HHS Issues Guidance to Teaching Hospitals and Medical Schools on Informed Consent Requirements
The Department of Health and Human Services (HHS) has written to the nation’s teaching hospitals and medical schools to clarify the requirement to obtain informed consent from patients before they are subjected to sensitive examinations, especially on patients under anesthesia. HHS Secretary Xavier Becerra, Office for Civil Rights Director Melanie Fontes Rainer, and CMS administrator Chiquita Brooks-LaSure explained in the letter that they are aware of media reports and medical and scientific literature that indicate that as part of the training of medical students, patients are subjected to sensitive and intimate examinations – including pelvic, breast, prostate, or rectal examinations – while under anesthesia, when proper informed consent has not been obtained from the patients. The letter stresses that it is vital for hospitals and medical schools to obtain and document informed consent before examinations are performed and that informed consent is required in all circumstances. Patients have the right to refuse to have sensitive examinations performed for teaching...
OSHA Publishes Final Rule for Employee Representation during Inspections
The Occupational Safety and Health Administration (OSHA) has issued a final rule that confirms that employees are entitled to representation during OSHA inspections, and employee representatives do not have to be employees. The Occupational Safety and Health (OSH) Act gives employees and employers the right to authorize a representative to accompany OSHA personnel during workplace inspections. The final rule clarifies that workers may authorize another employee to serve as a representative or they may select a non-employee, and if the latter is chosen, the individual must be reasonably necessary to the conduct of an effective and thorough inspection. For instance, the non-employee must have the skills, knowledge, or experience, such as knowledge or experience with hazards or conditions in the workplace or similar workplaces, or language or communication skills. There are no specific qualifications required for employer representatives nor for employee representatives who are employees of the employer. The update stems from a 2017 court ruling where the court acknowledged that the...
OCR Settles HIPAA Right of Access Investigation with Phoenix Healthcare for $35,000
The Department of Health and Human Services’ Office for Civil Rights (OCR) has announced that a $35,000 settlement has been reached with Phoenix Healthcare to resolve a HIPAA Right of Access violation. This is the 47th investigation of a HIPAA Right of Access case to result in a financial penalty. The HIPAA Right of Access provision of the HIPAA Privacy Rule requires patients or their personal representatives to have timely access to their health information. Access/copies of the requested information must be provided within 30 days of the request being received. OCR received a complaint from a daughter whose mother was a patient of Phoenix Healthcare, an Oklahoma multi-facility organization that provides nursing care. The daughter was the personal representative of her mother and had not been provided with timely access to her mother’s medical records. The daughter requested the records on multiple occasions and had to wait almost a year to receive the requested data. The requested records were provided 323 days after the initial request was made. The daughter reported the...
MFA Bypassed in Cyberattack on L.A. County Department of Mental Health
Cyberattacks and data breaches have been reported by the L.A. County Department of Mental Health, Healthfirst, Wyndemere Senior Care, Risas Dental & Braces, and Baylor College of Medicine. Los Angeles County Department of Mental Health The Los Angeles County Department of Mental Health has recently notified the California Attorney General about a breach of an employee’s email account. The email account had multi-factor authentication (MFA) in place; however, MFA was bypassed. The cyber threat actors bypassed MFA using a technique known as push notification spamming, where a user is sent multiple MFA push notifications to their mobile device in the hope that they will eventually respond. The employee did respond, resulting in their email account being compromised. According to the Department of Mental Health, the attack stemmed from a breach at the City of Gardena Police Department (GDP). “GPD’s email exchanges with the Department of Mental Health (DMH) allowed the malicious actor or actors to send an email to a DMH employee and get access to that employee’s...
Is Uber Health HIPAA Compliant?
Uber Health is HIPAA compliant and can be used by healthcare providers to organize transport for patients or to arrange deliveries of groceries, over-the-counter items, and filled prescriptions – subject to healthcare providers that qualify as covered entities (or that work for a covered entity) agreeing to the terms of Uber Health’s Business Associate Addendum. . What is Uber Health? Uber Health consists of an online dashboard that healthcare providers can use to schedule transport for patients or organize deliveries. Provided the patient has a mobile phone, he/she will receive a notification about the collection and drop off location via text message. In contrast to the standard Uber service, Uber Health does not require the use of a smartphone app. By using Uber Health, healthcare providers can potentially reduce the number of no shows and ensure more patients turn up on time for their appointments. Rides can be scheduled when the patient is in a facility, ensuring they have transport arranged for follow up appointments. The service could also be used for caregivers and...



