Anne Wojcicki, the cofounder and CEO of direct-to-consumer DNA testing firm 23andMe, told 60 Minutes that she believes that her company adheres to stricter security measures than HIPAA requires.
HARRISBURG – As a result of the COVID-19 Coronavirus outbreak, State Senator Doug Mastriano (R-33) is introducing a measure calling upon the federal government to temporarily suspend the Health Insurance Portability and Accountability Act (HIPAA).
While HIPAA covered entities and business associates are required to investigate all security incidents, a '"breach" is not determined until the entities confirm that "acquisition, access, use or disclosure of PHI in a manner not permitted [under the regulations] which compromises the security or privacy of the PHI" occurred, she notes.
A dental practice has been fined $10,000 by the HHS’ Office for Civil Rights for violating Health Insurance Portability and Accountability Act (HIPAA) Rules by disclosing patients’ protected health information (PHI) on Yelp when responding to patient reviews.
CNBC later reported, and the companies confirmed, that they had signed an industry-standard agreement that allows for some sharing of protected health information under the current health privacy rules, known as HIPAA, but forbids either company from using that data for any purpose but to provide patient care.
HIPAA does govern several aspects of patient data privacy, but one of these provisions allows “covered entities” (such as a hospital or medical office subject to the law) to share data to Business Associates — which are companies that may help the covered entity carry out its health care functions.
Medico, Inc.’s IT vendor’s error left at least two Amazon buckets unsecured More than 300,000 files contained protected health information related to patient billing, complete with insurance information and treatment codes Leaks were independently discovered by at least three researchers using different search methods It’s been a rough few months in terms of business associates or third parties disclosing breaches of protected health information.