Wetherington Hamilton, P.A.
  • Services
  • Process
  • Compliance
  • Attorneys
  • News
  • Contact
  • Payments
  • Refer A Claim
  • Menu Menu

Tag Archive for: HIPAA privacy and security compliance

health apps

HIPAA Privacy: Is There an App for That?

March 11, 2016/in Articles, General/by Ted Hamilton

health applications

Health apps are very popular in our tech savvy and health conscious society. Just Google “health apps” and you will be greeted with “The 10 Best Apps to Improve Your Health” and “The 25 Best Fitness Apps for 2016” among many other hits. Far down on the Google list, however, you might find this gem from Healthcare IT News: “8 Out of 10 Mobile Health Apps Open to HIPAA Violations, Hacking, Data Theft.”

The Healthcare IT News article claims that 84% of U.S. FDA-approved health apps that were tested by IT security vendor Arxan Technologies did not adequately address security issues. How is this possible? Don’t these apps need to comply with HIPAA, the federal privacy law?

Rules issued by the federal government under the Health Insurance Portability and Accountability Act (“HIPAA”) regulate the use and disclosure of individually identifiable health information. But HIPAA does not apply to all users of health information, only those who are specifically covered by the law. The HIPAA regulations apply to health care providers such as doctors, dentists, hospitals and nursing homes, as well as health insurance companies and organizations known as “healthcare clearinghouses.” Healthcare clearinghouses are entities that serve as weigh stations, processing non-standard data into standardized data elements that are recognizable by insurance companies, the federal government and others who pay for health care services. These entities that are subject to the HIPAA regulations are known as “covered entities.”

Covered entities often outsource functions that require access to health information. For example, many physician groups contract with medical billing companies, which review medical information provided by the doctor and prepare bills that are transmitted electronically to health insurance companies for payment.   Medical billing companies and other contractors that collect, create, receive, maintain or transmit health information on behalf of covered entities are known as “business associates.” These business associates are also subject to the HIPAA regulations, as are any subcontractors of the business associates.

App developers have long sought better guidance from the federal government about how HIPAA applies to their industry.   In response, on February 11, 2016, the Department of Health and Human Services’ Office for Civil Rights (“OCR”) released “Health App Use Scenarios & HIPAA” (the “Health App Guidance”). The Guidance sets out various factual scenarios involving health apps and OCR’s conclusion whether or not the HIPAA regulations would apply to the app developer in each scenario. The Health App Guidance builds upon OCR’s previous guidance concerning business associates and frames the scenarios in terms of whether or not the app developer is a business associate, and thus subject to the HIPAA regulations.

Unless the app is being developed by a health care provider, health insurer or healthcare clearinghouse, the app developer is almost assuredly not a covered entity. But under certain circumstances it is entirely possible that the app developer is a business associate of a covered entity and is therefore subject to the HIPAA regulations. The scenarios provided in the Guidance illustrate the basic analysis that must be performed to determine whether or not the app developer is a business associate.

The Health App Guidance makes clear that health apps that are downloaded and used solely by individual consumers are generally not subject to HIPAA because the developer is not collecting, creating, receiving, maintaining or transmitting health information on behalf of a covered entity. However, health apps that are offered directly by or on behalf of healthcare providers or their business associates and that collect, store or transmit health data very likely are subject to HIPAA. In those cases where the app developer is providing a service on behalf of the covered entity itself, or on behalf of a business associate of the covered entity, that app developer is, itself, a business associate subject to HIPAA.

While it is in every health app developer’s interest to make sure its app maintains the confidentiality and security of its customers’ health data, not all health app developers are subject to the HIPAA regulations. The Health App Guidance provides 6 scenarios that illustrate OCR’s analysis of the regulations. There are countless other scenarios not covered by the Guidance, however. Health app developers should seek advice from qualified attorneys with experience in health law in general and the HIPAA regulations in particular. The lawyers at Wetherington Hamilton are available to advise health app developers on these, and other regulatory matters.

Matthew J. Lapointe, Esq.

https://whhlaw.com/wp-content/uploads/2016/03/health-apps.jpg 550 1600 Ted Hamilton https://whhlaw.com/wp-content/uploads/2026/06/Wetherington-Hamilton-logo.png Ted Hamilton2016-03-11 17:29:392016-03-11 17:29:39HIPAA Privacy: Is There an App for That?
hipaa enforcement

HIPAA Enforcement – Small Physician Groups Are Not Immune

January 25, 2016/in Articles, General/by Ted Hamilton

hipaa enforcementSmall medical practices who think they don’t need to worry about HIPAA privacy and security compliance had better think again.

In December 2013, Adult & Pediatric Dermatology, a 12-physician group in Massachusetts, agreed to pay $150,000 to US Health & Human Services for alleged violations of the HIPAA Privacy, Security, and Breach Notification Rules arising out of a lost, unencrypted flash drive containing patient information. In addition to the cash settlement, HHS required the group to implement a corrective action plan, including developing a risk analysis and risk management plan to address and mitigate any security risks and vulnerabilities.

Prior to the Massachusetts case, HHS reached a $100,000 settlement with a 5-physician group in Phoenix, Arizona. HHS accused Phoenix Cardiac Surgery, P.C. of a “multi-year, continuing failure … to comply with the requirements of the Privacy and Security Rules.” The practice was posting clinical and surgical appointments for its patients on an Internet-based calendar that was publicly accessible. In addition, the practice had failed to implement even the most basic requirements of the Privacy and Security Rules – such as appointing a security official or adopting basic policies and procedures to appropriately safeguard patient information.

A review of the HHS website on which OCR posts examples of its enforcement actions reveals that most of the examples involve large hospitals, national drugstore chains, and large health insurance companies. The list of private practices facing enforcement actions appears to be growing, however. Surprisingly, many of the enforcement actions cited on the website deal with a private practice’s misunderstanding of the patient’s right to access his or her own medical records. For example:

  • A practice refused to honor an individual’s request for a complete copy of her minor son’s medical record.
  • A practice improperly billed a patient a $100.00 “records review fee” in connection with the patient’s request for a copy of his medical record.
  • A practice denied an individual access to his records on the basis that a portion of the individual’s record was created by a physician not associated with the practice.
  • A physician requested that patients sign an agreement entitled “Consent and Mutual Agreement to Maintain Privacy.” The agreement prohibited the patient from directly or indirectly publishing or airing commentary about the physician, his expertise, and/or treatment in exchange for the physician’s compliance with the Privacy Rule.
  • A private practice physician denied a patient access to her medical records because the patient had an outstanding balance for services the physician had provided.

Each of these cases arose out of a complaint filed with the OCR by an individual patient.   And each of these cases involves one of the most basic provisions of the HIPAA Privacy Rule.

The experiences of Adult & Pediatric Dermatology and Phoenix Cardiac Surgery should serve as clear warnings that HHS is not only investigating those complaints brought against large health insurers and drug store chains, but that complaints against small, private practices are going to be investigated and prosecuted as well. Physicians, dentists and other private providers would be well advised to make sure they have the necessary policies and procedures in place to comply with HIPAA and that staff members are being properly trained. If you have an “off the shelf” generic HIPAA manual, Wetherington Hamilton, P.A. has the resources to help you tailor the policies to your practice and to provide you with the necessary staff training. If you don’t have a HIPAA manual or you aren’t providing training to your staff you are risking big fines.

 

Matthew J. Lapointe, Esq.

https://whhlaw.com/wp-content/uploads/2016/01/hipaa-enforcement.jpg 800 1200 Ted Hamilton https://whhlaw.com/wp-content/uploads/2026/06/Wetherington-Hamilton-logo.png Ted Hamilton2016-01-25 11:34:322016-01-25 11:34:32HIPAA Enforcement – Small Physician Groups Are Not Immune

News Categories

  • Articles
  • Bankruptcy
  • Construction Law
  • Debt Collection
  • General
  • Litigation
Search Search

News Archive

  • 2025
  • 2021
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015
  • 2014
  • 2013
Wetherington Hamilton, P.A.

Wetherington Hamilton, P.A.

812 W. Dr. MLK Jr., Blvd., Suite 203, Tampa, FL 33603
Phone: (813) 225-1918 • Fax: (813) 225-2531 • Email

Wetherington Hamilton, P.A.

Wetherington Hamilton, P.A.

812 W. Dr. MLK Jr., Blvd., Suite 203, Tampa, FL 33603
Phone: (813) 225-1918 • Fax: (813) 225-2531 • Email

© 2026 Wetherington Hamilton, P.A., All Rights Reserved. | Website Hosting & Web Development by RAD TECH
  • Privacy Policy
  • Accessibility
Scroll to top Scroll to top Scroll to top