From Report on Patient Privacy - With the news that the Minnesota attorney general has brought the first-ever HIPAA suit against a business associate, the compliance world again sees that state officials are willing to go where no federal officials have gone before.
The Office for Civil Rights, already under fire from Congress for its sluggish enforcement efforts against covered entities, has said that until its final enforcement rule is in effect, it won’t enforce the provisions of the 2009 HITECH Act that hold business associates (BAs) accountable for privacy and security compliance (RPP 5/11, p.
Read more