BC Advantage - 2020 Issue 1
2019 HIPAA Settlements and Take-Aways
Subscribe or sign in to view the full article.
Article Overview
This article reviews selected 2019 enforcement settlements involving HIPAA privacy and security matters, with emphasis on patient access concerns and information security safeguards. It is aimed at healthcare providers, covered entities, business associates, compliance teams, and others responsible for protecting protected health information. The article also discusses broader privacy and security obligations, including organizational safeguards, risk analysis, encryption, training, policies and procedures, and business associate oversight.
Why This Topic Matters
The article helps readers understand current HIPAA enforcement priorities and the types of compliance lapses that can lead to regulatory settlements. It is useful for organizations assessing privacy, security, and breach-risk practices in healthcare operations.
Article Sections
-
HIPAA and HITECH background
Introduces the federal privacy and security framework governing protected health information and the responsibilities of covered entities and related parties.
-
Settlement Analysis
Summarizes selected settlement actions and the broad compliance issues they illustrate.
-
Bayfront Hospital (September 2019)
Describes an enforcement action involving patient access to medical records and related timing and fee issues.
-
The University of Rochester Medical Center (URMC) (November 2019)
Reviews a settlement tied to information security safeguards, risk analysis, and handling of electronic protected health information.
-
Conclusion
Provides a general summary of ongoing privacy and security obligations and the types of organizational measures discussed in the article.
What You Will Learn
- The general HIPAA and HITECH compliance issues highlighted by 2019 settlement actions
- How enforcement actions can relate to patient access and information security
- The types of organizational safeguards emphasized in healthcare privacy compliance
- Why risk analysis, encryption, training, and business associate oversight matter for compliance programs
Who Should Read This
- Healthcare providers
- Covered entities
- Business associates
- Healthcare compliance professionals
- Privacy and security officers
- Healthcare attorneys
- Risk management teams
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com