The Impact of Proposed Changes to the HIPAA Security Rule for Business Associates
A final rule updating the HIPAA Security Rule is due for release as early as May 2026. According to HHS/OCR,…
Get The FREE
Business Associate
HIPAA Checklist
Reduce Risk & Stay Compliant
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Learn the basics of HIPAA, including who it applies to, what it protects, and why it matters for companies serving healthcare organizations.
A final rule updating the HIPAA Security Rule is due for release as early as May 2026. According to HHS/OCR,…
A HIPAA security risk assessment assesses threats to the privacy and security of PHI, the likelihood of a threat occurring,…
HIPAA compliance training for business associates should include Security Rule security awareness training, applicable Privacy Rule training, Breach Notification Rule…
HIPAA violation cases are compliance investigations that result from a data breach being reported to the Department of Health and…
HIPAA Privacy Rule training for business associates should explain how employees may use, disclose, access, protect, amend, restrict, and report…
As aBusiness Associate, it is important to be aware of which HIPAA compliance standards apply to your organization. Do you…
In any organization that qualifies as a HIPAA Business Associate, every member of the workforce is part of the environment…
The consequences of non-compliance in healthcare depend on the compliance obligations of the individual or entity, the nature of the…
Protected Health Information is an individual’s health, treatment, or payment for treatment information – and certain information maintained in the…
The Confidentiality of Medical Information Act (CMIA) is just one of several state laws and regulations that apply to medical…
In addition to HIPAA and the Texas Medical Records Privacy Act/HB300, several other laws apply to the privacy and security…
A HIPAA Business Associate Agreement is most often a contract between a HIPAA covered entity and a business or individual…
The HIPAA password requirements are a combination of Administrative and Technical Safeguards designed to manage and monitor access to PHI.…
Under HIPAA PHI is considered to be an individual’s health, treatment, and payment information, and any related information maintained in…
The HIPAA Privacy Rule provides a federal floor of privacy standards that protects individuals’ health information and other identifying information…
HIPAA violations occur when covered entities, business associates, or members of either’s workforces fail to comply with a standard of…
The HIPAA Conduit Exception Rule applies to organizations that would normally be considered business associates, but who are exempted from…
Covered entities and business associates are responsible for HIPAA compliance, the compliance of their workforces, and the compliance of any…
The phrase HIPAA compliance and medical billing relates to Part 162 transactions such as eligibility checks, authorization requests, claims, and…
The HIPAA rules and regulations are the standards and implementation specifications adopted by federal agencies to streamline healthcare transactions and…
HIPAA training is a legal and ethical requirement for any organization that handles protected health information (PHI), but for Business…
HIPAA is important for billing and coding because these functions depend on the lawful, accurate, and secure handling of protected…
Yes, billing information is protected under HIPAA when it relates to an individual and can be linked to their identity,…
HIPAA compliance for business associates has acquired greater significance since the publication of proposals to align the HIPAA Security Rule…
HIPAA certification is the process in which an independent third party organization audits a medical organization or practice to certify…
The terms covered entity and business associate are used widely through HIPAA legislation, but what are the differences between a…
HIPAA compliance for software development is an important consideration for vendors and service providers who intend to develop or provide…
HIPAA compliance for SaaS consists of ensuring the software product or service complies with all applicable Security Rule standards, and…
Cyber actors are increasingly exploiting vulnerabilities at vendors, suppliers, and software providers to infiltrate the networks of organizations. According to…
The HIPAA Security Rule covers a subset of individually identifiable health information protected by the Privacy Rule and it applies…
The HIPAA permitted disclosures of PHI are summarized in §164.502 of the Privacy Rule, with more details about each type…
Examples of HIPAA violations by employers are easy to find because almost every avoidable HIPAA violation is indirectly attributable to…
HIPAA Business Associates are subject to the same fines as HIPAA-Covered Entities.
An investigation by regulators in Missouri into the 2024 hacking incident at Conduent Business Services has stalled. The Missouri Department…
There have been several announcements about data breaches at business associates of HIPAA-regulated entities recently, including Providence St. Joseph Orange…
HIPAA violation cases are compliance investigations that result from a data breach being reported to the Department of Health and…
Rocky Mountain Care in Utah has announced a January 2026 data breach, and Corewell Health in Michigan has confirmed that…
Orthopaedic Institute of Western Kentucky has notified patients that their PHI was compromised in two security incidents at their managed…
Jackson Hospital and Clinic in Montgomery, Alabama, has notified 14,485 individuals about a July 2024 data breach at one of…
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its second enforcement action of…
The U.S. medical device manufacturer UFP Technologies has submitted a FORM 8-K filing to the U.S Securities and Exchange Commission (SEC)…
Vikor Scientific (now rebranded as Vanta Diagnostics), a molecular diagnostics company based in Charleston, South Carolina, has been affected by…
Cyberattacks and data breaches have recently been announced by the healthcare technology company Insightin Health and the Colorado-based medical billing…
Gryphon Healthcare, a Houston, TX-based revenue cycle, coding, compliance, consultancy, and management services vendor, faced multiple class action lawsuits over…
The healthcare technology company Veradigm Inc. (formerly Allscripts) has agreed to settle a class action lawsuit that was filed in…
Mid Michigan Medical Billing Service, a Flint, MI-based revenue cycle management company that provides billing support services to HIPAA-covered entities,…
Marlton, NJ-based Continuum Health Alliance, a provider of health management and patient services, has agreed to a settlement to resolve…
Data breaches have been announced by the medical malpractice law firm Davies, McFarland & Carroll, the sex therapy and couples…
On November 19, 2025, Wyandot Center, a nonprofit community behavioral health center in Kansas City, KS, disclosed a cybersecurity incident…
Two sleep specialists, Persante Health Care in New Jersey and SomnoSleep Consultants in Virginia, have recently disclosed security incidents that…
The Danville, Pennsylvania-based healthcare provider Geisinger Health and its former IT vendor Nuance Communications, Inc., have agreed to a $5…
Data breaches have recently been announced by the EHR vendor CareTracker (Amazing Charts) and the Wisconsin health system, Marshfield Clinic.…
Wakefield & Associates, a Knoxville, Tennessee-based vendor that offers revenue cycle & collections services to healthcare providers, has recently announced…
Approximately 462,000 current and former customers of Blue Cross Blue Shield of Montana (BCBSMT) have been affected by a cyberattack…
As of December 18, 2025, OCR has added 41 data breaches affecting 500 or more individuals to its data breach…
Outcomes One, a Florida-based business associate of health plans, has disclosed a phishing incident that has affected almost 150,000 individuals.…
Medusind has agreed to pay $5,000,000 to settle a consolidated class action lawsuit over a 2023 data breach. Medusind is…
Central Valley Regional Center, a Fresno, California-based state-funded provider of services to individuals with developmental disabilities, has notified patients about…
A cyberattack on a business associate has resulted in unauthorized access to the protected health information of patients of Keys…
The HHS’ Office for Civil Rights (OCR) has announced another settlement to resolve an alleged violation of the risk analysis…
The Texas Health and Human Services Commission (HHSC) has been affected by an insider breach at one of its business…
A HIPAA-covered entity is suing one of its business associates over an alleged failure to comply with the terms of…
Cyber actors are increasingly exploiting vulnerabilities at vendors, suppliers, and software providers to infiltrate the networks of organizations. According to…
Health Fitness Corporation, an Illinois business associate, has agreed to settle an alleged HIPAA risk analysis failure with the HHS’…
A business associate of Adventist Health Tulare has identified unauthorized access to the information of 70,000 patients, and Columbia University…
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle potential HIPAA violations…
The HHS’ Office for Civil Rights (OCR) has agreed to settle a HIPAA investigation of an Arkansas business associate that…
Associates in Dermatology, a network of dermatology clinics in Indiana, Kentucky, and New York, has started notifying patients that some…
Adventist Health Physicians Network in Simi Valley, California has been ordered to pay $40,000 in civil momentary penalties by the…
The City of New Haven, Connecticut has agreed to pay a $202,400 financial penalty to the Department of Health and…
HIPAA update and news plus the latest data breaches and fines.
Free downloadable template for a HIPAA Business Associate Agreement
This downloadable template provides a reference for what should be contained in a HIPAA Business Associate Agreement.
Insights into the costs of non-compliance, including real-world examples of HIPAA fines and enforcement actions.
An investigation by regulators in Missouri into the 2024 hacking incident at Conduent Business Services has stalled. The Missouri Department…
There have been several announcements about data breaches at business associates of HIPAA-regulated entities recently, including Providence St. Joseph Orange…
HIPAA violation cases are compliance investigations that result from a data breach being reported to the Department of Health and…
Get The FREE
Business Associate
HIPAA Checklist
Reduce Risk & Stay Compliant
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Rocky Mountain Care in Utah has announced a January 2026 data breach, and Corewell Health in Michigan has confirmed that…
Orthopaedic Institute of Western Kentucky has notified patients that their PHI was compromised in two security incidents at their managed…
Jackson Hospital and Clinic in Montgomery, Alabama, has notified 14,485 individuals about a July 2024 data breach at one of…
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its second enforcement action of…
The U.S. medical device manufacturer UFP Technologies has submitted a FORM 8-K filing to the U.S Securities and Exchange Commission (SEC)…
Vikor Scientific (now rebranded as Vanta Diagnostics), a molecular diagnostics company based in Charleston, South Carolina, has been affected by…
Cyberattacks and data breaches have recently been announced by the healthcare technology company Insightin Health and the Colorado-based medical billing…
Gryphon Healthcare, a Houston, TX-based revenue cycle, coding, compliance, consultancy, and management services vendor, faced multiple class action lawsuits over…
The healthcare technology company Veradigm Inc. (formerly Allscripts) has agreed to settle a class action lawsuit that was filed in…
Mid Michigan Medical Billing Service, a Flint, MI-based revenue cycle management company that provides billing support services to HIPAA-covered entities,…
Marlton, NJ-based Continuum Health Alliance, a provider of health management and patient services, has agreed to a settlement to resolve…
Data breaches have been announced by the medical malpractice law firm Davies, McFarland & Carroll, the sex therapy and couples…
On November 19, 2025, Wyandot Center, a nonprofit community behavioral health center in Kansas City, KS, disclosed a cybersecurity incident…
Two sleep specialists, Persante Health Care in New Jersey and SomnoSleep Consultants in Virginia, have recently disclosed security incidents that…
The Danville, Pennsylvania-based healthcare provider Geisinger Health and its former IT vendor Nuance Communications, Inc., have agreed to a $5…
Data breaches have recently been announced by the EHR vendor CareTracker (Amazing Charts) and the Wisconsin health system, Marshfield Clinic.…
Wakefield & Associates, a Knoxville, Tennessee-based vendor that offers revenue cycle & collections services to healthcare providers, has recently announced…
Approximately 462,000 current and former customers of Blue Cross Blue Shield of Montana (BCBSMT) have been affected by a cyberattack…
As of December 18, 2025, OCR has added 41 data breaches affecting 500 or more individuals to its data breach…
Outcomes One, a Florida-based business associate of health plans, has disclosed a phishing incident that has affected almost 150,000 individuals.…
Medusind has agreed to pay $5,000,000 to settle a consolidated class action lawsuit over a 2023 data breach. Medusind is…
Central Valley Regional Center, a Fresno, California-based state-funded provider of services to individuals with developmental disabilities, has notified patients about…
A cyberattack on a business associate has resulted in unauthorized access to the protected health information of patients of Keys…
The HHS’ Office for Civil Rights (OCR) has announced another settlement to resolve an alleged violation of the risk analysis…
The Texas Health and Human Services Commission (HHSC) has been affected by an insider breach at one of its business…
A HIPAA-covered entity is suing one of its business associates over an alleged failure to comply with the terms of…
Cyber actors are increasingly exploiting vulnerabilities at vendors, suppliers, and software providers to infiltrate the networks of organizations. According to…
Health Fitness Corporation, an Illinois business associate, has agreed to settle an alleged HIPAA risk analysis failure with the HHS’…
A business associate of Adventist Health Tulare has identified unauthorized access to the information of 70,000 patients, and Columbia University…
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has agreed to settle potential HIPAA violations…
The HHS’ Office for Civil Rights (OCR) has agreed to settle a HIPAA investigation of an Arkansas business associate that…
Associates in Dermatology, a network of dermatology clinics in Indiana, Kentucky, and New York, has started notifying patients that some…
Adventist Health Physicians Network in Simi Valley, California has been ordered to pay $40,000 in civil momentary penalties by the…
The City of New Haven, Connecticut has agreed to pay a $202,400 financial penalty to the Department of Health and…