Sources for HHS OIG Fraud, Waste, and Abuse Guidelines
The HHS OIG fraud, waste, and abuse guidelines are intended to support healthcare organizations in their efforts to self-monitor compliance…
Get The FREE
Compliance Software Guide
Learn How Software Can Significantly Improve Compliance Programs
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Insights and analysis to navigate evolving regulations, mitigate risks, and strengthen compliance programs.
The HHS OIG fraud, waste, and abuse guidelines are intended to support healthcare organizations in their efforts to self-monitor compliance…
Information blocking in healthcare is any practice by a healthcare provider, certified health IT developer, or Health Information Network (collectively…
Is your organization prepared for a HIPAA security incident? Review incident response, business continuity, and breach notification requirements and download…
45 CFR 164.308(a)(5) is the administrative safeguard provision of the HIPAA Security Rule that mandates security awareness and training for…
Outsourced HIPAA compliance is when a HIPAA-regulated entity engages external consultants to manage part, or all, of the organization’s HIPAA…
The OIG Stark Law in healthcare is the section of the Social Security Act that prohibits physicians from referring Medicare…
HIPAA changes to claims attachments.
The role of compliance officers in HHS OIG regulations is to ensure policies and procedures are in place to mitigate…
An HHS OIG compliance program consists of best practices that should be included in an integrated healthcare compliance program to…
This guide to HIPAA designated record sets is designed to reduce common misunderstandings about how individually identifiable non‑health information may…
HHS OIG penalties vary depending on the nature of the offense, the scale of the offense, and the cooperation of…
The HHS OIG anti-kickback regulations prohibit the remuneration of individuals or organizations in Federal healthcare programs when the purpose of…
Healthcare-adjacent data is any health‑related or health‑influenced information that falls outside HIPAA’s definition of Protected Health Information because it is…
Hackers focus on medical records because the combination of demographic data, insurance details, clinical information, and financial identifiers creates a…
HIPAA compliance for self-insured group health plans – or self-administered health group plans – is a complicated area of HIPAA…
A HIPAA Compliance Officer is an individual who has been designated the role of HIPAA Privacy Officer and/or assigned responsibility…
A HIPAA sanctions policy should consist of appropriate sanctions against workforce members who fail to comply with privacy and security…
These seven elements of a HIPAA compliance program help healthcare organizations develop a culture of compliance in the workplace, streamline…
The HIPAA medical records destruction rules relate to the safeguards covered entities and business associates must implement to ensure Protected…
HIPAA continuity of care is when ongoing care is provided within a healthcare organization or Organized Health Care Arrangement, or…
ChatGPT for Healthcare is an enterprise version of ChatGPT built for regulated healthcare environments. Launched in January 2026, the product…
The HIPAA breach notification requirements are that HHS’ Office for Civil Rights and individuals whose unsecured Protected Health Information (PHI)…
HIPAA Compliance Officer training helps an individual who is designated the responsibility for HIPAA compliance better understand how a HIPAA…
How you should respond to an accidental HIPAA violation depends on the nature of the accidental violation and the potential…
California medical privacy laws.
In addition to HIPAA and the Texas Medical Records Privacy Act/HB300, several other laws apply to the privacy and security…
The HIPAA password requirements are a combination of Administrative and Technical Safeguards designed to manage and monitor access to PHI.…
A HIPAA violation can be grounds for termination depending on the nature of the violation, the consequences of the violation,…
Medical records can be subpoenaed because every type of record can be subpoenaed, and a more relevant question would be…
HIPAA violations occur when covered entities, business associates, or members of either’s workforces fail to comply with a standard of…
HIPAA updates and changes happen more frequently than many people are aware of because of the nature of the updates…
New HIPAA regulations may be implemented in 2026, such as the proposed update to the HIPAA Privacy Rule, a final…
Section §164.528 of the Privacy Rule is better known as the HIPAA disclosure accounting standard and states that an individual…
The top HIPAA threats are threats from insiders who, either due to a lack of HIPAA training or a lack…
The de-identification of Protected Health Information enables covered entities and business associates to use or disclose health information to third…
Comprehensive HIPAA training courses.
The term Z1 offense wanted by HHS relates to an individual who has been excluded from the System for Award…
HIPAA enforcement discretion is one of several options available to the Secretary for Health and Human Services (HHS) during public health emergencies to ensure that healthcare services continue to…
State privacy law supersedes HIPAA when a state law provides greater privacy protections for individually identifiable health information than HIPAA…
Background checks for healthcare employees are an important safeguard in environments in which the well-being of patients and the integrity…
It is not a HIPAA violation to send to collections provided the minimum necessary Protected Health Information is disclosed and…
A HIPAA confidentiality agreement for employees is similar to a non-disclosure agreement inasmuch as members of the workforce agree not…
The HIPAA marketing rules are that direct B2C marketing communications must be for a permitted purpose and that any uses…
A HIPAA risk assessment for a covered entity or business associate determines whether existing policies, procedures, and security mechanisms are…
Companion bills have recently been introduced in the House of Representatives and the Senate that seek to make violent attacks…
Healthcare compliance software is a comprehensive management tool that helps chief compliance officers to effectively oversee compliance efforts across their…
An 834 file in healthcare is a benefit enrollment and maintenance file used to electronically exchange information about health plan…
A breach of HIPAA is considered to be any acquisition, access, use, or disclosure of protected health information which compromises…
Jail terms for HIPAA violations by employees are relatively rare, but there have been several cases where employee HIPAA violations…
The anti-kickback law in healthcare is a federal law that prohibits individuals and organizations from offering, paying, soliciting, or receiving…
Breaches of patient confidentiality – defined as disclosures of private information without the patient’s consent – occur more often than…
The latest HIPAA compliance and OIG news and regulatory updates
Perspectives, emerging trends and thought leadership on HIPAA compliance
The HIPAA Journal has compiled healthcare data breach statistics from October 2009, when the Department of Health and Human Services…
There has been some good news for the HIPAA-regulated entities that feel unprepared for the proposed changes to the HIPAA…
At a Thursday hearing, the Senate Health, Education, Labor and Pensions (HELP) Committee heard testimony from Thomas Keane, M.D., M.B.A.,…
Get The FREE
Incident Management Checklist
Learn How To Implement An Effective HIPAA Incident Management Plan
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
One of the benefits of cryptocurrencies is greater financial accessibility for unbanked populations, which includes individuals in remote areas who do…
The Privacy Department is led by the HIPAA Privacy Manager, but who is the Department? For some small organizations, it’s…
The HIPAA Journal has released the results of its 2025 Annual HIPAA Compliance Survey, offering a detailed snapshot of how…
50+ Facts and Statistics about the State of Cybersecurity in the US Healthcare Industry Spending and Resources Cybersecurity Ventures predicts…
Minefields HIPAA Covered Entities and Business Associates Should Avoid HIPAA Covered Entities beware! Your vendors are probably implementing artificial intelligence…
One of the objectives of the HIPAA Journal 2024/25 Annual Survey was to obtain insights into HIPAA compliance best practices.…
One of the objectives of the 2024/25 HIPAA Journal Annual Survey was to identify challenges to HIPAA compliance. Several challenges…
When the Office for Civil Rights (OCR) reviews your HIPAA training during an investigation into a HIPAA violation, it is…
Exploring a Healthcare Future Redefined by Quantum Computing As artificial intelligence (AI) continues to permeate countless enclaves within the healthcare…
For the fourth consecutive year, more than 700 data breaches of 500 or more healthcare records were reported to the…
It has been three decades since President Clinton signed the Health Insurance Portability and Accountability Act (HIPAA) into law in…
Healthcare cybersecurity incidents continue to skyrocket, with millions of patient records exposed each month. In the first half of 2024…