OCR’s Publicly Disclosed Large Breaches Now Top 20 Million Impacted Individuals

May 16, 2012.  The Department of Health and Human Services’ (HHS) HIPAA/HITECH Act privacy and security enforcement arm, Office for Civil Rights (OCR), is responsible under the HITECH Act to publicly disclose privacy and security breaches that affect 500 or more individuals on its Breach Notification Web site.  With the now reported Utah Department of Health hacking/IT incident breach occurring in the period March 10-April 2, 2012 and affecting a reported 780,000 individuals, the total number in 435 breaches reported since September 22, 2009, now totals 20,079,189 impacted individuals.  Of the total number of breaches where location of breached information is known (e.g., electronic or hard copy source), 72% of…


Reported Breaches of 500 or More Individuals up to 93 and Affecting Over 2.5 Million Individuals; Enforcement and Penalties

As of Friday, June 4, 2010, 93 breaches affecting 500 or more individuals have been reported on the Office for Civil Rights (OCR) Web site. The total number affected has gone beyond 2-1/2 million individuals today, and stands at 2,565,352 individuals. Of the 87 breaches involving breach of hard copy or electronic protected health information, 26% involve hard copy or paper records and 74% records on electronic media or devices. Overall, 71% of the 93 breaches involve theft or loss of records, many of which might have been avoided by appropriate securing of hard copy records and electronic media and devices. Below we remind readers of the Department of Health…


Proposed Rule for Electronic Claims Attachments

DEPARTMENT OF HEALTH AND HUMAN SERVICES Office of the Secretary 45 CFR Part 162 | [CMS–0050–P] | RIN 0938–AK62 HIPAA Administrative Simplification: Standards for Electronic Health Care Claims Attachments AGENCY: Office of the Secretary, HHS. ACTION: Proposed rule. Download (Requires Acrobat Reader)

National Provider Identifier Final Rule

DEPARTMENT OF HEALTH AND HUMAN SERVICES Office of the Secretary 45 CFR Part 162 | [CMS–0045–F] | RIN 0938–AH99 HIPAA Administrative Simplification: Standard Unique Health Identifier for Health Care Providers AGENCY: Centers for Medicare & Medicaid Services, HHS. ACTION: Final rule. Download (Requires Acrobat Reader)