HIPAA Compliance for Emergency Care
HIPAA compliance for emergency care professionals can be harder than for other healthcare professionals due to the variety of emergency events they attend and the behaviors of patients and their families during emergency events. We look at why this is the case and what covered entities can do to prevent unintentional HIPAA violations in emergencies. In 2020, a study into “emotionally evocative patients in the emergency department […] and the implications for patient safety” found that patient behaviors and issues with hostile family members left the majority of emergency care professionals angry, frustrated, or irritated. Many professionals admitted failing to provide the best possible care or act professionally following an angry encounter. The study backed up previous research suggesting that emotions can influence clinical reasoning and behavior, raised concerns that negative encounters could evoke negative emotions that could compromise patient safety in emergency situations, and concluded that emergency care professionals should receive additional training to promote awareness...
HIPAA and Canada
HIPAA can apply in Canada in several different ways, even when a company is physically located only in Canada. In practice, it comes into play whenever a Canadian organization handles Protected Health Information for U.S. HIPAA Covered Entities, signs Business Associate Agreements with U.S. healthcare clients, or uses subcontractors and services that are part of a cross border healthcare data ecosystem. Providing Services to U.S. HIPAA Covered Entities A Canadian company can fall under HIPAA when it provides services to a U.S. HIPAA Covered Entity such as a hospital, clinic, telehealth provider, or health plan. If the work involves handling, viewing, or using Protected Health Information, or PHI, on behalf of that U.S. client, then the Canadian company fits the definition of a HIPAA Business Associate. The fact that the company is physically located in Canada does not remove those obligations, because HIPAA is concerned with who is doing work for the Covered Entity and how PHI is handled, rather than limiting its reach only to vendors inside the United States. Scope Based On...
DOGE Turns Attention to the CMS and is Given Access to Key Systems
The Department of Government Efficiency (DOGE) staff has been provided access to key payment and contracting systems at the HHS Centers for Medicare and Medicaid Services (CMS) to look for opportunities for improving efficiency and to identify fraud and ineffective use of resources. Privacy advocates have expressed concern about the privacy risks from providing DOGE with access to CMS systems, as the agency provides health coverage to more than 160 million Americans through various programs including Medicare, Medicaid, and the Children’s Health Insurance Program. The CMS is a natural target for DOGE due to the size of its workforce and budget and the long history of fraud in health insurance. The CMS employs more than 6,700 individuals and spent $1.5 trillion last year, which is around $22% of the federal total. Elon Musk considers the CMS to be a source of big money fraud, and DOGE staff will be taking a close look at CMS systems to identify fraud and wasteful spending. The CMS has issued a statement confirming two senior agency veterans are leading the collaboration with DOGE,...
Lawsuit Filed Against Rhode Island HIE by Whistleblower Who Alleged Impermissible Uses of HIE Data
A lawsuit has been filed against the Rhode Island Quality Institute (RIQI) by a former HIPAA officer who alleges she was terminated for blowing the whistle on impermissible disclosures of HIE data. RIQI is a Rhode Island state government contractor and was the operator of the state health information exchange (HIE) – CaseCurrent – from 2021 to July 2024, when the contract was awarded to another vendor. Darlene Morris first started working for RIQI in 2012 in the role of Manager of the Electronic Health Record Adoption Program. Morris was promoted on several occasions and was appointed Senior Director, Programs in 2019. Two years later she started serving as RIQI’s HIPAA Privacy Officer and, in 2023, her job title was changed to Senior Director, Risk Management & Compliance/HIPAA Compliance Officer. In that role, Morris reported to RIQI’s President and CEO, Dr. Indra Neil Sarkar. Morris remained in that role until July 2024 when she was terminated. Dr. Sarkar was appointed to the position of President and CEO of RIQI in 2020, after serving as the interim President and CEO. Dr....
Hospital Sisters Health System: August 2023 Data Breach Affected 883K Individuals
Hospital Sisters Health System (HSHS) in Springfield, IL, and Prevea Health in Green Bay, WI, were affected by a cyberattack in late August which caused an outage on August 27, 2023, that affected their computer systems, phone lines, and websites. The outage lasted for several days, during which time HSHS and Prevea operated under downtime procedures. The attack took its websites and certain applications offline, including the MyChart and MyPrevea applications. HSHS was also unable to process online payments as its computer system was offline, but care continued to be provided to patients. HSHS decided to suspend collecting payments for outstanding bills while it was recovering from the attack, although some of its partners in Illinois and Wisconsin continued to send bills to patients. In early September, HSHS published an open letter to patients warning them about the potential misuse of their information, as reports had been received from some patients who had been contacted by email, SMS, and phone by an unidentified third party that claimed to be an HSHS representative who was...



