Missouri Attorney General Files Lawsuit in Response to WU Refusal to Provide Transgender Patients’ Records
The Missouri Attorney General has filed a counterclaim in response to a lawsuit filed by Washington University (WU) over the legal basis of civil investigative demands for documentation about medical procedures performed on transgender patients. WU is refusing to provide records from its Transgender Center that contain patient information, which the Missouri Attorney General claims are essential to the investigation. Missouri Attorney General, Andrew Bailey, issued civil investigative demands for documentation in February 2023 pursuant to an investigation of the Washington University Transgender Center, including records of patients who received treatment. The investigation was initiated in response to allegations by a whistleblower that the clinic had administered experimental drugs, puberty blockers, and cross-sex hormones without sufficient assessments and also pressured parents into giving consent. WU strongly denies the allegations. Washington University complied with the investigative demand and provided documentation but did not provide patient records as it did not believe...
Is DocuSign HIPAA Compliant?
DocuSign is HIPAA compliant provided organizations subscribe to a plan that supports HIPAA compliance and provided the capabilities of the electronic signature software are configured to comply with the HIPAA Security Rule. Healthcare organizations and providers will also need to configure access controls to comply with CMS’ Medicare Electronic Signature Requirements. What is DocuSign? DocuSign is a San Francisco-based provider of electronic signature technology and transaction management services. Via DocuSign, organizations can accelerate patient intake, medical consents, and HIPAA authorizations. Organizations can also send documents to patients, contracts to suppliers, and agreements to business associates for remote signing. However, if the service is used in connection with any electronic protected health information, DocuSign would be classed as a business associate. HIPAA requires all business associates to enter into a HIPAA-compliant business associate agreement with covered entities prior to being provided with or given access to ePHI. Is DocuSign HIPAA Compliant? Rather...
Healthplex Settles Data Breach Investigation with NY Attorney General for $400,000
The New York Attorney General has agreed to settle alleged violations of New York’s data security and consumer protection laws with Healthplex, one of New York’s largest providers of dental insurance. Healthplex has agreed to pay a penalty of $400,000 to resolve the investigation with no admission of wrongdoing. Attorney General Letitia James launched an investigation of Healthplex after being notified about a breach of the personal and protected health information of 89,955 individuals, including 62,922 New York residents to determine if Healthplex had complied with the requirements of the Health Insurance Portability and Accountability Act (HIPAA) and New York’s data security and consumer protection laws. The data breach occurred on or around November 24, 2021, and was the result of an employee responding to a phishing email and disclosing her account credentials. The account contained more than 12 years of emails, some of which included customer enrolment information. Credentials alone should not be sufficient to gain access to email accounts; however, Healthplex had not...
Is Trello HIPAA compliant?
Trello is not HIPAA compliant and the platform cannot be used to receive, store, or share Protected Health Information due to a clause in Trello’s Terms of Services which prohibits customers using Trello to process sensitive personal information. However, provided the platform is not used to receive, store, or share PHI, Trello can help increase productivity. Owned by Atlassian, Trello offers a range of tools that help to coordinate workflows, facilitate collaboration between co-workers, and automate specific tasks. Such project-management platforms are increasingly popular solutions across a variety of organizations, and they have great potential for use in the healthcare sector. But before Trello is used to manage a project which includes the disclosure of PHI, covered entities must ensure Trello can be used in a HIPAA-compliant manner. This means the service must implement minimum security standards that ensure the safety, confidentiality, and accessibility of protected health information (PHI). This requirement is stipulated by the HIPAA Security Rule. Without these minimum...
When Should You Promote HIPAA Awareness?
HIPAA awareness should be promoted whenever possible by integrating HIPAA-related tasks into daily routines and sharing responsibilities for events such as obtaining an acknowledgement of a Notice of Privacy Practices or documenting a patient’s request to withhold disclosures of PHI. However, the most practical time to promote HIPAA awareness is during HIPAA training. HIPAA training should ideally be provided before any employee is given access to PHI. HIPAA-covered entities, business associates and subcontractors are all required to comply with HIPAA Rules, and all workers must receive training on HIPAA. Training should cover the allowable uses and disclosures of PHI, patient privacy, data security, job-specific information, internal policies covering privacy & security, and HIPAA best practices. The penalties for HIPAA violations, and the consequences for individuals discovered to have violated HIPAA Rules, must also be explained. If employees do not receive training, they will not be aware of their responsibilities and privacy violations are likely to occur. Additional...



