Subscribe (Free) to
Daily or Weekly Newsletters
Post a Job

Featured Jobs

Retirement Plan Relationship Manager

ERISA Services, Inc.
(Remote)

ERISA Services, Inc. logo

Regional Sales Director (West)

July Business Services
(CA)

July Business Services logo

Retirement Plan Administrator

Retirement Solutions Specialists
(Remote / Jacksonville FL / Hybrid)

Retirement Solutions Specialists logo

Client Service Manager

July Business Services
(Remote)

July Business Services logo

Defined Contribution Account Manager

Nova 401(k) Associates
(Remote)

Nova 401(k) Associates logo

Retirement Plan Consultant

July Business Services
(Remote)

July Business Services logo

Defined Contributions Compliance Consultant

Loren D. Stark Company (LDSCO)
(Remote)

Loren D. Stark Company (LDSCO) logo

Senior Specialist 401k Recordkeeping

T Bank N.A.
(Dallas TX)

T Bank N.A. logo

Compliance Officer

New York City District Council of Carpenters Benefit Funds
(New York NY)

New York City District Council of Carpenters Benefit Funds logo

Retirement Account Manager

Fringe Benefit Group
(Remote / Austin TX)

Fringe Benefit Group logo

TPA Retirement Plan Consultant

EPIC RPS (TPA/DPS)
(Remote)

EPIC RPS (TPA/DPS) logo

View More Employee Benefits Jobs

Free Newsletters

“BenefitsLink continues to be the most valuable resource we have at the firm.”

-- An attorney subscriber

Mobile app icon
LinkedIn icon     Twitter icon     Facebook icon

Search 97,197 News Items Curated by BenefitsLink®

News

All News > HIPAA

Get this news and more in our free daily email newsletters.
Health and Welfare Benefits Monthly Update, April 2024 (PDF)
Alston & Bird Link to more items from this source
[Guidance Overview]
Apr. 11, 2024

29 presentation slides. Topics: [1] Washington update; [2] STLDI and fixed indemnity regulations; [3] Wellness incentives/surcharges: benefits areas of concern; [4] Updates to HIPAA online tracking; and [5] Compliance corner.

Tags: HIPAA  •  Health Plan Administration  •  Health Plan Design

Cybersecurity Best Practices for Employers in the Wake of the Change Healthcare Attack
Burnham Benefits Link to more items from this source
Apr. 11, 2024

"As a group health plan sponsor, an employer's responsive obligations arising in the context of certain cybercrime events depends largely upon the underlying funding status of the employer's core employee benefit plans ... Additional privacy and security related obligations for the employer may be detailed in various state-level statutory mandates or even within certain international laws or other global-scope regulations.... Several notifications may be required as a consequence of a data breach.... Communication with employees is important[.]"

Tags: Cybersecurity  •  HIPAA

HHS Aligns Part 2 Rules with the HIPAA Privacy Rules: Effects on Self Insured Plan Sponsors
Kilpatrick Townsend Link to more items from this source
[Guidance Overview]
Apr. 4, 2024

"Part 2 imposes requirements for substance use disorder (SUD) treatment records ... The Part 2 regulations will come into play typically with employee assistance programs, as well as mental health and substance abuse disorder vendors for a medical plan.... Even though a self-insured health plan sponsor contracts with an EAP or SUD vendor and requires the EAP and SUD vendor to comply with Part 2 and the HIPAA privacy rules (as well as signing a BAA), under the HIPAA privacy rules, self-insured health plans remain responsible for HIPAA privacy compliance."

Tags: HIPAA

HHS Submits Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance
Benesch Link to more items from this source
Apr. 3, 2024

"Notwithstanding the challenges faced by OCR in enforcing HIPAA compliance amidst rising cybersecurity threats and increasing regulatory responsibilities, the Report provides valuable insight into the OCR investigation process.... [The] steeper penalties resulting from failure to maintain recognized security practices should serve as a cautionary tale to covered entities and business associates. Based on the findings highlighted in the Report, here are ... recommendations for entities regulated by HIPAA to improve compliance and enhance data protection efforts."

Tags: HIPAA

Change Healthcare Provides Update on 'Impacted Data' Analysis and Notification Plan
BakerHostetler Link to more items from this source
Mar. 29, 2024

"[As of March 27,] CHC is still determining the contents of the 'data that was taken by the threat actor.' ... A third-party vendor has been engaged to assist with data analysis.... It could be some time before CHC announces the scope of data involved.... CHC data has not been found on the dark web.... CHC will be offering to provide notifications for customers 'where permitted.' ... The latest statement from CHC itself does not start any covered entity's '60-day timeline.' "

Tags: Cybersecurity  •  HIPAA

Is Your Data Secure? HHS Opens Investigation into Change Healthcare Cyberattack
Haynes and Boone, LLP Link to more items from this source
Mar. 27, 2024

"Although the OCR stated it is not prioritizing investigations of health care providers, health plans or business associates that were impacted by this cyberattack, the OCR did remind entities that have partnered with Change Healthcare and UHG of their regulatory obligations and responsibilities, including ensuring that up-to-date business associate agreements are in effect, and that timely breach notifications to HHS and the affected individuals are provided."

Tags: Cybersecurity  •  HIPAA

Understanding OCR's Updated Guidance on Health Data Tracking and HIPAA Privacy Rule
Constangy, Brooks, Smith & Prophete LLP Link to more items from this source
[Guidance Overview]
Mar. 25, 2024

"OCR's updated guidance reflects its view that tracking technologies used by regulated entities on user-authenticated webpages and mobile applications generally do collect protected health information, referred to as PHI. Where the new guidance differs, however, is on the information collected via tracking technologies on unauthenticated webpages."

Tags: HIPAA

Revised OCR Guidance Raises Questions About Use of Online Tracking Technologies by HIPAA-Covered Entities and Business Associates
Health Law Advisor, Epstein Becker Green Link to more items from this source
[Guidance Overview]
Mar. 22, 2024

"OCR has now ... opined that the information collected may not be PHI depending on the individual user's reason for visiting a Regulated Entity's unauthenticated pages on a website or mobile app.... The updated guidance does not address how an individual's reason for visiting its website ... can be discerned at the point of collection through these automated electronic processes. Nor does the guidance expressly state that consideration of the reason for the individual's visit may be considered by OCR in its enforcement efforts."

Tags: HIPAA

HHS Reminds HIPAA Covered Entities of Obligations in Wake of Change Healthcare Cyberattack
Thomson Reuters / EBIA Link to more items from this source
Mar. 21, 2024

"OCR urges covered entities to review cybersecurity measures 'with urgency' ... Covered entities should address in their risk analysis and risk management plans their due diligence process in selecting business associates, including ensuring that contracts include appropriate provisions to safeguard ePHI. If a covered entity knows of a pattern of activity or practice of a business associate that constitutes a material breach of the contract, it may be obligated to take certain steps to cure the breach and, if those steps are unsuccessful, to terminate the contract."

Tags: HIPAA

HHS Updates Pixels and Trackers Guidance for HIPAA Regulated Entities
Foley & Lardner LLP Link to more items from this source
[Guidance Overview]
Mar. 20, 2024

"[B]ased on the examples given by HHS in the Bulletin, if the tracking technologies are accessing information regarding an individual seeking health care services (e.g., looking at oncology services to seek treatment options, scheduling an appointment, or using a symptom tracker tool even without entering credentials), that tracking technology has access to PHI. This would mean the HIPAA regulated entity needs a business associate agreement with the third party or a HIPAA compliant authorization for the sharing."

Tags: HIPAA

Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates
U.S. Department of Health and Human Services [HHS] Link to more items from this source
[Official Guidance]
Mar. 19, 2024

"[B]ecause of the proliferation of tracking technologies collecting sensitive information, OCR is providing this reminder that it is critical for regulated entities to ensure that they disclose PHI only as expressly permitted or required by the HIPAA Privacy Rule. To this end, this Bulletin provides guidance for regulated entities to consider when contemplating the use of tracking technologies, including an overview of how the HIPAA Rules apply to regulated entities' use of tracking technologies."

Tags: Cybersecurity  •  HIPAA

OCR Guidance Reminds Health Plans to Ensure Online Tracking HIPAA Compliance
Solutions Law Press Link to more items from this source
[Guidance Overview]
Mar. 19, 2024

"The Guidance reminds covered entities that the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules (HIPAA Rules) apply to their use of online tracking technologies like Google Analytics or Meta Pixel, collect and analyze information about how users are interacting with a regulated entity's website or mobile application."

Tags: HIPAA

Manage Health Plan HIPAA, ERISA and Other Exposures from Change Healthcare Ransomware Attack
Solutions Law Press Link to more items from this source
Mar. 18, 2024

"While UHG works to remediate and restore the operability and security of the Choice Health tools and systems, health plans, and insurers, their fiduciaries, plan sponsors, and fiduciaries should take timely and prudent steps in response to the breach and resulting disruptions to mitigate the exposure of their health plans, and themselves under HIPAA and ERISA."

Tags: Cybersecurity  •  HIPAA

HHS Launches HIPAA Compliance Investigation of Change Healthcare Following Cyberattack
Thomson Reuters Practical Law Link to more items from this source
[Guidance Overview]
Mar. 15, 2024

"HHS's investigation of the target company, a business associate (BA) under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), will focus on whether the target company and its corporate parent (a major health insurer) complied with HIPAA's privacy, security, and breach notification rules."

Tags: HIPAA

HHS Office for Civil Rights Issues Letter and Opens Investigation of Change Healthcare Cyberattack
U.S. Department of Health and Human Services [HHS] Link to more items from this source
[Official Guidance]
Mar. 14, 2024

"[HHS'] Office for Civil Rights (OCR) issued a 'Dear Colleague' letter addressing the cybersecurity incident impacting Change Healthcare ... The cyberattack is disrupting health care and billing information operations nationwide and poses a direct threat to critically needed patient care and essential operations of the health care industry." [Also available: Fact Sheet]

Tags: HIPAA  •  Health Plan Administration

Change Healthcare Cyber Incident and Potential Customer Impacts
Willis Towers Watson Link to more items from this source
Mar. 11, 2024

"For organizations with potential exposures arising from the Change Healthcare cyber incident, it's imperative to connect with your internal stakeholders to proactively identify possible financial impacts.... [O]rganizations who have been impacted should strongly consider putting their cyber insurers on notice. Further, organizations that use UnitedHealthcare, Optum or Change Healthcare, but are not yet sure they have been impacted by this incident, should ... determine whether proactively issuing a notice of circumstance is the right course of action."

Tags: Cybersecurity  •  HIPAA  •  Health Plan Administration

Are HIPAA Covered Entities and Business Associates Required to Have a Risk Analysis and a Risk Management Plan? (PDF)
Thomson Reuters / EBIA Link to more items from this source
[Guidance Overview]
Mar. 8, 2024

"The risk analysis ... must address all ePHI across the entire enterprise and identify deficiencies in compliance programs when compared to the HIPAA security rule. Based on the results of the risk analysis, the risk management plan is created to determine what safeguards need to be implemented to bring the identified risks and vulnerabilities to a reasonable level."

Tags: HIPAA

HHS Reports to Congress on 2022 HIPAA Compliance and Breach Notifications
Thomson Reuters / EBIA Link to more items from this source
Mar. 6, 2024

"OCR received 30,435 complaints in 2022 -- about 11% fewer than in 2021.... OCR notes that it received 626 large breach notifications affecting approximately 41,747,613 individuals, with hacking incidents the most frequent type of breach and network servers the most frequent breach location. Almost 64,000 small breach notifications were reported affecting 257,105 individuals, with unauthorized access or disclosure the most frequent type of breach and paper records the most frequent breach location."

Tags: Cybersecurity  •  HIPAA

Navigating EAP Compliance: A Guide for Employers
EisnerAmper Link to more items from this source
[Guidance Overview]
Feb. 27, 2024

"[T]he increased need to address employees' mental and physical health conditions is expected to expand EAP services by 11% or more in each of the three successive years, 2024-2027. The continued expansion of assistance services means employers with these programs must maintain ongoing compliance.... [1] How to comply with ERISA  ... [2] COBRA election notices  ... [3] HIPAA considerations for EAP compliance."

Tags: COBRA  •  HIPAA  •  Health Plan Administration  •  Health Plan Design

Federal Regulators Unveil Revised Final Guidance for Healthcare Cybersecurity and HIPAA Compliance
Ogletree Deakins Link to more items from this source
[Guidance Overview]
Feb. 26, 2024

"HHS and NIST issued new guidance to provide information and serve as a resource for HIPAA-regulated entities to improve cybersecurity and compliance with the HIPAA Security Rule. The guidance comes after HHS announced a new carrots-and-sticks strategy to improve cybersecurity in the healthcare industry with additional resources and a proposal to increase civil penalties for data breaches to incentivize security measures."

Tags: Cybersecurity  •  HIPAA

In Its Second-Ever HIPAA Settlement on Ransomware, HHS Offers Best Practices for Avoiding Cyber-Attacks
Thomson Reuters Practical Law Link to more items from this source
Feb. 26, 2024

"The CAP also requires the provider to develop (or update) its HIPAA policies and procedures. As revised, the policies and procedures must address -- at a minimum -- a lengthy set of issues under HIPAA's Privacy and Security Rules[.]"

Tags: Cybersecurity  •  HIPAA

HHS Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance for Calendar Year 2022 (PDF)
U.S. Department of Health and Human Services [HHS] Link to more items from this source
Feb. 22, 2024

26 pages. "OCR received 626 notifications of breaches affecting 500 or more individuals, representing an increase of 3% from the number of reports received in calendar year 2021. These reported breaches affected a total of approximately 41,747,613 individuals.... OCR completed 799 breach investigations ... OCR resolved three breach investigations with resolution agreements, corrective action plans, and monetary payments totaling $2,425,640."

Tags: HIPAA

In Updated HIPAA Security Rule Guide, NIST Addresses Cybersecurity and Other Topics
Thomson Reuters Practical Law Link to more items from this source
[Guidance Overview]
Feb. 22, 2024

"The 2024 guide offers drill-down information on complying with the Security Rule's administrative, physical, and technical safeguards for protected health information (PHI) in electronic form."

Tags: Cybersecurity  •  HIPAA  •  Health Plan Administration

OCR Continues Holding Healthcare Entities Accountable for Protected Health Information Breaches
McGuireWoods Link to more items from this source
Feb. 21, 2024

"HHS released voluntary cybersecurity performance goals catered to the healthcare and public health sectors. In addition, healthcare organizations -- no matter how big or small -- can access helpful guidance through HHS' and the Cybersecurity & Infrastructure Security Agency's joint cybersecurity toolkit. With these resources available, if healthcare entities become victims of a breach of ePHI without having adequate security measures in place, they may face an OCR investigation and similar penalties or enforcement actions."

Tags: HIPAA

Text of OCR/NIST Publication SP 800-66 Rev. 2, Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guide (PDF)
Office for Civil Rights [OCR], U.S. Department of Health and Human Services [HHS], and National Institute of Standards and Technology [NIST] Link to more items from this source
[Official Guidance]
Feb. 16, 2024

122 pages. "The HIPAA Security Rule focuses on safeguarding electronic protected health information (ePHI) held or maintained by regulated entities. The ePHI that a regulated entity creates, receives, maintains, or transmits must be protected against reasonably anticipated threats, hazards, and impermissible uses and/or disclosures. This publication provides practical guidance and resources that can be used by regulated entities of all sizes to safeguard ePHI and better understand the security concepts discussed in the HIPAA Security Rule." [Also available: HIPAA Security Rule Resources (18 pages)]

Tags: Cybersecurity  •  HIPAA

© 2024 BenefitsLink.com, Inc.