News
Do I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business AssociatesYour 'Success Story' Program Just Cost This Rehab Facility $182,000: The Cadia Healthcare HIPAA Settlement · OCR EnforcementAn Accounting Firm Just Paid a HIPAA Fine: BST and Co. CPAs and What It Means for Professional Services Firms · OCR Enforcement15 Million Records, a $10,000 Fine, and a Company That No Longer Exists: The MMG Fusion Story · OCR EnforcementOCR Creates Religious Discrimination Units: What the Restructuring Means for HIPAA Enforcement · Rule UpdateOCR Director: The Cost of Doing Nothing Is Very High · Rule UpdateHIPAA Victims May Soon Receive a Share of OCR Fines: What the Proposed Compensation Program Means · Rule UpdateOCR Restructured: Three New Divisions and What It Means for HIPAA Enforcement · Rule UpdateRehab Center Pays $103,000 After Phishing Attack: OCR's 11th Risk Analysis Enforcement Action · OCR EnforcementConcentra Pays $112,500 After Patient Made Six Records Requests Over 13 Months · OCR EnforcementHIPAA Security Rule Final Rule: May Deadline Passes With No Announcement · Rule UpdateDo I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business AssociatesYour 'Success Story' Program Just Cost This Rehab Facility $182,000: The Cadia Healthcare HIPAA Settlement · OCR EnforcementAn Accounting Firm Just Paid a HIPAA Fine: BST and Co. CPAs and What It Means for Professional Services Firms · OCR Enforcement15 Million Records, a $10,000 Fine, and a Company That No Longer Exists: The MMG Fusion Story · OCR EnforcementOCR Creates Religious Discrimination Units: What the Restructuring Means for HIPAA Enforcement · Rule UpdateOCR Director: The Cost of Doing Nothing Is Very High · Rule UpdateHIPAA Victims May Soon Receive a Share of OCR Fines: What the Proposed Compensation Program Means · Rule UpdateOCR Restructured: Three New Divisions and What It Means for HIPAA Enforcement · Rule UpdateRehab Center Pays $103,000 After Phishing Attack: OCR's 11th Risk Analysis Enforcement Action · OCR EnforcementConcentra Pays $112,500 After Patient Made Six Records Requests Over 13 Months · OCR EnforcementHIPAA Security Rule Final Rule: May Deadline Passes With No Announcement · Rule Update
resolution agreement

FAQs for Professionals: Corrective action / RA

Resolution ,

Penalty

Corrective action / RA

Action type

Resolution agreement

Entity profile

Case number

What went wrong

FAQs for Professionals

  • Navigate to: Authorizations (30) Business Associates (41) Compliance Dates (2) Covered Entities (14) Decedents (9) Disclosures for Law Enforcement Purposes (5) Disclosures for Rule Enforcement (1) Disclosures in Emergency Situations (2) Disclosures Required by Law (6) Disclosures to Family and Friends (28) Disposal of Protected Health Information (6) Facility Directories (7) Family Medical History

Full description

Navigate to: Authorizations (30) Business Associates (41) Compliance Dates (2) Covered Entities (14) Decedents (9) Disclosures for Law Enforcement Purposes (5) Disclosures for Rule Enforcement (1) Disclosures in Emergency Situations (2) Disclosures Required by Law (6) Disclosures to Family and Friends (28) Disposal of Protected Health Information (6) Facility Directories (7) Family Medical History Information (3) FERPA and HIPAA (10) Group Health Plans (3) Incidental Uses and Disclosures (10) Judicial and Administrative Proceedings (8) Minimum Necessary (14) Notice of Privacy Practice (20) Preemption of State Law (10) Privacy Rule: General Topics (12) Protected Health Information (2) Public Health Uses and Disclosures (13) Research Uses and Disclosures (20) Right to an Accounting of Disclosures (8) Right to File a Complaint (1) Right to Request a Restriction (4) Safeguards (13) Security Rule (24) Smaller Providers and Businesses (145) Student Immunizations (8) Transition Provisions (3) Treatment, Payment, and Health Care Operations Disclosures (31) Workers Compensation Disclosures (5) Limited Data Set (6) Marketing (17) Marketing - Refill Reminders (16) Personal Representatives and Minors (12) Right to Access and Research (58) Mental Health (34) Health Information Technology (39) Telehealth (11) HIPAA FAQs for Professionals Search frequently asked questions about HIPAA by category, number, or keyword. Please note that some older FAQs have been sent to archive. This content is searchable using the search term ‘HIPAA FAQs’ at https://archive-it.org/collections/4657. FAQs by Category Select a Category Authorizations Business Associates Compliance Dates Covered Entities Decedents Disclosures for Law Enforcement Purposes Disclosures for Rule Enforcement Disclosures in Emergency Situations Disclosures Required by Law Disclosures to Family and Friends Disposal of Protected Health Information Facility Directories Family Medical History Information FERPA and HIPAA Group Health Plans Incidental Uses and Disclosures Judicial and Administrative Proceedings Minimum Necessary Notice of Privacy Practice Preemption of State Law Privacy Rule: General Topics Protected Health Information Public Health Uses and Disclosures Research Uses and Disclosures Right to an Accounting of Disclosures Right to File a Complaint Right to Request a Restriction Safeguards Security Rule Smaller Providers and Businesses Student Immunizations Transition Provisions Treatment, Payment, and Health Care Operations Disclosures Workers Compensation Disclosures Limited Data Set Marketing Marketing - Refill Reminders Personal Representatives and Minors Right to Access and Research Mental Health Health Information Technology Telehealth Search HIPAA FAQs by questions or keywords: Search HIPAA FAQs by questions or keywords Search Content last reviewed October 12, 2017

Timeline

  • Resolution,
  • Incident and investigation milestones are not consistently published by OCR in machine-readable form.

Key takeaways for your organization

  • Document permitted uses and disclosures; obtain valid authorizations before marketing or public-facing communications that include PHI.
  • Align policies, procedures, and evidence with the specific CFR provisions cited in OCR resolutions affecting your entity type.
  • Run tabletop exercises for breach response, OCR inquiry handling, and privilege-preserving communications with counsel.
  • Revisit business associate inventory and downstream vendor security assurances after major enforcement themes in your sector.

Related actions

Source

U.S. Department of Health and Human Services release

Source: U.S. Department of Health and Human Services, Office for Civil Rights. medcomply.ai aggregates public materials for educational use, not legal advice.