HHS-OIG Excludes Theranos Founder and CEO from Federal Health Programs for 90 Years
The Department of Health and Human Services (HHS) Office of Inspector General (OIG) has added the founder and CEO of the health technology firm Theranos, Inc. to the OIG exclusions list, which means Elizabeth Holmes is prohibited from participation in Federal health care programs for 90 years. The Theranos Scandal Theranos was a blood testing startup founded by Elizabeth Holmes in 2003. The company claimed to have developed revolutionary technology that could be used to perform hundreds of blood tests from a single blood sample. Instead of requiring a vial of blood, the technology could perform more than 200 blood tests using a single pinprick of blood. The company claimed its technology automated blood testing and that tests were inexpensive and fast. Holmes was able to raise $700 million in investment and the company was valued at around $9 billion at its peak, with Holmes owning more than half of the company’s shares. The Wall Street Journal Pulitzer Prize-winning journalist John Carreyrou received a tip that the company’s technology was not what it claimed to be. Carreyrou...
Is HIPAA Training a Federal Requirement?
Yes, HIPAA training is mandated by the Health Insurance Portability and Accountability Act (HIPAA) and is a federal requirement for healthcare providers, insurance companies, and their business associates in the United States to ensure the confidentiality, integrity, and security of protected health information. HIPAA training is mandated by both the HIPAA Privacy Rule (45 CFR § 164.530) and the HIPAA Security Rule (45 CFR § 164.308(a)(5)), requiring healthcare entities to provide regular, role-specific training on handling protected health information (PHI) and electronic PHI (ePHI) to all workforce members, ensuring ongoing awareness and compliance with privacy and security measures. HIPAA Training Required under HIPAA Privacy Rule (45 CFR § 164.530) The HIPAA Privacy Rule mandates that covered entities – which include healthcare providers, health plans, and healthcare clearinghouses – must train all members of their workforce on the policies and procedures with respect to PHI. The HIPAA training must be provided to each new member of the workforce within a reasonable period...
Is HelloFax HIPAA Compliant?
HelloFax is HIPAA compliant provided organizations subscribe to a “Standard” or “Premium” business plan with Dropbox Sign, agree to the terms of the Dropbox Sign Business Associate Agreement, and configure the digital fax service to comply with the Administrative and Technical Safeguards of the Security Rule. In addition, it may also be necessary to train HelloFax users on permissible disclosures of Protected Health Information (PHI) and the Minimum Necessary Standard. In 2019, HelloSign – the parent company of HelloFax – was acquired by Dropbox. The digital fax service was rebranded Dropbox Fax and included in the new Dropbox Sign suite of products. However, due to the popularity of HelloFax prior to the acquisition of its parent company, the former name is often still used to identify the service. Indeed, the FAQ section of the Dropbox Fax web page, HelloFax is referenced in all the answers to the frequently asked questions. Is Dropbox Fax/HelloFax HIPAA Compliant? When subscribed to as part of a “Standard” or “Premium” Dropbox Sign business plan (*), Dropbox Fax/HelloFax has...
Is Twilio SendGrid HIPAA Compliant?
Twilio SendGrid is not HIPAA compliant and cannot be used to send email communications containing Protected Health Information (PHI) as to do so would not only be a violation of HIPAA but also a violation of SendGrid’s Terms of Service. However, SendGrid can be used by healthcare organizations to send general healthcare-related communications and marketing campaigns. SendGrid is a versatile email communication platform with multiple features to help organizations automate transactional communications and run effective email marketing campaigns. Since 2019, SendGrid has been part of the Twilio product family and available as a standalone email platform or as part of an integrated customer engagement solution. Making the Use of Twilio SendGrid HIPAA Compliant Although Twilio does offer some HIPAA Eligible Products and Services, SendGrid is not among them. SendGrid states on its website that the platform does not natively support HIPAA compliant data transmission and refers visitors to a clause in its Terms of Service that prohibits customers from “using the service for any purpose or...
HIPAA Compliance and Healthcare Information
Storing and Communicating Healthcare Information in Compliance with HIPAA When the Final Omnibus Rule enacted regulations within the Health Insurance Portability and Accountability Act (HIPAA) in 2013, it raised issues for healthcare organizations and other covered entities about HIPAA compliance and healthcare information storage and communication. In a healthcare environment in particular, the increased use of mobile devices in the workplace has driven efficiency and accelerated communications. However the new regulations concerning storing and communicating healthcare information in compliance with HIPAA effectively mean that “traditional” channels of mobile communication – such as email and SMS – are no longer considered secure. The Significance of the HIPAA Security Rule Most of the relevant legislation regarding HIPAA compliance and healthcare information is contained within the HIPAA Security Rule. The HIPAA Security Rule includes specific physical, technical and administrative safeguards to prevent healthcare information from being compromised when it is at rest...



