Category: OCR

  • OCR Releases Guidance for Implementing the HIPAA Security Rule

    On February 16, the U.S. Department of Health and Human Services (HHS) released of the final version of Special Publication 800-66 Rev. 2, titled โ€œImplementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guideโ€.

    Overview

    The HIPAA Security Rule is a critical framework for safeguarding electronic protected health information (ePHI) held or maintained by regulated entities. To address the evolving cybersecurity landscape, the National Institute of Standards and Technology (NIST) has revised and updated Special Publication 800-66 to provide practical guidance and resources for regulated entities.

    Key Details

    • Publication Title: Special Publication (SP) 800-66 Rev. 2
    • Date Published: February 2024
    • Supersedes: SP 800-66 Rev. 1 (10/23/2008)

    Purpose and Scope

    The revised publication, developed in collaboration with the HHS Office for Civil Rights, serves several purposes:

    1. Risk Assessment and Management: It assists regulated entities (including HIPAA-covered entities and business associates) in assessing and managing risks related to ePHI.
    2. Information Security Program: It identifies typical activities that regulated entities should consider implementing as part of their information security program.
    3. Cybersecurity Guidance: It offers practical guidance to improve cybersecurity posture and achieve compliance with the HIPAA Security Rule.

    Key Content Areas

    The resource guide covers the following topics:

    1. Administrative Safeguards: Strategies for managing ePHI security at the organizational level.
    2. Physical Safeguards: Measures to protect physical access to ePHI.
    3. Technical Safeguards: Recommendations for securing ePHI through technology controls.
    4. Risk Assessment and Risk Management: Practical approaches to identifying and mitigating risks.
    5. Mappings to NIST Cybersecurity Framework: Aligning HIPAA Security Rule standards with NIST Cybersecurity Framework subcategories.
    6. Relevant NIST Publications: Listings of NIST publications relevant to each HIPAA Security Rule standard.

    Conclusion

    For the most part, the totality of the release is a collection of links to access supplemental documentation. Organizations that have never conducted an accurate and thorough Security Risk Assessment will probably find the documentation to be overwhelming. Even for experienced assessors, most of what is provided is not new but more of a one-stop location to find these resources.

    As the healthcare industry continues to rely on electronic health records and digital systems, adherence to the HIPAA Security Rule is paramount. Regulated entities, especially small to mid-size organizations, can use this resource guide to enhance knowledge of cybersecurity practices and how to better protect sensitive health information.

    Remember, safeguarding ePHI is not just a legal requirementโ€”itโ€™s essential for maintaining trust and ensuring patient privacy in this very connected digital world.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    Helping Organizations Achieve HIPAA Complianceโ„ข

    HIPAA compliance is vital to maintain a thriving compliant organization. Colington Consulting offers scalable solutions and compliance consultations to help healthcare practices and vendors meet HIPAA regulatory compliance requirements. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review.

  • OCR Announces a Significant HIPAA Settlement of $1.3 Million

    OCR just announced a significant HIPAA settlement of $1.3 million with LA Care, one of the largest health plan providers in the country. There where substantial “potential” violations found by OCR which included failure an organization-wide risk assessment and failure to implement sufficient procedures to regularly review records of information system activity.

    LA Care agreed to a comprehensive corrective action plan for three years to ensure compliance with HIPAA requirements.

    Read the full press release: https://www.hhs.gov/about/news/2023/09/11/hhs-office-civil-rights-settles-with-la-care-health-plan-potential-hipaa-security-rule-violations.html

  • OCR Settles Another HIPAA Right of Access Case

    On December 15, The HHS Office for Civil Rights (OCR) announced another settlement of their HIPAA Right of Access Initiative. According to the information released through the OCR Listserv, “Health Specialists of Central Florida Inc. paid $20,000 to OCR and agreed to implement a corrective action plan (CAP) to resolve this investigation.” The CAP will be monitored by OCR for two years. This is the 42nd HIPAA Right of Access Initiative case to be settled by OCR.

    The release stated “In August 2019, a complaint was filed by a daughter acting as a personal representative on behalf of her deceased father, who had been a patient of Health Specialists of Central Florida Inc. The complainant alleged that Health Specialists of Central Florida Inc. had failed to provide her with timely access to the requested medical records, despite multiple requests.

    OCRโ€™s investigation determined that Health Specialists of Central Florida Inc.’s failure to provide timely access to the requested medical records was a potential violation of the HIPAA right of access standard, which requires a covered entity to take action on an access request within 30 days of receipt (or within 60 days if an extension is applicable). As a result of OCR’s investigation, the daughter finally received all of the requested records, nearly five months after her initial request.”

    See the full Resolution Agreement and CAP.

  • Use of Healthcare Related Tracking Technologies

    On December 1, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) issued a bulletin to highlight the obligations of HIPAA covered entities and business associates under the HIPAA Privacy, Security, and Breach Notification Rules when using online tracking technologies. OCR administers and enforces the HIPAA Rules, including by investigating breach reports and complaints about regulated entitiesโ€™ noncompliance with the HIPAA Rules. A regulated entityโ€™s failure to comply with the HIPAA Rules may result in a civil money penalty.

    The bulletin states, “Regulated entities are not permitted to use tracking technologies in a manner that would result in impermissible disclosures of PHI to tracking technology vendors or any other violations of the HIPAA Rules.”

    According to the bulletin, “a tracking technology is a script or code on a website or mobile app used to gather information about users as they interact with the website or mobile app. After information is collected through tracking technologies from websites or mobile apps, it is then analyzed by owners of the website or mobile app (โ€œwebsite ownerโ€ or โ€œmobile app ownerโ€), or third parties, to create insights about usersโ€™ online activities.” These insights could be used in beneficial ways to help improve care or the patient experience. However, this tracking information could also be misused to promote misinformation, identity theft, stalking, and harassment.

    If your organization is utilizing these technologies, it is important to fully read the entire bulletin.

    Since this blog article was posted in December of 2022, a federal court vacated parts of the HHS Office for Civil Rights (OCR) bulletin that classified an IP address combined with visits to unauthenticated public health pages as Protected Health Information. While this struck down the strict guidance, healthcare entities must still navigate strict federal privacy and consumer laws.

    Current Legal & Regulatory Reality

    • The Court Ruling: In American Hospital Association v. Becerra, a Texas federal judge ruled that HHS overstepped its authority under HIPAA by treating general website visitor metadata (like IP addresses linked to public unauthenticated webpages) as individually identifiable health information.
    • What Remains in Effect: Healthcare providers are still strictly prohibited from using tracking tools (like pixels or session replay) on authenticated pages (e.g., patient portals) without robust safeguards and Business Associate Agreements (BAAs).

    This post was updated on June 14, 2026, and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • OCR Issues Quarterly Cybersecurity Newsletter

    On March 17, the HHS Office for Civil Rights issued its quarterly cybersecurity newsletter. The big take away from the newsletter and the OCR mantra, is most cybersecurity attacks in the healthcare sector can “prevented or substantially mitigated” if organizations implemented all the required safeguards under the HIPAA Security Rule. According to the newsletter, “the number of breaches due to hacking or IT incidents accounted for 66% of all breaches affecting 500 or more individuals reported to OCR in 2020.”

    However, in a recent presentation made by Nicholas Heesters, OCR’s Senior Advisor for Cybersecurity, at the HIPAA Summit, hacking and IT related incidents now account for 73% of all reported breaches. Regardless of the current percentages, this is concerning and organizations must do more to address technical safeguard requirements. Also troubling is the vector of the breaches with 52% affecting network servers and 28% by email, most likely due to phishing.

    There needs to a holistic approach to overall compliance which includes the integration of technical safeguards along with program management. Small to mid-size healthcare organizations that outsource their IT requirements must use managed service providers that understand the world of HIPAA compliance. The days of trying to handle IT inhouse, as small to mid-size provider, should be over. Most HIPAA Security Officers have too much on their plates now to handle vast IT requirements. As the newsletter bluntly states, “A regulated entity that has weak cybersecurity practices makes itself an attractive soft target.”

    Although not required by the HIPAA Security Rule, organizations should consider conducting a cybersecurity assessment to fully understand the landscape of potential threats. In addition, add some type of IT vulnerability assessment to enhance the requirement of a HIPAA Security Risk Assessment. Being proactive with a systematic approach to cybersecurity safeguards and HIPAA compliance program management can go a long way to help prevent hacking and breaches to occur.

    To read the OCR newsletter, click here.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management | Helping Organizations Achieve HIPAA Complianceโ„ข

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    This article was updated on June 14, 2026, and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

  • OCR Provides Ransomware Resources

    On September 21, the HHS Office for Civil Rights pushed out through their Listserv, a list of information to ensure that “HIPAA regulated entities are aware of the resources available to assist in preventing, detecting, and mitigating breaches of unsecured protected health information caused by hacking and ransomware.” Depending on the size of the organization and internal resources, some may handle theses critical issues in house. If this support is contracted to a managed service provider, your organization may want to make this information available to them.

    Healthcare data is a prime target for bad actor. Organizations must be pro-active in fighting cybersecurity threats, whether handled in house or contracted out as a service. The HIPAA regulations require a contingency plan be in place, regardless of the size of the organization in case ePHI data is compromised.

    Here is the list of those resources:

    HHS Health Sector Cybersecurity Coordination Center Threat Briefs:

    ยท https://www.hhs.gov/about/agencies/asa/ocio/hc3/products/index.html#sector-alerts

    HHS Resources on Section 405(d) of the Cybersecurity Act of 2015:

    OCR Guidance:

    CISA Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches:

    CISA Ransomware Guide:

    FBI Ransomware Resources:

    OCR Cybersecurity Newsletters:

    REMINDER: A ransomware attack may result in a breach of unsecured protected health information that triggers reporting requirements under the HIPAA Breach Notification Rule. HIPAA covered entities and business associates should review OCRโ€™s ransomware guidance at https://www.hhs.gov/sites/default/files/RansomwareFactSheet.pdffor information regarding potential breach notification obligations following a ransomware attack.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • OCR Settles Multiple Complaints Regarding Patient Right of Access

    by Jay Hodes โ€“ President, Colington Consulting

    In March and April of this year, the HHS Office for Civil Rights (OCR) announced its enforcement discretion when it came to some provisions within the HIPAA Security and Privacy Rules due to COVID-19. These notices were limited and narrow in scope. The March notice stated OCR would โ€œnot impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency.โ€ The April notice specified OCR โ€œwill not impose penalties for violations of certain provisions of the HIPAA Privacy Rule against health care providers or their business associates for the good faith uses and disclosures of protected health information (PHI) by business associates for public health and health oversight activities during the COVID-19 nationwide public health emergency.โ€

    It is my belief some in the healthcare sector, especially in the small to mid-size provider community, interpreted these notices to mean OCR was not going to enforce any of the HIPAA rules. That misunderstanding of enforcement discretion was enough for some organizations to put their HIPAA compliance programs on the back burner. The operational mindset, then and in some cases now, was there was not a need to perform required Security Risk Assessments, review or create HIPAA policies and procedures, or adhere to many of the obligations in the HIPAA Privacy Rule.

    Let me be clear; the rules are still the rules. Healthcare organizations and business associates must still comply with the HIPAA requirements. As the notices indicate, there still must be adherence to the good faith provision. That means regardless of any enforcement discretion, organizations must still be able to demonstrate compliance with the rules and show the effort to do so.

    As proof enforcement actions continue, this week OCR announced five settlements for violations under the HIPAA Privacy Rule that pertain to individualsโ€™ rights to access their medical records. Although not earth-shattering monetary settlement amounts that ranged from $3,500 to $70,000, these cases serve as another wake-up call to providers. There is just as much culpability under the Privacy Rule as the Security Rule.

    The two types of infractions in these recent cases involve (1) refusals by healthcare providers to give patients access and copies of their medical records and (2) when requests for medical records were made by personal representatives seeking access to those records for family members were denied.

    The OCR listserv email regarding these cases states โ€œOCR’s enforcement actions are designed to send a message to the health care industry about the importance and necessity of compliance with the HIPAA Rules.โ€ Message sending indeed as OCRโ€™s right of access initiative continues. OCR Director Roger Severino stated in the email “Today’s announcement is about empowering patients and holding health care providers accountable for failing to take their HIPAA obligations seriously enough.”

    Has your organization ever conducted a Privacy Assessment to see if requirements of the HIPAA Privacy Rule are being met and understood? This type of assessment is part of our overall assessment process for both Covered Entities and Business Associates.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • OCR Provides Guidance on Telehealth During the COVID-19 Emergency

    Yesterday, the HHS Office for Civil Rights (OCR), announced it will exercise its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. This notification is effective immediately.

    Here is the complete transcript of the OCR notification:

    Notification of Enforcement Discretion for Telehealth Remote Communications during the COVID-19 Nationwide Public Health Emergency

    We are empowering medical providers to serve patients wherever they are during this national public health emergency. We are especially concerned about reaching those most at risk, including older persons and persons with disabilities. โ€“ Roger Severino, OCR Director.

    The Office for Civil Rights (OCR) at the Department of Health and Human Services (HHS) is responsible for enforcing certain regulations issued under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act, to protect the privacy and security of protected health information, namely the HIPAA Privacy, Security and Breach Notification Rules (the HIPAA Rules).

    During the COVID-19 national emergency, which also constitutes a nationwide public health emergency, covered health care providers subject to the HIPAA Rules may seek to communicate with patients, and provide telehealth services, through remote communications technologies. Some of these technologies, and the manner in which they are used by HIPAA covered health care providers, may not fully comply with the requirements of the HIPAA Rules.

    OCR will exercise its enforcement discretion and will not impose penalties for noncompliance with the regulatory requirements under the HIPAA Rules against covered health care providers in connection with the good faith provision of telehealth during the COVID-19 nationwide public health emergency. This notification is effective immediately.

    A covered health care provider that wants to use audio or video communication technology to provide telehealth to patients during the COVID-19 nationwide public health emergency can use any non-public facing remote communication product that is available to communicate with patients. OCR is exercising its enforcement discretion to not impose penalties for noncompliance with the HIPAA Rules in connection with the good faith provision of telehealth using such non-public facing audio or video communication products during the COVID-19 nationwide public health emergency. This exercise of discretion applies to telehealth provided for any reason, regardless of whether the telehealth service is related to the diagnosis and treatment of health conditions related to COVID-19.

    For example, a covered health care provider in the exercise of their professional judgement may request to examine a patient exhibiting COVID- 19 symptoms, using a video chat application connecting the providerโ€™s or patientโ€™s phone or desktop computer in order to assess a greater number of patients while limiting the risk of infection of other persons who would be exposed from an in-person consultation. Likewise, a covered health care provider may provide similar telehealth services in the exercise of their professional judgment to assess or treat any other medical condition, even if not related to COVID-19, such as a sprained ankle, dental consultation or psychological evaluation, or other conditions.

    Under this Notice, covered health care providers may use popular applications that allow for video chats, including Apple FaceTime, Facebook Messenger video chat, Google Hangouts video, or Skype, to provide telehealth without risk that OCR might seek to impose a penalty for noncompliance with the HIPAA Rules related to the good faith provision of telehealth during the COVID-19 nationwide public health emergency. Providers are encouraged to notify patients that these third-party applications potentially introduce privacy risks, and providers should enable all available encryption and privacy modes when using such applications.

    Under this Notice, however, Facebook Live, Twitch, TikTok, and similar video communication applications are public facing, and should not be used in the provision of telehealth by covered health care providers.

    Covered health care providers that seek additional privacy protections for telehealth while using video communication products should provide such services through technology vendors that are HIPAA compliant and will enter into HIPAA business associate agreements (BAAs) in connection with the provision of their video communication products. The list below includes some vendors that represent that they provide HIPAA-compliant video communication products and that they will enter into a HIPAA BAA.

    • Skype for Business
    • Updox
    • VSee
    • Zoom for Healthcare
    • Doxy.me
    • Google G Suite Hangouts Meet

    Note: OCR has not reviewed the BAAs offered by these vendors, and this list does not constitute an endorsement, certification, or recommendation of specific technology, software, applications, or products. There may be other technology vendors that offer HIPAA-compliant video communication products that will enter into a HIPAA BAA with a covered entity. Further, OCR does not endorse any of the applications that allow for video chats listed above.

    Under this Notice, however, OCR will not impose penalties against covered health care providers for the lack of a BAA with video communication vendors or any other noncompliance with the HIPAA Rules that relates to the good faith provision of telehealth services during the COVID-19 nationwide public health emergency.

    OCR has published a bulletin advising covered entities of further flexibilities available to them as well as obligations that remain in effect under HIPAA as they respond to crises or emergencies at https://www.hhs.gov/sites/default/files/february-2020-hipaa-and-novel-coronavirus.pdf – PDF.

    Guidance on BAAs, including sample BAA provisions, is available at https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html.

    Additional information about HIPAA Security Rule safeguards is available at https://www.hhs.gov/hipaa/for-professionals/security/guidance/index.html.

    HealthIT.gov has technical assistance on telehealth at https://www.healthit.gov/telehealth.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • How to Avoid a $100,000 HIPAA Settlement

    By Jay Hodes, President โ€“ Colington Consulting

    Question: How can an organization avoid a large HIPAA settlement with the HHS Office for Civil Rights (OCR)?

    Up to this point, the OCR has settled HIPAA violation cases with predominantly larger healthcare organizations. However, OCRโ€™s enforcement priority and direction has changed and all healthcare providers, regardless of size, must be on guard for the โ€œmessage sending casesโ€ on which OCR is currently focusing.

    As a case in point, on the first day of the recent National HIPAA Summit held in Arlington, Virginia, OCR announced a $100,000 settlement for a HIPAA violation case involving the practice of Steven A. Porter, M.D., a gastroenterological services provider and solo practitioner. This โ€œmessage sendingโ€ was twofold: 1) Serena Mosley-Day, Senior Advisor for HIPAA Compliance and Enforcement for OCR, provided a presentation emphasizing that small providers are not immune to OCR scrutiny and must meet the same requirements under HIPAA as do larger healthcare organizations; and 2) Announcing the settlement at a Summit where attendees included attorneys, Chief Compliance Officers, HIPAA Security and Privacy Officials, IT and cybersecurity experts was timed for maximum impact.

    According to the HIPAA Settlementโ€™s press release, Dr. Porter โ€œfiled a breach report with OCR related to a dispute with a business associate. OCRโ€™s investigation determined that Dr. Porter had never conducted a risk analysis at the time of the breach report, and despite significant technical assistance throughout the investigation, had failed to complete an accurate and thorough risk analysis after the breach and failed to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.โ€

    OCR Director Roger Severinoโ€™s comments in the press release are especially noteworthy. He states that โ€œAll health care providers, large and small, need to take their HIPAA obligations seriously,โ€ and โ€œthe failure to implement basic HIPAA requirements, such as an accurate and thorough risk analysis and risk management plan, continues to be an unacceptable and disturbing trend within the health care industry.โ€

    OCR has previously said that 95% of reported breaches are resolved with technical guidance. The key to avoiding a costlier outcome is to demonstrate to OCR that your organization has a HIPAA compliance plan in place and to cooperate with the OCR breach investigation.

    Answer: To reduce the risk of penalty or settlement or the cost of mitigating a breach, an organization MUST implement and maintain a HIPAA compliance program as follows:

    • Develop and implement policies and procedures to address all the HIPAA Security Standards and Implementation Specifications.
    • Prepare a HIPAA Risk Management Plan that includes policies and procedures, asset inventories, HIPAA-related forms and reports, a facility security plan, and a documented contingency plan.
    • Conduct he required HIPAA Security Risk Assessment.
    • Provide HIPAA Security Awareness Training to the entire workforce.
    • Assign HIPAA Security and Privacy Officer(s) to manage a HIPAA compliance program. Regardless of size, an organization must designate a workforce member(s) to handle these required responsibilities.

    Take Action Now

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

  • Important Notice Regarding Individualsโ€™ Right of Access to Health

    On January 28, the HHS Office for Civil Rights issued an important notice regarding an individualsโ€™ right of access to health records and more specifically, when a request is made to transmit medical records to a third party.

    Here is the full transcript of the notice:

    On January 25, 2013, HHS published a final rule entitled โ€œModifications to the HIPAA Privacy, Security, and Enforcement Rules Under the Health Information Technology for Economic and Clinical Health Act, and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules.โ€ (2013 Omnibus Rule). A portion of that rule was challenged in federal court, specifically provisions within 45 C.F.R. ยง164.524, that cover an individualโ€™s access to protected health information. On January 23, 2020, a federal court vacated the โ€œthird-party directiveโ€ within the individual right of access โ€œinsofar as it expands the HITECH Actโ€™s third-party directive beyond requests for a copy of an electronic health record with respect to [protected health information] of an individual . . . in an electronic format.โ€ Additionally, the fee limitation set forth at 45 C.F.R. ยง 164.524(c)(4) will apply only to an individualโ€™s request for access to their own records, and does not apply to an individualโ€™s request to transmit records to a third party.

    The right of individuals to access their own records and the fee limitations that apply when exercising this right are undisturbed and remain in effect. OCR will continue to enforce the right of access provisions in 45 C.F.R. ยง 164.524 that are not restricted by the court order. A copy of the court order in Ciox Health, LLC v. Azar, et al., No. 18-cv-0040 (D.D.C. January 23, 2020), may be found at https://ecf.dcd.uscourts.gov/cgi-bin/show_public_doc?2018cv0040-51.

    What Healthcare Providers Should Know

    The HIPAA Privacy Rule permits a covered entity to impose a reasonable, cost-based fee to provide the individual (or the individualโ€™s personal representative) with a copy of the individualโ€™s PHI, or to direct the copy to a designated third party. The fee may include only the cost of certain labor, supplies, and postage:

    1. Labor for copying the PHI requested by the individual, whether in paper or electronic form.ย  Labor for copyingย includes onlyย labor for creating and delivering the electronic or paper copy in the form and format requested or agreed upon by the individual, once the PHI that is responsive to the request has been identified, retrieved or collected, compiled and/or collated, and is ready to be copied.ย  Labor for copyingย does not includeย costs associated with reviewing the request for access; or searching for and retrieving the PHI, which includes locating and reviewing the PHI in the medical or other record, and segregating or otherwise preparing the PHI that is responsive to the request for copying.
    2. Supplies for creating the paper copy (e.g.,ย  paper, toner) or electronic media (e.g., CD or USB drive)ย ifย theย  individual requests that the electronic copy be provided on portable media.ย  However, a covered entity mayย notย require anย  individual to purchase portable media; individuals have the right to have theirย  PHI e-mailed or mailed to them upon request.
    3. Labor to prepare an explanation or summary of the PHI, if the individualย in advanceย both chooses to receive an explanation or summaryย andย agrees to the fee that may be charged.
    4. Postage, when the individual requests that the copy, or the summary or explanation, be mailed.

    Thus, costs associated with updates to or maintenance of systems and data, capital for data storage and maintenance, labor associated with ensuring compliance with HIPAA (and other applicable law) in fulfilling the access request (e.g., verification, ensuring only information about the correct individual is included, etc.) and other costs not included above,ย even if authorized by State law, areย not permitted for purposes of calculating the fees that can be charged to individuals.ย  See 45 CFR 164.524(c)(4).

    Further, while the Privacy Rule permits the limited fee described above, covered entities should provide individuals who request access to their information with copies of their PHI free of charge.ย  While covered entities should forgo fees for all individuals, not charging fees for access is particularly vital in cases where the financial situation of an individual requesting access would make it difficult or impossible for the individual to afford the fee.ย  Providing individuals with access to their health information is a necessary component of delivering and paying for health care. We will continue to monitor whether the fees that are being charged to individuals are creating barriers to this access, will take enforcement action where necessary, and will reassess as necessary the provisions in the Privacy Rule that permit these fees to be charged.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.