OCR, FTC Publish Online Tracking Technology Warning Letters
The Department of Health and Human Services’ Office for Civil Rights (OCR) and the Federal Trade Commission (FTC) have published the letters that were sent to hospital systems and telehealth providers in July 2023 advising them about the privacy risks associated with website tracking technologies such as Meta Pixel and Google Analytics. The widespread use of these tools on hospital websites and the risk of impermissible disclosures of protected health information (PHI) prompted OCR to issue guidance for HIPAA-regulated entities in December 2022. OCR stated in the guidance that these tools are not permitted under HIPAA unless consent is obtained via HIPAA authorizations or if there is a valid business associate relationship with the technology provider and a corresponding HIPAA-compliant business associate agreement (BAA). The FTC has also taken an interest in these tools and has taken action against non-HIPAA-regulated entities for alleged violations of the FTC Act and the FTC’s Health Breach Notification Rule with respect to tracking technologies. The July 2023 letters...
Is Google Voice HIPAA Compliant?
Google Voice is HIPAA compliant and can be used to collect, store, or share PHI provided the service is used as part of a business Workspace or Cloud Identity plan and a Business Associate Addendum is signed with Google. The free consumer version of the service should not be used to collect or share PHI as this version lacks the controls to support HIPAA compliance. Is Google Voice HIPAA Compliant? Google Voice is a popular and convenient telephony service that includes voicemail, voicemail transcription to text, the ability to send text messages free of charge, and many other useful features. Due to its capabilities, it is unsurprising that many healthcare professionals would like to use the service at work, as well as for personal use. In order for any service to be used in healthcare to collect, store, or share protected health information (PHI), it must include several capabilities that can be configured to support HIPAA compliance. There would need to be access and authentication controls, audit controls, integrity controls, and transmission security for messages sent through...
What Does OSHA Do?
The Occupational Safety and Health Administration (OSHA) is a federal agency within the U.S. Department of Labor that is responsible for the regulation and enforcement of workplace safety and health standards, and the provision of training and outreach to educate workers and employers on best safety and health practices. This article answers the questions what does OSHA do about: Developing Safety Standards Requiring Hazard Communications Recordkeeping and Reporting Training and Outreach Enforcing OSHA Standards Emergency Preparedness and Response Protecting Whistleblowers from Retaliation What Does OSHA Do about Developing Safety Standards When OSHA was first established in 1971, it was instructed to adopt standards for workplace safety and health within two years. Due to the tight timeframe, the agency started by adopting existing standards from sources such as the American National Standards Institute and the National Fire Protection Administration, and states that had existing safety and health programs. Once a base of standards had been adopted, OSHA set about developing new...
Healthcare Facilities Symposium and Expo: September 19-21, Charlotte, NC
The annual Healthcare Facilities Symposium and Expo will take place at the Charlotte Convention Center in North Carolina, September 19-21. The event is one of the country’s largest shows dedicated to healthcare design and facilities and is now in its 36th year. Each year, the event is attended by architects, designers, engineers, contractors, healthcare providers, and government agencies who share their research and ideas and provide fresh perspectives on the ever-changing healthcare industry. Attendees will be able to attend compelling keynote presentations, networking events, and informative sessions. The educational and insightful sessions, case studies, and keynotes are meant to inspire and improve current and future healthcare facilities. There will be more than 60 sessions over the 3-day event where attendees can hear from architects, engineers, contractors, and healthcare providers, and gain takeaways to implement in their current and upcoming projects, as well as earn up to 15.25 CEUs from the AIA, IDCEC and EDAC. The sessions will span multiple topics including Pediatrics,...
Employee Health Plan Data Exposed in Forever 21 Data Breach
Fashion retailer Forever 21 has notified the Maine Attorney General of a data breach in which the health plan data of 539,207 current and former employees was exposed. Breach notification letters are being sent to everyone potentially affected by the breach. However, the letters reveal little about the nature of the attack or what specific data was exposed. According to the notification published on the Maine Attorney General website, Forever 21 experienced an “external system breach” between January 5 and March 21, 2023. The nature of the information breached is “name or other personal identifier in combination with Social Security number”, and identity theft services are being offered to those potentially affected. The notification also includes a link to the company’s breach notification letter to potentially affected individuals. The letter provides limited information about the nature of the attack or what specific data was exposed, stating that an unauthorized third party “accessed certain Forever 21 systems” and “obtained select files from certain Forever 21 systems”. With...



