Health IT Security and Compliance


HIPAA Settlement on Repeat

By Matt Fisher – Stop if you’ve heard this story before: a dental practice was unhappy with patient reviews left on Yelp, so responded. In responding, the practice disclosed patient information including names and diagnoses. That is the basic outline of the latest settlement announced by the OCR to resolve an alleged HIPAA violation.


End of Year SRA

By Art Gross – A security risk assessment must be conducted to maintain HIPAA compliance per the Security Rule. A security risk assessment is also referred to as an SRA. It is a requirement for government plans such as Medicare, Obamacare, and Medicaid.


Managing Access Control in Hospitals

By Patrick Chown – The security of the hospital and its assets is a primary concern for hospital facility managers. A hospital houses vulnerable patients, regulated drugs, and plenty of sensitive data. Safeguarding these from any malicious actors is critical to ensure smooth hospital operations.


Cybersecurity is Patient Safety

The College of Healthcare Information Management Executives (CHIME) and the Association for Executives in Healthcare Information Security (AEHIS) provided comments on Senator Mark Warner’s (D-VA) policy options paper, titled “Cybersecurity is Patient Safety.”