Failure to Provide a Medical Screening Examination Results in HHS-OIG Penalty
Two hospitals have entered into settlement agreements with the Department of Health and Human Services (HHS) Office of Inspector General (OIG) to resolve alleged violations of the Emergency Medical Treatment and Labor Act (EMTALA). EMTALA requires Medicare-participating hospitals with emergency departments to provide a medical screening examination and stabilizing treatment for any patient, regardless of the patient’s ability to pay. Patients must not be transferred unless they have first been provided with stabilizing treatment, unless the patient requests a transfer in writing, the benefits outweigh the risks, and if the receiving hospital agrees to accept the patient. Transfers are also permitted if the hospital does not have the capabilities to stabilize the patient, in which case, the patient can be transferred to a hospital with specialized capabilities. Cordell Memorial Hospital in Oklahoma was investigated by HHS-OIG after an alleged failure to provide a medical screening examination to a pregnant patient in active labor, who presented at the hospital on January 27,...
HIPAA Training for Physical Therapists
Physical therapists must receive documented HIPAA training that covers the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule, is provided during onboarding and refreshed annually as an industry best practice, and is reinforced through security awareness training so protected health information is used, disclosed, safeguarded, and reported in a manner consistent with HIPAA requirements and organizational policies. Physical therapy services routinely involve protected health information in evaluations, plan of care documentation, progress notes, referrals, prior authorizations, billing records, and communications with physicians, payers, and care coordinators. Training must account for these routine touchpoints where privacy, security, and incident reporting obligations arise. HIPAA training should be provided to physical therapists during onboarding within a reasonable period after the start of work or access authorization and aligned with the point at which access to systems and records is granted. Training completion should be tracked before independent...
HIPAA Training for Receptionists
HIPAA training for receptionists is mandatory workforce training on the HIPAA Privacy Rule, HIPAA Security Rule, HIPAA Breach Notification Rule, and HIPAA Minimum Necessary Rule that prepares front-desk staff to safeguard protected health information during registration, scheduling, telephone calls, visitor management, payments, and routine coordination of care, with training provided during onboarding and repeated as an annual HIPAA refresher training. All workforce members must receive HIPAA training when they join the organization. HIPAA training is mandatory for workforce members who handle protected health information. Annual HIPAA training is industry best practice. Training on HIPAA rules and regulations is the first step. Internal policies and procedures follow after staff understand the regulatory requirements and baseline HIPAA administrative safeguards that apply across workflows. Receptionist Work Activities That Create HIPAA Exposure Receptionists interact with protected health information in high-traffic areas and in time-pressured exchanges. Common exposure points...
Director of Operations and HIPAA Compliance Oversight in Small Practices
Article Contents Physical safeguards require securing areas with PHI. Contingency planning depends on tested disaster recovery plans. Compliance coordination aligns IT, clinical, and administrative teams. Directors of Operations oversee key compliance activities. Compliance budgeting balances ongoing and reactive costs. Multi-location practices need consistent compliance across sites. Vendor oversight confirms technical safeguards are documented. Compliance metrics help track program performance. Breach response coordinates recovery and compliance. When a Director of Operations Overseas HIPAA Compliance A Director of Operations oversees HIPAA compliance in a small practice by securing the physical spaces where patient data is stored or accessed, maintaining a tested contingency plan for system outages and disasters, coordinating compliance efforts across clinical, administrative, and IT functions, and budgeting for the infrastructure a compliance program requires. This role carries broader operational scope than a Practice Administrator’s day-to-day program management,...
DOCS Dermatology Group; Center for Neuropsychology and Learning Disclose Data Breaches
Central States Dermatology Services (DOCS Dermatology Group) in Ohio and The Center for Neuropsychology and Learning in Michigan have identified unauthorized access to patient data. Central States Dermatology Services, Ohio Central States Dermatology Services, LLC, doing business as DOCS Dermatology Group (DOCS), has disclosed a security incident that was identified on November 27, 2025. Suspicious activity was identified within its network, and, assisted by third-party cybersecurity experts, DOCS determined that an unauthorized third party had access to its network from November 19, 2025, to November 27, 2025. The data review is ongoing, so the number of affected individuals had yet to be confirmed; however, DOCS has determined that the data compromised in the incident includes names in combination with one or more of the following: address, email address, phone number, date of birth, Social Security number, treatment/diagnosis information, prescription/medication information, dates of service, provider name, medical record number, patient account number, Medicare/Medicaid ID...



