Generated by All in One SEO Pro v4.9.7, this is an llms.txt file, used by LLMs to index the site. # PrivaPlan PrivaPlan Associates is a leading provider in HIPAA compliance, training & cybersecurity ## Sitemaps - [XML Sitemap](https://privaplan.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [Microsoft Alerts Organizations to Large-Scale Phishing Campaign](https://privaplan.com/microsoft-alerts-organizations-to-large-scale-phishing-campaign/) - Microsoft is warning about a recent sophisticated phishing campaign that targeted more than 13,000 organizations, mostly in the US. - [HIPAA-Compliant Medical Records Destruction: What Healthcare Organizations Need to Know](https://privaplan.com/hipaa-compliant-medical-records-destruction-what-healthcare-organizations-need-to-know/) - Secure destruction of PHI is one of the most overlooked and high-risk areas of HIPAA compliance. Learn what needs to be destroyed and the proper methods. - [Key Obligations Under the HIPAA Privacy Rule](https://privaplan.com/key-obligations-under-the-hipaa-privacy-rule/) - This article is about what the Privacy Rule requires, where organizations are falling short, and why 2026 may be the year it finally gets the attention it deserves. - [Healthcare Leads in AI Adoption, New Reports Show](https://privaplan.com/healthcare-leads-in-ai-adoption-new-reports-show/) - Healthcare is one of the fastest-growing sectors adopting AI, alongside technology and manufacturing, according to recent reports. - [Who Needs a HIPAA Business Associate Agreement?](https://privaplan.com/who-needs-a-hipaa-business-associate-agreement/) - Understanding Business Associates and Business Associate Agreements Navigating healthcare privacy can be tricky, especially when it comes to understanding the role of HIPAA business associates. These third-party vendors play a crucial role in keeping patient information secure and compliant, but their exact roles often go overlooked. Whether you're a healthcare provider vetting your vendors or a business - [Ambient AI Scribe & HIPAA Compliance: What Every Healthcare Clinic Needs to Know (2026)](https://privaplan.com/ai-ambient-scribes-is-your-health-care-clinic-ready/) - Learn about Ambient AI Scribes what they are, their benefits, and how your clinic can prepare for a seamless and successful integration. - [The Notice of Privacy Practices Is More Than a Form. It's a Promise.](https://privaplan.com/the-notice-of-privacy-practices-is-more-than-a-form-its-a-promise/) - Your Notice of Privacy Practices (NPP) is a small document with an outsized job. Learn more about why it deserves a refresh. - [What Healthcare Can Learn from the Stryker Cyberattack ](https://privaplan.com/what-healthcare-can-learn-from-the-stryker-cyberattack/) - Learn key cybersecurity lessons from the Stryker cyberattack, including vendor risk, operational disruption, and strategies for building cyber resilience. - [Health Care Cybersecurity and Resiliency Act Advances in Senate](https://privaplan.com/health-care-cybersecurity-and-resiliency-act-advances-in-senate/) - If enacted, it would require HHS to develop a cybersecurity incident response plan and strengthen oversight of cybersecurity in healthcare and public health. - [New Jersey Expands HIPAA-Based Exemptions Under Privacy Law](https://privaplan.com/new-jersey-expands-hipaa-based-exemptions-under-privacy-law/) - New Jersey joins Colorado, Oregon, and Minnesota in adopting a data-level approach to HIPAA-based exemptions within comprehensive privacy laws. - [LastPass Issues Warning Amid Rising Phishing Attacks on Password Managers](https://privaplan.com/lastpass-issues-warning-amid-rising-phishing-attacks-on-password-managers/) - Password managers are one of the most effective defenses against weak credentials, but attackers are increasingly impersonating trusted platforms like LastPass. - [OpenAI for Healthcare Launches: What You Need to Know](https://privaplan.com/openai-for-healthcare-launches-what-you-need-to-know/) - OpenAI for Healthcare is an enterprise-focused suite that enables healthcare organizations to adopt AI without relying on consumer-grade tools that introduce compliance risk. - [OCR Enforcement of SUD Privacy Rules Begins February 16, 2026](https://privaplan.com/ocr-enforcement-of-sud-privacy-rules-begins-february-16-2026/) - Are you ready for the HIPAA 42 CFR Part 2 updates? Health organizations who treat substance abuse disorders must fully comply by February 16, 2026. - [What ChatGPT Health Means for Healthcare Providers and Data Privacy](https://privaplan.com/what-chatgpt-health-means-for-healthcare-providers-and-data-privacy/) - Generative AI is rapidly becoming part of the healthcare information ecosystem with important implications for data governance. - [NCA Predicts Cybersecurity Threats in 2026](https://privaplan.com/nca-predicts-cybersecurity-threats-in-2026/) - The greatest risks in 2026 will stem from human behavior, misuse of technology, and habits lagging behind our digital reality - [Where Healthcare Is Using AI: 2025 Report](https://privaplan.com/where-healthcare-is-using-ai-2025-report/) - Healthcare organizations are accelerating their use of AI to improve efficiency and ease administrative burden, according to new research. - [Health Information Under HIPRA: How the New Privacy Act Will Reshape Apps and Consumer Data](https://privaplan.com/health-information-under-hipra-how-the-new-privacy-act-will-reshape-apps-and-consumer-data/) - Learn how the proposed Health Information Privacy Reform Act (HIPRA) expands health data protections beyond HIPAA and how healthcare organizations can prepare. - [Proposed Updates to the HIPAA Security Rule Still Pending](https://privaplan.com/proposed-updates-to-the-hipaa-security-rule-still-pending/) - Proposed updates to the HIPAA Security Rule are pending, but the direction is clear: HHS is raising the baseline for protecting ePHI. Make sure you're ready. - [HHS Unveils New AI Strategy to Transform Agency Operations](https://privaplan.com/hhs-unveils-new-ai-strategy-to-transform-agency-operations/) - HHS released a new strategy on Dec. 4 to expand AI use across internal operations, research programs, health agencies, and public-health activities. - [Understanding Adobe Cloud's Business Associate Agreement for Health Care](https://privaplan.com/understanding-adobe-clouds-business-associate-agreement-for-health-care/) - Which Adobe products are HIPAA compliant and need a Business Associate Agreement (BAA) for a health care business to use them? - [Ensuring HIPAA Compliance in Generative AI Systems](https://privaplan.com/ai-guide-for-hipaa/) - Your Essential Guide for maximizing the impact of generative AI without compromising HIPAA Security compliance. - [Managing Cybersecurity Risks in Healthcare APIs](https://privaplan.com/managing-cybersecurity-risks-in-healthcare-apis/) - Healthcare APIs are the quiet couriers of healthcare data. They make sure a doctor’s click in a patient portal instantly fetches lab results from an EHR and that diagnostic images appear seamlessly on clinical dashboards. - [OCR Issues New HIPAA Privacy Rule FAQs ](https://privaplan.com/ocr-issues-new-hipaa-privacy-rule-faqs/) - The HHS OCR has released new and updated guidance on specific parts of the HIPAA Privacy Rule in the form of frequently asked questions. - [The Hidden Danger of Forgotten Service Accounts](https://privaplan.com/the-hidden-danger-of-forgotten-service-accounts/) - Forgotten, out-of-date or orphaned, service accounts refer to accounts whose credentials have expired or are no longer valid. - [AI Fuels Surge in Fake Sites Ahead of Holidays](https://privaplan.com/ai-fuels-surge-in-fake-sites-ahead-of-holidays/) - Fake Amazon and eBay sites are surging ahead of Black Friday as AI makes it easier for scammers to clone websites without coding skills. - [Cyberattacks Increasingly Linked to Patient Care Disruptions ](https://privaplan.com/cyberattacks-increasingly-linked-to-patient-care-disruptions/) - Cyberattacks in healthcare reach far beyond IT systems. A new study reveals that these incidents increasingly disrupt patient care and clinical operations. - [Colorado Healthcare Facilities Experience Surge in Suspicious Phone Calls](https://privaplan.com/colorado-healthcare-facilities-experience-surge-in-suspicious-phone-calls/) - Colorado healthcare organizations face a surge in suspicious calls, hinting at reconnaissance efforts to disrupt operations and strain frontline staff. - [Mount Sinai Settles Web Trackers Privacy Claim for $5.3M](https://privaplan.com/mount-sinai-settles-web-trackers-privacy-claim-for-5-3m/) - Healthcare organizations are learning that they must be aware of web trackers and have a clear understanding of what data is being collected. - [Joint Commission Releases AI Guidance for Healthcare](https://privaplan.com/joint-commission-releases-ai-guidance-for-healthcare/) - The Joint Commission and the CHAI issued their first joint guidance on the responsible use of AI in healthcare to help hospitals adopt the technology safely. - [AI Helpers Pose New Cybersecurity Risks](https://privaplan.com/os-agents-pose-new-cybersecurity-risks/) - Recent studies highlight potential security risks associated with OS agents being able to control devices and access sensitive information. - [Postcard Error May Have Exposed PHI at Michigan Medicine](https://privaplan.com/postcard-error-may-have-exposed-phi-at-michigan-medicine/) - A postcard sent without an envelope possibly exposed patient health information, highlighting the importance of staying HIPAA compliant with all mail pieces. - [The AI Security Surge: Why Compliance with the HIPAA Security Rule Can't Wait](https://privaplan.com/the-ai-security-surge-why-compliance-with-the-hipaa-security-rule-cant-wait/) - In this article, we explore why HIPAA compliance is more important in the era of AI and how organizations can effectively apply the HIPAA Security Rule to... - [Syracuse ASC Pays $250K Fine for Alleged HIPAA Violations](https://privaplan.com/syracuse-asc-pays-250k-fine-for-alleged-hipaa-violations/) - A New York surgery center has agreed to pay a $250,000 penalty for potential violations of the HIPAA Security and Breach Notification Rules. - [HIPAA Policy Templates Toolkit](https://privaplan.com/hipaa-toolkit/) - The HIPAA Toolkit is an essential resource with customizable templates and comprehensive resources, the Toolkit makes it easy to meet HIPAA regulations. - [Microsoft Says Chinese Hackers Exploited SharePoint Flaws](https://privaplan.com/microsoft-says-chinese-hackers-exploited-sharepoint-flaws/) - Microsoft accuses Chinese hackers of exploiting flaws in the SharePoint document management software on in-house servers. - [Health Care Sector Urged to be Cyber Vigilant Ahead of July 4th](https://privaplan.com/health-care-sector-urged-to-be-cyber-vigilant-ahead-of-july-4th/) - Leading up to Independence Day, health care organizations are advised to brace for potential cyberattacks from Iranian state-sponsored or affiliated actors. - [FBI Warns: North Korean IT Workers Conduct Data Extortion](https://privaplan.com/fbi-warns-north-korean-it-workers-conduct-data-extortion/) - The FBI issues a new warning about North Korean IT workers regarding their increasingly malicious activities, which now include data extortion. - [Remote Workers Access Patient Data Using False Identities](https://privaplan.com/remote-workers-access-patient-data-using-false-identities/) - Sentara Health has confirmed that two remote workers using false identities may have accessed sensitive patient information from January to April 10, 2025. - [New Executive Order to Strengthen Cybersecurity Defenses ](https://privaplan.com/new-executive-order-to-strengthen-cybersecurity-defenses/) - President Donald Trump signed a new executive order to update and consolidate U.S. cybersecurity policy in response to increasing global cyber threats. - [Study Finds Hacking Behind 88% of Patient Record Breaches](https://privaplan.com/study-finds-hacking-behind-88-of-patient-record-breaches/) - A new study shows hacking drives most health care data breaches. The recent Kettering Health ransomware attack proves the threat is far from over. - [The Hidden Cost of Undisclosed Tracking Pixels: Lost Trust, Big Fines](https://privaplan.com/the-hidden-cost-of-undisclosed-tracking-pixels-lost-trust-big-fines/) - Regulators and consumers are responding to companies that don't disclose the use of tracking pixels on their websites with lawsuits and costly fines. - [Verizon 2025 Report: Ransomware and Third-Party Breaches Rise](https://privaplan.com/verizon-2025-report-ransomware-and-third-party-breaches-rise/) - Verizon’s newly released 2025 Data Breach Investigations Report (DBIR) reveals several unsettling trends in cybersecurity. - [PrivaPlan Releases Essential Guide for AI and HIPAA Security Compliance](https://privaplan.com/privaplan-releases-essential-guide-for-ai-and-hipaa-security-compliance/) - PrivaPlan has released a critical new resource to help health care organizations navigate the adoption of generative AI while staying fully HIPAA compliant. - [Phishing Tops the IRS Dirty Dozen Tax Scams](https://privaplan.com/phishing-tops-the-irs-dirty-dozen-tax-scams/) - Scammers are relentless as the IRS continues to see a surge of email and text scams designed to steal personal and financial information. - [Business Associate Fined for Alleged Risk Analysis Failure](https://privaplan.com/business-associate-fined-for-alleged-risk-analysis-failure/) - The OCR’s investigation determined that Health Fitness violated the HIPAA Security Rule’s Risk Analysis provision protecting ePHI. - [Security Reminder Advised After Amazon Echo News](https://privaplan.com/security-reminder-advised-after-amazon-echo-news/) - Amazon will remove the "Do Not Send Voice Recordings" privacy feature for Echo speakers on March 28, raising security concerns for HIPAA-covered entities. - [FBI Warns of Mail Scam Targeting Healthcare](https://privaplan.com/fbi-warns-of-mail-scam-targeting-healthcare/) - The FBI reports that recent letters to healthcare organizations threatening to leak patient data for ransom appear to be a hoax. - [Comments Deadline Closes for HIPAA Security Rule Proposed Changes](https://privaplan.com/comments-deadline-closes-for-hipaa-security-rule-proposed-changes/) - The HIPAA Security Rule comment deadline was March 7. Experts urge healthcare groups to adopt cybersecurity best practices now. - [Warby Parker to Pay $1.5 Million for HIPAA Violations](https://privaplan.com/warby-parker-to-pay-1-5-million-for-hipaa-violations/) - The OCR announced its first financial penalty of 2025 for HIPAA violations regarding the ePHI of nearly 200,000 individuals. - [Callback Phishing Attacks Surge](https://privaplan.com/callback-phishing-attacks-surge/) - As callback phishing attacks rise, it's critical to recognize the tactics threat actors employ and how to avoid being fooled. - [Are AI Chatbots Safe? 9 Expert Tips for Secure Usage](https://privaplan.com/are-ai-chatbots-safe-9-expert-tips-for-secure-usage/) - Whether you're using DeepSeek, ChatGPT, or any other AI chatbot, following security best practices can help protect your personal and professional data. - [Biden Signs Executive Order to Advance AI Infrastructure](https://privaplan.com/biden-signs-executive-order-to-advance-ai-infrastructure/) - During his final week in the Oval Office, President Joe Biden issued a new Executive Order to advance U.S. leadership in AI infrastructure. - [2025 Cybersecurity Outlook: Challenges and Preparedness](https://privaplan.com/2025-cybersecurity-outlook-challenges-and-preparedness/) - The National Cybersecurity Alliance released its predictions for cybersecurity challenges in 2025, with incidents experienced in 2024 expected to rise. - [Strengthening ePHI Security: Insights on the Latest HIPAA Rulemaking](https://privaplan.com/strengthening-ephi-security-insights-on-the-latest-hipaa-rulemaking/) - Learn about the proposed HIPAA Security Rule to enhance cybersecurity and improve ePHI security. - [Secure Your Phone: Lessons from the Chinese Telecom Hack](https://privaplan.com/secure-your-phone-lessons-from-the-chinese-telecom-hack/) - The FBI and CISA urge Americans to encrypt their phones following a cyberattack on U.S. telecom giants by the Chinese cyber espionage group Salt Typhoon. - [Follow 4 Simple Steps to Stay Cyber Secure](https://privaplan.com/follow-4-simple-steps-to-stay-cyber-secure/) - Cybercriminals often gain access because employees overlook essential online safety practices. Here are four key steps to reduce the risk of cyberattacks - [Prepare for the Upcoming HIPAA Deadline](https://privaplan.com/prepare-for-the-upcoming-hipaa-deadline/) - By December 23, 2024, HIPAA-covered entities and their business associates must comply with the HIPAA Privacy Rule to Support Reproductive Health Care Privacy. - [Do You Use Any of the Top Common Passwords?](https://privaplan.com/do-you-use-any-of-the-top-common-passwords/) - A new report reveals the top common passwords used at home and work. Learn why they're easy to hack and how to stay safe. - [Online Holiday Shoppers Beware: 2024 Threats](https://privaplan.com/online-holiday-shoppers-beware-2024-threats/) - Social engineering activity is predicted to be rampant during the 2024 holiday period, along with phishing scams. Shop safely online! - [New Advisory Warns of Surge in Zero-Day Exploits](https://privaplan.com/new-advisory-warns-of-surge-in-zero-day-exploits/) - Cybersecurity advisory warns that malicious cyber actors are increasingly exploiting zero-day vulnerabilities to compromise enterprise networks. - [QR Code Phishing Attacks Surge in 2024](https://privaplan.com/qr-code-phishing-attacks-surge-in-2024/) - QR code phishing has surged up to 270% monthly as cybercriminals begin using QR codes in PDF attachments to fool employees. - [Ransomware Attacks in Healthcare Disrupt Emergency Care](https://privaplan.com/ransomware-attacks-in-healthcare-disrupt-emergency-care/) - Ransomware attacks have increased by 300% since 2015, and the consequences go beyond data being held hostage; people's lives are at risk. - [OCR Imposes $240,000 Fine in Ransomware Case](https://privaplan.com/ocr-imposes-240000-fine-in-ransomware-case/) - Providence Medical fined $240K for HIPAA violations after a ransomware attack. Learn key steps to protect patient data and avoid breaches. - [PCI Compliance and Third-Party Trackers: Risks, Challenges, and Best Practices](https://privaplan.com/pci-compliance-and-third-party-trackers-risks-challenges-and-best-practices/) - How do website trackers put your PCI compliance at risk? Third-party trackers introduce potential security risks and the possibility of a compliance breach. - [Malvertising Campaigns Target Google Ads](https://privaplan.com/malvertising-campaigns-target-google-ads/) - Malvertising is on the rise! Discover how hackers use fake Google ads in searches and learn top tips to protect yourself from threats. - [Ransomware Group Targets Healthcare Via Phishing](https://privaplan.com/ransomware-group-targets-healthcare-via-phishing/) - A joint cybersecurity advisory warns that RansomHub is using phishing attacks to hack healthcare organizations and other critical infrastructure sectors. - [CrowdStrike Outage Prompts Microsoft Security Summit](https://privaplan.com/crowdstrike-outage-prompts-microsoft-security-summit/) - Microsoft will hold the Windows Endpoint Security Ecosystem Summit to improve Windows security after CrowdStrike outage. - [What is the Privacy Impact of Website Tracking Technologies?](https://privaplan.com/what-is-the-privacy-impact-of-website-tracking-technologies/) - Are you aware of the third-party web trackers lurking on your website? Effective website management involves more than just routine content updates. - [Delayed Access to Patient Records Proves Costly](https://privaplan.com/delayed-access-to-patient-records-proves-costly/) - AMR paid a civil monetary penalty of $115,200 to the OCR for failing to provide a patient with timely access to her medical records. - [CrowdStrike Outage Could Cost Health Care $1.9B](https://privaplan.com/crowdstrike-outage-could-cost-health-care-1-9b/) - Following the July 19 CrowdStrike IT outage, Fortune 500 companies in the health care sector are expected to suffer the largest direct financial losses. - [Is Adobe's New Terms of Service Agreement HIPAA Compliant?](https://privaplan.com/is-adobes-new-terms-of-service-agreement-hipaa-compliant/) - Adobe's recent updates to its terms of service agreement, is causing confusion about whether the new terms encompass HIPAA compliance - [Website Compliance Tracking](https://privaplan.com/trackerreveal/) - Ensure Website Compliance with TrackerReveal by PrivaPlan | Powered by Cyndelos - [What's On Your Website?](https://privaplan.com/whats-on-your-website/) - The partnership combines PrivaPlan's industry-leading guidance with Cyndelos' AI technology to pinpoint website vulnerability and uphold website compliance. - [Changes to Health Breach Notification Rule Begin in July](https://privaplan.com/changes-to-health-breach-notification-rule-begin-in-july/) - FTC Health Breach Notification Rule changes take effect July 29 to strengthen and clarify how it applies to health apps and technologies not covered HIPAA. - [HIPAA Privacy Rule to Support Reproductive Health Care Privacy is in Effect](https://privaplan.com/hipaa-privacy-rule-to-support-reproductive-health-care-privacy-is-in-effect/) - The HIPAA Privacy Rule to Support Reproductive Health Care Privacy is now in effect, prohibiting the disclosure of PHI in certain circumstances. - [Prepare for Upcoming HIPAA Security Rule Updates](https://privaplan.com/prepare-for-upcoming-hipaa-security-rule-updates/) - This spring the HHS plans to begin HIPAA Security Rule updates to improve cyber resiliency and protect patient safety, based on its December concept paper. - [Phishing Attacks Fool LastPass Users](https://privaplan.com/phishing-attacks-fool-lastpass-users/) - LastPass warns users about a new phase of a phishing campaign that uses email, SMS, and calls to trick targets into divulging their master passwords. - [Ascension Confirms Ransomware Attack](https://privaplan.com/ascension-confirms-ransomware-attack/) - Ascension Health System says a ransomware attack is responsible for disrupting EHR systems and other clinical services at its 140 hospitals. - [Kaiser Permanente Notifies Members of Data Breach](https://privaplan.com/kaiser-permanente-notifies-members-of-data-breach/) - Kaiser Permanente is notifying 13.4 million current and former health plan members of a data breach traced to tracking technologies. - [Final Rule to Support Reproductive Health Care Privacy Takes Effect June 25](https://privaplan.com/final-rule-to-support-reproductive-health-care-privacy-takes-effect-june-25/) - Learn what it means when the HIPAA Privacy Rule to Support Reproductive Health Care Privacy (Final Rule) goes into effect on June 25, 2024. - [Why Having a Website Tracking Tool is Essential](https://privaplan.com/why-having-a-website-tracking-tool-is-essential/) - New requirements set by the FTC and the PCI DSS V4.0 make website tracking tools like TrackerReveal essential to the financial industry and consulting sectors. - [Ascension Ransomware Incident Tied to Employee Mistake](https://privaplan.com/ascension-ransomware-incident-tied-to-employee-mistake/) - The cause of the Ascension ransomware attack on May 8 is being linked to one employee who made a mistake. - [Is Your Organization Ready for the HIPAA 42 CFR Part 2 Updates?](https://privaplan.com/is-your-organization-ready-for-the-hipaa-42-cfr-part-2-updates/) - Discover how recent HIPAA 42 CFR Part 2 regulation updates impact healthcare providers and ensure compliance of Substance Use Disorder (SUD) treatment records. - [Threat Actors Target Healthcare IT Help Desks](https://privaplan.com/threat-actors-target-healthcare-it-help-desks/) - The US Health Department recently issued a warning regarding financially-motivated social engineering attacks targeting healthcare IT help desks. - [Is Your Website Data HIPAA Compliant?](https://privaplan.com/is-your-website-data-hipaa-compliant/) - Since the HHS has determined that website tracking technologies can result in the collection of data that violates the HIPAA Privacy Rule, officials responsible - [Policies & Procedures Development](https://privaplan.com/policies-procedures/) - We work with you to create individual and unique specifications for policies & procedures development that fit your organization’s needs. - [HIPAA Breach Notification](https://privaplan.com/hipaa-breach-notification/) - We offer guidance for HIPAA Breach Notification or choose to have one of our professional associates manage the notification for you. - [Managed Phishing](https://privaplan.com/managed-phishing/) - Create long-term security literacy and protect your workforce with our reliable and trusted managed phishing & cybersecurity awareness services. - [Data Governance](https://privaplan.com/data-governance/) - Leverage your organization and data with a data governance framework. Data governance allows you to proactively mitigate risk while increasing data productivity. - [HIPAA Privacy Compliance Review](https://privaplan.com/hipaa-privacy-compliance/) - Gather a complete picture of your HIPAA Privacy Compliance standards with our comprehensive assessment that shows your vulnerabilities and how to remediate them. - [HIPAA Security Risk Analysis](https://privaplan.com/hipaa-security-risk/) - We offer full HIPAA Security Risk Analysis program that adapts to your organizational needs with onsite and remote options. - [Disaster & Recovery Planning](https://privaplan.com/disaster-recovery-planning/) - What will you do when disaster strikes? Effective disaster recovery planning and testing keeps you focused on your business when disaster strikes. - [HIPAA Certification Program](https://privaplan.com/hipaa-certification-program/) - We provide the most comprehensive HIPAA certification and training in the field. This includes our library of HIPAA training and security reminder videos. - [HIPAA Education & Literacy Training](https://privaplan.com/hipaa-education-training/) - We create customized HIPAA Education & Literacy Compliance Training for all types of covered entities or business associates. - [Vendor Risk Assessment](https://privaplan.com/vendor-risk-assessment/) - Meet your business needs by understanding your vendor's security protocols, compliance efforts, and potential risks with a vendor risk assessment. - [Privacy Risk Assessments](https://privaplan.com/privacy-risk-assessment/) - Assess and enhance your compliance standards with our detailed Privacy Risk Assessment! - [Government Agencies Release Advisory on Play Ransomware](https://privaplan.com/government-agencies-release-advisory-on-play-ransomware/) - Today, the FBI, CISA, and ASD's ACSC released a joint Cybersecurity Advisory (CSA) regarding Play ransomware with recommendations for mitigating incidents. - [ONC Releases Draft Health IT Plan for Comment](https://privaplan.com/onc-releases-draft-health-it-plan-for-comment/) - Health IT plan aims to cultivate a healthier, more innovative, and equitable healthcare experience by steering federal efforts in healthcare IT. - [OCR Revises Guidance for Using Tracking Technologies](https://privaplan.com/ocr-revises-guidance-for-using-tracking-technologies/) - OCR releases revised guidance to make it perfectly clear to regulated entities that online tracking technologies are subject to HIPAA Rules. - [Lessons from the Change Healthcare Cyberattack Incident](https://privaplan.com/lessons-from-the-change-healthcare-cyberattack-incident/) - The recent Change Healthcare cyberattack highlights the growing problem of cyber threats against healthcare organizations. - [OCR Releases HIPAA Compliance and Data Breaches Reports](https://privaplan.com/ocr-releases-hipaa-compliance-and-data-breaches-reports/) - The OCR's annual reports on HIPAA Compliance and Data Breaches of PHI show 17% more HIPAA complaints and a 107% increase in large breaches over four years. The OCR's annual reports on HIPAA Compliance and Data Breaches of PHI show 17% more HIPAA complaints and a 107% increase in large breaches over four years. - [New HIPAA Requirements for Website Analytics](https://privaplan.com/new-hipaa-requirements-for-website-analytics/) - Are your website analytics HIPAA compliant? This is the question healthcare organizations need to start asking. - [Top Cybersecurity Threat Predictions for 2024](https://privaplan.com/top-cybersecurity-threat-predictions-for-2024/) - Experts predict cybersecurity threats will gain momentum worldwide in 2024. Here are the top threats. - [Holiday Hackers Count on Impulse Clicks](https://privaplan.com/holiday-hackers-count-on-impulse-clicks/) - It’s the most wonderful time of the year for cybercriminals to take advantage of impulse clicks, especially by those awaiting the delivery of holiday packages. - [The Hidden Risks of QR Codes & How to Stay Secure](https://privaplan.com/the-hidden-risks-of-qr-codes-how-to-stay-secure/) - QR codes have become a popular target for malicious actors looking to steal information. Discover security measures you can take to protect yourself. - [US Joins Global Effort to Secure AI Systems](https://privaplan.com/us-joins-global-effort-to-secure-ai-systems/) - The United States and 18 other countries released the first detailed global agreement on Nov. 26 to secure AI systems from rogue actors. - [AI Makes Phishing Scams Seem Legitimate](https://privaplan.com/ai-makes-phishing-scams-seem-legitimate/) - AI helps hackers write in perfect English, making phishing emails seem legitimate. This trend may contribute to a surge in online scams during the holidays. - [Tech Pros Needed as Healthcare Cyber Threats Rise](https://privaplan.com/tech-pros-needed-as-healthcare-cyber-threats-rise/) - Rising cyber threats in healthcare fuel the need for more tech and security professionals to tackle this dangerous trend. - [SEC's Cybersecurity Disclosure Rules Start Soon](https://privaplan.com/sec-cybersecurity-disclosure-rules-start-soon/) - The SEC's cybersecurity disclosure rules go into effect in December, but many publicly traded companies aren’t waiting to comply. - [Executive Order Sets Standards for AI Safety](https://privaplan.com/executive-order-sets-standards-for-ai-safety/) - The Executive Order issued by President Biden includes the most sweeping actions ever taken to protect Americans from the potential risks of AI systems. - [Board-Level Cybersecurity Committees on the Rise](https://privaplan.com/board-level-cybersecurity-committees-on-the-rise/) - 78% of CISOs and other security leaders surveyed say there are dedicated board-level cybersecurity committees at their organizations. - [OCR Provides Guidance for Safe Telehealth Use](https://privaplan.com/ocr-provides-guidance-for-safe-telehealth-use/) - The OCR/HHS issued resources to help patients understand the privacy and security risks when using telehealth services and how to reduce the risks. - [Microsoft AI Employee Accidentally Exposes 38TB of Private Data](https://privaplan.com/microsoft-ai-employee-accidentally-exposes-38tb-of-private-data/) - Corporate secrets, passwords, & over 30,000 internal Microsoft Teams messages lost their cloak of invisibility when Microsoft AI researchers misconfigured a URL - [PrivaPlan's CEO David Ginsberg Receives Distinguished Award From WEDI!](https://privaplan.com/privaplan-ceo-david-ginsberg-award-wedi/) - At their 2012 Fall Conference, the Workgroup for Electronic Data Interchange (WEDI) awarded a distinguished service award to David Ginsberg our CEO of PrivaPlan. - [Google Introduces AI Search Capabilities for Clinicians](https://privaplan.com/google-introduces-ai-search-capabilities-for-clinicians/) - Google says its new AI-powered search tool will help clinicians access information from different data sources quickly and reduce provider burnout. - [NSA and CISA Identify Top 10 Cybersecurity Misconfigurations](https://privaplan.com/nsa-and-cisa-identify-top-10-cybersecurity-misconfigurations/) - #post_excerptNSA and CISA assessments of large company networks identify the 10 most common cybersecurity misconfigurations. - [Penetration Testing](https://privaplan.com/penetration-testing/) - Safeguarding digital assets ensures organizational resilience against cyber threats. Invest in penetration testing services today and fortify your defenses against evolving threats. - [Protecting Organizational Reputation with Two-Step Verification](https://privaplan.com/protecting-organizational-reputation-with-two-step-verification/) - Two-step verification has become a key element in enhancing security and business reputation. - [Achieve HIPAA Compliance Easily with PrivaPlan's Toolkit](https://privaplan.com/achieve-hipaa-compliance-easily-with-privaplans-toolkit/) - Stay up-to-date with your HIPAA regulations with PrivaPlan's Toolkit. Toolkit contains all the tools and resources you need to achieve HIPAA compliance. - [How To Recognize Phishing Scams](https://privaplan.com/how-to-recognize-phishing-scams/) - Are you familiar with the concept of phishing and its impact on data security? Do you know what phishing is and why it's such an important topic for healthcare workforce members? With some essential facts and tips about phishing, you can help keep your workforce and patient information safe from attackers. What is Phishing? - [Why Password Strength is Essential to Your Security](https://privaplan.com/why-password-strength-is-essential-to-your-security/) - Examining password strength is the easiest way to maintain healthy security standards and can be the first line of defense to prevent unauthorized access. - [OCR Holds Healthcare Provider Accountable for HIPAA Right of Access](https://privaplan.com/ocr-holds-healthcare-provider-accountable-for-hipaa-right-of-access/) - It took five months for a dentist's office to provide requested medical records. And that was only after the Office for Civil Rights (OCR) investigated the complaint. - [What the OCR Has to Say About Data Security and Patient Privacy](https://privaplan.com/what-the-ocr-has-to-say-about-data-security-and-patient-privacy/) - Find out what the Office for Civil Rights in HSS has said about data security, patient privacy, and how healthcare providers should respond. - [Failure to Run a HIPAA Security Risk Analysis Gets Costly](https://privaplan.com/failure-to-run-a-hipaa-security-risk-analysis-gets-costly/) - Effective HIPAA security risk analysis is the first step in implementing all of the HIPAA Security Rule requirements. - [Supreme Court Ruling Leads to New OCR Guidance for Patient Privacy and PHI](https://privaplan.com/ocr-guidance/) - Itʼs important to familiarize yourself with how the Supreme Court Ruling affects patient privacy and PHI and reading through the OCRʼs new guidance is a good step. - [Are You Ready for the Internet Explorer 11 Retirement?](https://privaplan.com/are-you-ready-for-the-internet-explorer-11-retirement/) - June 13, 2022 - [What HIPAA Sanctions and Penalties are Waived in Declared Emergencies?](https://privaplan.com/what-hipaa-sanctions-and-penalties-are-waived-in-declared-emergencies/) - rivacy issues during declared disasters: You should know when some HIPAA requirements are set aside or modified to better serve those who might otherwise suffer. - [The Great Resignation Has Great Consequences on Your Data: 3 Tips for Protecting Data When Employees Quit](https://privaplan.com/the-great-resignation-has-great-consequences-on-your-data3-tips-for-protecting-data-when-employees-quit/) - Quitters. They’re everywhere. At least this is true concerning the Great Resignation where, in the past few years, millions have quit their jobs to seek out higher pay or better employment. If you are worried that former employees may still know how to access your data, these 3 steps will help. - [The 5 enemies of healthcare IT security](https://privaplan.com/healthcare-it-security/) - We know we have an important job to do in healthcare IT, especially in keeping the greedy little hands of cyber attackers out of the personal files of patients and providers. A recently released report from Critical Infrastructure Technology backs this up. - [Phishing campaign uses PDF attachments](https://privaplan.com/phishing-campaign-uses-pdf-attachments/) - The SANS Internet Storm Center warns about an active phishing campaign that utilizes PDF attachments to harvest email credentials from victims. - [Google Docs used in latest phishing attack](https://privaplan.com/google-docs-used-in-latest-phishing-attack/) - A widespread phishing attack using Google Docs is currently hitting inboxes. This is a good time to be extra cautious about clicking links. - [PrivaPlan advises rural health care staff to train, train and retrain](https://privaplan.com/privaplan-advises-rural-health-care-staff-to-train-train-and-retrain/) - Train, train and retrain is at the top of PrivaPlan’s list of practical solutions for being HIPAA compliant. - [Health Sector Cybersecurity Coordination Center opens](https://privaplan.com/health-sector-cybersecurity-coordination-center-opens/) - The Health Sector Cybersecurity Coordination Center underscores HHS’ commitment to support and improve the health sector’s cybersecurity defenses. - [Email breaches in three states expose protected health information](https://privaplan.com/email-breaches-in-three-states-expose-protected-health-information/) - Three email system breaches in three states exposed protected health information and each healthcare entity is stepping up efforts so it won't happen again. - [HHS reduces maximum civil penalties for HIPAA violations](https://privaplan.com/hhs-reduces-maximum-civil-penalties-for-hipaa-violations/) - The HHS published a Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties that changes the interpretation of fines for violations defined under the HITECH Act, effectively reducing some of the annual limits. - [Are your Business Associates protecting your patient data?](https://privaplan.com/are-your-business-associates-protecting-your-patient-data/) - This week, American Medical Collection Agency (AMCA), the billing collections vendor for both Quest Diagnostics and LabCorp, reported to both companies that the data of nearly 20 million customers may have been compromised. - [HHS releases proposal to overhaul patient privacy rules for addiction treatment](https://privaplan.com/hhs-releases-proposal-to-overhaul-patient-privacy-rules-for-addiction-treatment/) - The Department of Health and Human Services (HHS) announced proposed changes late last week to the federal regulations governing the confidentiality of patient records created by federally-assisted substance use disorder treatment programs, known as 42 CFR Part 2. Drafted in 1975, 42 CFR Part 2 was designed to protect patient records created by federally-assisted programs - [Smishing Is To Texts What Phishing Is To Emails And It’s Getting Worse](https://privaplan.com/smishing-is-to-texts-what-phishing-is-to-emails-and-its-getting-worse/) - Smishing attacks are on the rise, capable of stealing credentials and distributing malware right into that device in the palm of your hand – your phone. The term smishing is a combination of "SMS" (short message services, widely referred to as texting) with phishing. - [U.S. Government Announces New One-Stop Ransomware Website](https://privaplan.com/u-s-government-announces-new-one-stop-ransomware-website/) - The U.S. Government has launched a new website touted as a “One-Stop Location to Stop Ransomware.” Aptly named, StopRansomeware.gov, it is designed to help public and private organizations defend against the rise in ransomware cases. - [Be Aware of Cyber Criminals During Amazon Prime Day](https://privaplan.com/be-aware-of-cyber-criminals-during-amazon-prime-day/) - Along with all the legitimate promotions that continue to pop up on your screen from Amazon, the bad guys are also sending special deals to lure enthusiastic online shoppers into various phishing campaigns... - [Vendor Mistakes Are Being Blamed for Latest Data Breaches](https://privaplan.com/vendor-mistakes-are-being-blamed-for-latest-data-breaches/) - CVS Health and Volkswagen have been contacting millions of their customers to tell them that their personal information has been exposed. In two separate incidences, both companies were recently alerted that vendor errors compromised their data. - [New COVID-19 vishing scam targets nursing homes](https://privaplan.com/new-covid-vishing-scam-targets-nursing-homes/) - A new COVID-19 phone scam is targeting nursing homes in the Midwest. Called vishing, these phone calls use the guise of test results to steal personal information. - [The COVID-19 Vaccine Phishing Campaigns are Here](https://privaplan.com/the-covid-19-vaccine-phishing-campaigns-are-here/) - The COVID-19 vaccines began arriving in U.S. hospitals this week, and as expected, the phishing campaigns are in full force, with an increase in suspicious texts or emails claiming to have information about the vaccine in exchange for personal information. - [OCR Proposes Big Changes to HIPAA Privacy Rule](https://privaplan.com/ocr-proposes-big-changes-to-hipaa-privacy-rule/) - This week, the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) released proposed changes to the HIPAA Privacy Rule that would “break down barriers that have stood in the way of commonsense care coordination and value-based arrangements for far too long,” according HHS Secretary Alex Azar. - [Alert: Imminent and increased threat of cybercrime attacks against healthcare industry](https://privaplan.com/alert-imminent-and-increased-threat-of-cybercrime-attacks-against-healthcare-industry/) - The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Department of Health and Human Services (HHS) issued a Joint Cybersecurity Advisory October 28 siting “credible information” they have on an “imminent and increased” threat of cybercrime attacks against the US healthcare industry with the goal of locking down systems, stealing data, and extorting money. - [Sign up now for Oct. 27th Webinar: Managing Cybersecurity During a Pandemic](https://privaplan.com/sign-up-now-for-oct-27th-webinar-managing-cybersecurity-during-a-pandemic/) - BlueNovo and PrivaPlan will provide tips and tricks to safeguard your systems and people. - [Alert: Postcard Disguised as Official OCR Communication is in the Mail](https://privaplan.com/alert-postcard-disguised-as-official-ocr-communication-is-in-the-mail/) - Though the postage is marked first class, the mailer’s intent is not. In fact, it is another low-class act by scammers. The United States Office for Civil Rights (OCR) released a statement on August 6 about postcards that are being sent to health care organizations disguised as official OCR communications, claiming to be notices of a mandatory HIPAA compliance risk assessment. - [OCR Ensures Patients Can Receive Religious Visitations During COVID-19 in a Maryland Health System](https://privaplan.com/ocr-ensures-patients-can-receive-religious-visitations-during-covid-19/) - Tuesday the Office for Civil Rights (OCR) at the U.S Department of Health and Human Services (HHS) announced the resolution of a religious discrimination complaint against Prince George’s Hospital Center of the University of Maryland Medical System (UMMS) after UMMS adopted new policies ensuring clergy access to patients for religious purposes during the COVID-19 pandemic. - [Microsoft Warns of COVID-19 Phishing Attack via Excel](https://privaplan.com/microsoft-warns-of-covid-19-phishing-attack-via-excel/) - Microsoft is warning users about a phishing attack with an infected Excel email attachment that can wreak major havoc when opened. - [OCR Warns There is an Individual Posing as OCR Investigator](https://privaplan.com/ocr-warns-there-is-an-individual-posing-as-ocr-investigator/) - On April 3, the Office for Civil Rights (OCR) issued an alert that an individual posing as an OCR Investigator has contacted HIPAA covered entities in an attempt to obtain protected health information (PHI). - [Cyberthreats are lurking in COVID-19 pandemic](https://privaplan.com/cyber-attacks-rise-with-pandemic-be-aware-of-phishing-threats/) - “As more of our employees work from home and are under the collective stress of the COVID-19 pandemic we become easy victims,” said David Ginsberg, PrivaPlan president. “Security reminders and awareness at this time are essential.” - [Best HIPAA Practices Working From Home During the COVID-19 Emergency](https://privaplan.com/best-hipaa-practices-working-from-home-during-the-covid19-emergency/) - During the Coronavirus emergency, physicians and healthcare providers may want to adopt telemedicine as a way to provide patient care. This is an acceptable practice under HIPAA and California data and privacy laws but some precautions should be followed. - [Can I share a coronavirus patient’s information to protect the public?](https://privaplan.com/can-i-share-a-coronavirus-patients-information-to-protect-the-public/) - This month in light of the Novel Coronavirus (2019-nCoV) outbreak, the Department of Health and Human Services (HHS) released a bulletin reminding HIPAA covered entities and their business associates of the ways they may share patient information during an outbreak of infectious disease or other emergency situations. - [Important notice regarding individuals’ right of access to health records](https://privaplan.com/important-notice-regarding-individuals-right-of-access-to-health-records/) - The Department of Health and Human Services’ Office for Civil Rights has released an announcement that certain legislative changes regarding individuals’ right of access to health records have been reversed. - [Windows 7 support ends January 14, 2020](https://privaplan.com/windows-7-support-ends/) - On January 14, 2020, Microsoft stopped free support for Windows 7 just as promised. - [Do you understand what PHI is?](https://privaplan.com/do-you-understand-what-phi-is/) - An apparent lack of understanding of what defines Protected Health Information (PHI) has cost one hospital system $2.175 million in fines to the Office for Civil Rights (OCR) at the U.S Department of Health and Human Services (HHS). - [Unencrypted mobile devices lead to $3 million HIPAA settlement](https://privaplan.com/unencrypted-mobile-devices-lead-to-3-million-hipaa-settlement/) - One lost flash drive and one stolen laptop are costing one hospital system $3 million because both mobile devices were not encrypted. - [October is Cybersecurity Awareness Month – Are You Cyber Smart?](https://privaplan.com/october-is-cybersecurity-awareness-month-are-you-cyber-smart/) - Cybersecurity Awareness Month kicks off this week, now in its 18th year and hosted by the Cybersecurity & Infrastructure Security Agency (CISA) and the National Cyber Security Alliance (NCSA). - [HIPAA Updates are Focus of Proposed Legislation](https://privaplan.com/hipaa-updates-are-focus-of-proposed-legislation/) - What happens online stays online. It’s a fact of modern living. However, when that pertains to patient data, is enough being done to protect who has access to it? - [Top 5 HIPAA Compliance Issues and Who Commits Them](https://privaplan.com/top-5-hipaa-compliance-issues-and-who-commits-them/) - Every hour of every day an average of two HIPAA complaints come into the Department of Health and Human Services’ Office for Civil Rights (OCR). Let us help you stay in compliance and stay off the OCR’s complaint list. - [Payroll phishing scam targets university employees](https://privaplan.com/payroll-phishing-scam-targets-university-employees/) - Three university personnel began the new year without paychecks after falling victim to a payroll phishing scam. - [PrivaPlan HIPAA Certification Program promotes culture of compliance](https://privaplan.com/privaplan-hipaa-certification-program/) - PrivaPlan’s HIPAA Certification Program is giving healthcare professionals access to what had once been next to impossible to find: a one-stop shop to become a certified HIPAA expert. - [HHS waives HIPAA sanctions and penalties for hurricane-affected hospitals](https://privaplan.com/hhs-waives-hipaa-sanctions-for-hurricane-hospitals/) - As Hurricane Florence continues its destructive path, hospitals affected by the storm have been given the go ahead to break certain provisions of the HIPAA Privacy Rule. - [Verizon’s 2018 Data Breach Investigations Report Shows Healthcare Suffers Most Breaches](https://privaplan.com/verizons-2018-data-breach-investigations-report-shows-healthcare-suffers-most-breaches/) - Can you hear me now? Verizon reports that the healthcare industry had more breaches than any other industry in 2017. In the recently released 2018 Data Breach Investigations Report (DBIR) by Verizon, Personally Identifiable Information and Protected Health Information were shown to be the most common types of data compromised overall, even more than payment - [Judge rules in favor of OCR, orders cancer center to pay $4.3 for HIPAA violations ](https://privaplan.com/judge-orders-cancer-center-to-pay-for-hipaa-violations/) - A HHS Administrative Law Judge has ruled that MD Anderson violated HIPAA and is requiring the Texas cancer center to pay $4.3 million in penalties to the OCR. - [World's worst criminal phishing botnet gets trickier](https://privaplan.com/worlds-worst-criminal-phishing-botnet-gets-trickier/) - The notorious Necurs botnet has upped its crime game by adopting a retro trick to make itself more evasive and less likely to having its phishing intercepted by your filters. - [Hacking group targets healthcare industry worldwide](https://privaplan.com/hacking-group-targets-healthcare-industry-worldwide/) - Cybersecurity firm Symantec announced this week that a hacking group called Orangeworm appears to have been targeting the healthcare industry in the United States, Europe, and Asia. - [Vendor email attachments could be phishing bait](https://privaplan.com/vendor-email-attachments-could-be-phishing-bait/) - One of the latest reported email phishing schemes is very hard to beat and it always includes an attachment. What can you do about it? - [HIMSS survey shows significant security incidents](https://privaplan.com/himss-survey-shows-significant-security-incidents/) - The annual HIMSS cybersecurity survey released March 8 revealed that nearly 76 percent of health information security professionals believe their organizations experienced a significant security incident in the past 12 months. - [Latest phishing scams target payroll direct deposits](https://privaplan.com/latest-phishing-scams-target-payroll-direct-deposits/) - Scammers are cashing in on company paydays much to the chagrin of employees who had a lapse in judgment and shared their log-in credentials. Warn your employees NOW about this latest phishing scam involving payroll portals. - [W-2 phishing season is here…again](https://privaplan.com/w-2-phishing-season-is-hereagain/) - As the tax season gets underway, you can bet that cyber criminals are doing their tax preparations for W-2 phishing; they’re preparing to dupe hundreds of payroll and HR departments into providing W-2 data on their employees. - [Phishing scam exposes PHI of patients at Colorado Mental Health Institute](https://privaplan.com/phishing-scam-exposes-phi-at-colorado-mental-health-institute/) - As the year comes to an end, there appears to be no end in sight for healthcare data hacks. An employee at the Colorado Mental Health Institute at Pueblo recently fell for a phishing scam that potentially exposed the PHI of 650 patients. - [Will a Federal Data Security and Breach Notification Act finally get passed?](https://privaplan.com/will-a-federal-data-security-and-breach-notification-act-finally-get-passed/) - Three Democratic Senators re-introduced a Data Security and Breach Notification Act on Thursday that has failed to get legislative approval since 2015. - [Protect your data: 10 tips for online shopping](https://privaplan.com/protect-your-data-10-tips-for-online-shopping/) - The National Retail Foundation says that 78 million people plan to do online shopping on Cyber Monday. No doubt a good number of those will do that at work. - [New HIPAA guidance released in opioid crisis](https://privaplan.com/new-hipaa-guidance-released-in-opioid-crisis/) - Responding to the opioid crisis, the OCR explains when and how healthcare providers can share a patient’s health information without violating HIPAA. - [Our experts talk security with rural health care group](https://privaplan.com/experts-talk-security-rural-health-care-group/) - David Ginsberg talked about cyber security during one of the three sessions he led at the Colorado Rural Health Care Annual Rural Health Conference this week. - [Expect phishing attacks to follow Equifax hack](https://privaplan.com/expect-phishing-attacks-to-follow-equifax-hack/) - With news that cyber criminals stole 143 million credit records in a hacking scandal at Equifax, highly targeted spear phishing attacks are expected. - [Latest HIMSS cybersecurity report: threats rise, so does security](https://privaplan.com/cybersecurity-report-threats-rise-so-does-security/) - The August 2017 HIMSS Cybersecurity Report indicates that respondents are taking proactive steps to stay ahead of security threats. - [A new cyber threat is also a HIPAA Security threat](https://privaplan.com/a-new-cyber-threat-is-also-a-hipaa-security-threat/) - Recent analysis of a new variant of what appeared to be ransomware turns out instead to be malicious software that erases files on computers. - [Worldwide ransomware attack is on the move](https://privaplan.com/ransomware-attack/) - A quickly spreading ransomware attack is hitting countries across the world, including the United States. - [GOP data firm causes largest US voter data leak to date](https://privaplan.com/gop-data-firm-causes-largest-us-voter-data-leak/) - Political data of 198 million US citizens was exposed after a marketing firm contracted by the Republican National Committee stored internal documents on a publicly accessible Amazon server. - [New expiration for ABN form goes in effect June 21](https://privaplan.com/new-expiration-abn-form-in-effect-june-21/) - CMS is implementing mandatory use of the revised ABN form on June 21 with the newly incorporated March 2020 expiration date. - [Use extreme caution in WannaCry Ransomware Attack](https://privaplan.com/use-extreme-caution-wannacry-ransomware-attack/) - The largest cyberattack in history is hitting the U.S. today. Last week, multiple countries around the world reported falling victim to the WannaCry ransomware attack. Numerous hospitals and healthcare information systems were impacted. - [Survey finds 68% healthcare employees will share sensitive info](https://privaplan.com/healthcare-employees-will-share-sensitive-info/) - Results from a recent survey reveal that 68% of healthcare employees occasionally share confidential or regulated data. - [Health data breaches rise significantly in March](https://privaplan.com/health-data-breaches-rise-in-march/) - The number of health data breaches for March was more than January and February combined. - [FBI warns of cyber attacks on FTP servers in healthcare](https://privaplan.com/fbi-warns-of-cyber-attacks-on-ftp-servers-in-healthcare/) - An FBI alert warns the healthcare sector that cyber criminals have stepped up attacks targeting their FTP servers. - [HIPAA settlement proves value of audit controls](https://privaplan.com/hipaa-settlement-proves-value-of-audit-controls/) - Having policies and procedures in place is good, as long as you have audit controls to ensure they’re implemented, unlike this Florida healthcare system. - [CMS extends Medicare EHR attestation deadline](https://privaplan.com/cms-extends-medicare-ehr-attestation-deadline/) - Providers participating in the Medicare EHR Incentive Program – widely referred to as Meaningful Use – have a little more time to attest to requirements. - [PrivaPlan partner QVH Systems releases MIPS Navigator™ ](https://privaplan.com/privaplan-partner-qvh-mips-navigator/) - PrivaPlan partner QVH Systems recently released a new software solution called MIPS Navigator to help physicians and other health professionals achieve success under Medicare’s new merit-based incentive payment system. - [Hospital’s fate warns of tax season scams](https://privaplan.com/tax-season-scams/) - On January 25, it was discovered that the tax information of 1,457 hospital employees had fallen into a scammer’s hands in one of the latest W-2 business email compromise attacks. - [Patient behind breach using hospital library laptop](https://privaplan.com/patient-behind-breach-using-hospital-library-laptop/) - The New Hampshire DHHS says a former patient is behind a breach that began on a laptop in the hospital library, affecting approximately 15,000 patients. - [Hack of Quest Diagnostics affects 34k people](https://privaplan.com/quest-diagnostics-hacked/) - Quest Diagnostics Inc. is investigating a hack into an internet application on its network that exposed the PHI of about 34,000 people. - [Beware of images posted in Facebook Messenger](https://privaplan.com/beware-images-facebook-messenger/) - Clicking on images in Facebook Messenger could unleash a devastating ransomware attack on your organization. - [Be on the alert for App ID Theft](https://privaplan.com/be-on-the-alert-for-app-id-theft/) - Want to give personal information to a scammer this holiday season? There’s an app for that. Actually, there are hundreds of apps for that and many are masquerading as legitimate retailers. - [Latest HIPAA settlement proves why managing security risk is critical](https://privaplan.com/latest-hipaa-settlement-proves-why-managing-security-risk-is-critical/) - St. Joseph Health will pay $2.14 million for HIPAA violations, serving as an unfortunate example of why managing security risk is critical. - [OCR releases guidance on Cloud Computing and HIPAA](https://privaplan.com/ocr-guidance-on-cloud-computing-and-hipaa/) - The OCR released a guidance on October 6 that attempts to clear things up regarding cloud service providers and HIPAA. - [Latest HIPAA settlement shows importance of up-to-date BA agreements](https://privaplan.com/hipaa-settlement-shows-importance-of-up-to-date-ba-agreements/) - On Sept. 23, 2016, the OCR announced its second HIPAA enforcement action against a business associate to the tune of $400,000. The hospital had previously entered into a settlement of $150,000 for its part in the breach. - [Join Oct. 12 webcast: BAs, HIPAA Risk Management](https://privaplan.com/webcast-business-associates-hipaa-risk-management/) - More and more, HIPAA breaches are caused by the Business Associates of HIPAA covered entities. Learn how to manage these risks in Oct. 12 webcast. - [OCR is stepping up its investigations of smaller breaches](https://privaplan.com/ocr-investigations-smaller-breaches/) - The OCR has begun an initiative to more widely investigate the root causes of smaller breaches affecting fewer than 500 individuals. - [Data Breach at Banner Health affects 3.7 million](https://privaplan.com/data-breach-at-banner-health-affects-3-7-million/) - News of a massive data breach at Banner Health continues to make headlines since first being announced Aug. 3. - [OCR Desk Audits are Beginning](https://privaplan.com/ocr-desk-audits-beginning/) - This week selected covered entities began receiving notification letters for Phase Two of OCR’s HIPAA audit program which involve desk audits. - [Sign up for June 20 webcast: MACRA + MIPS, Education and Action Planning](https://privaplan.com/webcast-macra-mips-education/) - Join David Ginsberg, CEO of PrivaPlan Associates, Inc., as he addresses the not-so-distant future of Medicare payment reform and how this will affect meaningful use and planning for certified electronic health records. - [Recent Breach Shows Importance of Business Associate Agreements](https://privaplan.com/recent-breach-shows-importance-of-ba-agreements/) - Carefully managing Business Associates agreements is important. Take a lesson from the breach of 4300 patient files through a vendor of a Boston hospital. - [Plaintext data compromises patient info](https://privaplan.com/plaintext-data-compromises-patient-info/) - A hacker claims to steal nearly 10 million patient records using readily available plaintext data. How can you protect patient info? - [David Ginsberg explains new HIPAA audits in webinar](https://privaplan.com/ginsberg-hipaa-audits-webinar/) - PrivaPlan President David Ginsberg leads June 28 webinar hosted by CORHIO about new HIPAA audits of covered entities and their business associates. - [Can you name 10 technologies with the greatest vulnerabilities?](https://privaplan.com/technologies-with-greatest-vulnerabilities/) - There are 10 technologies emerging in the next five years with the greatest vulnerabilities in terms of cybersecurity, finance, personal health and safety. Two directly impact the health care industry. - [Lack of HIPAA Business Associate Agreement is costly](https://privaplan.com/hipaa-business-associate-agreement/) - Putting off a HIPAA Business Associate Agreement puts sensitive health information at risk of being misused or improperly disclosed. That’s certainly not good, and neither is the steep financial penalty you could incur for overlooking this critical step. - [AMA’s top 9 list includes focus on health IT](https://privaplan.com/amas-top-9-list-includes-focus-on-health-it/) - This month the American Medical Association (AMA) released a list of the nine top issues they believe physicians should watch in the coming year and why, and what the AMA is doing to address the issues. We’re going to look at the two that call out health IT. - [Congress makes it easier to reach Meaningful Use](https://privaplan.com/congress-makes-it-easier-to-reach-meaningful-use/) - The Patient Access and Medicare Protection Act (S. 2425) was passed by both chambers of Congress on Friday, December 18. - [Don't wait until the 11th hour to update to IE 11](https://privaplan.com/dont-wait-until-the-11th-hour-to-update-to-ie-11/) - There is no better time to make sure you’re using the latest version of Internet Explorer. True to their word, January 12, 2016 is the end of the Microsoft Support Lifecycle on versions of Internet Explorer older than version 11. - [HIPAA Security Risk Analysis](https://privaplan.com/hipaa-security-risk-analysis/) - HIPAA Security Risk Analysis – HIPAA Risk Analysis (per 45 CFR 164.308(a)(1)(ii)(A) is an essential requirement of both the HIPAA Security Rule, and also a "CORE" meaningful use measure for those organizations seeking EHR incentive payments. PrivaPlan's innovative solutions for completing a HIPAA Risk Analysis have been field tested since the HIPAA Security Rule took effect - [DOJ hits eClinicalWorks hard with $155 million settlement](https://privaplan.com/doj-hits-eclinicalworks-hard-155-million-settlement/) - Last week, eClinicalWork, a prominet ambulatory EHR vendor (who also just released their inpatient product), will pay $155 million as a result of a lawsuit settlement with the Department of Justice. The allegations include false representation of the product's capabilities during ONC testing, as well as paying customers to use the software - violations of - [Protect your data from phishing and ransomware](https://privaplan.com/protect-data-phishing-ransomware/) - Defending patient privacy means protecting electronic Protected Health Information, or ePHI, from those unauthorized to view such sensitive information. A covered entity must be confident that its users know how to protect themselves from becoming victims of cybercrime, such as phishing schemes. - [Phase 2 of HIPAA Audit Program is underway: Check your email!](https://privaplan.com/phase-2-hipaa-audit-program-underway-check-email/) - On March 21, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) began its next phase of audits of covered entities and their business associates as part of its continued efforts to assess compliance with the HIPAA Privacy, Security and Breach Notification Rules.Following this news, we at PrivaPlan have a - [Harriet Serota - Director of Patient Accounts | Connecticut Family Orthopedics, P.C.](https://privaplan.com/harriet-serota-director-of-patient-accounts-connecticut-family-orthopedics-p-c/) - "We enjoyed the webinar tremendously. David Ginsberg is so knowledgeable and we have enjoyed hearing him speak for several years now. We learned a lot and were glad to have the opportunity to listen on Wednesday. Thanks again." - [How Do You Handle Patients Who Bring in Their Medical Records on USB Drives?](https://privaplan.com/electronic-health-records-patients-medical-records-usb-drives/) - What is the best way to handle patient USB drives? The increase of Electronic Health Records has means patients often bring their medical records on USB drives. - [Are Chiropractors Required by Law to be HIPAA Compliant?](https://privaplan.com/are-chiropractors-required-to-be-hipaa-compliant/) - Watch the included video from PrivaPlan President David Ginsberg who answers this very question. - [Testimonials For the PrivaPlan™ HIPAA Security Risk Analysis Services](https://privaplan.com/hipaa-security-risk-analysis-services/) - "PrivaPlan is an excellent resource when dealing with the many aspects of HIPAA. I am especially fond of the quick response to email when I have inquired regarding specific issues. I think PrivaPlan has made the implementation and continued understanding of HIPAA much easier."Michelle PorterContract/Compliance Coordinator,North State Radiology,California and Federal review and reporting "I would like - [Testimonials For the PrivaPlan™ HIPAA Privacy and Security Compliance Online Toolkit - CMA Edition](https://privaplan.com/hipaa-privacy-rule-and-security-compliance-online-toolkit/) - "If you enjoy agonizing uncertainty, fruitless research, and sleepless nights, then you should not bother calling David Ginsberg and PrivaPlan! However, if you prefer to avoid these torments, then Mr. Ginsberg can quickly provide relief.PrivaPlan have proved invaluable to Prowers Hospital/Medical Center. Through site visits, phone calls, and email conversations, he has provided expert guidance - [Testimonials For the PrivaPlan™ HIPAA Privacy and Security Compliance Online Toolkit](https://privaplan.com/hipaa-privacy-and-security-compliance-online-toolkit/) - "If you enjoy agonizing uncertainty, fruitless research, and sleepless nights, then you should not bother calling David Ginsberg and PrivaPlan! However, if you prefer to avoid these torments, then Mr. Ginsberg can quickly provide relief.PrivaPlan have proved invaluable to Prowers Hospital/Medical Center. Through site visits, phone calls, and email conversations, he has provided expert guidance - [Endorsements and Key Client Sectors](https://privaplan.com/endorsements-and-key-client-sectors/) - Validation of PrivaPlan Associates, Inc.®, the PrivaPlan™ HIPAA Online Privacy and Security Compliance Resource Kit, and our many services including HIPAA reviews and HIPAA Security Risk Analyses comes from a constantly expanding list of satisfied clients, organizations and groups including:California Medical Association (CMA) - CMA has endorsed the PrivaPlan™ toolkit. In a unique agreement with - [Michelle Porter - Contract/Compliance Coordinator, North State Radiology, California](https://privaplan.com/michelle-porter/) - "PrivaPlan is an excellent resource when dealing with the many aspects of HIPAA. I am especially fond of the quick response to email when I have inquired regarding specific issues. I think PrivPlan has made the implementation and continued understanding of HIPAA much easier." - [Lisa Zwerdlinger, MD - Rocky Mountain Family Practice, Leadville, CO](https://privaplan.com/lisa-zwerdlinger-md/) - “PrivaPlan was easy to use and helped my practice meet it’s objectives quickly. The support of the staff was helpful and made completion of the project timely. I would recommend PrivaPlan to anyone attempting Meaningful Use.” - [Laverna Hubbard - Administrator, North State Radiology, CA | President, Medical Business Solutions, CA](https://privaplan.com/laverna-hubbard/) - “I have found this program to be the most user friendly compliance program available. Your questions and answer forum gives subscribers a way to discuss real life issues that are constantly arising in a medical office. Thank you for creating such a great over all program on compliance.” - [Ann Davis, Denver Skin Clinic](https://privaplan.com/ann-davis-denver-skin-clinic/) - “I thought the Training...was very well done and appreciate the ability to train in this manner. Well worth the money and I plan to pass it along to my fellow managers . . .” - [Tailored HIPAA Education & Training](https://privaplan.com/hipaa-training-and-education-courses/) - Tailored HIPAA Education & Training – Many organizations make the mistake of believing that a "HIPAA 101" online or written training is sufficient for HIPAA compliance. The Privacy rule clarifies that HIPAA training courses should be included in the covered entity's own HIPAA Privacy Policies and Procedures. While “HIPAA 101” training is beneficial to establish - [Final HIPAA Omnibus Rule has Been Released](https://privaplan.com/final-hipaa-omnibus-rule-has-been-released/) - HIPAA Omnibus Rule has been released and will be published in the Federal Register on January 25, 2013 - [Final Guidance from OCR Released on De-identification of PHI](https://privaplan.com/deidentification-phi-hipaa-privacy-rule/) - The Office of Civil Rights has updated guidance on methods of de-identification of PHI that is available now. - [If You're Complying with HIPAA, You Should Be Able to Meet Stage 2 of Meaningful Use](https://privaplan.com/hipaa-compliance-stage-2-meaningful-use/) - The proposed certification rule included particular technical requirements when dealing with patient requests to amend their electronic data. The final rule allows for more flexibility in this technical capability. ## Pages - [Homepage](https://privaplan.com/) - Experience seamless HIPAA security and privacy compliance with our team of leading experts in the field! - [About Us](https://privaplan.com/about-us/) - Experience seamless compliance with PrivaPlan's team of leading experts in the field! With over 20 years of compliance guidance we offer a variety of solutions. - [Privacy Policy](https://privaplan.com/privacy-policy/) - Our Privacy Policy. Learn how we collect, use, and share your information on www.privaplan.com. - [Privacy & Security Services](https://privaplan.com/privacy-security-services/) - Enhance your organization's privacy and security with our comprehensive solutions and services. Explore our toolkit for HIPAA compliance today. - [Our Solutions](https://privaplan.com/our-solutions/) - Ensure compliance with PrivaPlan's expert guidance on security and privacy! We offer a variety of compliance solutions. - [Health Care Services](https://privaplan.com/health-care-services/) - Enhance HIPAA compliance with our managed healthcare services. Access website compliance tracking, education, training, security risk assessments, and more! - [Contact Us](https://privaplan.com/contact-us/) - Connect with PrivaPlan for updates and compliance support. Contact us via phone or email! - [PrivaPlan Toolkit](https://privaplan.com/privaplan-toolkit/) - Enhance your HIPAA compliance with PrivaPlan's Toolkit, featuring templates, policies, and guidance on HIPAA compliance. - [Blog](https://privaplan.com/blog/) - Our Blog HOME Blog Microsoft Alerts Organizations to Large-Scale Phishing Campaign Microsoft is warning about a recent sophisticated phishing campaign that targeted more than 13,000 organizations, mostly in the US. Learn More + May 6, 2026 No Comments HIPAA-Compliant Medical Records Destruction: What Healthcare Organizations Need to Know Secure destruction of PHI is one of - [Toolkit Subscription Purchase](https://privaplan.com/toolkit-subscription-purchase/) ## My Templates - [Blog Post TOC](https://privaplan.com/?elementor_library=blog-post-toc) - Table of Contents - [Blog Single Post](https://privaplan.com/?elementor_library=blog-single-post) - Back to Blog Blog Single Post May 19, 2022 Quitters. They’re everywhere. At least this is true concerning the Great Resignation where, in the past few years, millions have quit their jobs to seek out higher pay or better employment. In January 2022 alone, the U.S. Department of Labor reports that nearly 4.3 million left - [PrivaPlan Header New](https://privaplan.com/?elementor_library=privaplan-header-new) - Content area - [New Toolkit 7-24](https://privaplan.com/?elementor_library=new-toolkit-7-24) - HIPAA Privacy & Security Compliance Toolkit Health Care Compliance Doesn't Have to Compete With Your Other Priorities HIPAA Policy Templates for Covered Entities & Business Associates What’s Inside the Toolkit A Smarter, More Sustainable Way to Manage HIPAA Expert-Developed ContentCreated by compliance professionals with decades of experience in HIPAA and health care operations. The PrivaPlan - [MidPage: Toolkit NEW](https://privaplan.com/?elementor_library=midpage-toolkit-new) - A Smarter, More Sustainable Way to manage HIPAA. HIPAA Privacy & Security Policy Templates Created by compliance professionals and trusted by healthcare organizations nationwide, our Toolkit helps you confidently implement HIPAA with structure, guidance, and efficiency. Follow clear, actionable guidance with our signature PrivaGuides. Each guide provides focused, actionable instructions supporting you from the initial - [New Home Page 7-24](https://privaplan.com/?elementor_library=new-home-page-7-24) - PrivaPlan Protect Data Privacy Enforce Data Security Build Trust LEARN MORE Our Mission PrivaPlan Associates handles compliance in the next dimension of information technology, privacy, and security. Built upon two decades of experience in HIPAA privacy and security compliance solutions, we understand the criticality of safeguarding confidential information. Whether your goal is to safeguard protected health - [Footer](https://privaplan.com/?elementor_library=footer) - Content area - [Email List Promo](https://privaplan.com/?elementor_library=email-list-promo) - Content area - [AI Guide Download](https://privaplan.com/?elementor_library=ai-guide-download) - Content area - [Vendor Risk Assessment Promo](https://privaplan.com/?elementor_library=vendor-risk-assessment-promo) - Content area - [Security Risk Analysis Promo](https://privaplan.com/?elementor_library=security-risk-analysis-promo) - Content area - [Security Risk Analysis Popup](https://privaplan.com/?elementor_library=security-risk-analysis-popup) - Content area - [Toolkit Promo](https://privaplan.com/?elementor_library=toolkit-promo) - Content area - [Newsletter sign up](https://privaplan.com/?elementor_library=newsletter-sign-up) - Content area - [TrackerReveal Promo](https://privaplan.com/?elementor_library=trackerreveal-promo) - Content area - [Post CTA](https://privaplan.com/?elementor_library=post-cta) - Learn More - [TrackerReveal](https://privaplan.com/?elementor_library=trackerreveal) - Introducing TrackerReveal Ensure HIPAA Compliance with TrackerReveal by PrivaPlan | Powered by Cyndelos TrackerReveal Your Solution to HIPAA Compliant Website Tracking Websites and mobile apps commonly use tracking technologies to collect and analyze information from users. However, for HIPAA Covered Entities and Business Associates, compliance is paramount to prevent unauthorized disclosures of Protected Health Information - [Tracker Footer](https://privaplan.com/?elementor_library=tracker-footer) - Content area - [Header](https://privaplan.com/?elementor_library=header) - Content area - [Searches + Archives](https://privaplan.com/?elementor_library=elementor-archive-226) - Template: Searches + Archives Microsoft Alerts Organizations to Large-Scale Phishing Campaign Microsoft is warning about a recent sophisticated phishing campaign that targeted more than 13,000 organizations, mostly in the US. Learn More + HIPAA-Compliant Medical Records Destruction: What Healthcare Organizations Need to Know Secure destruction of PHI is one of the most overlooked and high-risk - [MidPage Section: Vendor Assessment](https://privaplan.com/?elementor_library=midpage-section-vendor-assessnent) - The Four Main Aims Of A Risk Assessment IncludeCompliance Assurance: For industries that rely on regulations to protect information, such as healthcare, staying compliant is a daily task. Trusting who manages business functions on your behalf is an ingredient for compliance assurance.Improved Vendor Selection: Make informed decisions that align with your data security and integrity - [Solutions CTA](https://privaplan.com/?elementor_library=solutions-cta) - Be Proactive In Compliance Contact Privaplan Today - [Our Solution Single Post](https://privaplan.com/?elementor_library=single-post) - HOME Our Solutions Our Solution Single Post Table of Contents Fake Compliance Emails Used to Gain Trust Microsoft is warning about a sophisticated phishing campaign that targeted over 35,000 users across more than 13,000 organizations in 26 countries, with 92% of the attacks aimed at organizations in the United States. According to a May 4 - [MidPage Section: Disaster Recovery](https://privaplan.com/?elementor_library=midpage-section-disaster-recovery) - Data Classification and Criticality: We can help you identify and classify PHI, PII (personally identifiable information), corporate and strategic data, and other important information. This includes, ranking all data types by their criticality to assist in understanding their priority within a disaster recovery plan.Data Backup: Most organizations have a data backup process, but it may not - [MidPage Section: HIPAA Education](https://privaplan.com/?elementor_library=midpage-section-hipaa-education) - HIPAA Compliance Education Literacy & Training for EmployeesWe offer training options for any type of covered entity or business associate. With online courses and the opportunity to customize training for your organization, we deliver solutions to meet your needs including:Live on-site trainingSelf-paced online courses accessible in our librarySecurity reminder videosIndividualized recorded trainingCustom training options - [MidPage Image: Certification](https://privaplan.com/?elementor_library=midpage-image-certification) - Is HIPAA Certification Worth It?The PrivaPlan Compliance Certification empowers you and your organization to: Shift your organization’s focus from problems to preventionOptimize internal compliance systems and workflowsIncrease patient trustImprove the efficiency and coordination of all of your compliance effortsImplement and maintain best practices in data privacy and cyber security - [MidPage Section: Policy and Procedure](https://privaplan.com/?elementor_library=midpage-section-policy-and-procedure) - Build Consistency & Guarantee Workforce GuidancePolicies and procedures provide a framework for consistent operations within an organization. Standardized procedures enhance efficiency, productivity, and customer service.Well developed policies and procedures serve as essential tools for workforce guidance and training. Clear communication of expectations, roles, and responsibilities helps your workforce understand their obligations and enhances consistent organizational - [MidPage Section: Managed Phishing](https://privaplan.com/?elementor_library=midpage-section-managed-phishing) - Our specialized services include the following:Annual or multi-year phishing testingCustomizable and current campaigns and email templatesRobust data reportingAn array of follow-up and training options to reduce your risk levels We also offer regular “Phish Alert” and “Training Moment” emails to keep you apprised of timely issues and offer quick reminders to your workforce. - [Default Kit](https://privaplan.com/?elementor_library=default-kit) - [MidPage Section: Data Governance](https://privaplan.com/?elementor_library=midpage-section-data-governance) - What’s included in our Data Governance Program Build a data governance framework Locate data classification and criticality programs Identify ownership and operational requirements of data Keep regulatory requirements in check Assist with vendor management Develop an ecosystem for data, including digital asset and metadata review Identify and assist in assigning the operationalizing of roles and - [MidPage Section: Privacy Risk Assessment](https://privaplan.com/?elementor_library=midpage-section-privacy-risk-assessment) - Our team will:Assess your information security infrastructureAssess policies and procedures and determine if they are relevant and implementedConduct internal and external vulnerability testsConduct user and human vulnerability tests including managed phishingReview physical security including the challenges of the new work from home (WFH) paradigm Available for in person or virtual assessments - [Access Toolkit](https://privaplan.com/?elementor_library=access-toolkit) - Content area - [*23 About](https://privaplan.com/?elementor_library=23-about) - Why PrivaPlan? For starters, PrivaPlan™ Associates is a leading provider in HIPAA compliance, education, training, cybersecurity, and guidance. We’ve been guiding people through HIPAA compliance since 2001 before the HIPAA Privacy Rule went into effect. Every day our highly experienced team demonstrates a commitment to providing compliance solutions to the healthcare community, and their HIPAA - [Newsletter button](https://privaplan.com/?elementor_library=newsletter-button) - Sign Up for Updates - [Home Page](https://privaplan.com/?elementor_library=home-page) - PrivaPlan:Your Solution to HIPAA Regulations & Compliance LEARN MORE Our Mission Focus on improving your HIPAA Compliance with personalized, actionable steps that have guaranteed results. PrivaPlan Associates has over 20 years of HIPAA intelligence and customized approaches for all aspects of healthcare.We don’t just recommend a plan and then walk away. Our team works alongside - [MidPage Section: Toolkit](https://privaplan.com/?elementor_library=midpage-section-toolkit) - PrivaPlan’s Toolkit Benefits:Get your HIPAA compliance program off the ground quickly and easily.Access comprehensive guides for completing HIPAA compliance forms such as policies and procedures.Minimize effort and reduce duplication.Tailor the documents to fit your specific needs.Stay current with changes in the HIPAA regulations with our continuously updated documents.Access anytime and anywhere - [MidPage Section: Breach Notification](https://privaplan.com/?elementor_library=midpage-section-breach-notification) - How to handle the HIPAA Breach Notification ProcessHIPAA Breach Notification may require:Determining if you have up-to-date contact informationPosting a notice on your websiteObtaining a toll-free number for individuals to callSending the notificationNotifying the Office for Civil RightsAnd in some States, notifying the Attorney General or the Department of Health - [MidPage Section: Security Risks](https://privaplan.com/?elementor_library=midpage-section-security-risks) - Security risks are evaluated in these four areas:Administrative Safeguards are the people and processes that safeguard PHI. From vetting business agreements to employee training, documentation of operations are essential to maintaining HIPAA compliance.Physical Safeguards include the physical security of your organization including the new work from home model. We conduct our assessment either in person - [MidPage Section: Privacy Compliance](https://privaplan.com/?elementor_library=midpage-section-privacy-compliance) - What you receive from our HIPAA Privacy Assessment:A written report of findings, including gaps or deficienciesRecommended improvements including new forms and updated policies and proceduresUnlock additional value with our HIPAA education literacy and training along with suggested microlearning modules Guidance from our specialists at every step - [our solutions](https://privaplan.com/?elementor_library=our-solutions) - Our Solutions Delivering HIPAA Compliance Results You Can Measure HOME Our Solutions PrivaPlan’s innovative solutions have been field tested since the HIPAA Privacy Rule took effect in 2003. Our associates are committed to compliance evolution and are ready to make the impossible possible. Every detail of our offerings are intentionally designed to help you navigate a - [Icon List](https://privaplan.com/?elementor_library=icon-list) - HOME Our Solutions - [Default Button](https://privaplan.com/?elementor_library=default-button) - LEARN MORE - [footer widget](https://privaplan.com/?elementor_library=footer-widget) - Get Started Today Email us at info@privaplan.com or submit the form below: First Name Last Name Business Email Company Message Submit ## Categories - [Uncategorized](https://privaplan.com/category/uncategorized/) - [Solutions](https://privaplan.com/category/solutions/) - [Service](https://privaplan.com/category/service/) - [Quotes](https://privaplan.com/category/quotes/) - [Testimonials](https://privaplan.com/category/testimonials/) - [Toolkit](https://privaplan.com/category/toolkit/) - [Blog](https://privaplan.com/category/blog/) - [Final Rule](https://privaplan.com/category/final-rule-2/) - [HIPAA](https://privaplan.com/category/hipaa/) - [OCR](https://privaplan.com/category/ocr/) - [PHI](https://privaplan.com/category/phi/) - [Articles](https://privaplan.com/category/articles/) - [Breach](https://privaplan.com/category/breach/) - [Security](https://privaplan.com/category/security/) - [HIPAA Training](https://privaplan.com/category/hipaa-training/) - [EMR](https://privaplan.com/category/emr/) - [Privacy](https://privaplan.com/category/privacy/) - [Technology](https://privaplan.com/category/technology/) - [Federal HIPAA Changes](https://privaplan.com/category/federal-hipaa-changes/) - [Meaningful Use](https://privaplan.com/category/meaningful-use/) - [Medicare](https://privaplan.com/category/medicare/) - [Security Risk Analysis](https://privaplan.com/category/security-risk-analysis/) - [Medicaid](https://privaplan.com/category/medicaid/) - [Policies & Procedures](https://privaplan.com/category/policies-and-procedures/) - [Training Materials](https://privaplan.com/category/training-materials/) - [ONC](https://privaplan.com/category/onc/) - [HIPAA Reference Materials](https://privaplan.com/category/hipaa-reference-materials/) - [Phishing](https://privaplan.com/category/phishing/) - [Ransomware](https://privaplan.com/category/ransomware/) - [HIPAA Privacy Rule](https://privaplan.com/category/hipaa-privacy-rule/) - [Passwords](https://privaplan.com/category/passwords/) - [Cybersercurity](https://privaplan.com/category/cybersercurity/) - [Privacy & Security Services](https://privaplan.com/category/solutions/privacy-security-services/) - [Health Care Services](https://privaplan.com/category/solutions/health-care-services/) - [AI](https://privaplan.com/category/ai/) - [Business Associate Agreement](https://privaplan.com/category/business-associate-agreement/) - [TrackerReveal](https://privaplan.com/category/trackerreveal/) - [PCI Compliance](https://privaplan.com/category/pci-compliance/) - [HIPAA Security Rule](https://privaplan.com/category/hipaa-security-rule/) - [Web Trackers](https://privaplan.com/category/web-trackers/) - [HIPRA](https://privaplan.com/category/hipra/) - [AHI](https://privaplan.com/category/ahi/) - [Notice of Privacy Practices](https://privaplan.com/category/notice-of-privacy-practices/) - [Ambient AI Scribes](https://privaplan.com/category/ambient-ai-scribes/) - [Business Associates](https://privaplan.com/category/business-associates/) ## Tags - [HIPAA](https://privaplan.com/tag/hipaa/) - [Certification](https://privaplan.com/tag/certification/) - [Program](https://privaplan.com/tag/program/) - [Omnibus Rule](https://privaplan.com/tag/omnibus-rule/) - [Awards](https://privaplan.com/tag/awards/) - [Meaningful Use](https://privaplan.com/tag/meaningful-use/) - [Final Rule](https://privaplan.com/tag/final-rule/) - [Hi-Tech](https://privaplan.com/tag/hi-tech/) - [OCR](https://privaplan.com/tag/ocr/) - [Service](https://privaplan.com/tag/service/) - [Quotes](https://privaplan.com/tag/quotes/) - [Testimonials](https://privaplan.com/tag/testimonials/) - [HIPAA Reference Materials](https://privaplan.com/tag/hipaa-reference-materials/) - [Policies & Procedures](https://privaplan.com/tag/policies-procedures/) - [Training Materials](https://privaplan.com/tag/training-materials/) - [Security Risk Analysis](https://privaplan.com/tag/security-risk-analysis/) - [Security Reminders](https://privaplan.com/tag/sr/) - [Blog](https://privaplan.com/tag/blog/) - [hipaa compliance](https://privaplan.com/tag/hipaa-compliance/) - [EMR](https://privaplan.com/tag/emr/) - [Patients](https://privaplan.com/tag/patients/) - [Privacy](https://privaplan.com/tag/privacy/) - [Technology](https://privaplan.com/tag/technology/) - [audit](https://privaplan.com/tag/audit/) - [eclinicalworks](https://privaplan.com/tag/eclinicalworks/) - [ehr](https://privaplan.com/tag/ehr/) - [EHR Incentive](https://privaplan.com/tag/ehr-incentive/) - [MU](https://privaplan.com/tag/mu/) - [ONC](https://privaplan.com/tag/onc/) - [risk](https://privaplan.com/tag/risk/) - [settlement](https://privaplan.com/tag/settlement/) - [vendor](https://privaplan.com/tag/vendor/) - [Data Breach](https://privaplan.com/tag/data-breach/) - [email breach](https://privaplan.com/tag/email-breach/) - [phishing](https://privaplan.com/tag/phishing/) - [protected health information](https://privaplan.com/tag/protected-health-information/) - [security training](https://privaplan.com/tag/security-training/) - [Articles](https://privaplan.com/tag/articles/) - [Security](https://privaplan.com/tag/security/) - [Federal HIPAA Changes](https://privaplan.com/tag/federal-hipaa-changes/) - [PHI](https://privaplan.com/tag/phi/) - [Ransomware](https://privaplan.com/tag/ransomware/) - [Breach](https://privaplan.com/tag/breach/) - [Medicare](https://privaplan.com/tag/medicare/) - [HIPAA Training](https://privaplan.com/tag/hipaa-training/) - [Medicaid](https://privaplan.com/tag/medicaid/) - [managed phishing](https://privaplan.com/tag/managed-phishing/) - [health care](https://privaplan.com/tag/health-care/) - [cybersecurity](https://privaplan.com/tag/cybersecurity/) - [AI](https://privaplan.com/tag/ai/) - [toolkit](https://privaplan.com/tag/toolkit/) - [policies and procedures](https://privaplan.com/tag/policies-and-procedures/) - [multi-factor authentication](https://privaplan.com/tag/multi-factor-authentication/) - [two-step authentication](https://privaplan.com/tag/two-step-authentication/) - [passwords](https://privaplan.com/tag/passwords/) - [health privacy](https://privaplan.com/tag/health-privacy/) - [electronic medical records](https://privaplan.com/tag/electronic-medical-records/) - [business associate](https://privaplan.com/tag/business-associate/) - [board](https://privaplan.com/tag/board/) - [cyber risk](https://privaplan.com/tag/cyber-risk/) - [CISO](https://privaplan.com/tag/ciso/) - [executive order](https://privaplan.com/tag/executive-order/) - [artificial intelligence](https://privaplan.com/tag/artificial-intelligence/) - [healthcare](https://privaplan.com/tag/healthcare/) - [cybersecurity awareness training](https://privaplan.com/tag/cybersecurity-awareness-training/) - [website analytics](https://privaplan.com/tag/website-analytics/) - [website trackers](https://privaplan.com/tag/website-trackers/) - [medical devices](https://privaplan.com/tag/medical-devices/) - [Cyndelos](https://privaplan.com/tag/cyndelos/) - [HIPAA Privacy Rule](https://privaplan.com/tag/hipaa-privacy-rule/) - [Substance Use Disorder](https://privaplan.com/tag/substance-use-disorder/) - [42 CFR Part 2](https://privaplan.com/tag/42-cfr-part-2/) - [notice of privacy practices](https://privaplan.com/tag/notice-of-privacy-practices/) - [FTC](https://privaplan.com/tag/ftc/) - [Breach Notification Rule](https://privaplan.com/tag/breach-notification-rule/) - [website compliance](https://privaplan.com/tag/website-compliance/) - [compliance](https://privaplan.com/tag/compliance/) - [FTC compliance](https://privaplan.com/tag/ftc-compliance/) - [TrackerReveal](https://privaplan.com/tag/trackerreveal/) - [BAA](https://privaplan.com/tag/baa/) - [Business Associates Agreement](https://privaplan.com/tag/business-associates-agreement/) - [Adobe](https://privaplan.com/tag/adobe/) - [Adobe Sign](https://privaplan.com/tag/adobe-sign/) - [PCI compliance](https://privaplan.com/tag/pci-compliance/) - [privacy risk assessment](https://privaplan.com/tag/privacy-risk-assessment/) - [HIPAA updates](https://privaplan.com/tag/hipaa-updates/) - [HIPAA compliace](https://privaplan.com/tag/hipaa-compliace/) - [HIPAA Security Rule](https://privaplan.com/tag/hipaa-security-rule/) - [web trackers](https://privaplan.com/tag/web-trackers/) - [forgotten service accounts](https://privaplan.com/tag/forgotten-service-accounts/) - [out-of-date accounts](https://privaplan.com/tag/out-of-date-accounts/) - [orphaned accounts](https://privaplan.com/tag/orphaned-accounts/) - [APIs](https://privaplan.com/tag/apis/) - [Healthcare APIs](https://privaplan.com/tag/healthcare-apis/) - [health information](https://privaplan.com/tag/health-information/) - [health-related data](https://privaplan.com/tag/health-related-data/) - [Health Information Privacy Reform Act](https://privaplan.com/tag/health-information-privacy-reform-act/) - [Applicable Health Information](https://privaplan.com/tag/applicable-health-information/) - [AHI](https://privaplan.com/tag/ahi/) - [ChatGPT](https://privaplan.com/tag/chatgpt/) - [ChatGPT Health](https://privaplan.com/tag/chatgpt-health/) - [SUD](https://privaplan.com/tag/sud/) - [uses and disclosures](https://privaplan.com/tag/uses-and-disclosures/) - [NPP](https://privaplan.com/tag/npp/) - [psychotherapy notes](https://privaplan.com/tag/psychotherapy-notes/) - [ambient AI scribes](https://privaplan.com/tag/ambient-ai-scribes/) - [business associates](https://privaplan.com/tag/business-associates/) - [minimum necessary](https://privaplan.com/tag/minimum-necessary/) - [patient rights](https://privaplan.com/tag/patient-rights/) - [rights to access](https://privaplan.com/tag/rights-to-access/)