This includes all BYOD.
    • Implement a secure email service for exchanges between staff, providers and others who may need to view PHI and PII. This service includes the ability to securely upload attachments.
    • Ensure all computers/laptops have appropriate anti-malware and anti-virus software that is updated often.
    • Set auto log-off if the device is left unattended for a certain period of time, such as 10 or 15 minutes.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Updated on June 21, 2026 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Regulatory Sources: The HIPAA Privacy Rule (45 CFR ยง 164.524): This is the core federal regulation that establishes a set of national standards for the protection of certain health information. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) provides official regulatory guidance and actively enforces these timelines under its ongoing Right of Access Initiative, which targets covered entities that fail to provide timely access to records. 45 CFR 164.502(e), 164.504(e), 164.532(d) and (e), address Business Associates and when Business Associate Agreements are required.

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • Insider Threat โ€“ A Growing Concern in the Healthcare Sector

    by Jay Hodes, President – Colington Consulting

    As a healthcare provider or business associate, do you conduct a pre-employment background check on all potential new hires? Do you routinely conduct periodic background checks for the current workforce? If the answer to either of these questions is โ€œno,โ€ you may want to reconsider and implement a policy.

    There is a growing concern in the healthcare sector regarding insider threats. Being HIPAA compliant puts the necessary administrative, technical and physical safeguards in place. But most of these safeguards address how to ensure systems and the workforce properly manage risk. Even with the minimum necessary requirement of the HIPAA Privacy Rule, think about those in your practice or business who have access to protected health information, especially paper charts and records. Access to paper records, notes and charts poses a greater risk for a breach than electronic health records because, with paper records, there is the lack of an IT-based audit trail.

    In May, Beckerโ€™s Health IT & CIO Review reported that during a 14 day period, there were six insider threat cases the public was made aware of. In one case, a nurse at Albany (N.Y.) Medical Center was arrested at the hospital and charged with stealing patient information. In another case, an employee who processed billing for Baylor All Saints Medical Center in Fort Worth, Texas, may have stolen patient information over a seven month period. There was no information provided in either case indicating that background checks were conducted on these employees and if there was, how thorough the checks were.

    When the Ponemon Institute released its Fourth Annual Benchmark Study on Patient Privacy & Data Security last March, a significant finding stood out. According to the report, โ€œEmployee negligence is considered the biggest security riskโ€ when it comes to safeguarding health data. The report went to say, โ€œ75 percent of organizations (surveyed) say employee negligence is their biggest worry.โ€

    There appears to be a failure to exercise reasonable care when it comes to safeguarding protected health information, whether a compromise of records is intentional or unintentional. Background checks wonโ€™t help prevent human error and circumstances where the breach was unintentional. Better security awareness training can address that issue.

    But when the circumstances are intentional and an employee is to blame, you will need to look at the employee and hiring practices. As a hiring manager who has an employee arrested for theft, there is no worse feeling than when the police inform you about a prior criminal record that employee had. However, pre-employment background checks may not help if the employee has no criminal record and just goes rogue for financial gain. This is why I recommend a policy to conduct background checks on a regular basis for all employees, not just new hires. You may want to include a credit check as part of your background check policy.

    Stacy Skinner is the President of SCS Health and Security Associates, a company that offers background checks as part of their portfolio of services. According to Skinner, โ€œConducting background checks for all applicants is a great idea because you want to reduce the risk of a negligent hire. Every time an employer hires an employee, they take a risk and by conducting a background check, it helps to mitigated risk. It comes down to protecting sensitive information, patient confidentiality, patient safety, safety of the staff, and that of the business. Know more about who you are hiring. It can make a difference.โ€

    Here are 5 suggestions for implementing or modifying an existing background check policy.

    1. Be consistent with a background check policy. That is a must. Background checks must be conducted for the entire workforce, including contract and temporary employees. Consider using a tiered approach that is dependent on the position to be filled. For example, a doctor would warrant a more comprehensive check than a receptionist.
    2. Always check the U.S. Department of Health and Human Services, Office of Inspector General Excluded Individuals/Entities List (LEIE). The LEIE is an excellent way to see if an employee has previous sanctions preventing him/her from working in the healthcare sector.
    3. Consider conducting periodic background checks for those workforce members who have been on-board for a while. Rescreening workforce members can help to make sure an employee does not slip through the cracks by not notifying management of any recent criminal convictions.
    4. Drug screening – if a program is not in place, consider implementing one. The screening would be applicable to job applicants along with the current workforce.
    5. Consider contracting with a reputable investigations company that specializes in background checks. Leave this job to the professionals who know how to conduct background checks. Trying to obtain criminal background checks on your own can vary from state-to-state and be a time consuming process in some cases.

    Before implementing or updating a policy regarding background checks, credit checks and drug testing, it is always prudent to seek advice of legal counsel. For more information about background checks, visit the U.S. Equal Employment Opportunity Commission website.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • Substantial HIPAA Data Breaches: Only a Matter of Time

    by Jay Hodes, President – Colington Consulting

    With all the news about data breaches and the potential for personally identifiable information (PII) to make its way into the wrong hands of criminals or hackers, is it only a matter of time before there is a substantial breach of patient records? When checking the U.S. Department of Health and Human Services (HHS) Breach List, you will find these occurrences already happening on a regular basis. In June, the state of Montana announced 1.3 million people were affected by a recent health records data breach.

    Between March 1 and May 30, 2014, there were eight separate breach notifications made to HHS, each affecting 500 or more individuals, totaling almost 35,000 compromised patient records. The largest breach affected more than 8,800 individuals from an HMO and related insurance provider. But these breaches affect small healthcare providers, also. One of the reported breaches affecting 1,000 individuals was at a podiatry office and another at a dental practice that involved 6,900 individuals. There is no percipience with the size and type of healthcare practice, and most breaches appear to be theft related.

    There is usually limited press coverage of these breaches, except by those who track these industry occurrences. But when a newsworthy and extensive breach of millions of records does happen, it will be front page news. When will the tsunami of a health record breach occur? Regrettably, it may be sooner than later. When the FBI recently warned healthcare providers that their cybersecurity networks are more susceptible than retail and financial sectors, hopefully the alarm bells went off and proper information technology countermeasures are now being implemented.

    According to Chris Albright, network security expert and owner of CMIT Solutions of Centreville (VA), โ€œHackers, just like other predators, always go after the most vulnerable or โ€˜softโ€™ targets first. This approach guarantees the hacker greater success with the least amount of effort. More often than not, data breaches are not professional hackers in the traditional sense. Rather, it is members of the medical staff who know there are no policies or effective security measures in place, and they know the violation will go unnoticed. Healthcare offices that fail to address HIPAA head on are essentially sitting on a time bomb.โ€

    Conducting a HIPAA Risk Assessment is an excellent way to identify vulnerabilities and threats to patient electronic health records. Besides being a fundamental requirement of HIPAA compliance, the assessment helps professionals to recognize problem areas where the potential for unauthorized access, lack of proper internal protocols for tampering and outright theft of protected health information may occur.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Updated on June 21, 2025 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • Why Should HIPAA Compliance Matter to You?

    by Jay Hodes, President – Colington Consulting

    Healthcare Professionals

    If you are a healthcare provider or business associate, HIPAA compliance should matter because it is the law. According to the Code of Federal Regulation (CFR), if you are a provider or business associate who utilizes electronic health records, you must ensure the confidentiality, integrity, and availability of all records created, received, maintained, or transmitted. Civil monetary penalties for noncompliance that cause a breach of electronic patient records can be assessed up to $2.2 million. Criminal penalties can range from one to ten years in prison.

    I believe one of the biggest issues facing small healthcare providers is lack of knowledge of exact requirements for HIPAA security compliance. Part of the problem for small providers is they often have an unclear understanding of what safeguards need to be in place for electronic health records. I see this as a huge concern. The U.S. Department of Health and Human Services (HHS) has done a better job providing specific guidance to small providers. Navigating through the HHS website to find particular HIPAA compliance information has improved, but can be daunting to find specific information.

    I should know because I used to work for HHS and had oversight of complex health care fraud investigations. We had teams of lawyers and analysts to guide us in the regulatory world, whereas a small healthcare provider, if lucky, maybe will find the necessary guidance on the HHS website. Even then, the information becomes subject to interpretation by a provider with limited exposure to HIPAA regulatory compliance. Ask yourself how comfortable you are with this.

    Patients

    With more and more healthcare providers utilizing electronic health records, consumers (patients) need to ask those providers if they are doing everything they can to secure their health information. For consumers, HIPAA compliance matters because it equals assurance that the proper safeguards are in place to prevent unauthorized access, tampering, and theft of medical records.

    A recent study by the Ponemon Institute found criminal attacks on healthcare providers have increased dramatically, up 100% since 2010. Unlike having credit information stolen where the bank or credit card company may notify the consumer about suspicious activity in a timely manner, health information compromises take longer to recognize. With all the recent emphasis on newsworthy data breaches, this is a wake-up call for patients who must treat their online health information as they would their credit information.

    Medical identity theft is a profitable industry for criminals who can make a lot more money selling health information than credit card numbers. According to Dell Secure Works, an information security services company, criminals can get paid $20 for a personโ€™s stolen health identity information, as compared to credit card numbers that may yield $1 to $2 apiece. As a former Assistant Inspector General for Investigations at HHS, I know that Medicare card numbers could be sold for up to $50 apiece. In addition, there is much more personal data at stake with health records, which can include sensitive information such as pre-existing conditions, full-blown medical histories, and prescriptions, along with a plethora of financial, employment, and family information.

    So the next time you go to your healthcare provider and you are asked to sign a HIPAA release form, read the fine print. Know your rights and expectations of privacy. Most importantly, ask your providers what they are doing to protect your electronic health records.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    • This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.