HIPAA Compliance Tools
HIPAA compliance tools are used as part of the HIPAA compliance process, for example, forms and notices, and to measure HIPAA compliance, for example, assessment tools or checklists that guide covered entities and business associates through the basics of HIPAA compliance. The HIPAA Journal has a number of free resources that help HIPAA-Covered Entities with their HIPAA compliance. HIPAA Business Associate Agreement Template This downloadable template provides a reference for what should be contained in a HIPAA Business Associate Agreement. Click to Download HIPAA Business Associate Agreement Template (Word document, 18K) HIPAA Release Form Releasing medical records without a HIPAA authorization form is a HIPAA violation. Click here for HIPAA release form (free PDF document – Opens directly in the browser) Two US states have their own forms Click here for California HIPAA release form Click here for Texas HIPAA release form HIPAA Notice of Privacy Practices HHS’ Office for Civil Rights has produced a Notice of Privacy Practices template that is free to download. Instructions...
Is GroupMe HIPAA Compliant?
GroupMe is not HIPAA compliant and cannot be used to create, collect, store, or transmit Protected Health Information due to its lack of Technical Safeguards. In addition, GroupMe’s owners – Microsoft – will not enter into a Business Associate Agreement with users of the GroupMe service as it is not an “in-scope” service. GroupMe is a free text messaging service that connects friends, family members, student groups, and/or work colleagues via SMS, IM, audio, and video. Available on Windows desktops, via the Internet, and mobile apps, the service allows users to create groups, invite members, host events, and run polls. Users can also search for and apply to join groups that may be of interest to them. GroupMe and Protected Health Information While GroupMe can be used to connect groups of healthcare professionals, it lacks the Technical Safeguards required by the HIPAA Security Rule to protect Protected Health Information from authorized access and disclosures. For example, GroupMe does not allow group moderators to manage access controls, audit logs, or user...
What is HIPAA Compliant Voicemail?
There are three answers to the question what is HIPAA compliant voicemail – the first relating to the systems used to record incoming messages, the second to the greeting recorded on a healthcare provider’s voicemail system, and the third to voicemail messages left on patients’ answerphone machines. For healthcare providers, it is important that all three types of voicemails are HIPAA compliant. What is HIPAA compliance? Who is required to comply with HIPAA? What is a HIPAA compliant voicemail system? What is a HIPAA compliant voicemail greeting? What is a HIPAA compliant voicemail message? Conclusion and HIPAA compliant voicemail FAQs. What is HIPAA Compliance? HIPAA compliance means complying with the applicable Administrative Simplification Regulations of the Health Insurance Portability and Accountability Act (HIPAA). These regulations can be found at 45 CFR Subtitle A Subchapter C and include well-known HIPAA Rules such as the Privacy Rule, the Security Rule, and the Breach Notification Rule. The primary objectives of the Administrative Simplification Rules are to...
Saint Louis University Agrees to $2 Million Settlement to Resolve Data Breach Lawsuit
A settlement has been reached to resolve a class action lawsuit against St. Louis University and SSM Health Saint Louis University Hospital (SSM-SLUH) over a 2023 data breach. Under the terms of the settlement, a fund of $2 million will be created to cover claims, attorneys’ fees, and legal costs and expenses. St. Louis University identified suspicious activity within its email system in March 2023. The investigation confirmed that a cybercriminal group accessed a limited number of employee email accounts after conducting a phishing campaign. The unauthorized access spanned from December 2022 to July 2023, and while there was unauthorized access, no evidence was found to indicate there had been any misuse of the exposed data. The compromised accounts contained the personal information of students, employees, and hospital patients, including names, addresses, telephone numbers, dates of birth, driver’s license numbers, passport numbers, digital signatures, Social Security numbers, health insurance information, and medical information. Up to 93,000 individuals potentially had...
Loretto Hospital Confirms Patient Data Involved in January Hacking Incident
Loretto Hospital in Chicago has confirmed that patient data was exposed in a January hacking incident. Data breaches have also been announced by Family Centers Inc. in Connecticut and Maryhaven in Ohio. Loretto Hospital, Illinois Loretto Hospital in Chicago, Illinois, has warned patients about a recent hacking and data theft incident. It is unclear from the breach notice exactly when the incident was detected; however, the forensic investigation confirmed that there was unauthorized access to its network between January 17 and February 1, 2025, during which time files were copied from its network. Further, Loretto Hospital determined that from the evening of February 2, 2025, through the afternoon of February 4, 2025, patient information was entered into its electronic medical record system that was not saved. Efforts were made to recover that data, but some records may not have been recovered or fully recreated. It is currently unclear how many individuals have been affected as the file review has not yet concluded. In the interim, the breach has been reported to the HHS’ Office...



