Hello world,
Today’s Paubox Weekly is 571 words - a 2 minute read.
Want to get this type of content delivered to your inbox every Friday? Subscribe to Paubox Weekly.
The US Department of Health and Human Services’ Office for Civil Rights has announced that it will revive its HIPAA compliance program after a seven-year hiatus.
What was said: OCR director Melanie Fontes Rainer said the "OCR intends to initiate audits of HIPAA-regulated entities later this year."
In the know: Some experts believe that HHS OCR has violated the HITECH Act because it did not conduct annual periodic audits as required by law.
86% of covered entities failed the risk analysis audit
We'll be at both ViVE and HIMSS this year! Stop by, meet the Paubox team, and pick up some Paubox swag.
Why it matters: ViVE 2024 is set to be a groundbreaking event for digital health innovators and HIMSS is the most influential health information technology event of the year, attended last year by 35,000+ professionals.
The details:
A cyberattack on Change Healthcare has caused widespread disruptions, affecting pharmacies and patient care across the nation, and appears to be ongoing.
Why it matters: The attack's impact on Change Healthcare's systems led to delays and challenges for pharmacies in fulfilling prescriptions, directly impacting patients.
Still working to restore affected services
Amid escalating healthcare data breaches, the National Institute of Standards and Technology (NIST) has revealed updated HIPAA Security Rule implementation guidance.
The backstory: Audits by the OCR in 2016 and 2017 uncovered widespread noncompliance, particularly in risk analysis and risk management areas.
No audited entities achieved full compliance
INTEGRIS Health is under fire for how they handled communication of a cyberattack in Nov. 2023, exposing sensitive patient data of 2.3 million individuals.
What happened: They updated the breach notice on February 6, 2024, incorporating language that some critics argue minimizes the seriousness of the incident and the organization's obligation to notify affected individuals.
Escalated when hackers contacted patients directly