HIPAA Round-Up: Feds Ramp Up Enforcement Post-PHE

Subscribe or sign in to view the full article.

Note:  The following article synopsis was NOT provided by AAPC. It was created by Find-A-Code/innoviHealth.

Article Overview

This article summarizes a mid-year wave of HHS Office for Civil Rights enforcement actions following the end of the COVID-19 public health emergency. It is aimed at healthcare providers, covered entities, business associates, and compliance professionals who want to understand the broad categories of HIPAA issues drawing enforcement attention, including patient access, impermissible disclosures, cybersecurity-related safeguards, workforce conduct, and social media-related privacy complaints.

Why This Topic Matters

The roundup helps organizations gauge current enforcement priorities and identify recurring compliance risk areas that may affect privacy and security programs. It is useful for readers reviewing policies, training, vendor oversight, and incident-response practices in the post-PHE environment.

Article Sections

  1. Right of Access

    This section covers an OCR settlement involving delayed patient record access and a corrective action plan. It places the matter in the context of the agency’s broader access-focused enforcement activity.

  2. Unlawful disclosure

    This section summarizes a settlement involving an unsecured server, business associate oversight, and privacy and security rule concerns. It emphasizes the compliance implications for vendors and their contracting relationships.

  3. Social media

    This section discusses a complaint arising from a provider’s online response to a negative review and the resulting enforcement action. It highlights the growing visibility of internet- and social-media-related privacy complaints.

  4. Workforce

    This section addresses insider access to patient information by hospital security personnel and the resulting settlement. It focuses on workforce conduct and related compliance monitoring.

  5. Impermissible disclosure

    This section reviews another breach-related settlement involving a vendor server and related security-rule concerns. It reinforces the importance of organizational risk analysis and data protection practices.

What You Will Learn

  • How recent OCR settlements reflect post-PHE HIPAA enforcement priorities
  • Which broad compliance areas are drawing attention in current settlement activity
  • How access, privacy, security, and workforce issues appear in recent HIPAA cases
  • Why vendor oversight and online conduct remain important compliance topics

Who Should Read This

  • Healthcare compliance professionals
  • Covered entities
  • Business associates
  • Healthcare providers
  • Privacy and security officers
  • Revenue cycle and vendor management teams

Subscribe or sign in to view the full article.

Keep pace with evolving Medicare regulations — and onboard your team — with timely analysis of critical updates interpreted in an easy-to-follow, easy-to-apply format. Your subscription to TCI's Medicare Compliance & Reimbursement Alert will equip you to navigate code and guideline changes, CCI edits, and revisions to modifiers, payer policies, the fee schedule, OIG target areas, and more.

  • Current newsletters added each month
  • Fully searchable archives - over 4200 articles
  • ALL years/issues back to 2003 organized by year and issue
  • Codes mentioned in articles are linked to Code Information pages
  • Code Information pages link back to related articles

This feature is currently unavailable for online purchase. For more information, please call 801-770-4203 or Contact Us.

Thank you for choosing Find-A-Code, please Sign In to remove ads.

Aimee- AI -powered coding assistant - Try it now for Free Would you like Aimee - AI
to help you with this?