Category Archives: Employee data privacy and security

Apply Now for HIPAA-standard Health Plan Identifier

Health plans now may begin applying for the standard health plan identifier required by HIPAA, CMS has announced. The online application was posted March 29 on CMS’ Health Plan and Other Entity Enumeration System (HPOES). Most HIPAA-covered health plans, including employer…

Share

Implementing a Mandatory Flu Shot Policy: What Every Employer Should Know

By: Sarah Swank Credit: Ober|Kaler Published: January 16, 2013 In 2009, concerns about a swine flu pandemic convinced some employers to consider requiring employees to be vaccinated. Now that we are in the midst of another flu epidemic, some employers…

Share

EEOC’s Confidentiality Requirements Are Too Strict, Court Says

Federal guidance on the Americans with Disabilities Act states that all employee medical information must be kept confidential, but that goes above and beyond what the statute requires, the 7th U.S. Circuit Court of Appeals ruled Nov. 20. Despite what…

Share

Arizona Surgery Practice to Pay $100,000 in HIPAA Settlement

A heart surgery group practice agreed to pay $100,000 to settle federal allegations that it chronically neglected standard HIPAA requirements such as risk assessment, training and business associate contracts, the U.S. Department of Health and Human Services (HHS) announced April…

Share

Final Health Reform Exchange Rules Flesh Out Privacy and Security Requirements

Final rules that will govern the state-based insurance exchanges created by health reform include more detailed privacy and security requirements for the exchanges themselves and participating insurers. These restrictions also will apply indirectly to agents, brokers and others involved in…

Share

Breach Notice Brings $1.5M HIPAA Enforcement Action

A health insurer agreed to pay $1.5 million and adopt a detailed corrective action plan to resolve HIPAA security allegations stemming from a 2009 data breach. This is the first HIPAA enforcement action to result from the breach reports now…

Share

HHS to Step Up HIPAA Privacy Enforcement in ‘Abject Failure’ Cases

The U.S. Department of Health and Human Services (HHS) is refocusing its HIPAA privacy enforcement efforts on seeking monetary penalties in cases of “abject failure” to comply, the head of HHS’ Office for Civil Rights (OCR) indicated. “The majority of…

Share

Common-sense Steps Can Reduce Privacy Risks From Mobile Devices

The proliferation of mobile devices has blurred the line between employer and employee information, and created new threats to sensitive data that are all too well chronicled. But common-sense steps can still be taken to minimize these risks without stifling…

Share

A Busy Year for the California Legislature; And Now Employers Must Come Up to Speed

California lawmakers stayed busy throughout the year, passing a number of new wage, hour, leave and anti-discrimination laws.  Here, in no particular order, are some of the biggies that go into effect Jan. 1: Pregnancy Disability Leave All employers with…

Share

HHS Kicks Off HITECH Privacy Audits

A wave of HIPAA privacy audits far more comprehensive than anything attempted to date was officially launched Nov. 8 by the U.S. Department of Health and Human Services (HHS). While their official purpose is not enforcement, these audits are likely…

Share

Marketo