Patient Privacy: Is New Technology Leaving Your Organization Open to HIPAA Violations?

Subscribe or sign in to view the full article.

Note:  The following article synopsis was NOT provided by AAPC. It was created by Find-A-Code/innoviHealth.

Article Overview

This article explains a HIPAA settlement tied to the use of internet-based document sharing tools and a separate portable-device breach incident. It is aimed at healthcare compliance, privacy, and security teams that need to understand common operational risk areas, workforce safeguards, incident response expectations, and the kinds of corrective actions highlighted by OCR and outside counsel. The piece provides a practical overview of the compliance themes raised by the case without serving as a substitute for the underlying resolution agreement or legal analysis.

Why This Topic Matters

It helps covered entities and compliance leaders recognize how new technology, risk assessment practices, employee training, and device security can create HIPAA exposure if not managed carefully.

Article Sections

  1. Background

    Introduces the enforcement matter and the organizations involved. Summarizes the general compliance context surrounding the settlement.

  2. Beware of Using Internet Applications

    Discusses concerns raised by internet-based document sharing tools and the broader security issues associated with storing protected information in online applications.

  3. Perform a Risk Analysis Before Using New Tech

    Covers the role of security risk analysis and the importance of evaluating safeguards before adopting new technologies. Also notes related compliance review themes for covered entities and business associates.

  4. Train Your Staff & Know What They’re Doing

    Describes workforce oversight, policy awareness, and self-assessment topics tied to organizational procedures and incident reporting. Addresses employee training and internal compliance checks.

  5. Encrypt all Portable Devices Containing any PHI

    Focuses on the separate portable-device breach incident and the security issues raised by laptops, removable media, and other mobile equipment. Highlights the article’s emphasis on device protection and response practices.

What You Will Learn

  • How HIPAA enforcement can arise from the use of online document-sharing tools
  • Why security risk analysis is a recurring compliance theme when adopting new technology
  • What kinds of workforce policy and training areas are emphasized in corrective actions
  • Why portable-device safeguards and encryption are central to privacy and security programs
  • How a settlement can involve both policy deficiencies and a separate breach event

Who Should Read This

  • HIPAA compliance officers
  • Privacy and security officers
  • Healthcare legal and risk management teams
  • Covered entities
  • Healthcare administrators

Subscribe or sign in to view the full article.

Keep pace with evolving Medicare regulations — and onboard your team — with timely analysis of critical updates interpreted in an easy-to-follow, easy-to-apply format. Your subscription to TCI's Medicare Compliance & Reimbursement Alert will equip you to navigate code and guideline changes, CCI edits, and revisions to modifiers, payer policies, the fee schedule, OIG target areas, and more.

  • Current newsletters added each month
  • Fully searchable archives - over 4200 articles
  • ALL years/issues back to 2003 organized by year and issue
  • Codes mentioned in articles are linked to Code Information pages
  • Code Information pages link back to related articles

This feature is currently unavailable for online purchase. For more information, please call 801-770-4203 or Contact Us.

Thank you for choosing Find-A-Code, please Sign In to remove ads.

Aimee- AI -powered coding assistant - Try it now for Free Would you like Aimee - AI
to help you with this?