On February 17, 2023, the HHS Office for Civil Rights (OCR) released two annual reports to Congress summarizing the agency’s key HIPAA enforcement activities during the 2021 calendar year as required by the Health Information Technology for Economic and Clinical Health (HITECH) Act. The first report, HIPAA Privacy, Security, and Breach Notification Rule Compliance, identifies the number of complaints received, the method by which those complaints were resolved, and other OCR HIPAA compliance enforcement activities. The second report, Breaches of Unsecured Protected Health Information, identifies the number and nature of breaches of unsecured protected health information (PHI) that were reported to the HHS and the actions taken in response to the breaches.
Due to a lack of financial resources, OCR did not conduct any audits in 2021. Further, OCR requested that the HITECH civil penalty caps be increased in the HHS Fiscal Year 2023 Legislative Supplement sent to Congress to secure enough staff and resources to carry out OCR’s enforcement activities.
The highlights of these two reports are as follows:
The appendices sections of both reports include:
These annual reports are an important reminder of the agency’s HIPAA compliance enforcement activities. So it is crucial that employers are educated in overall HIPAA rules and review their HIPAA compliance.
HHS: Annual Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance for Calendar Year 2021 » HHS: Annual Report to Congress on Breaches of Unsecured Protected Health Information for Calendar Year 2021 »
PPI Benefit Solutions does not provide legal or tax advice. Compliance, regulatory and related content is for general informational purposes and is not guaranteed to be accurate or complete. You should consult an attorney or tax professional regarding the application or potential implications of laws, regulations or policies to your specific circumstances.
Sign up to have it delivered straight to your inbox.
Sign up