What are the OSHA Emergency Action Plan Requirements?
The OSHA Emergency Action Plan requirements are that every qualifying employer must develop a Plan that meets minimum elements and must provide training on the Plan to key personnel. Qualifying employers must also implement and maintain an employee alarm system to alert employees to emergencies. The OSHA Emergency Action Plan Requirements The OSHA Emergency Action Plan requirements (as per §1910.38) are that qualifying employers must develop a plan that includes the following minimum elements: The procedures for reporting a fire or other emergency. The procedures for emergency evacuation, including type of evacuation and exit route assignments. The procedures to be followed by employees who remain to operate critical plant operations before they evacuate. The procedures to account for all employees after evacuation. The procedures to be followed by employees performing rescue or medical duties. The name or job title of every employee who may be contacted by employees who need more information about the plan or an explanation of their duties under the plan. The Plan must be written...
Investigation Highlights Ease at Which Police Can Access Pharmacy Records
On Monday, three Democratic Senators wrote to the Secretary of the Department of Health and Human Services (HHS) Xavier Becerra to express their concern about pharmacies disclosing prescription records to the police without a warrant. Sen. Ron Wyden (D-OR) and Reps. Pramila Jayapal (D-WA) and Sara Jacobs (D-CA) launched an investigation following the Supreme Court decision in Dobbs v. Jackson Women’s Health Organization, which removed the federal right to an abortion and left it to individual states to set their own laws on abortion. Many states have implemented bans or severe restrictions on abortions, which has resulted in women, and in some cases, children, traveling to more permissive states to receive the reproductive care they need, and there are growing fears that individuals who seek legal reproductive health care out of state may face prosecution in their home state. The HHS issued guidance on HIPAA and reproductive healthcare following the overturning of Roe v Wade, stressing that while the HIPAA Privacy Rule permits disclosures of PHI to law enforcement, the disclosures...
AHA Opposes HHS Plan to Penalize Hospitals for Cybersecurity Failures
The American Hospital Association (AHA) is urging the U.S. Department of Health and Human Services (HHS) to reconsider its plan to make it mandatory for hospitals to comply with new cybersecurity requirements and issue financial penalties if they fail to do so. Last week, the HHS published its healthcare cybersecurity strategy, which outlines the steps the HHS has taken and plans to take in the future to improve healthcare cybersecurity. Those plans include introducing two tiers of Healthcare and Public Health Sector-specific Cybersecurity Performance Goals (HPH CPGs) – essential and enhanced. The essential HPH CPGs will include high-impact cybersecurity requirements for improving cyber resiliency and are intended to establish a baseline for cybersecurity, whereas the enhanced HPH CPGs are desirable cybersecurity requirements to further improve security and protect patient privacy. While both tiers of HPH CPGs would be voluntary initially, the HHS explained in its cybersecurity strategy that it plans to make the essential HPH CPGs enforceable in the future and will be working with...
Is Constant Contact HIPAA Compliant?
Constant Contact is HIPAA compliant and can be used for sending digital communications containing ePHI provided that the platform is configured to support HIPAA compliance and the organization engaged in digital marketing (i.e., a covered entity) agrees to Constant Contact’s Business Associate Agreement. It is also important to be aware of the restrictions that apply to Constant Contact’s BAA or that an individual has themselves placed on disclosures of ePHI. Sending Marketing Emails Containing ePHI The HIPAA Privacy Rule does not prohibit HIPAA-covered entities from sending marketing emails, but before any PHI is disclosed in a marketing email or other digital communication, a valid authorization must be obtained from the subject of the PHI. It is also the case that individuals have the right to opt out of receiving marketing communications or select a channel of communication through which to receive them. In order to improve efficiency, an email marketing solution may be considered, but HIPAA-covered entities need to exercise caution. Not all email marketing platforms have the...
HIPAA Law and Employers
Because a lot of the text of the Health Insurance Portability and Accountability Act (HIPAA) relates to health insurance reforms, and because around 40% of employers operate self-insured health plans, a lot of content connects HIPAA law and employers. However, the most complex areas of HIPAA law for employers are the Administrative Simplification Regulations in Title II which include the Privacy, Security, and Breach Notification Rules. While these Rules are often considered as only being applicable to HIPAA covered entities, there are standards some employers who are not covered entities may have to comply with. Exclusions From HIPAA Law and Employers One potentially confusing area of the Administrative Simplification Regulations relates to employment records. This is because the definition of individually identifiable health information in §160.103 includes “information collected from an individual or created or received by a health care provider, health plan, employer, or health care clearinghouse.” However, the definition of Protected Health Information (also in §160.103)...



