HHS Delays Effective Date of HIPAA Final Rule Implementing Modified Retail Pharmacy Standard
In December 2024, the Department of Health and Human Services published a final rule in the Federal Register modifying the National Council for Prescription Drug Programs (NCPDP) Retail Pharmacy Standards and the Medicaid Pharmacy Subrogation Standard. The effective date for those modifications was initially set as February 11, 2025; however, the HHS has now delayed the effective date until April 14, 2025. The final rule adopted updated versions of the retail pharmacy standards for electronic transactions for health care claims or equivalent encounter information; eligibility for a health plan; referral certification and authorization; and coordination of benefits, and the adoption of a modified standard for the Medicaid pharmacy subrogation transaction. The delay to the effective and compliance dates is due to President Trump’s January 20, 2025, Presidential memorandum, titled “Regulatory Freeze Pending Review.” Dorothy A. Fink, Acting Secretary of the Department of Health and Human Services, said the 60-day postponement of the effective date was made “for the purpose of reviewing...
HIPAA Compliance for Psychologists
In most cases, HIPAA compliance for psychologists consists of complying with all applicable HIPAA Administrative Simplification Regulations when a psychologist is a qualifying sole practitioner or in charge of a qualifying practice, or complying with an organization’s HIPAA policies and procedures when a psychologist is a member of a HIPAA covered organization’s workforce. However, there are scenarios in which a psychologist may qualify as a hybrid entity, or when they may work as a sole practitioner in an affiliated entity but are not solely responsible for HIPAA compliance. It may also be possible that a psychologist does not qualify as a HIPAA covered entity, but still has to comply with applicable HIPAA regulations when working for a covered organization as a business associate. In addition, psychologists may have to comply with other federal or state regulations that preempt HIPAA. These can relate to permissible disclosures of certain types of records (i.e., substance use disorder records) or obtaining affirmative consent before collecting, processing, or sharing sensitive...
Nurse Patient Communication
Nurse patient communication is not only important for the identification of symptoms and feedback on treatments, but it can also help improve the patient experience, increase the prospects of recovery, and reduce readmissions – saving healthcare facilities money through CMS’ Hospitals Readmission Reduction program. Effective communication between nurses and patients is a fundamental part of good nursing care. Good nurse patient communication makes patients feel valued, cared for, and safe. When patients are admitted into hospital it is common for them to feel like they have lost control of their lives. Everyday things they used to take care of themselves are placed in the hands of others. Being totally reliant on hospital staff can leave patients feeling helpless. When nurses spend time talking with patients and practice patient-centered communication, patients feel valued as a person and they will be more likely to speak openly about how they are feeling. This will put nurses in a better position to formulate a comprehensive, individualized care plan for the patient. Good nurse...
Law Enforcement Operation Takes Down 8Base Ransomware Group
An international law enforcement operation has taken down the negotiation and data leak sites of the 8Base ransomware group. The operation saw four individuals – two men and two women – arrested across different locations in Phuket, Thailand, with law enforcement officers seizing mobile phones, laptop computers, and digital wallets. The four individuals now face charges of conspiracy to commit an offense against the United States and conspiracy to commit wire fraud. The 8Base ransomware group emerged in March 2022, initially keeping a low profile until June 2023 when the group started leaking data stolen in its attacks. The group is believed to consist of experienced hackers, potentially from a different ransomware group. VMWare has linked the group to another ransomware operation, RansomHouse, due to similarities in their data leak sites and ransom notes, although it is unclear if the same individuals operate both ransomware groups. 8Base was responsible for more than 1,000 ransomware attacks worldwide, including attacks on healthcare organizations. The U.S. Department...
HIPAA Compliance for Behavioral Health Practices
HIPAA compliance for behavioral health practices not only consists of complying with the HIPAA Privacy, Security, and Breach Notification Rules, but also with any other federal or state regulations that preempt HIPAA’s “federal floor” of privacy protections. These regulations include (for example) the Part 2 “SUD” regulations and the Texas Medical Records Privacy Act. Most behavioral health professionals are subject to the HIPAA Privacy, Security, and Breach Notification Rules inasmuch as they are either solo practitioners who qualify as a HIPAA Covered Entity, or they work for a behavioral health practice that has implemented policies and procedures to comply with the HIPAA Rules. In terms of HIPAA compliance for behavioral health practices, if a solo practitioner qualifies as a Covered Entity, they are responsible for implementing measures to protect the privacy of individually identifiable health information and that ensure the confidentiality, integrity, and availability of electronic Protected Health Information (PHI). In multi-practitioner behavioral health practices, these...



