CMS Confirms Policy on Texting Patient Information among Healthcare Providers

Share

The Centers for Medicare & Medicaid Services (CMS) recently issued a State Survey & Certification Memorandum effective immediately in order to clarify its position on texting patient information among health care providers.

Although CMS acknowledges that the use of texting to communicate with other members of a patient’s health care team has become a common and invaluable practice, it acknowledges that such practice risks noncompliance with the Medicare Conditions of Participation (CoPs) or Conditions for Coverage (CfCs).  In order to text and comply with the CoPs or CfCs, CMS requires providers to use, maintain, and routinely assess secure, encrypted systems or platforms and minimize the risks to patient privacy and confidentiality per the Health Insurance Portability and Accountability Act and other requirements under the CoPs or CfCs.

Continue reading “CMS Confirms Policy on Texting Patient Information among Healthcare Providers”

Oncology Services Provider Reaches $2.3 Million Settlement with HHS for Data Breach

Share

21st Century Oncology, Inc. (21CO), a Florida-based oncology services provider, has agreed to pay $2.3 million in a no-fault resolution to the Department of Health and Human Services (HHS), Office for Civil Rights (OCR) to settle potential civil money penalties stemming from a 2015 cyberattack on its network SQL database.  The Federal Bureau of Investigation (FBI) was first to detect that an unauthorized third party illegally obtained patient information from 21CO in October 2015.  Upon further investigation by 21CO and OCR, it was determined that 21CO:

  • Impermissibly disclosed the protected health information (PHI), including names, social security numbers, and diagnoses, and treatments, of 2,213,597 of its patients.   
  • Failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic protected health information (ePHI).   
  • Failed to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.   
  • Failed to implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports.   
  • Disclosed protected health information to  third party vendors, acting as its business associates, without obtaining satisfactory assurances in the form of a written business associate agreement.

Continue reading “Oncology Services Provider Reaches $2.3 Million Settlement with HHS for Data Breach”

Recent OCR Action Provides HIPAA Guidance Related to Opioid Crisis and Privacy Rule in Research

Share

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) recently released several new tools and guidance to ensure that patients and their family members can gain access to information needed to prevent and address opioid abuse and overdose, as well as mental health crises. The materials are focused on the Health Insurance Portability and Accountability Act (HIPAA) and also serve to fulfill certain clarification requirements on HIPAA and research under the 21st Century Cures Act (the “Cures Act”).  The Cures Act was passed by Congress in 2016 and requires, in part, that “health care providers, professionals, patients and their families, and others involved in mental [health] or substance use disorder treatment have adequate, accessible, and easily comprehensible resources relating to appropriate uses and disclosures of protected health information (PHI) under . . . [HIPAA].”

Continue reading “Recent OCR Action Provides HIPAA Guidance Related to Opioid Crisis and Privacy Rule in Research”

©2024 Faegre Drinker Biddle & Reath LLP. All Rights Reserved. Attorney Advertising.
Privacy Policy