Blog: ePHI

 

Our Blogs

Lessons from OCR HIPAA Settlements – Mobile Device Security Standards

Posted on May 3, 2017 by
Blog

In the first known case involving a wireless provider, a cardiology service provider agreed to pay a $2.5 million settlement based on the impermissible disclosure of unsecured electronic protected health information (ePHI).  The company provides remote mobile monitoring of and rapid response to patients at risk for cardiac arrhythmias.  The company disclosed to the Office […]

OCR Settlement Lessons – Failing to Perform an Electronic Access Risk Analysis Before an Unauthorized Access Occurs

Posted on May 3, 2017 by
Blog

Failure to conduct a risk assessment before a hacking incident occurred resulted in a $400,000 settlement between the Office of Civil Rights (OCR) and a Federally Qualified Health Clinic (FQHC).  The FQHC filed a breach report upon learning its employee emails had been hacked and the hacker had access to electronic health information of over […]