New Figures on HIPAA Privacy Enforcement

June 24, 2011
On May 12, the Office for Civil Rights ("OCR") posted new information on its website regarding the agency's resolution of HIPAA privacy complaints

On May 12, the Office for Civil Rights ("OCR") posted new information on its website regarding the agency's resolution of HIPAA privacy complaints and investigations during the first five years of HIPAA enforcement. While the data was new, it confirmed several familiar themes in HIPAA privacy enforcement:

1. Sixty-five percent of HIPAA complaints (16,528 of the 25,536 complaints filed between 2003 and 2007) were resolved after the initial intake and review stage. Most HIPAA complaints are resolved by OCR after receipt of a single response letter from the covered entity that is the subject of the complaint.

2. Of the cases that were referred for further investigation and review, OCR took "corrective action" 6,418 times and found "no violation" 2,690 times. OCR fails to explain what sorts of "corrective actions" it is taking.

3. OCR still has not imposed civil money penalties on a covered entity for a HIPAA privacy violation. Clearly, OCR's "corrective actions" have stopped short of the imposition of fines.

4. The total number of annual HIPAA privacy complaints has steadily risen each year, from 1, 508 in 2003 to 7,176 in 2007.

Given the continued rise in HIPAA privacy complaints, it is surprising that OCR has yet to find a violation meriting the imposition of penalties. Not that HIPAA covered entities are complaining …

Sponsored Recommendations

A Cyber Shield for Healthcare: Exploring HHS's $1.3 Billion Security Initiative

Unlock the Future of Healthcare Cybersecurity with Erik Decker, Co-Chair of the HHS 405(d) workgroup! Don't miss this opportunity to gain invaluable knowledge from a seasoned ...

Enhancing Remote Radiology: How Zero Trust Access Revolutionizes Healthcare Connectivity

This content details how a cloud-enabled zero trust architecture ensures high performance, compliance, and scalability, overcoming the limitations of traditional VPN solutions...

Spotlight on Artificial Intelligence

Unlock the potential of AI in our latest series. Discover how AI is revolutionizing clinical decision support, improving workflow efficiency, and transforming medical documentation...

Beyond the VPN: Zero Trust Access for a Healthcare Hybrid Work Environment

This whitepaper explores how a cloud-enabled zero trust architecture ensures secure, least privileged access to applications, meeting regulatory requirements and enhancing user...