The past several years have proven difficult for healthcare entities due to increasing cybersecurity threats, breaches and regulatory enforcement. Following these trends, on April 6, 2022, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) released a Request for Information (RFI) soliciting public comment on how regulated entities are voluntarily implementing security practices under the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act) and also seeking public input on sharing funds collected through enforcement with individuals who are harmed by Health Insurance Portability and Accountability Act of 1996 (HIPAA) rule violations.
On January 5, 2020, HR 7898, became law amending the Health Information Technology for Economic and Clinical Health Act (HITECH Act), 42 U.S.C. 17931, to require that “recognized cybersecurity practices” be considered by the Secretary of Health and Human Services (HHS) in determining any Health Insurance Portability and Accountability Act (HIPAA) fines, audit results or mitigation remedies. The new law provides a strong incentive to covered entities and business associates to adopt “recognized cybersecurity practices” and risk reduction frameworks when complying ...
Blog Editors
Recent Updates
- Medicaid Behavioral Health Investigations and Payment Suspensions in D.C. Are Increasing – How Providers Can Limit Risk
- ‘Emilie’ Is Not a Psychiatrist: Pennsylvania Board of Medicine Alleges Unlawful Practice of Medicine by an AI Chatbot
- DOJ’s West Coast Strike Force to Target Health Care Fraud in Arizona, Nevada, and Northern California
- DOJ FOCUS Initiative Prioritizes “High Quality” Data Miner Actions by FCA Whistleblowers
- FDA Proposal Would Leave Semaglutide, Tirzepatide, and Liraglutide Off 503B Bulks List