The past several years have proven difficult for healthcare entities due to increasing cybersecurity threats, breaches and regulatory enforcement. Following these trends, on April 6, 2022, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) released a Request for Information (RFI) soliciting public comment on how regulated entities are voluntarily implementing security practices under the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act) and also seeking public input on sharing funds collected through enforcement with individuals who are harmed by Health Insurance Portability and Accountability Act of 1996 (HIPAA) rule violations.
Only a few days remain before the enforcement delay that the Centers for Medicare & Medicaid Services (CMS) exercised due to COVID-19 will end and the agency will require certain payors to publish a Patient Access application programming interface (“API”) and a Provider Directory API under the requirements of the CMS Interoperability and Patient Access Final Rule. Starting on July 1, 2021, all health plans that offer Medicare Advantage, Medicaid and Children’s Health Insurance Program (CHIP) and most Qualified Health Plans offered through the Federally-facilitated ...
Recent Updates
- FTC Reverses Course on Health App Privacy
- The Battle Continues: No Appointments Clause Problem, BUT Eleventh Circuit Directs District Court to Consider Whether False Claims Act Qui Tam Provisions Violate Take Care, Vesting Clauses
- Bill Gates Gazes into the AI Crystal Ball: What are the Implications on the Healthcare and Life Sciences Industry
- 250+ Health Care Entities Targeted by HHS, DOJ Over Gender-Affirming Care for Minors
- Exclusion Authority (It’s Not Just the HHS-OIG Anymore …)