Meaningful Use Stage 2 Requirements
Update: The Meaningful Use program was renamed in 2018 to the Promoting Interoperability program to highlight CMS´ focus on interoperability between health IT systems and improving patient access to health information. The new program was effectively Meaningful Use Stage 3. In 2022, CMS discontinued the Medicaid Promoting Interoperability Program. Eligible clinicians that previously participated in the Meaningful Use and Promoting Interoperability incentive programs are now required to participate in the Merit-based Incentive Payment System (MIPS). XXXXXXXXXXXXXXXXXXXXXXXXXXXX Progression from Meaningful Use Stage 1 to Stage 2 requires eligible professionals (EPs), Eligible Hospitals (EHs), and Critical Access Hospitals (CAHs) to have satisfied the core objectives and other Meaningful Use Stage 1 requirements for two years, with progression to Stage 3 requiring 2 years of meeting Meaningful Use Stage 2 requirements. Meaningful use requirements are cumulative, so as EPs, CHs, and CAHs progress through the stages, they are required to continue to demonstrate meaningful use of the...
HIPAA Breach Report: June 2014
June 2014 HIPAA Breach Summary: The Breach Notification Rule of HIPAA places a requirement on covered entities and their Business Associates to notify the Department of Health and Human Services’ Office for Civil Rights of data breaches affecting more than 500 individuals. The time limit for doing so this is stipulated in the Breach Notification Rule as 60 days from discovery of the breach. This report contains a summary of the breaches reported to the OCR during the month of June, 2014. Major HIPAA Breaches in June 2014 Three major data breaches were reported in June which exposed tens of thousands of medical records. NRAD Medical Associates, P.C. (NY) reported an incident in which a former member of staff gained access to, and copied, the records of 97,000 patients. The employee was believed to have taken the data with intent of using the information for personal gain. Santa Rosa Memorial Hospital (CA), recently acquired by the St. Joseph Health System, suffered a break-in at the Redwood Regional Medical Group offices which resulted in 33,702 unencrypted medical records being...
Fines for Violations Issued for HIPAA Non-Compliance and Data Breaches
Following on from high profile data breaches in recent months, in particular the breach of PHI across 209 hospitals operated by CHS, compliance with HIPAA regulations is now high on the agenda, especially considering the steep fines being issued by the OCR. Any data breach involving more than 500 individuals must be reported at both state and national levels, with the report launching an investigation by the OCR. The investigation will assess how the data breach occurred and the measures and safeguards put in place to protect data. Fines are issued for any breaches which have resulted from failures to adhere to HIPAA guidelines. However data breaches alone are not the only reason for fines being issued. Compliance with HIPAA requires policies to be adopted and procedures to be followed to ensure security risks are effectively dealt with. When an organization is assessed it will be against a standard to determine if there has been willful neglect, and whether a violation has occurred. A failure to conduct a thorough risk analysis is a violation of HIPAA regulations. If the risk...
Memorial Hermann Health System Announces 10K-Record HIPAA Breach
The Memorial Hermann Health System (MHHS) has discovered that a worker accessed the Protected Health Information of over 10,000 patients while employed at the hospital, with the HIPAA violations dating back some six and a half years. The offenses took place between December 2007 and July 2014, and during that time 10,604 patient records are understood to have been accessed. The information viewed by the unnamed employee included medical records and insurance details, medical record numbers, personally identifiable information including, dates of birth, names and addresses as well as some Social Security numbers. It is not clear why the employee accessed the information, but a spokesperson from the health system said there was “no indication it involved fraudulent purposes.” MHHS discovered the unauthorized access on July 7, 2014 and immediately blocked the employee’s access to patient records while an investigation was conducted. Outside experts in computer forensics were employed to determine which records had been accessed and the extent of the HIPAA violation. Breach...
Ohio Patients Suffer First Hacking-Related Data Breach
Members of the Huntington Bancshares’ wellness program in Ohio have been notified of a data breach in which their healthcare information was potentially compromised. Close to 4,500 state residents have been affected. This is the first large scale data breach to affect Ohio residents. The data breach did not occur at Huntington Bancshares, but was part of a data breach affecting a Business Associate (BA) of StayWell Health Management LLC, Onsite Health Diagnostics. The data breach exposed 60,652 records in total, with hacker’s first gaining access to the database on January 4 of this year. The data breach was discovered on March 25, although a breach notice was delayed and has only just been released. Hackers were able to gain access to a scheduling database of Onsite Health Diagnostics. The information was being used for health screening purposes. The data exposed was limited to Personally Identifiable Information (PII). No health, insurance or financial data was exposed, and neither were Social Security numbers. Patient names, addresses, dates of birth, gender, email addresses and...



