The decision to enter into an arrangement to have another organization host your data will be driven by a number of factors such as: resource availability, technical considerations, location diversity, and cost. One of the factors which must be considered is the HIPAA Security Rule. If the hosting arrangement […]
Health Law Alert
Data Hosting: A New Venture with New Risks
Hospitals and health care organizations are more frequently hosting data or back-up data at off-site data locations. While segregating data by hosting data off site is generally an advisable risk management strategy, hospitals have also entered arrangements to host data for third parties (including other hospitals). This practice may leave […]
The Next Decade of HIPAA: Omnibus Final Rule Brings Challenges and Increased Enforcement
As we near the ten year anniversary of covered entities complying with the original HIPAA Privacy Rule (April 14, 2003), the Office for Civil Rights (OCR) has issued a wake-up call with the publication of a consolidated final rule implementing new and enhanced standards for Privacy, Security, Enforcement and Breach […]
Employers Must Use Revised FCRA Forms
For employers performing backgroundchecks, the standard notices that employers routinely use to fulfill their obligations under the Fair Credit Reporting Act (FCRA) have been revised by the Consumer Financial Protection Bureau (CFPB). Use of the new forms was required effective January 1, 2013. Consumer reports are routinely used by […]
Expanding Risks from Medical Staff Peer Review of Employed Physicians
A recent federal court decision in Ohio highlights one of several “new” risks arising from direct employment of physicians by health care facilities. In Nathan v. Ohio State University, a cardiac anesthesiologist sued her former employer, a university medical center and its physician practice group, after her termination of employment, […]

