CISA logo

2 min read

The CISA Preransomware Notifications Initiative

The Preransomware Notifications Initiative is a program by the Cybersecurity and Infrastructure Security Agency (CISA) that provides early warnings to organizations about potential ransomware threats.

Read More
law gavel with stethoscope

2 min read

Do covered entities need to inform patients about info shared in litigation?

Patients can request an accounting of disclosures that includes information shared by their covered entity during litigation, as per 45 CFR 164.528.

Read More
law gavel on us flag

2 min read

What are the primary forms of preemption?

Preemption is a principle that promotes a uniform legal framework across states, particularly in areas where federal regulation is needed to address...

Read More
Image of tax calculator for blog about Title III of HIPAA

1 min read

Title III of HIPAA

Title III of HIPAA is the Tax-Related Health provision, which establishes tax-preferred treatment for medical savings accounts (MSAs) and provides...

Read More
FBI seal

1 min read

FBI warns of HiatusRAT malware threat

The FBI Cyber Division released a private industry notification on December 16, 2024, warning organizations discussing HiatusRAT1 scanning campaigns.

Read More
Delaware state capitol

1 min read

HHS OCR and Delaware settle disability rights case

The HHS announced a resolution with the Delaware Department of Health and Social Services following a failure to meet their responsibilities towards...

Read More
Image of lock for blog about What is DevSecOps?

2 min read

What is DevSecOps?

DevSecOps, or development, security, and operations revolves around integrating security practices into the entirety of the software development...

Read More
Image of government building for blog about Do the staff of the state attorney's office need to comply with HIPAA?

2 min read

Do the staff of the state attorney's office need to comply with HIPAA?

The staff of the state attorney's office are enforcers of HIPAA and have duties that may place their staff in contact with health data. To prevent...

Read More
medical symbol on shield

2 min read

The concept of breach vs. disclosure under HIPAA

Section 160.103 of the HIPAA Privacy Rule defines a disclosure as the release, transfer, provision of access to, or divulging of PHI outside the...

Read More
Image of women showing benefits for blog about When can health plans communicate without patient authorization?

2 min read

When can health plans communicate without patient authorization?

Health plans can communicate patient information without their authorization primarily for purposes related to treatment, payment, or healthcare...

Read More
Image of someone tapping a gavel for blog about The impact of judicial interpretation on data privacy

2 min read

The impact of judicial interpretation on data privacy

Judicial interpretation helps clarify existing laws, influencing the development of state-specific regulations, and addressing challenges brought by...

Read More
Image of paper with data for blog about Why should EHRs be audited? 

2 min read

Why should EHRs be audited? 

Regular audits help identify vulnerabilities in electronic health records (EHRs), allowing organizations to pinpoint improvement areas. Auditing EHR...

Read More
connectoncall logo

1 min read

ConnectOnCall breach impacts over 900,000 individuals

The ConnectOnCall data breach occurred between February 16, 2024, and May 12, 2024. The breach exposed the protected health information (PHI) of...

Read More