tci Medicare Compliance & Reimbursement - 2023 Issue Q3
HIPAA Round-Up: Feds Ramp Up Enforcement Post-PHE
Subscribe or sign in to view the full article.
Article Overview
This article summarizes a mid-year wave of HHS Office for Civil Rights enforcement actions following the end of the COVID-19 public health emergency. It is aimed at healthcare providers, covered entities, business associates, and compliance professionals who want to understand the broad categories of HIPAA issues drawing enforcement attention, including patient access, impermissible disclosures, cybersecurity-related safeguards, workforce conduct, and social media-related privacy complaints.
Why This Topic Matters
The roundup helps organizations gauge current enforcement priorities and identify recurring compliance risk areas that may affect privacy and security programs. It is useful for readers reviewing policies, training, vendor oversight, and incident-response practices in the post-PHE environment.
Article Sections
-
Right of Access
This section covers an OCR settlement involving delayed patient record access and a corrective action plan. It places the matter in the context of the agency’s broader access-focused enforcement activity.
-
Unlawful disclosure
This section summarizes a settlement involving an unsecured server, business associate oversight, and privacy and security rule concerns. It emphasizes the compliance implications for vendors and their contracting relationships.
-
Social media
This section discusses a complaint arising from a provider’s online response to a negative review and the resulting enforcement action. It highlights the growing visibility of internet- and social-media-related privacy complaints.
-
Workforce
This section addresses insider access to patient information by hospital security personnel and the resulting settlement. It focuses on workforce conduct and related compliance monitoring.
-
Impermissible disclosure
This section reviews another breach-related settlement involving a vendor server and related security-rule concerns. It reinforces the importance of organizational risk analysis and data protection practices.
What You Will Learn
- How recent OCR settlements reflect post-PHE HIPAA enforcement priorities
- Which broad compliance areas are drawing attention in current settlement activity
- How access, privacy, security, and workforce issues appear in recent HIPAA cases
- Why vendor oversight and online conduct remain important compliance topics
Who Should Read This
- Healthcare compliance professionals
- Covered entities
- Business associates
- Healthcare providers
- Privacy and security officers
- Revenue cycle and vendor management teams
Subscribe or sign in to view the full article.
Thank you for choosing Find-A-Code, please Sign In to remove ads.


Quick, Current, Complete - www.findacode.com