decisionhealth Newsletters, Part B News - 2022 Issue 12 (December)
Unsafe handling: PHI disposed in the garbage leads to OCR resolution
Subscribe or sign in to view the full article.
Article Overview
This article explains a HIPAA enforcement resolution involving a dermatology practice and the disposal of PHI in regular trash, then expands into practical compliance themes for healthcare organizations. It is aimed at providers, privacy and security officers, compliance staff, and business associates who need to understand the types of safeguards, policies, training, and oversight discussed in OCR resolution agreements.
Why This Topic Matters
Improper disposal of PHI can lead to enforcement action, corrective action plans, and ongoing monitoring. The article helps readers understand why disposal practices, written policies, workforce training, and privacy governance matter for HIPAA compliance.
Article Sections
-
Behind the breach
Summarizes the reported incident and the broad categories of privacy concerns identified in the OCR investigation. It also outlines the types of corrective measures included in the resolution agreement.
-
Another ‘disheartening’ finding
Provides expert commentary on the incident and discusses the compliance shortcomings highlighted by the resolution. It also addresses how small and moderate-sized practices may struggle with privacy program implementation.
-
Is it a small entity problem?
Explores whether resource constraints contribute to privacy and security gaps in smaller covered entities. The section discusses the importance of assigning privacy responsibility and maintaining attention to HIPAA obligations.
-
Policy and procedure woes
Focuses on the need for written privacy and security policies and procedures, including structured documentation for smaller offices. It also addresses how safeguards should be tailored to the organization’s risks.
-
Beef up workforce training
Discusses workforce training expectations and the role of documented procedures in shaping training content. The section emphasizes ongoing training needs for staff and relevant personnel.
-
Lack of security means increased risk
Describes disposal-related security risks and the compliance concerns raised by the handling of physical PHI. It includes general risk assessment and audit themes raised by the experts quoted in the article.
-
Action steps for compliance
Lists broad categories of controls and operational practices organizations may consider for protecting PHI during disposal. It also references different types of disposal methods and oversight of vendors and processes.
What You Will Learn
- How OCR enforcement can arise from improper disposal of protected health information
- What types of compliance gaps are commonly discussed in HIPAA resolution agreements
- How privacy policies, training, and accountability roles are framed in the article
- What broad disposal and safeguarding themes are emphasized for physical and electronic PHI
- Why small and medium-sized healthcare organizations may need structured privacy programs
Who Should Read This
- Healthcare providers
- Medical practice administrators
- HIPAA privacy officers
- HIPAA security officers
- Compliance professionals
- Business associates
- Health information management professionals
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com