Does HIPAA Apply to Animals?
HIPAA does apply to animals if details of an animal could be used to identify the subject of Protected Health Information maintained in the same designated record set by a covered entity or business associate. However, HIPAA does not apply to animals in all other circumstances – including when details of animals are maintained in a veterinary medical record. The most common answer to the question does HIPAA apply to animals is “no”, because the HIPAA Administrative Simplification Regulations apply to Protected Health Information created, received, maintained, or transmitted by a covered entity or business associate that relates to an individual’s health condition, treatment for the health condition, or payment for the treatment. An “Individual” is defined in HIPAA (§160.103) as “the person who is the subject of the Protected Health Information”, and “person” is defined as “a human who is born alive”. This would imply that HIPAA does not apply to animals. However, there are circumstances in which information about an animal could assume the same protections as Protected Health...
Indiana AG Agrees to $350,000 Penalty to Resolve Egregious HIPAA Violations
An Indianapolis dental practice has agreed to pay a financial penalty of $350,000 to the Office of the Indiana Attorney General (OIG) to resolve multiple alleged violations of federal and state laws related to an unreported October 2020 ransomware attack and data breach. Several dental practices operate under the name Westend Dental, including Westend Dental LLC, Arlington Westend Dental LLC, Sherman Westend Dental LLC, Fountain Square Westend Dental LLC, Lafayette Westend Dental LLC, and Affordable Westend Dental LLC, all of which are owned by Dr. Pooja Mandalia D.D.S. The Indiana OIG initiated an investigation of Westend Dental following a complaint from a patient who had requested a copy of their dental records, which could not be provided due to a hacking incident. The Indiana OIG investigation uncovered evidence that Westend Dental had experienced a ransomware attack on or around October 20, 2020, involving state residents’ protected health information. Westend Dental submitted a data breach notification form to the Indiana OIG on October 28, 2022, more than two years...
What is TPA in Healthcare?
TPA in healthcare stands for Third Party Administrator – most often a state-licensed individual or organization that acts as an independent intermediary between an employer’s self-funded health plan and healthcare providers. Although independent, the purpose of a TPA in healthcare is to support self-funded health plans by managing administrative tasks and processes on health plans’ behalf. Most employers with fifty or more full-time employees – including full-time equivalent (FTE) employees – are required to provide health insurance under the Affordable Care Act (ACA). Those with fewer than fifty FTE employees may choose to provide health insurance in order to attract and retain employees, or to benefit from Small Business Health Care Tax Credits or the Small Business Health Options Program (also known as the SHOP Marketplace). To comply with ACA, private sector employers have several health plan options. These include, but are not limited to: Fully insured employer-sponsored health plans, in which employers pay a fixed premium to a commercial insurance carrier that...
What is PHI in HIPAA?
PHI in HIPAA is an acronym for Protected Health Information – health information that is created, collected, maintained, or transmitted by a covered entity that relates to an individual’s past, present, or future physical or mental condition, treatment for the condition, or payment for the treatment, and that is protected by HIPAA from impermissible uses and disclosures. In addition to individuals’ health information being protected from impermissible uses and disclosures, HIPAA also applies to individually identifiable non-health information stored in the same designated record set as PHI that could identify the subject of the PHI or be used with other information stored in the same designated record set to identify the subject of the PHI. The application of HIPAA protections to non-health information can create misunderstandings about what information should be protected and when it should be protected (evidenced by multiple sources mistaking the “18 HIPAA identifiers” as PHI). This article aims to resolve potential misunderstandings about what is PHI in HIPAA by answering three...
Las Palmas Del Sol Healthcare Discovers 2-Year Insider Data Breach
Cyberattacks have been announced by VisionPoint Eye Center in Illinois and Vickers Engineering in Michigan. Las Palmas Del Sol Healthcare has discovered a former employee has accessed patient records without authorization and may have disclosed patient information to other unauthorized individuals. El Paso Healthcare System (Las Palmas Del Sol Healthcare) El Paso Healthcare System, Ltd. d/b/a Las Palmas Del Sol Healthcare, has recently notified 1,854 patients about an insider data breach detected on February 23, 2024. A former employee was discovered to have accessed patients’ medical records without authorization and may have disclosed patient information to other unauthorized individuals. When unauthorized medical record access was detected, a review was conducted to determine the extent of the HIPAA breach. The employee was found to have accessed patient records without authorization between January 1, 2018, and March 12, 2021. The review of the records confirmed that the following information was viewed and potentially copied: name, address, date of birth, health plan...



