Category: #CCHIPAA

  • OCR Announces a Significant HIPAA Settlement of $1.3 Million

    OCR just announced a significant HIPAA settlement of $1.3 million with LA Care, one of the largest health plan providers in the country. There where substantial “potential” violations found by OCR which included failure an organization-wide risk assessment and failure to implement sufficient procedures to regularly review records of information system activity.

    LA Care agreed to a comprehensive corrective action plan for three years to ensure compliance with HIPAA requirements.

    Read the full press release: https://www.hhs.gov/about/news/2023/09/11/hhs-office-civil-rights-settles-with-la-care-health-plan-potential-hipaa-security-rule-violations.html

  • Data Breach Costs at an All-Time High According to 2022 Report

    Guest article authored by Gabby Williams โ€“ Content Specialist at New Reach Marketing

    Data breaches have become a pervasive and costly problem in today’s digital world. With the increasing reliance on technology and the proliferation of data, the risk of data breaches has risen exponentially.

    According to the IBM Security Cost of a Data Breach Report 2022, 83% percent of organizations studied have experienced more than one data breach, and just 17% said this was their first data breach. Due to the increased occurrence of data breaches, 60% of organizations studied stated that they increased the price of their services or products.

    In this article, we will explore the rising cost of data breaches, examining the reasons behind the trend, the industry impacted the most, and the steps that can be taken to mitigate the risks.

    What Is a Data Breach?

    Data breaches refer to unauthorized access, theft, or exposure of sensitive data. This can include personal information such as names, addresses, phone numbers, Social Security numbers, financial information, and even intellectual property or trade secrets.

    Cybercriminals and hackers are constantly seeking vulnerabilities in systems and networks to gain unauthorized access and exploit sensitive data for various purposes, including financial gain, identity theft, corporate espionage, and more.

    Rising Cost of Data Breaches

    The cost of data breaches has also been on the rise in recent years, with numerous high-profile incidents grabbing headlines and affecting millions of individuals and businesses around the world.

    The IBM Report showed that the cost of a data breach averaged USD 4.35 million in 2022. This figure represents a 2.6% increase from the previous year, when the average breach cost was USD 4.24 million. Compared to 2020, the average cost has climbed 12.7% from USD 3.86 million.

    It is evident that data breaches are becoming more expensive for organizations, with the financial impact of such incidents rising each year.

    Data Breaches in Healthcare

    Healthcare organizations are particularly vulnerable to data breaches due to the wealth of personal and sensitive data stored within their systems. Patient records, medical history, insurance information, and payment details are what make them prime targets for cybercriminals seeking access to valuable data for various malicious purposes.

    Regulatory fines and legal liabilities for non-compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) alone are extremely costly.

    HIPAA Compliance

    All regulated entities must comply with HIPAA Privacy, Security, and Breach Notification Rules to ensure the protection and security of patient privacy and medical records. Failing to follow HIPAA safeguards greatly increases the risk of cyberattacks and results in non-compliance penalties.

    As the healthcare industry remains the primary target for data breaches, it is the responsibility of each organization, provider, and employee to maintain HIPAA compliance. Some of the most effective ways to negate data breaches and HIPAA violations include routine HIPAA compliance and cybersecurity training, penetration testing tools, and conducting required security risk assessments.

    A lack of training and assessment of daily practices can lead to unintentional HIPAA violations, a common issue among healthcare organizations. For example, failing to follow the HIPAA Breach Rule Notification Requirements, whether unintentional or not, can lead to significant consequences.

    In another example, say your healthcare practice has been using online forms to gather new patient information without ensuring they are HIPAA-compliant. While this may have been a small oversight, these forms resulted in the theft of your patientsโ€™ protected health information (PHI).

    This could have been prevented by following HIPAA compliance and cybersecurity best practices, such as proper training and conducting assessments. Utilizing one of these 5 HIPAA-compliant form builders helps to ensure HIPAA compliance requirements.

    Impact of Data Breaches on Healthcare Organizations

    Data breaches can significantly impact healthcare organizations, both financially and reputationally.

    • Legal and financial consequences: Healthcare organizations may face legal and financial consequences as a result of data breaches. This may include fines, penalties, and legal settlements, as well as potential lawsuits from affected patients.
    • Loss or theft of PHI: A data breach can result in the loss or theft of PHI, which can be very costly to remediate. The healthcare organization may be required to offer credit monitoring or identity theft protection services to affected patients, which can be expensive. The organization may also have to pay fines and penalties, both from regulatory bodies and potentially from affected patients who may take legal action.
    • Reputational damage: A data breach can harm the organization’s reputation. Patients may lose trust in the organization’s ability to protect their PHI and seek services elsewhere. This can result in a loss of revenue and difficulty in attracting new patients.
    • Operational disruption: A data breach can disrupt the normal operations of a healthcare organization. Organizations may need to dedicate significant resources to investigating and resolving the breach, including IT resources, staff time, and external consulting services. This can result in operational disruptions, increased costs, and diversion of resources away from other critical activities.

    Why Are Data Breaches Getting Costly?

    There are several reasons behind the rising cost of data breaches:

    Increased Use of Technology

    The increased use of technology has created a larger attack surface for cybercriminals to target. Take Microsoft statistics, for example. In 2020, Microsoft Office 365 usage rose by 20%. However, about 67% of IT leaders who use this software reported an increase in data breaches.

    With the proliferation of connected devices, cloud computing, and the Internet of Things (IoT), the volume of data generated and transmitted has skyrocketed. This provides more opportunities for cybercriminals to infiltrate systems and networks.

    Increased Implementation of Data Protection Regulations

    Another factor contributing to the rising cost of data breaches is the growing regulatory landscape around data protection. Many countries and regions have implemented stringent data protection laws, such as HIPAA, the European Union’s General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

    They impose significant fines and penalties for non-compliance. In the event of a data breach, organizations may face not only the direct costs of investigating and mitigating the breach but also regulatory fines and legal liabilities. These costs can add up quickly, leading to significant financial burdens.

    Increased Online Presence

    The impact of data breaches extends beyond financial costs. Businesses also face reputational damage, loss of customer trust, and potential legal liabilities. In today’s hyper-connected world, news of a data breach can spread quickly through social media and other online channels, resulting in negative publicity and damage to a company’s brand image.

    Customers may lose trust in the affected organization’s ability to protect their data, leading to customer churn and loss of business opportunities. Additionally, businesses may face legal actions from affected customers, partners, or regulators, resulting in costly legal battles and financial settlements.

    Conclusion

    It is clear from the IBM Security Cost of a Data Breach Report 2022 that data breaches are becoming more expensive for organizations, with the financial impact of such incidents rising each year. Healthcare organizations, in particular, are at risk due to the sensitive data stored within their systems.

    Maintaining HIPAA compliance is crucial to protect patients’ privacy and avoid penalties for non-compliance. Colington Consulting can assist in conducting HIPAA security risk assessments, developing risk management plans, and providing workforce security awareness and privacy training to reduce the risk of data breaches and HIPAA violations.

    By taking the necessary steps to protect sensitive data, organizations can prevent the costly consequences of data breaches and safeguard their reputation and finances. Don’t wait for a data breach to occur; contact Colington Consulting today to protect your organization’s sensitive information.

  • OCR Settles Another HIPAA Right of Access Case

    On December 15, The HHS Office for Civil Rights (OCR) announced another settlement of their HIPAA Right of Access Initiative. According to the information released through the OCR Listserv, “Health Specialists of Central Florida Inc. paid $20,000 to OCR and agreed to implement a corrective action plan (CAP) to resolve this investigation.” The CAP will be monitored by OCR for two years. This is the 42nd HIPAA Right of Access Initiative case to be settled by OCR.

    The release stated “In August 2019, a complaint was filed by a daughter acting as a personal representative on behalf of her deceased father, who had been a patient of Health Specialists of Central Florida Inc. The complainant alleged that Health Specialists of Central Florida Inc. had failed to provide her with timely access to the requested medical records, despite multiple requests.

    OCRโ€™s investigation determined that Health Specialists of Central Florida Inc.’s failure to provide timely access to the requested medical records was a potential violation of the HIPAA right of access standard, which requires a covered entity to take action on an access request within 30 days of receipt (or within 60 days if an extension is applicable). As a result of OCR’s investigation, the daughter finally received all of the requested records, nearly five months after her initial request.”

    See the full Resolution Agreement and CAP.

  • Use of Healthcare Related Tracking Technologies

    On December 1, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) issued a bulletin to highlight the obligations of HIPAA covered entities and business associates under the HIPAA Privacy, Security, and Breach Notification Rules when using online tracking technologies. OCR administers and enforces the HIPAA Rules, including by investigating breach reports and complaints about regulated entitiesโ€™ noncompliance with the HIPAA Rules. A regulated entityโ€™s failure to comply with the HIPAA Rules may result in a civil money penalty.

    The bulletin states, “Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors or any other violations of the HIPAA Rules.”

    According to the bulletin, “a tracking technology is a script or code on a website or mobile app used to gather information about users as they interact with the website or mobile app. After information is collected through tracking technologies from websites or mobile apps, it is then analyzed by owners of the website or mobile app (โ€œwebsite ownerโ€ or โ€œmobile app ownerโ€), or third parties, to create insights about usersโ€™ online activities.” These insights could be used in beneficial ways to help improve care or the patient experience. However, this tracking information could also be misused to promote misinformation, identity theft, stalking, and harassment.

    If your organization is utilizing these technologies, it is important to fully read the entire bulletin.

    Since this blog article was posted in December of 2022, a federal court vacated parts of the HHS Office for Civil Rights (OCR) bulletin that classified an IP address combined with visits to unauthenticated public health pages as Protected Health Information. While this struck down the strict guidance, healthcare entities must still navigate strict federal privacy and consumer laws.

    Current Legal & Regulatory Reality

    • The Court Ruling: In American Hospital Association v. Becerra, a Texas federal judge ruled that HHS overstepped its authority under HIPAA by treating general website visitor metadata (like IP addresses linked to public unauthenticated webpages) as individually identifiable health information.
    • What Remains in Effect: Healthcare providers are still strictly prohibited from using tracking tools (like pixels or session replay) on authenticated pages (e.g., patient portals) without robust safeguards and Business Associate Agreements (BAAs).

    This post was updated on June 14, 2026, and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Improve Your Organization’s Cybersecurity & Prevent Data Breaches

    Guest article authored by Gabby Williams โ€“ Content Specialist at Hushmail

    With the growing cybersecurity threats to businesses today, having a reliable and sturdy security solution is not a luxury but an absolute necessity. Not every organization is capable of enduring the legal, financial, and reputational consequences of a significant data breach. Ignoring the risks can lead to serious consequences.

    According to a 2022 report sponsored by IBM, the actual cost of a data breach increased 10% over the past 12 months โ€” the highest recorded increase in the last seven years. It is estimated that the average cost of a single data breach is $4.35 million globally and $9.44 million in the U.S.

    In the healthcare industry, the average cost of a data breach is $10.10 million. From a business continuity perspective, the impact can be devastating.

    In Jan 2021, an amendment to the HITECH Act was made into a law requiring the U.S. Department of Health and Human Services (HHS) to consider certain recognized security practices of covered entities and business associates when making certain determinations.

    Section 13412 makes clear the incentives for covered entities having certain recognized security practices, which are defined as the โ€œstandards, best practices, guidelines, procedures, methodologies, and processes developedโ€ under section 2(c)(15) of the National Institute of Standards and Technology (NIST) Act.

    Cybersecurity among healthcare organizations is more important than ever. Here are 10 key steps you can take to improve your organizationโ€™s cybersecurity and prevent data breaches.

    1. Locate your sensitive data

    Hackers target confidential and sensitive information. In order to prevent data breaches, your organization needs to determine where your most sensitive datasets are located. Make a consolidated inventory of this sensitive data and update, review, and back it up regularly.

    2. Keep strict tabs on privileged access

    The leading cause of data breaches is human error. In fact, 82% of data breaches involve a vulnerability caused by a human. Organizations have a responsibility to ensure the integrity of data, and most have privileged access accounts that allow designated users to access certain information.

    Even with the best intentions, granting privileged access to contractors and employees puts data at an unnecessary risk for breaches. Itโ€™s important to foster policies that keep strict tabs on who has elevated levels of access. There are numerous privileged access management tools that can facilitate this.

    3. Properly patch your infrastructure

    Your cybersecurity measures are only as strong as your organizationโ€™s underlying infrastructure. Your organizationโ€™s top priority should be patching your networks and systems. With the surging number of new discoveries of zero-day exploits every day, hackers can easily exploit unpatched software to access critical information. Regular patching can help strengthen your cybersecurity and prevent data breaches.

    4. Fortify your network perimeter

    While 39% of data breaches in the healthcare industry come from inside the organization, the majority come from external threats. Your network perimeter is your first line of defense against outsiders with malicious intent. This perimeter mainly consists of a firewall, intrusion detection system, intrusion prevention system, access controls lists, and a couple of other tools that facilitate seamless data flow while restricting intruders and unauthorized entries.

    5. Get rid of redundant data

    Safely disposing sensitive data is crucial. Many organizations, especially those in healthcare, finance, education, and the public sector, handle sensitive information as part of their daily routine. Ensuring safe and secure data purging mechanisms helps prevent stale data from being forgotten and stolen.

    There are three main ways to properly dispose of data: overwriting, degaussing, and physical destruction. However, each method has its pros and cons. A sound system for disposing of redundant data will go a long way toward saving your organization from a potential data breach.

    6. Ensure endpoint protection

    Ensuring the systematic implementation of endpoint security controls is essential for your organization. It has never been more important than it is today, with so many remote devices connected to your network.

    Remote workers often fall outside of legacy perimeter security tools. Endpoint protection can be a reliable shield against common internet threats like malware and ransomware. Laptops, mobile devices, and tablets should all be secured with endpoint protection, leaving behind no loopholes for hackers who would want to exploit them.

    7. Encrypt data at rest and in transit

    Unencrypted data is like a bank with an open vault. If data isnโ€™t encrypted, anyone can access it or even steal it since thereโ€™s no protection. No matter where the sensitive data is at any time, its encryption is essential to prevent unauthorized access. Data encryption is not only important for data at rest, but equally vital for data in transit within a corporate network.

    8. Establish a robust password policy

    The importance of a sound password policy canโ€™t be emphasized enough. Itโ€™s a necessity for all services and applications running on a network. Here are some general password policy requirements:

    • Minimum of 8-10 characters
    • 4 character types including uppercase, lowercase, number, and special character
    • Must not have 3 consecutive or repeating characters
    • 90-day password rotation policy
    • Multi-factor authentication may also be enforced using email or soft token

    9. Prepare business continuity and disaster recovery plans

    Properly responding to a data breach is a challenge. Ensure your organization has a reliable business continuity and disaster recovery plan, and review and update it regularly. Unfortunately, many organizations miss the importance of these plans and neglect to set them in place due to cost.

    New cloud-based high availability and disaster recovery plans are becoming popular because of their resilience, scalability, and flexibility. Conduct periodic audits of your system, and back up your systems regularly for data security strategy and future planning.

    10. Instill cybersecurity training across your organization

    Any cybersecurity strategy without thorough security workforce training is incomplete. Since most data breaches occur due to unintentional mistakes made by employees, partners, and contractors, holistic training that covers common threats, data usage guidelines, password policies, and awareness related to social engineering and scams should be mandatory and occur regularly.

    Conclusion

    With hackers becoming more sophisticated, itโ€™s vital for organizations to upgrade their cybersecurity arsenal to prevent data breaches. These 10 key steps are proven to help organizations develop a successful cybersecurity strategy. Each organization must find the right mixture of cybersecurity practices and policies in order to maximize their cybersecurity and prevent data breaches.

  • Helping Organizations Achieve HIPAA Compliance

    Jay Hodes, President of Colington Consulting, was recently interviewed by Best Startup. Topics covered the inspiration behind the business, facing challenges, buying into the vision of compliance, and what the magic sauce is in running the company. Click here to read the full article.

  • OCR Issues Quarterly Cybersecurity Newsletter

    On March 17, the HHS Office for Civil Rights issued its quarterly cybersecurity newsletter. The big take away from the newsletter and the OCR mantra, is most cybersecurity attacks in the healthcare sector can “prevented or substantially mitigated” if organizations implemented all the required safeguards under the HIPAA Security Rule. According to the newsletter, “the number of breaches due to hacking or IT incidents accounted for 66% of all breaches affecting 500 or more individuals reported to OCR in 2020.”

    However, in a recent presentation made by Nicholas Heesters, OCR’s Senior Advisor for Cybersecurity, at the HIPAA Summit, hacking and IT related incidents now account for 73% of all reported breaches. Regardless of the current percentages, this is concerning and organizations must do more to address technical safeguard requirements. Also troubling is the vector of the breaches with 52% affecting network servers and 28% by email, most likely due to phishing.

    There needs to a holistic approach to overall compliance which includes the integration of technical safeguards along with program management. Small to mid-size healthcare organizations that outsource their IT requirements must use managed service providers that understand the world of HIPAA compliance. The days of trying to handle IT inhouse, as small to mid-size provider, should be over. Most HIPAA Security Officers have too much on their plates now to handle vast IT requirements. As the newsletter bluntly states, “A regulated entity that has weak cybersecurity practices makes itself an attractive soft target.”

    Although not required by the HIPAA Security Rule, organizations should consider conducting a cybersecurity assessment to fully understand the landscape of potential threats. In addition, add some type of IT vulnerability assessment to enhance the requirement of a HIPAA Security Risk Assessment. Being proactive with a systematic approach to cybersecurity safeguards and HIPAA compliance program management can go a long way to help prevent hacking and breaches to occur.

    To read the OCR newsletter, click here.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management | Helping Organizations Achieve HIPAA Complianceโ„ข

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    This article was updated on June 14, 2026, and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

  • Telehealth: Is Your Practice Adhering to the HIPAA Rules?

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    While the concept of telehealth has been around for years, it recently became the new normal for many healthcare providers. The coronavirus pandemic has created a situation where more medical offices and clinics are finding themselves conducting routine patient visits and follow-up appointments via a laptop or mobile device to limit office visits and the interaction between staff and patients.

    Unfortunately, implementing telehealth solutions that effectively provide distance care in the middle of a pandemic came with its own challenges. When the virus was spreading quickly, providers scrambled to find solutions that could help them better deliver medical services and efficiently cater to the fast-growing number of patients; many went for the first option they could find. While these solutions may be suitable for short-term use, some telemedicine platforms used today may not work in the long term. Why? They are not HIPAA compliant. Chances are if your organization is using a free version of a telecommunications product, it is not meeting HIPAA requirements.

    HIPAA Guidelines on Telehealth

    The U.S. Department of Health and Human Services (HHS) defines telehealth as โ€œthe use of electronic information and telecommunications technologies to support and promote long-distance clinical health care, patient and professional health-related education, and public health and health administrationโ€. Because of the security risks involved in delivering these services online, the HIPAA Security Rule requires that Covered Entities (CEs) and their Business Associates (BAs) implement administrative, physical, and technical procedures to protect health information communicated electronically. Ideally, for telemedicine to be HIPAA compliant:

    • Only authorized users should have access to electronic Protected Health Information (ePHI).
    • A communications-monitoring system must be implemented to oversee communications containing ePHI and prevent accidental or malicious breaches.
    • The channels used to transmit ePHI must be secure enough to protect the integrity of patientsโ€™ data and communications. That said, non-secure, public facing platforms like Facebook Live, TikTok, or other video communication applications cannot be used. Because copies of communication can remain on the servers of these third parties, a CE is required to have a Business Associate Agreement (BAA) with, for example, Skype, Zoom, or Google to be compliant with HIPAA. However, because some service providers, whoโ€™s platforms were not designed for telehealth, will likely not enter into a BAA with a Covered Entity for telehealth services. The CE may be responsible for any penalties should there be an unauthorized disclosure of ePHI due to using these types of platforms that do not comply with HIPAA security guidelines.

    The good news? The HHS Office for Civil Rights has exercised its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. The bad? That wonโ€™t last, as there are obvious risks to continuing to use non-secure telemedicine solutions that may put ePHI in danger. As we enter the next phase of the pandemic, itโ€™s becoming clear that telemedicine will be an important part of patient care, which means healthcare organizations need to adopt platforms that can serve them for the long term. If your facility is operating a telehealth solution that is not HIPAA compliant, now itโ€™s time to set yourself up for success by investing in a platform or technology you will not have to abandon when the public health emergency ends. Remember, once your organization engages a telehealth delivery platform, an executed Business Associate Agreement must be in place with that vendor.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Understanding the Role of a HIPAA Business Associate

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    The continued complexity of modern healthcare systems and growth of patientsโ€™ data mean that medical records can be stored in more places than just the doctorโ€™s office. The information may be kept and maintained offsite in a storage facility or on a cloud-based server operated by a third party. Any entity or individual that uses, processes, or discloses this data on behalf of the healthcare provider is called a HIPAA Business Associate. If an organization is contracted by a HIPAA Covered Entity (CE) to perform activities that involve accessing Protected Health Information (PHI) or electronic PHI (ePHI) in any way, they are considered a Business Associate (BA). Because Business Associates use protected patientsโ€™ data to support the operations of covered entities, the U.S. Department of Health and Human Services (HHS) requires adherence to the Code of Federal Regulations (CFR) to comply with HIPAA requirements.

    Business Associate Agreement (BAA)

    The HIPAA Privacy Rule states that, โ€œA covered entity must obtain satisfactory assurances from its Business Associate that the Business Associate will appropriately safeguard the protected health information it receives or creates on behalf of the covered entity. The satisfactory assurances must be in writing, whether in the form of a contract or other agreement between the covered entity and the business associate.โ€

    This means that before a covered entity can work with a Business Associate, the BA must sign a BAA stating that they will safeguard and treat PHI the way CFRs and the covered entity require them to. It does not matter whose version of the BAA is signed, whether provided by the CE or the BA, as long it is executed. According to the Health Information Technology for Economic and Clinical Health (HITECH) Act, a BAA must include specific information to meet HIPAA compliance such as a description of the required and allowed uses of PHI, declarations that the Business Associate will disclose information only as required by law, and proper safeguards to protect patientsโ€™ data from breach including steps to take should there be such security violations.

    Why are Some Business Associates Not Complying with HIPAA Regulations?

    One of the major reasons is that most of them have no idea that the law considers them Business Associates. Covered entities have made great strides in following HIPAA compliance requirements, but many Business Associates are still not aware of the need to comply or are just reluctant to do so. Under HITECH, the Office of Civil Rights (OCR) holds Business Associates liable for breaches, and it is imperative that these entities take the necessary steps to ensure HIPAA compliance. In this press release where a Business Associate pays $2.3 million to settle a breach, the OCR Director at the time, Roger Severino terms โ€œThe failure to implement the security protections required by the HIPAA Rules in an industry known as a target for hackers and cyber thievesโ€ inexcusable. Sure, following all the steps required to obtain HIPAA compliance may seem overwhelming, but it offers better protection for patientsโ€™ data, which helps Business Associates avoid these types of federal penalties.

    Helping Organizations Achieve HIPAA Complianceโ„ข

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • OCR Provides Ransomware Resources

    On September 21, the HHS Office for Civil Rights pushed out through their Listserv, a list of information to ensure that “HIPAA regulated entities are aware of the resources available to assist in preventing, detecting, and mitigating breaches of unsecured protected health information caused by hacking and ransomware.” Depending on the size of the organization and internal resources, some may handle theses critical issues in house. If this support is contracted to a managed service provider, your organization may want to make this information available to them.

    Healthcare data is a prime target for bad actor. Organizations must be pro-active in fighting cybersecurity threats, whether handled in house or contracted out as a service. The HIPAA regulations require a contingency plan be in place, regardless of the size of the organization in case ePHI data is compromised.

    Here is the list of those resources:

    HHS Health Sector Cybersecurity Coordination Center Threat Briefs:

    ยท https://www.hhs.gov/about/agencies/asa/ocio/hc3/products/index.html#sector-alerts

    HHS Resources on Section 405(d) of the Cybersecurity Act of 2015:

    OCR Guidance:

    CISA Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches:

    CISA Ransomware Guide:

    FBI Ransomware Resources:

    OCR Cybersecurity Newsletters:

    REMINDER: A ransomware attack may result in a breach of unsecured protected health information that triggers reporting requirements under the HIPAA Breach Notification Rule. HIPAA covered entities and business associates should review OCRโ€™s ransomware guidance at https://www.hhs.gov/sites/default/files/RansomwareFactSheet.pdffor information regarding potential breach notification obligations following a ransomware attack.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.