Tag: hipaa

How Is HIPAA-Compliant Email Different from Secure Email?

June 21, 2017

Protected health information (PHI) is heavily regulated under HIPAA, but the exact details can be confusing. The regulations are designed to keep everyone’s private information safe, but they also put a significant amount of responsibility on businesses. HIPAA regulations apply to just about every aspect of a person’s medical information, including their transit, storage and […]

How do I send HIPAA-compliant lab results via email?

May 5, 2017

A question about HIPAA-compliant transactional email from Ask Erik: As a non-technical member of the founding team of a Health Care Startup I have a question about HIPAA-compliant email as we begin to send out lab test results to individuals and the health care providers we partner with: “Does one dedicated email address for results […]

If my web site is very simple, do I have to worry about HIPAA compliance?

March 24, 2017

We received this questions via Ask Erik from a Physicians’ Association: “Our company website does not contain any patient information. As a healthcare group, do we need to worry about HIPAA compliance for our site? It contains forms, news and some company polices and procedures but no patient information whatsoever. Thank you.” Thank you for […]

Why Are Hackers Targeting Your Medical Records?

March 2, 2017

Theft of Medical records is booming. Over the past few years, large scale breaches have become more common and increasingly severe. Last year in June, a hacker named thedarkoverlord was selling 650,000 US healthcare records as part of a long-running crime spree. The collection was listed on a deep web marketplace called the Real Deal […]

Is sharing my patient list with a marketing company OK under HIPAA?

February 11, 2017

We received this questions via Ask Erik from the head of a Dental Practice (who wished to remain anonymous): “I want to create a Refer-a-Friend program, for a dental practice, that will be managed by a third party marketing agency.  The third party needs only my patient names and address to do an on-going e-mail […]