In a recent interview with an official from the federal Office of Civil Rights (OCR), which enforces HIPAA privacy and security rules, three emerging areas of concern were identified for covered entities.
Hacking and ransomware continue to be a significant problem for the health-care sectors and covered entities must develop and maintain an incident response plan to deal with these attacks.
OCR also advised that health-care providers have to be particularly careful when responding to patient complaints on online platforms, if they respond at all. These responses could result in the wrongful disclosure of protected health information of their patients, resulting in significant OCR enforcement actions.
Finally, HIPAA-covered entities must exercise caution when employing website tracking technologies particularly around business associates agreements and obtaining patient consent.
Reference
Lewis J. (2023) OCR Official Speaks About Compliance Concerns for HIPAA-Covered Entities and Business Associates JDSUPRA (accessed August 21, 2023).
Recent Posts
The Hum
In the early 1970s, humans around the globe began reporting a persistent, low frequency (30-80 Hz) noise and dubbed it “The Hum”. While there are…
Exploring the Impact of Tinnitus on Work Productivity
Over 50 million people in the United States experience tinnitus; nearly half of those individuals struggle with it, and some even perceive it as debilitating (American Tinnitus…
Federal Judge Blocks Key Portion of Student Loan Rule: Department Includes Professional Degree Status for Audiology Programs
Audiology students received an important, though temporary, victory after a federal court blocked a key provision of the U.S. Department of Education’s new student loan…



