HIPAA Compliance in Multi-Site Medical Practices
The challenge of HIPAA compliance in multi-site medical practices is that different sites can have different approaches to governance, risk management, and HIPAA compliance – making it difficult for employees working in different sites to comply with each site’s policies and procedures. One way to overcome this challenge is to use multilocation HIPAA compliance management software to standardize policies and procedures. It is not unusual for healthcare organizations to operate across multiple sites. Even smaller medical practices can have separate offices for primary care, outpatient surgeries, and medical specialties. In such circumstances, it is often the case that each site conducts separate assessments for facility risks, clinical risks, emergency planning, etc., and develops its own policies and procedures to mitigate the risks and respond to incidents. However, what might be assessed as a risk in one location might not be assessed as a risk in another. For example, if a multi-site medical practice has separate offices for psychiatry and podiatry, the psychiatry office...
Hapy Bear Surgery Center Agrees to Settle Data Breach Lawsuit
A class action lawsuit filed against Hapy Bear Surgery Center over a December 2023 ransomware attack has been settled for an undisclosed sum. The Tulare, California pediatric dental clinic identified the cyberattack on or around December 27, 2024, and confirmed on March 19, 2024, that names, addresses, medical information, health insurance information, Social Security numbers, and driver’s license numbers had potentially been accessed or stolen. Notification letters were issued in April 2024. A class action lawsuit – In re: Hapy Bear Surgery Center Data Security Incident Litigation – was filed in California Superior Court for Tulare County over the data breach. The plaintiffs alleged that the dental clinic was negligent by failing to implement appropriate safeguards to ensure the confidentiality of patient data. The lawsuit also asserted claims of breach of implied contract, unjust enrichment, unfair business practices, and a violation of the California Confidentiality of Medical Information Act. Hapy Bear Surgery Center denies all claims and maintains that it did nothing...
Memorial Healthcare System Settles Alleged HIPAA Right of Access Violation
South Broward Hospital District, a Florida health system that does business as Memorial Healthcare System, has agreed to settle an alleged violation of the HIPAA Right of Access with the U.S. Department of Health and Human Services’ Office for Civil Rights (OCR). The HIPAA Privacy Rule gives individuals rights over their health records, including the right to obtain a copy of those records and to only be charged a reasonable cost-based fee. When a HIPAA-regulated entity receives a request, the records must be provided within 30 days, or in limited circumstances, a 30-day extension is possible. OCR received a complaint from a patient on June 23, 2021, who alleged he had submitted a request to Memorial Healthcare System on April 26, 2021, for a copy of specific health records but those records had not been provided. OCR investigated and found that while the patient had mailed a written request for the records on April 26, 2021, it was not the first time the records had been requested. The patient had requested a copy of an EEG tracing via the Memorial Healthcare System patient portal...
Digital Marketing for Dentists
‘Digital marketing for dentists can help resolve “empty chair” issues by attracting new patients in order to fill gaps in schedules. However, although digital marketing can be one of the most cost-effective methods of attracting new patients and increasing profitability, dentists must be careful not to violate HIPAA or other state and federal regulations. Each quarter, the American Dentistry Association Health Policy Institute publishes a report on the economic outlook and emerging issues in dentistry based on a survey of approximately one thousand private dentists (# responses varies each quarter). In the most recent report, one of the headline questions related to how busy dentists were over the last three months. An analysis of those who responded “not busy enough” later in the report shows that gaps in schedules affect all types of dentists – i.e., solo practitioners, group practices, and DSOs. While some empty chair issues are attributable to no shows and last minute cancellations, 37% of respondents to the question “what prevented your appointment schedule from reaching...
Jail Terms for HIPAA Violations by Employees
Jail terms for HIPAA violations by employees are relatively rare, but there have been several cases where employee HIPAA violations have been referred to the Department of Justice and have resulted in financial penalties and jail time. Some cases that have resulted in jail terms for HIPAA violations by employees are listed below, along with cases where jail time for HIPAA violations has only narrowly been avoided. The penalties for HIPAA violations by employees can be severe, especially those involving the theft of protected health information. HIPAA violations by employees can attract a fine of up to $250,000 with a maximum jail term for violating HIPAA of 10 years plus a further 2 years for aggravated identity theft. Jail Term for Former Transformations Autism Treatment Center Employee In February 2017, a former behavioral analyst at the Transformations Autism Treatment Center (TACT) was discovered to have stolen the protected health information of patients following termination. Jeffrey Luke, 29, of Collierville, TN gained access to a TACT Google Drive account containing the PHI...



