Is Microsoft Teams HIPAA Compliant?
Microsoft Teams is HIPAA compliant and can be used to collect, store, share, or transmit electronic PHI if an organization subscribes to an appropriate Business Plan, if the platform is configured to support HIPAA compliance, and if members of the workforce are trained to use Microsoft Teams compliantly. Microsoft Teams is a communications platform that includes secure chat, videoconferencing, and file sharing capabilities. The platform is widely used in business to “bridge the gap between in-person and remote teammates” and can ensure team members stay informed, organized, and connected. Microsoft Teams can also be integrated with hundreds of apps to enhance collaboration and streamline workflows. Because of its advanced capabilities and integrations, Microsoft Teams is one of the top ten communication platforms used in the healthcare industry. The platform can be used for corporate communications, onboarding, training, and scheduling, and for conducting wellness checks with frontline workers – an engagement activity that is practically essential in the healthcare industry at...
What is Healthcare Regulatory Compliance?
Healthcare regulatory compliance is the practice of meeting or exceeding the requirements of all applicable federal, state, local, and industry regulations and any voluntary standards a healthcare organization adopts in order to demonstrate a good faith effort to comply with the regulations. Due to the number of regulations and standards a healthcare organization may have to comply with, healthcare regulatory compliance is complex and has the potential for failure in many different areas. Most healthcare organizations are required to comply with dozens of federal, state, local, and industry regulations. The regulations can cover subjects as diverse as building safety, data security, codes of conduct, the regulation of controlled substances, and the provision of medical assistance in emergency circumstances. To complicate the challenge of healthcare regulatory compliance, some regulations conflict with each other, while others duplicate standards from other regulations. It can also be the case that some regulations exempt healthcare organizations from complying with some standards,...
Staff are the Weakest Link in HIPAA Cybersecurity
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) data breach portal shows that patients’ protected health information is being exposed and stolen at an unprecedented rate. From 2021 to 2024, more than 700 large healthcare data breaches were reported each year, and each of those data breaches affected at least 500 individuals, with an average breach size of 203,892 individuals. In those four years alone, the protected health information of more than 595 million individuals was compromised. Hackers have been targeting the healthcare and public health sector with increasing frequency, and hacking and other IT incidents now account for the bulk of the reported healthcare data breaches. Email accounts are accessed, networks are compromised, and in almost all cases, healthcare data is stolen by unauthorized individuals. While unauthorized third parties are the ones that access the data, when you delve into the root cause of the breach, it is often the actions of a healthcare employee or an employee of a business associate that caused the data breach....
Settlement Resolves Data Breach Litigation Against Falcon Healthcare-Interim Healthcare of Lubbock Texas
Falcon Healthcare, doing business as Interim Healthcare of Lubbock, Texas, a home care and home health care service provider, has agreed to settle class action litigation stemming from a hacking incident that was first identified in June 2022. An unauthorized third party had access to its computer network between April 29, 2022, and July 3, 2022, and downloaded the protected health information of 89,443 patients. Data compromised in the incident included names, addresses, dates of birth, Social Security numbers, driver’s license numbers, health insurance information, diagnoses, lab results, medications, and treatment information. The affected individuals were offered complimentary credit monitoring and identity theft protection services; however, it took until April 25, 2025, before the affected individuals were notified about the data breach. On May 1, 2024, a class action lawsuit – Dawn Rice v. Falcon Healthcare, Inc. d/b/a Interim Healthcare of Lubbock, Texas – was filed in the District Court of Lubbock County, Texas, seeking damages on behalf of a national class of...
What is Individually Identifiable Health Information?
Individually identifiable health information is information relating to an individual’s past, present, or future health condition, treatment for the condition, and payment for the treatment that identifies the individual or that could be used to identify the individual. It is important to be aware that information that could be used to identify an individual is not always Protected Health Information (PHI). HIPAA and Individually Identifiable Health Information Under HIPAA §160.103 , individually identifiable health information is defined as a subset of health information – including demographic information collected from an individual – created or received by a healthcare provider, health plan, employer, or health care clearinghouse that relates to the past, present, or future health condition, treatment for the condition, or payment for the treatment. To qualify as individually identifiable health information under HIPAA, the information also has to identify the individual who is the subject of the health information, or could be used with other information maintained in the same...



