tci Medicare Compliance & Reimbursement - 2015 Issue 17
Patient Privacy: Is New Technology Leaving Your Organization Open to HIPAA Violations?
Subscribe or sign in to view the full article.
Article Overview
This article explains a HIPAA settlement tied to the use of internet-based document sharing tools and a separate portable-device breach incident. It is aimed at healthcare compliance, privacy, and security teams that need to understand common operational risk areas, workforce safeguards, incident response expectations, and the kinds of corrective actions highlighted by OCR and outside counsel. The piece provides a practical overview of the compliance themes raised by the case without serving as a substitute for the underlying resolution agreement or legal analysis.
Why This Topic Matters
It helps covered entities and compliance leaders recognize how new technology, risk assessment practices, employee training, and device security can create HIPAA exposure if not managed carefully.
Article Sections
-
Background
Introduces the enforcement matter and the organizations involved. Summarizes the general compliance context surrounding the settlement.
-
Beware of Using Internet Applications
Discusses concerns raised by internet-based document sharing tools and the broader security issues associated with storing protected information in online applications.
-
Perform a Risk Analysis Before Using New Tech
Covers the role of security risk analysis and the importance of evaluating safeguards before adopting new technologies. Also notes related compliance review themes for covered entities and business associates.
-
Train Your Staff & Know What They’re Doing
Describes workforce oversight, policy awareness, and self-assessment topics tied to organizational procedures and incident reporting. Addresses employee training and internal compliance checks.
-
Encrypt all Portable Devices Containing any PHI
Focuses on the separate portable-device breach incident and the security issues raised by laptops, removable media, and other mobile equipment. Highlights the article’s emphasis on device protection and response practices.
What You Will Learn
- How HIPAA enforcement can arise from the use of online document-sharing tools
- Why security risk analysis is a recurring compliance theme when adopting new technology
- What kinds of workforce policy and training areas are emphasized in corrective actions
- Why portable-device safeguards and encryption are central to privacy and security programs
- How a settlement can involve both policy deficiencies and a separate breach event
Who Should Read This
- HIPAA compliance officers
- Privacy and security officers
- Healthcare legal and risk management teams
- Covered entities
- Healthcare administrators
Subscribe or sign in to view the full article.
Thank you for choosing Find-A-Code, please Sign In to remove ads.


Quick, Current, Complete - www.findacode.com