Interview: Dotty Bollinger, Founder, Integrity Healthcare Advisors
The HIPAA Journal has spoken with Dotty Bollinger, who is a healthcare compliance consultant and founder of Integrity Healthcare Advisors. Dotty graduated with a degree in Nursing from Maria College in Albany, New York, and later received a bachelor’s degree in management and marketing at the University of Maryland University College. Dotty earned a law degree from the University of South Dakota School of Law and holds a Master’s level certificate in healthcare compliance from George Washington University. Dotty Bollinger is an Executive Partner on the Compliance & Risk Management at SCALE Healthcare. What is your current position? I am a healthcare compliance consultant for a variety of healthcare practices – some private equity owned and others physician owned. I work across a wide range of healthcare specialties from physician practice to pharmacy services to DME. Tell the readers about any significant event in your career. As a registered nurse, I loved regulatory compliance and risk management. I loved the tie between smart application of rules to the outcome of...
Former Executive Sentenced to Probation for HIPAA Violation
Mark Kevin Robison, a former vice president of Commonwealth Health Corporation (now Med Center Health) in Kentucky has been sentenced to 2 years’ probation and ordered to pay $140,000 in restitution after reaching a plea agreement with federal prosecutors over a violation of HIPAA. Robison pled guilty to knowingly disclosing the protected health information of patients of Commonwealth Health Corporation (CHC) under false pretenses to an unauthorized third party between 2014 and 2015. Robison did not have authorization from the patients concerned nor from CHC to disclose the records. While Vice President of CHC, Robison hired Randy Dobson as a patient account collection vendor for CHC. In March 2011, Robison and Dobson set up a corporation – OPTA LLC – in Kentucky. The pair were the only registered members and Robison was the registered agent. Dobson was developing a software solution and together the pair hoped to market the software to healthcare companies. OPTA Kentucky was dissolved in 2014, and Delaware OPTA was incorporated the same year with Dobson listed as the sole owner....
Refuah Health Center Pays $450K HIPAA Fine; Agrees to $1.2 Million Cybersecurity Investment
New York Attorney General Letitia James has announced that an agreement has been reached with Refuah Health Center Inc. to resolve allegations it failed to maintain reasonable and appropriate cybersecurity controls to protect and limit access to sensitive patient data stored on its network. Under the terms of the agreement, Refuah Health Center has agreed to invest $1.2 million in cybersecurity and will pay $450,000 in penalties and costs. The NY AG launched an investigation of Refuah Health Center after being notified about a May 2021 ransomware attack that compromised the personal and protected health information of 260,740 individuals, including 175,077 New Yorkers. The Lorenz ransomware group gained access to internal systems in late May 2021, initially compromising a system that was used for viewing videos from internal cameras monitoring its facilities. That system was only protected with a four-digit code. The attackers stole administrator credentials that were used by a former IT vendor to remotely access the network. The credentials had not been changed for 11 years and...
HIPAA vs HITRUST
In the context of complying with HIPAA, HITRUST is one of the most commonly adopted Cyber Security Frameworks (CSFs) alongside the likes of NIST SP 800-66r2, ISO/IEC 27001, and AICPA’s System and Organization Controls 2 (SOC 2). In addition to supporting compliance with HIPAA, HITRUST supports compliance with many other federal and state laws, and can be customized to support compliance with some local or industry specific regulations. The HITRUST Alliance is a collaboration between several high profile organizations in the healthcare, technology, and information security industries. In 2007, the Alliance released the first HITRUST Cyber Security Framework (CSF) in response to the increasing number of threats to healthcare data and the increasing number of federal and state compliance requirements (i.e., HIPAA, the Texas Medical Records Privacy Act, etc.). Since 2007, the Alliance has updated the Framework and expanded the control categories and implementation specifications in response to changes to “authoritative sources” (i.e., NIST, ISO, etc.) and new rules and regulations. The...
How to Secure Healthcare Data
HIPAA-regulated entities must ensure that protected health information (PHI) is safeguarded against unauthorized access, but many covered entities and business associates do not know how to secure healthcare data properly and leave sensitive information exposed. The HIPAA Security Rule The HIPAA Security Rule established national standards to protect individuals’ electronic personal health information (ePHI) that is created, received, used, or maintained by HIPAA-covered entities and their business associates. The Security Rule requires appropriate administrative, physical, and technical safeguards to be implemented to ensure the confidentiality, integrity, and availability of ePHI. All regulated entities must assess security risks throughout their organziation and implement a range of different safeguards to protect against unauthorized ePHI access, and ensure all risks are reduced to a low and acceptable level. How to Protect Healthcare Data and Comply with HIPAA The HIPAA Security Rule was developed to be flexible to ensure that it applies to covered entities of all types...



