In a recent interview with an official from the federal Office of Civil Rights (OCR), which enforces HIPAA privacy and security rules, three emerging areas of concern were identified for covered entities.
Hacking and ransomware continue to be a significant problem for the health-care sectors and covered entities must develop and maintain an incident response plan to deal with these attacks.
OCR also advised that health-care providers have to be particularly careful when responding to patient complaints on online platforms, if they respond at all. These responses could result in the wrongful disclosure of protected health information of their patients, resulting in significant OCR enforcement actions.
Finally, HIPAA-covered entities must exercise caution when employing website tracking technologies particularly around business associates agreements and obtaining patient consent.
Reference
Lewis J. (2023) OCR Official Speaks About Compliance Concerns for HIPAA-Covered Entities and Business Associates JDSUPRA (accessed August 21, 2023).
Recent Posts
Update on Hearing Device Services Codes
As released publicly in the March 10, 2026, AMA’s Errata & Technical Corrections CPT 2026, the parentheticals related to code 92628 (Evaluation for hearing candidacy)…
Intratympanic Steroid Therapy as a Salvage Treatment for Sudden Sensorineural Hearing Loss
Fernandez et al. (2026) completed a retrospective analysis of 86 patients seen between 2019 and 2024 with sudden sensorineural hearing loss (SSNHL). This analysis compared…
Clinical Superiority of Belly-Tendon Montage Over Others for Recording Air-Conducted Ocular Vestibular Evoked Myogenic Potential
In a recent study published by Raveendran and Singh (2026), a number of ocular vestibular evoked myogenic potential (oVEMP) electrode montages were compared. This study…


